Privacy Policy
Last updated: March 29, 2026
1. Introduction & Data Controller
At Smasher Studio ("we," "our," or "us"), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered content generation platform.
Data Controller
Moïse Dicko, Entrepreneur individuel (Micro-entreprise), trading as Smasher Studio.
Full entity details: Mentions Légales
Data Protection Contact: privacy@smasher.studio
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, username, and password when you register.
- Profile Information: Name, company name, and profile photo if you choose to provide them.
- Payment Information: Billing details processed securely through our payment provider (Stripe).
- Content: Images, product photos, and other files you upload for AI processing.
- Communications: Messages you send to our support team.
- Launch Waitlist: If you join the Collection Launch list, we record your email address, the launch price displayed to you (which is locked for you), the page where you joined, and the time of registration, so we can notify you at launch and honor your locked price.
2.2 Information Collected Automatically
- Usage Data: Features used, generation history, and interaction patterns.
- Device Information: Browser type, operating system, and device identifiers.
- Log Data: IP address, access times, and pages viewed.
- Cookies: Session cookies and preferences (see Section 6).
3. How We Use Your Information & Lawful Basis
We use your information to:
- Provide, maintain, and improve the Service.
- Process your AI generation requests and deliver results.
- Process payments and manage your subscription.
- Send service-related notifications and updates.
- Respond to your inquiries and provide customer support.
- Analyze usage patterns to improve our AI models and features.
- Detect, prevent, and address fraud and abuse.
- Comply with legal obligations.
Lawful Basis (GDPR Article 6):
- Contract (Art. 6(1)(b)): Processing necessary to provide the Service — account management, AI generation, payment processing, credit allocation.
- Legitimate Interest (Art. 6(1)(f)): Security monitoring, fraud prevention, service improvement, and analytics. We balance these interests against your rights.
- Consent (Art. 6(1)(a)): Marketing communications and optional product updates. You can withdraw consent at any time via your notification settings.
- Legal Obligation (Art. 6(1)(c)): Tax records, billing data, and regulatory compliance.
4. Your Data & AI Training
No Training on Your Inputs: Our AI API providers (third-party AI providers for text orchestration, image generation, and video generation — see our Sub-Processor List in Section 5 for current providers) do NOT use your inputs or outputs to train their models. All API calls are made under enterprise agreements with zero-retention data policies.
Encrypted Storage: Your generated assets are stored on Storj, a decentralized encrypted storage network. Files are encrypted, split into pieces, and distributed across independent nodes worldwide. No single entity can access your data.
Content Processing: Images and files you upload are processed by our AI systems solely to generate the content you request. Processing data is ephemeral and not retained after generation completes.
Generated Content: AI-generated images, videos, and tech packs are stored in your account library for your access. You can delete this content at any time.
4a. GDPR, EU AI Act Compliance & Right to Erasure
Smasher Studio is committed to compliance with both the General Data Protection Regulation (GDPR) and the EU AI Act (Regulation 2024/1689). We process your data lawfully and transparently, and we are evaluating content provenance measures as anticipated under the EU AI Act's transparency obligations for AI-generated content (Article 50).
If you are in the European Economic Area (EEA), UK, or other jurisdictions with similar data protection laws, you have the right to:
- Full Data Export: Request a complete export of all your data in a machine-readable format.
- Right to Erasure: Request permanent deletion of all your data, including generated assets, account information, and usage history.
- Processing Basis: We process your data based on contractual necessity (to provide the Service) and legitimate interest (to improve the Service). We never rely on consent alone for core processing.
- Right to Object to Automated Decision-Making: Under GDPR Article 22, you have the right not to be subject to decisions based solely on automated processing that significantly affect you. AI content generation is a tool you direct — it does not make decisions about you.
To request data erasure, email privacy@smasher.studio. We will process your request within one month of your verified request, as required by GDPR Article 17.
Right to Lodge a Complaint: If you believe your data protection rights have been violated, you have the right to lodge a complaint with the French data protection authority: Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.
4b. Content Provenance & AI Transparency
To support content authenticity and comply with emerging AI transparency regulations, we may in the future embed provenance metadata in AI-generated content. This could include C2PA (Coalition for Content Provenance and Authenticity) manifests and invisible digital watermarks to help identify the AI-generated nature and origin of the content. Currently, only Google Gemini-generated content includes automated SynthID watermarks; additional provenance measures are under evaluation.
