Legal

Privacy Policy

Last Updated: January 4, 2026

Foca AI ("we," "us," or "our") provides professional-grade AI image processing for e-commerce. We are committed to protecting your commercial assets through industry-standard security and transparent data practices.

1. Information We Collect

  • User Content: We collect images you upload and the results generated by our AI. You retain full ownership.
  • Account Data: Information provided via Google, Apple, or email sign-in.
  • Usage Data: Technical logs and performance metrics to ensure our algorithms function correctly.
  • Cookies & Tracking: We use cookies and similar tracking technologies to track the activity on our Service and hold certain information (e.g., for analytics or session management). You can instruct your browser to refuse all cookies.

2. AI Privacy & Ethics

  • No Training: We do not use your uploaded or processed images to train our proprietary models or any public AI models.
  • Enterprise Processing: We utilize professional, paid AI interfaces. Under these terms, your data is processed privately and is not harvested for third-party AI development.

3. Data Retention & Deletion

  • Conditional Retention: To balance security and convenience, your creations are stored indefinitely as long as you maintain an active subscription or hold a remaining purchased credit balance (excluding bonus/trial credits). For accounts with no subscription and no purchased credits, a courtesy reminder is sent to your email. If no login occurs, all visual assets will be permanently deleted.
  • Manual Deletion: You may delete images from your dashboard at any time. This removes the asset from your account view immediately.
  • Administrative Window: We may retain deleted assets in a secure state for a brief period solely for diagnostic and quality-assurance purposes before they are permanently and irreversibly purged from our infrastructure.

4. Data Security & Access Control

  • Encryption: We employ industry-standard encryption protocols. All data is protected by secure transport layers (SSL/TLS) during transit and encrypted using enterprise-grade security at rest.
  • Edge Protection: Our infrastructure is protected by Cloudflare, providing advanced web security, DDoS protection, and secure global content delivery.
  • Access Control: Processing is primarily automated. Authorized technical personnel may access data only when strictly necessary for troubleshooting, debugging, or system optimization.

5. International Data Transfer

Your information, including visual assets, will be primarily stored and processed on secure servers located in Singapore and the United States via our cloud service providers (e.g., Cloudflare, AWS).

To provide technical support and system maintenance, you acknowledge that our global operation and support teams (which operate internationally) may have limited access to your data solely for troubleshooting, debugging, or quality assurance purposes.

We implement Standard Contractual Clauses (SCCs) and industry-standard encryption to ensure that your data receives the same level of protection regardless of where it is processed. By using the service, you consent to this cross-border transfer and processing.

6. Third-Party Services

We partner with leading providers to ensure a secure and reliable service:

  • Infrastructure: Hosted and secured by Cloudflare and other leading cloud providers.
  • AI Processing: We utilize enterprise-grade AI APIs (such as Google Cloud AI) for image optimization. These providers are bound by strict data privacy agreements and do not use your data to train their public models.
  • Payments: All transactions are handled securely via Apple In-App Purchase or Stripe. We do not store your credit card or financial account details on our servers.
  • Operations: Analytics tools (such as Firebase or PostHog) to monitor system stability.

We do not sell, rent, or trade your personal information or visual assets to third parties for marketing purposes.

7. Your Rights

You have the right to access, export, or delete your data at any time through your account settings. For users in the EU (GDPR) or California (CCPA), we honor all statutory rights regarding your personal information.

8. Contact Us

For privacy-related inquiries: