Privacy Policy
1. Introduction
Abni provides software that helps creative and marketing teams generate and manage brand-compliant content.
This Privacy Policy explains how we handle personal data when you use Abni, interact with us, or access our services.
We take data protection seriously and aim to be clear about what we do and don’t do.
2. Who we are
Abni is the provider of the platform and is responsible for handling your personal data in accordance with applicable data protection laws, including UK GDPR.
3. The data we collect
We collect and process different types of data depending on how you use Abni.
Account and contact data
- name
- email address
- company
- role
Usage data
- activity within the platform
- interaction with features
- generation and usage patterns
Content data
- prompts you submit
- brand materials you upload
- generated outputs
This may include personal data if you choose to include it in your content.
Billing data
- billing contact details
- subscription information
- payment records (processed via Stripe)
Technical data
- IP address
- device/browser information
- system logs
4. How we use data
We use data to:
- provide and operate the platform
- generate and process outputs
- manage accounts and billing
- improve performance and reliability
- maintain security
- communicate with you
We do not sell your data or use it to train AI models, whether ours or third parties’.
5. AI processing
Abni uses third-party AI providers to generate and process content. The providers and services we use as AI sub-processors are:
- Google Cloud (Google LLC):
- Vertex AI — Gemini 3.x for prompt building and visual auditing; Imagen 4 Ultra for image generation. Data sent: user prompts, uploaded images, generated outputs.
- Document AI — PDF parsing for brand guideline uploads. Data sent: PDFs you upload.
- Retention: approximately 55 days for abuse-monitoring logs.
- Anthropic (Anthropic PBC):
- Claude API — used by non-critical agents. Data sent: prompts and outputs.
- Retention: 30 days standard; up to 2 years if content is flagged for abuse review.
- KIE.ai (US-based):
- Image generation. Data sent: prompts and reference images.
- Retention: KIE.ai’s privacy policy specifies retention only for account-level information (email retained while the account is active) and does not state a retention window for prompts or generated images. Zero Data Retention is not offered.
- FAL.ai (Features & Labels Inc., US-based):
- Image generation. Data sent: prompts and reference images.
- Retention: FAL.ai’s privacy policy states that personal data is retained “for as long as necessary to carry out the purposes for which we originally collected it” and does not specify a retention window for prompts or generated images. Their policy includes contractual clauses for transfers from the UK/EEA. Zero Data Retention is not offered.
Zero Data Retention (ZDR) is not configured with any of these providers. Inputs and outputs may be retained for the periods above for abuse monitoring and service-quality purposes. We do not train AI models — ours or any third party’s — on your data.
You remain responsible for reviewing outputs before use.
6. Legal basis
We process data based on:
- Contract — to provide the service.
- Legitimate interests — to operate and improve the platform.
- Legal obligations — for example, tax and accounting.
- Consent — where required.
7. Data sharing
We share data only where necessary to provide the service. This includes:
- Hosting providers — AWS
- AI providers — Anthropic, Google, KIE.ai, FAL.ai
- Billing providers — Stripe
- Platform integrations — Slack
We do not sell or trade personal data.
If you are a business client, our Data Processing Agreement sets out how we process personal data on your behalf.
8. International transfers
Several of the sub-processors listed in Section 5 are based outside the UK and EEA, primarily in the United States. Where personal data is transferred internationally, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs) — the European Commission’s 2021 modules, used for transfers from the EEA.
- UK International Data Transfer Agreement (IDTA), or the SCCs combined with the UK Addendum, for transfers from the UK.
- Where a sub-processor offers them, equivalent contractual clauses set out in their own data-processing terms.
We assess each sub-processor for adequacy of these safeguards before sending personal data, and we keep our sub-processor list under review. If you would like a copy of the safeguards in place for a specific provider, contact privacy@abni.ai.
9. Data retention and deletion
We retain data only as long as necessary.
- active data is retained while your account is active
- inactive data may be retained for a limited period
- billing records may be retained for legal reasons (e.g. tax)
- you can request deletion at any time
Deletion process
When you request deletion we use a staged process:
- Data is disabled.
- Short grace period.
- Permanent deletion.
What gets deleted
- user data
- uploaded content
- generated outputs
- usage records (where permitted)
To request deletion, email privacy@abni.ai.
10. Your rights
You have the right to:
- access your data
- correct your data
- request deletion
- restrict or object to processing
- request portability
To exercise these rights, contact us at privacy@abni.ai.
11. Security
We use appropriate technical and organisational measures to protect your data, including:
- encryption
- access controls
- secure infrastructure
For a full overview of our security posture, see our Security Overview.
12. Changes
We may update this policy from time to time.
Contact
Privacy queries: privacy@abni.ai
General queries: team@abni.ai
Security disclosures: security@abni.ai