Privacy Policy

Last updated: June 2026

1. Who We Are

James Khalil is the data controller for CleanFit AI. This privacy policy explains how we collect, use, and protect your personal data when you use our service.

2. Data We Collect

We collect the following categories of personal data:

  • Identity data: name, email address
  • Account data: login credentials, account preferences
  • Usage data: images you upload for processing, project metadata, feature usage
  • Technical data: IP address, browser type, device identifiers
  • Communication data: support messages and correspondence

3. Purposes of Processing

We process your data for the following purposes:

  • To create and manage your account
  • To provide the image enhancement service
  • For security, fraud prevention, and service integrity
  • To improve and develop the product
  • For customer support
  • For marketing communications (only with your consent)

4. Legal Basis

We process your data based on: contract performance (providing the service), legitimate interests (security and improvement), consent (marketing), and legal obligations where applicable.

5. Data Sharing

We share your data with the following categories of recipients:

  • Service providers: hosting, analytics, and support tooling
  • Payment processor (Stripe): for subscription management, payments, tax compliance, and invoicing. For eligible transactions Stripe acts as Merchant of Record.
  • Professional advisers: legal and accounting professionals when necessary
  • Authorities: where required by law or to protect our rights

6. Data Retention

We retain your personal data for as long as necessary to provide the service and fulfill the purposes described in this policy. When data is no longer needed, we delete or anonymise it. Account data is retained while your account is active and for a reasonable period afterward for legal and operational purposes.

7. Your Rights

Under applicable data protection law, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Request erasure of your data
  • Restrict processing of your data
  • Data portability
  • Object to processing based on legitimate interests
  • Withdraw consent at any time
  • Lodge a complaint with a supervisory authority

We will respond to requests within one month. To exercise your rights, contact us through the support channels on our website.

8. International Transfers

Your data may be transferred to and processed in countries outside your own. We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses or adequacy decisions where required.

9. Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit and at rest, access controls, and regular security reviews.

10. Cookies

We use essential cookies for authentication and service functionality. We may use analytics cookies to understand how users interact with our service. You can manage cookie preferences through your browser settings.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes by posting the updated policy on this page with a revised date.

12. Contact

For privacy-related questions or to exercise your rights, please contact us through the support channels listed on our website.