Who is responsible for your data?
Unspecified is operated by NEW GAME, SAS, registered under 105 490 080 RCS Paris, with its registered office at 66 avenue des Champs-Élysées, 75008 Paris, France. NEW GAME is the controller for account administration, operating and securing the service, and handling enquiries described in this policy.
Our privacy contact is hello@unspecified.ai. You can also write to the registered office, marking your correspondence “Personal data — Unspecified”. The parent company’s role as president does not automatically give it access to your account or creations.
This policy covers the website and the image and video studio, including image, video and audio references. It also applies to people whose personal data is included in submitted content, subject to the respective roles explained below.
The information we process
Information needed to authenticate you and carry out a generation is required for those features. Google sign-in and adding references are optional. Without the information required for a feature, we cannot provide that feature.
Do not submit passwords, identity documents, payment card details, health records or other sensitive personal information that is unnecessary for your creative request. A face, voice, name or identifiable situation can be personal data even when it appears in a creative reference.
- Account and sign-in
- Email address, account identifier, authentication information, profile information supplied by the sign-in provider, account creation and sign-in dates, language, access rights and account settings. Password authentication is handled by Supabase Auth.
- Creative content
- Prompts, instructions, image references, video clips and audio excerpts you submit; generated images and videos, any accompanying audio, thumbnails, favourites and generation settings.
- File information
- Names of uploaded reference files, format, size, dimensions and duration where applicable, and identifiers linking references to your account and requests.
- Service operation
- Request identifiers, selected and delivered models, dates, statuses and error codes, quantities, quotas, credit balances and generation costs. The providers operating the service may also process connection and technical logs, including IP addresses, as part of request handling and security.
- Correspondence
- Contact details and information you send when requesting support, reporting content or exercising your rights.
Why we use it and on what basis
The contractual basis applies to the person who is party to the contract. Where content concerns someone else, the applicable legal basis must be established for that processing; your contract with us does not by itself authorise processing that person’s data. The respective roles for professional use are explained below.
The operations dashboard uses account and generation records, including failed or removed requests, to report consumption and costs. Its current interface does not display prompts or media links. These operational statistics are distinct from advertising or tracking your browsing across websites.
Automatic quota, technical or provider checks may prevent a generation. You can contact us to report or contest a restriction. Creating media does not involve using a generated result to make a legal or similarly significant decision about you.
- Provide the service
- Create and administer access, authenticate users, generate and display content, maintain the personal library, reuse settings and answer service enquiries. Legal basis: performing the contract with you or taking steps at your request before entering into it (GDPR Article 6(1)(b)).
- Protect and operate the service
- Apply quotas, prevent fraud and misuse, diagnose errors, reconcile generation costs and understand service consumption. Legal basis: our legitimate interests in the security, reliability and financial management of the service (Article 6(1)(f)), taking account of your rights and reasonable expectations.
- Meet legal requirements
- Respond to valid rights requests and binding requests from competent authorities, and retain legally required records where applicable. Legal basis: compliance with a legal obligation (Article 6(1)(c)).
- Optional activities
- Portrait permissions are described below. Any other feature requiring consent must disclose its purpose and withdrawal method before it begins. Accepting the terms of use is not blanket consent to advertising, model training or every use of your personal data.
Who receives information?
Access is limited to authorised people who need it to provide support, operate, secure or administer the service, and to the providers involved in those functions. Information may also be disclosed to competent authorities when legally required, or to professional advisers where necessary to establish or defend legal claims.
An account identifier may accompany image requests for request management and abuse prevention. Video requests also carry technical identifiers. Reference media may be made available to generation providers through temporary private download links for the time needed to process asynchronous requests.
We remain responsible for our obligations when engaging processors. Naming a model does not identify every company in its processing chain. Provider terms do not remove your GDPR rights or transfer our data protection responsibilities to you.
This policy does not grant us a separate authorisation to train models using your personal content. Retention and any permitted reuse by an AI provider depend on the terms applicable to that service. A model’s name alone does not guarantee that no data is retained or reused. Contact us for the conditions applicable to a model before submitting information subject to specific confidentiality or location requirements.
