Voasis legal

Privacy Policy

Last updated: July 19, 2026

1. Who we are

Voasis (voasis.io and app.voasis.io, the "Service") is an AI UGC content platform operated by MYTALEO LLC, a Wyoming limited liability company with its principal address at 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, USA. MYTALEO LLC is the data controller for the personal data described in this policy.

For any privacy question or request, contact us at hello@voasis.io.

2. Data we collect

Account data: your email address, display name and workspace name, and, if you sign in with Google, the basic profile information Google shares with us (email and name). We use passwordless authentication, so we never store a password for you.

Billing data: your subscription plan, billing history and Stripe customer reference. Payments are processed by Stripe; we never see or store your full card number.

Content you provide: prompts, creative briefs, scripts, product photos, logos, brand website URLs you ask us to research, and other assets you upload to create content.

Generated content and derived data: the videos and images the Service generates for you, brand research profiles built from the websites you submit, and the metadata around each generation (model used, credits spent, timestamps).

Team data: workspace membership, invitations you send (the invitee's email address), and which workspace you are acting in.

Usage and technical data: log data such as IP address, browser type, pages visited and API activity, collected by us and our hosting providers for security, debugging and capacity planning.

Waitlist data: if you join the waitlist, your email address, signup timestamp and signup source.

3. How we use your data

To provide the Service: authenticate you, run generations you request, store your content, operate workspaces and teams, and show your history.

To process payments and manage subscriptions, credits, upgrades, downgrades and cancellations through Stripe.

To communicate with you: transactional emails (magic links, receipts and billing notices, team invitations, subscription changes) and product updates about Voasis. You can opt out of non-essential product emails at any time.

To keep the Service secure and reliable: abuse prevention, fraud detection, debugging and monitoring.

To improve the Service: we analyze aggregated, de-identified usage patterns. We do not use your uploaded content or generated output to train our own AI models.

To comply with legal obligations, including tax and accounting rules.

4. Legal bases

Where GDPR or similar laws apply, we process your data on these bases: performance of our contract with you (providing the Service you signed up for), our legitimate interests (securing and improving the Service, communicating with our customers), your consent (marketing emails to waitlist members, which you can withdraw at any time), and compliance with legal obligations (billing records).

5. AI processing

When you generate content, the relevant inputs (your prompt, brand profile data, and any product photos or logos you attached) are transmitted to AI model providers to perform the generation. We access models from providers such as Google and OpenAI through OpenRouter, and language models from providers such as Anthropic for copywriting and analysis steps.

These providers process your inputs to return the generated result. We use API configurations that do not permit our customers' content to be used for the providers' model training, to the extent the providers offer such controls.

When you use the brand research feature, the public website URL you submit is fetched and its public content is analyzed to build your brand profile.

6. Who we share data with

We share personal data only with the service providers that run Voasis, and only to the extent needed: Supabase (database and authentication), Vercel (hosting and logs), Stripe (payments), Cloudflare (storage and delivery of generated media and uploaded assets), OpenRouter and the underlying AI model providers (generation, as described above), Resend (transactional email), and Google (if you choose Google sign-in).

We may also disclose data if required by law, to protect our rights or users' safety, or as part of a merger, acquisition or asset sale (in which case this policy continues to apply until amended).

We do not sell your personal data, and we do not share it with third parties for their own advertising.

7. International transfers

Our primary database is hosted in the European Union (Paris region). Some of our processors, including Stripe, Vercel, Cloudflare and the AI model providers, process data in the United States and other countries. Where personal data of EU or UK residents is transferred internationally, we rely on our processors' compliance mechanisms, such as Standard Contractual Clauses or Data Privacy Framework certification.

8. Retention

Account and content data are kept while your account is active. If you delete your account, or ask us to, we delete your personal data, uploaded assets and generated content within 30 days, except data we must keep longer for legal reasons.

Billing and transaction records are retained as required by tax and accounting law, generally up to 7 years.

Generated media you delete in the app is removed from our storage on deletion (subject to short-lived backups).

Waitlist emails are kept until you ask to be removed or until the waitlist is retired.

9. Security

We protect your data with encryption in transit (TLS), encryption at rest with our storage providers, row-level access controls in our database, scoped API keys, and the principle of least access for our own tooling. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and the relevant authorities as required by law.

10. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a copy in a portable format, restrict or object to certain processing, and withdraw consent where processing is based on consent.

If you are in the EU, UK or a similar jurisdiction, you also have the right to lodge a complaint with your local data-protection authority. If you are a California resident, you have equivalent rights under the CCPA/CPRA, including the right to know, delete and correct; we do not sell or "share" personal information as defined by the CPRA.

To exercise any right, email hello@voasis.io from the address associated with your account and we will respond within the legally required timeframe (at most 30 days in most cases).

11. Children

The Service is not directed at children and may not be used by anyone under 18. We do not knowingly collect data from minors; if you believe a minor has provided us data, contact us and we will delete it.

12. Cookies

We use only technically necessary cookies and browser storage: authentication session cookies (scoped to voasis.io), your active-workspace selection, and interface preferences such as theme and sidebar state. We do not use advertising or cross-site tracking cookies, so no cookie consent banner is required.

13. Changes

We may update this policy as the Service evolves. The date above always reflects the latest version. For material changes we will give notice on this page, in the app, or by email before they take effect.

14. Contact

MYTALEO LLC, 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, USA. Email: hello@voasis.io.