This metadata does not contain your personal information. It records technical details about the generation process, such as the AI model used and a timestamp, to support content verification and regulatory compliance.
5. Sharing Your Information & Sub-Processors
We do not sell your personal data. We share information with the following sub-processors to operate the Service:
| Sub-Processor | Purpose | Data Sent | Location |
|---|---|---|---|
| Anthropic (Claude) | Text orchestration | Chat prompts, conversation history | USA |
| Google (Gemini) | Image generation | Text prompts, reference images | USA |
| Black Forest Labs (Flux) | Image generation (fallback) | Text prompts only | Germany / USA |
| Luma AI | Image generation (fallback) | Text prompts, reference images | USA |
| FAL.ai (Kling) | Video generation (fallback) | Text prompts, image URLs | USA |
| Seedance (via fal.ai) | Video generation | Text prompts, image URLs | USA |
| Runway | Video generation (fallback) | Text prompts, image URLs | USA |
| Storj | Encrypted asset storage | Generated images/videos (encrypted) | Distributed (encrypted) |
| Stripe | Payment processing | Email, billing details | USA (PCI DSS L1) |
| Heroku (Salesforce) | Application hosting | Account data, usage logs | USA |
| Meta | Marketing analytics (with consent) | Page views, conversion events | USA |
| Resend | Transactional & nurture email delivery | Email address, name | USA |
| PostHog | Product analytics (with consent) | Usage events, session data, anonymized IP | EU (Frankfurt) |
All sub-processors process data under contractual data processing agreements. For transfers outside the EEA, Standard Contractual Clauses (SCCs) apply where required. We regularly review our sub-processors and will update this list as providers change.
We may also share information in the following circumstances:
- Legal Requirements: When required by law or to protect our rights.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
6. Cookies and Tracking
We use cookies and similar technologies to:
- Keep you signed in to your account.
- Remember your preferences (like dark mode).
- Understand how you use the Service.
- Improve and personalize your experience.
- Attribute signups to marketing campaigns: when you arrive via a campaign link, a first-party cookie (__smasher_utm) stores the campaign parameters from that link for 30 days. It is never shared with third parties.
You can control cookies through your browser settings. Note that disabling cookies may affect the functionality of the Service. For a complete list of cookies used, see our Cookie Policy.
7. Data Security
We implement industry-standard security measures to protect your data:
- Encryption of data in transit (HTTPS/TLS).
- Encryption of data at rest.
- Secure password hashing.
- Regular security audits and monitoring.
- Access controls and authentication requirements.
While we strive to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
8. Your Rights
Depending on your location, you may have the right to:
- Access: Request a copy of your personal data.
- Correction: Update inaccurate or incomplete data.
- Deletion: Request deletion of your data ("right to be forgotten").
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to certain processing of your data.
- Restriction: Request limited processing of your data.
To exercise these rights, contact us at privacy@smasher.studio
9. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Specific retention periods:
- Account data (email, profile, preferences): duration of your account plus 3 years after deletion for legal compliance.
- Generated content (images, videos, tech packs): duration of your account. Permanently removed within 30 days of account deletion.
- Payment & billing records: retained for 10 years as required by French tax law (Code général des impôts).
- Server logs (IP addresses, access logs): 90 days.
- Launch waitlist records (email, locked price, registration page): retained until launch, then through the 30-day price-honor window, plus 12 months as proof of the commitment.
- AI processing data: ephemeral — not retained after generation completes.
Data Export Grace Period: When you request account deletion, you will have a 30-day grace period to export your data in a machine-readable format (JSON) before permanent deletion begins. You can initiate a data export from your account settings at any time.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data:
- Storj (decentralized storage, US-based): Data is encrypted, split, and distributed across independent nodes. Protected by Standard Contractual Clauses (SCCs) under GDPR Article 46(2)(c).
- AI providers (Anthropic, Black Forest Labs, Google, FAL — US-based): API calls only; no data retention by providers. Protected by SCCs and enterprise zero-retention agreements.
- Stripe (payment processing, US-based): PCI DSS Level 1 certified. Adequacy decision and SCCs apply.
- Heroku/Salesforce (hosting, US-based): EU-US Data Privacy Framework certified.
10a. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights, we will notify the French supervisory authority (CNIL) within 72 hours of becoming aware, as required by GDPR Article 33. Where the breach is likely to result in a high risk to you, we will notify you directly without undue delay (GDPR Article 34).
11. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the Service. Your continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
For privacy-related questions or to exercise your rights, contact us at: