Privacy Policy
Last Updated: September 24, 2026
This Privacy Policy explains what personal data DayWaveAi ("we," "our," or "us") collects when you use daywaveai.com and our related AI generation tools (the "Service"), how we use and share it, and the choices and rights available to you. DayWaveAi is operated from the European Union and is the controller of your personal data under the EU General Data Protection Regulation (GDPR). You can reach us about anything in this Policy at daywaveai@gmail.com.
1. Scope of This Policy
This Policy applies to personal data we collect through the Service, including our website, generation tools, account and billing systems, and communications with you. It does not apply to third-party websites, applications, or services that we do not control, even if you access them through a link on the Service.
2. Information We Collect
Information you provide to us:
- Account information: When you sign up, we (through our authentication provider, Clerk) collect your email address, authentication identifiers, and, if you use a social login, basic profile information from that provider.
- Payment information: When you buy credits, our payment processors collect your billing details. Card payments are processed by Stripe; cryptocurrency payments are processed by a third-party crypto payment processor. We do not store your full card number or private wallet keys on our own servers.
- User Content: The text prompts, images, videos, audio, and other material you upload, and the images, videos, and audio our tools generate for you ("User Content").
- Communications: Information you provide when you contact support, respond to a survey, submit a Promotion, or otherwise correspond with us, including your email address and the content of your message.
- Referral information: If you participate in our referral program, we collect the referral code used and information about the accounts referred through it.
- Agreement records: The date and version of the Terms of Service you agreed to before using the creation tools.
Information we collect automatically:
- Usage data: The tools and features you use, the number and type of generations you request, pages visited, referring pages, and timestamps of activity.
- Device and log data: IP address, browser type and version, operating system, device identifiers, and standard server log data.
- Cookies and similar technologies: As described in Section 8 below.
- Moderation records: When our content moderation blocks a request, we log the account, the time, the tool used, the text of the prompt, which part of the request was flagged (the prompt or an image), and the category flagged. Blocked images themselves are not kept.
Information from third parties: We may receive limited information from our service providers (for example, payment confirmations from Stripe, or payment status and fraud signals from our crypto payment processor) that we use to operate billing, prevent fraud, and provide support.
3. How We Use Your Information
We use the information described above to:
- Provide, operate, and maintain the Service, including generating output from your Input and delivering it back to you.
- Create and manage your account, and authenticate you when you sign in.
- Process payments and refunds, manage your credit balance, and prevent fraudulent or unauthorized transactions.
- Operate the referral program and Promotions marketplace, including verifying eligibility and reviewing submissions.
- Communicate with you about your account, transactions, security alerts, and support requests, and, where you have not opted out, about product updates and offers.
- Monitor, investigate, and enforce our Terms of Service and Acceptable Use Policy, including detecting abuse, fraud, and prohibited content.
- Analyze aggregated or de-identified usage trends to improve the reliability, performance, and design of the Service.
- Comply with our legal obligations, respond to lawful requests from public authorities, and establish, exercise, or defend legal claims.
We do not use your private prompts or generated Content to train our own foundation models. Where a third-party AI model provider we integrate with may use API inputs to improve its own models, we select providers and, where available, configuration options intended to keep such data out of model training; see Section 5.
4. Legal Bases for Processing
Under the GDPR, we rely on the following legal bases to process your personal data:
- Performance of a contract (Art. 6(1)(b)): to create your account, provide the Service, run the generations you request, and process payments and refunds.
- Legitimate interests (Art. 6(1)(f)): to secure the Service, prevent fraud and abuse, screen prompts and images with automated content moderation, keep records of blocked requests, and enforce our Terms, balanced against your rights and interests. You can object to this processing (see Section 9).
- Consent (Art. 6(1)(a)): for marketing emails (except the occasional product update we may send existing customers about our own similar services, which relies on our legitimate interest and which you can opt out of in any email) and any other processing where we ask for your consent, which you may withdraw at any time without affecting processing that happened before.
- Legal obligation (Art. 6(1)(c)): to comply with tax and accounting rules, to answer lawful requests from authorities, and to report suspected child sexual abuse material.
Automated content moderation decides only whether a single request may go ahead; it does not by itself close accounts. A decision to suspend or ban an account is made or reviewed by a person, and you can contest it by contacting us.
5. How We Share Your Information
We do not sell your personal data, and we do not share your User Content with other users without your action (for example, choosing to submit a public Promotion or gallery entry). We share information with the following categories of service providers, each of which is only permitted to use your data to provide services to us:
- Clerk: user authentication, session management, account security, and the record of your agreement to our Terms.
- Stripe: processing of card payments and refunds.
- Crypto payment processor (NOWPayments): processing of cryptocurrency payments.
- Supabase: database hosting of account records, credit balances, and generation history.
- Cloudflare: storage and delivery of the images you upload and the Content generated for you.
- WaveSpeed AI and other AI model providers: your Input (prompts, images, audio) is transmitted to these providers solely to generate the output you request; it is processed as necessary to fulfill your request and is subject to that provider's own data handling terms.
- WaveSpeed AI (content moderation): the text of your prompts and the images you submit are screened by WaveSpeed's automated content moderation models before generation, so that we can block content prohibited by our Acceptable Use Policy. No account identifiers are sent with this check.
- Hosting and infrastructure providers: to host, serve, and secure the website and its underlying data.
- Email and communications providers: to send transactional messages and, where you have opted in, product updates.
We may also disclose information: (a) to comply with a subpoena, court order, or other legal process, or a lawful request from a public authority; (b) to investigate or respond to violations of our Terms, fraud, security incidents, or claims of illegal content, including reporting suspected child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC) or other relevant authorities where required by law; (c) to protect the rights, property, or safety of DayWaveAi, our users, or the public; and (d) in connection with a merger, acquisition, financing, or sale of all or part of our business, in which case personal data would remain subject to the protections described in this Policy or a policy at least as protective.
