BlauxPRIVACY POLICY
Last updated: April 4, 2026
This Privacy Policy explains how Blaux.ai collects, uses, stores, and protects personal data when you use our website and design generation services.
1. Controller
Controller for the processing of personal data on this website:
Zhenyuan Liu
Blaux.ai
Gartenstraße 21
73525 Schwäbisch Gmünd
Germany
E-mail: support@blaux.ai
Phone: +49 15565733989
2. Data We Process
Depending on how you use Blaux.ai, we may process the following categories of data:
Account data: name, e-mail address, authentication identifiers, login provider information, and account status.
Subscription and billing data: current plan, usage records, checkout and subscription identifiers, payment status, billing period dates, and related transaction metadata. Card details are processed by Stripe and are not stored by us.
Input data: prompts, uploaded sketches, uploaded reference images, and optional render instructions submitted by you.
Output data: generated renders, generated 3D model files, temporary previews, and related technical generation metadata.
Technical data: IP address, browser and device information, timestamps, request logs, and basic diagnostic data necessary to operate and secure the service.
Browser storage data: limited session or local storage entries used to maintain login state, restore your current dashboard workspace, and improve continuity during a browsing session.
3. Purposes and Legal Bases
We process personal data to provide the website and the design generation service, including account registration, login, generation of renders and 3D models, usage tracking, subscription management, billing handling, support, fraud prevention, and service security.
The main legal bases under the GDPR are:
Article 6(1)(b) GDPR for processing necessary to provide our services and perform our contract with you.
Article 6(1)(c) GDPR where processing is necessary to comply with legal obligations, including accounting and tax retention duties.
Article 6(1)(f) GDPR for our legitimate interests in maintaining security, preventing abuse, improving reliability, and operating the website efficiently.
4. AI Inputs and Outputs
Prompts, sketches, reference images, generated renders, and generated model files are processed only to provide the requested generation service.
Temporary input and output files are generally stored on the server for operational reasons and are scheduled for automatic deletion after approximately one hour. Temporary runtime metadata related to these generations is also cleaned up on the same short-term basis.
You should upload only material that you have the legal right to use and that does not infringe third-party rights.
5. Processors and Service Providers
We use third-party service providers to operate parts of the service, including:
Supabase for authentication, database infrastructure, and related backend services.
fal.ai for image generation and 3D generation workflows.
Stripe for payment processing, subscription handling, and checkout.
Google, where applicable, if you choose Google sign-in through Supabase Auth.
These providers may process personal data on our behalf or as independent controllers depending on the service involved.
6. International Transfers
Some of our service providers may process data outside the European Economic Area. Where this happens, we rely on appropriate safeguards, such as adequacy decisions or standard contractual clauses, where required.
7. Retention
Account, subscription, and usage data are retained for as long as necessary to provide the service and meet legal obligations.
Temporary generation inputs and outputs are generally deleted automatically after about one hour.
Payment and accounting related records may be retained for longer periods where required by German tax, commercial, or accounting law.
8. Your Rights
Under the GDPR, you may have the right to request access, rectification, erasure, restriction of processing, data portability, and to object to certain processing. You also have the right to lodge a complaint with a competent supervisory authority.
To exercise your rights, please contact us at support@blaux.ai.
9. Security
We use reasonable technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. However, no online service can be guaranteed to be completely secure.
10. Children
Blaux.ai is not restricted to users aged 18 or older. However, if you are under the age at which you can validly accept online terms under applicable law, you should use the service only with the involvement of a parent or legal guardian.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The version published on this page is the current version.
12. Contact
If you have privacy questions or requests, please contact:
support@blaux.ai