RefinAI
PRIVACY & LGPD

Privacy Policy

Version 1.2 - updated on August 2, 2026.

This Policy explains how RefinAI processes personal data to operate the platform, process images, manage accounts, payments, security, communications, analytics, and product improvement.

1. Who we are

RefinAI is a platform by VirtuView Studio LTDA, CNPJ 57.149.918/0001-14, focused on AI-assisted architectural visualizations.

For personal data processed directly on the platform, we act as controller under Brazil's LGPD. When we process data on behalf of business customers in specific contexts, we may act as processor under the applicable contract.

2. Data we collect

We may collect name, email, avatar, authentication data, language and cookie preferences, technical access data, session identifiers, usage events, uploaded images, generated images, prompts, refinement settings, and usage history.

For payments, we may process information needed for billing, such as CPF/CNPJ, selected plan, amount, charge status, and Asaas provider identifiers. Full card data is processed by the payment provider, not by RefinAI.

3. Purposes and legal bases

We use data to create and protect your account, run refinements, edits, and enhancements, store results, calculate Refins, process payments, respond to requests, prevent abuse, comply with legal obligations, and improve product stability.

Legal bases may include performance of contract, compliance with legal or regulatory obligations, regular exercise of rights, legitimate interest with necessity and proportionality assessment, and consent when required, such as for marketing and optional cookies.

4. Images, prompts, and artificial intelligence

Images, prompts, and instructions you submit are used to deliver the requested service and may be sent to AI processing providers required to generate the result.

You should only upload files you own or are authorized to use, and avoid unnecessary sensitive personal data, children's data, and confidential information.

5. Analytics, logs, and monitoring

We use operational events and analytics tools to understand product usage, diagnose failures, measure performance, prevent abuse, and improve the experience. This may include Vercel Analytics, PostHog, and Sentry, as configured in the environment.

PostHog client-side respects your cookie/analytics choice and does not receive email or name through user identification. Sentry is used for errors and stability with filters to redact emails, CPF/CNPJ, tokens, cookies, signed URLs, and other sensitive data before sending.

6. Sharing with providers

We share data only with providers required for operation, such as hosting, database, storage, authentication, AI processing, payments, email, analytics, error monitoring, and security.

We do not sell personal data. We may share information when necessary to comply with legal obligations, competent authority orders, or to protect the platform and users' rights.

7. Retention

Account, profile, images, prompts, renders, and public links are kept while the account is active and may be deleted or anonymized after request. Final account deletion uses a 15-day operational window.

Payments, subscriptions, and transactions are kept in minimized form for 5 years for legal, tax, anti-fraud, chargeback, and legal defense obligations. Internal logs, events, and transactional email logs follow operational retention of up to 180 days; product analytics up to 12 months; Sentry up to 30 days; personal-data incidents for 5 years.

8. Security

We apply technical and administrative controls to reduce risks of unauthorized access, loss, alteration, or disclosure, including authentication, per-user data isolation, signed links, encryption of sensitive tax data, and audit records.

No system is completely immune to incidents. If a relevant incident occurs, we will take proportionate measures and make communications required by law.

9. Data subject rights

You may request confirmation of processing, access, correction, anonymization, blocking, deletion, portability when applicable, information about sharing, and consent revocation.

We may request additional data strictly necessary to confirm your identity before fulfilling a request. Some requests may be limited when there is a legal obligation, necessary retention, or regular exercise of rights.

10. International transfer

Some providers may process or store data outside Brazil, including hosting, analytics, monitoring, email, AI, storage, and payment providers.

When this happens, we will use providers and mechanisms compatible with the protection required by LGPD and keep an internal inventory of processors, country/region, purpose, data category, and applicable transfer mechanism.

11. Cookies and similar technologies

We use cookies and local storage necessary for login, security, language, session, cookie notice, and platform operation.

With your choice, we may also use optional categories, such as preferences, analytics, and marketing. Optional analytics respect the consent saved in the banner or equivalent controls.

12. California Privacy Notice

Without stating that RefinAI is necessarily subject to CCPA/CPRA, we take a conservative approach for California residents by disclosing collected categories, purposes, providers, retention, and privacy request channels.

We do not sell personal data and do not share personal data for cross-context behavioral advertising. You may request access, correction, deletion, information about sharing, and non-discrimination for exercising privacy rights.

13. Changes

This Policy may be updated to reflect changes in the product, providers, or legislation. The current version will remain available on this page.