6. AI Processing of Your Content
When you submit a prompt, image, or other Input for generation, that Input (and the resulting output) is transmitted to the third-party AI model provider we use to run that particular tool in order to produce your result. We select providers that offer API-level processing rather than consumer-facing products, and we do not knowingly permit those providers to use your Input to train models available to other customers; however, each provider's own retention and processing practices govern how long they hold data needed to service the request (for example, brief retention for abuse monitoring). Please avoid uploading sensitive personal data belonging to other people (such as another person's photo used without their consent) that you are not authorized to share.
Before any Input is generated from, it is screened by automated content moderation (see Section 5). If an image you submit is not already stored on our servers, we store a temporary copy only for as long as the check takes and delete it immediately afterward. The result of the check is used only to allow or block your request and, if it is blocked, to enforce our Terms of Service.
7. Data Retention
We retain account information for as long as your account is active and for a reasonable period afterward to comply with legal, accounting, and fraud-prevention obligations. We retain generated Content and transaction records for as long as reasonably necessary to provide the Service (for example, so you can access your generation history), to resolve disputes, and to enforce our agreements. You may request deletion of your account and associated Content at any time as described in Section 9; some information may be retained in backups or anonymized form for a limited period after deletion. Payment and invoice records are kept for as long as tax and accounting law requires. Records of blocked requests are kept while your account exists and for up to two years after it is closed, so repeated attempts can be detected, unless we need them longer for a legal claim or a report to the authorities.
8. Cookies and Similar Technologies
We only use cookies, local storage, and similar technologies that are strictly necessary to provide the Service, so we do not show a cookie consent banner. They are used to:
- Keep you signed in and secure your session (set by Clerk, our authentication provider).
- Remember a referral for 30 days when you arrive through a friend's referral link, so the referral can be credited.
- Remember simple preferences in your browser, such as settings you chose in a tool.
We do not use analytics, advertising, or tracking cookies. If we ever add them, we will ask for your consent first. You can delete cookies through your browser settings, but blocking strictly necessary cookies will stop parts of the Service, such as signing in, from working.
9. Your Privacy Rights
Under the GDPR you have the right to: access the personal data we hold about you and get a copy of it; have inaccurate data corrected; have your data deleted; restrict or object to certain processing, including processing based on our legitimate interests; receive the data you gave us in a portable format; and withdraw your consent at any time where we rely on it. You can also delete your account at any time.
To exercise any of these rights, email us at daywaveai@gmail.com from the address associated with your account. We will respond within one month, which may be extended by two further months for complex requests (we will tell you if so). Exercising your rights is free.
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU/EEA country where you live or work, or where you believe your data was misused. We would appreciate the chance to deal with your concern first, so please contact us. If you live outside the EU (for example, in California), you may have similar rights under local law, and you can use the same email address to exercise them; we do not sell or share personal information for advertising.
10. Data Security
We use technical and organizational measures designed to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including encryption of data in transit, access controls, and reliance on reputable infrastructure providers for authentication, payments, and storage. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
11. International Data Transfers
Some of our service providers (for example Clerk, Stripe, and our AI model and moderation providers) process data outside the European Economic Area, including in the United States. When personal data is transferred outside the EEA, we make sure it is protected as the GDPR requires: either the recipient is covered by an adequacy decision of the European Commission (such as the EU-U.S. Data Privacy Framework, for certified companies), or the transfer is covered by the European Commission's Standard Contractual Clauses. You can ask us for more information about these safeguards at daywaveai@gmail.com.
12. Children's Privacy
You must be an adult (the age of majority where you live) to create an account, as required by our Terms of Service. The Service is not directed to children, and we do not knowingly collect personal data from anyone under that age. If we learn that we have, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at daywaveai@gmail.com.
13. Marketing Communications
We may send you transactional and account-related emails (such as receipts, security alerts, and service notices) regardless of your marketing preferences, as these are necessary to operate the Service. Where we send optional marketing or product-update emails, every such message includes an unsubscribe link, and you may opt out at any time without affecting your ability to use the Service.
14. Third-Party Links
The Service may contain links to third-party websites, including Promotion destinations submitted by other users. We are not responsible for the privacy practices or content of any third-party site, and we encourage you to review the privacy policy of any site you visit.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will post the updated Policy on this page and revise the "Last Updated" date above. If we make material changes, we will tell you in advance by email or with a notice on the Service.
16. Google User Data
- What we access: If you sign in using Google, we receive basic profile information from Google through OpenID Connect (scopes:
openid,email,profile) — your name, email address, and profile picture. - How we use it: Solely to create and authenticate your DayWaveAI account and to provide the user-facing features of the Service, such as displaying your name and letting you sign back in.
- Who we share it with: We do not sell or share this information with third parties, except with Clerk, our authentication provider, as necessary to operate sign-in (see Section 5).
- How we protect it: As described in Section 10 (Data Security) — encrypted in transit, access-controlled, and stored with our authentication provider rather than on our own servers.
- Retention and deletion: Retained for as long as your account is active. If you delete your account or revoke access, we delete the Google profile data associated with it, other than what we must keep for legal or fraud-prevention purposes as described in Section 7.
- What we don't do with it: We do not use Google user data for advertising, do not sell it, do not use it for credit assessment or lending purposes, and do not use it to train generalized (non-personalized) AI or machine learning models.
Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. You can review or revoke DayWaveAI's access to your Google account at any time at myaccount.google.com/permissions.
17. Contact Us
DayWaveAi is the controller of your personal data and is operated from the European Union. If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at daywaveai@gmail.com.