- Supabase
- Authentication, database and private storage of account records, references and creations.
- Vercel
- Website and application hosting, request handling, and AI Gateway, which connects generation requests to the selected model and its inference providers.
- Higgsfield
- When the dedicated Seedance 2.5 connection is enabled, receives the prompt, selected reference media and generation settings to produce the requested video. Credentials remain on our server; reference media are supplied through temporary private links.
- AI models and inference providers
- Receive the prompts, selected references and technical generation information needed for the requested model. The catalogue includes models published by Google, OpenAI, xAI, Meta, ByteDance, Black Forest Labs and Recraft for images, and Google, ByteDance, Kling AI, Alibaba, MiniMax and xAI for video. Availability and the actual inference provider depend on the selected model and the Gateway’s routing.
- Google, if used for sign-in
- Provides the sign-in component and authentication identity described in the next section.
- Resend
- Sends service email notifications to our support team. Report notifications contain a case identifier and a link to the protected administration area; the report description and attachments are not included in the email.
- Namecheap
- Forwards messages addressed to hello@unspecified.ai to our support mailbox, including the sender’s address and the content of their email.
Google sign-in
When Google sign-in is enabled, its component loads on the sign-in page. Google therefore receives the technical information needed to deliver that component before you click the sign-in button. Google manages its own infrastructure and account settings under its privacy policy.
If you choose to continue with Google, an identity token and basic profile information, such as your email address, name and profile picture, are shared with Unspecified through Supabase to authenticate you. We do not request access to your Gmail messages, Google contacts or Google Drive files. Email and password sign-in remains available to existing accounts.
Where information is processed
The documented Supabase project location is Paris, France. This database location does not mean that every website, support, authentication or AI processing operation takes place in France or in the European Economic Area (EEA).
Vercel, Google and the providers involved in a selected AI model may process information outside the EEA. The protection of a transfer depends on its destination and recipient: an applicable adequacy decision, or appropriate safeguards such as the European Commission’s standard contractual clauses with any necessary supplementary measures. There is no single destination or safeguard common to every model.
Contact hello@unspecified.ai to request information about the destinations and safeguards applicable to your processing, or a copy of the relevant safeguards, subject to the protection of confidential information. Specific restrictions on location or onward transfers require an agreed framework before the relevant data is submitted.
Retention and removal
Account information is used for as long as the account remains open and is needed to provide access. Prompts, references and creations are kept to provide your history and allow reuse. The current studio does not apply a general automatic expiry period to stored creations or completed video-reference uploads.
Retention depends on the purpose: providing your account and library; handling a pending request or dispute; preventing misuse and reconciling usage; or satisfying a specific legal retention obligation. Restricted retention for a legal claim must be limited to the relevant limitation period and any proceedings. Records subject to a statutory retention period are limited to the information required by that obligation. This does not justify keeping all creative content indefinitely.
Temporary signed links currently last about one minute for images and generated videos, and two minutes for video-reference previews. Links supplied to video generation providers may remain valid for up to 24 hours. These are access-link lifetimes, not retention periods for the files themselves.
Deleting data from active storage does not itself guarantee simultaneous erasure from all provider logs or backups. Any remaining copy must be handled according to its purpose, applicable retention requirements and your rights; no universal backup-erasure period is promised here.
- Deleting images
- Deleting a whole image creation, or its last remaining image, removes it from the library and clears its prompt and attached reference records. The action also requests removal of the associated files. Technical and consumption records remain so that deletion does not reset quotas. A storage removal error can require further cleanup.
- Deleting videos
- The current action hides the video from your history and attempts to remove its output files. It does not, by itself, erase all prompts, settings, processing records or uploaded references associated with the request. Request further erasure through our privacy contact.
- Removing a reference from the editor
- Removes it from the request being prepared. It does not necessarily delete a previously uploaded or reused source from private storage. Contact us to request deletion of retained source files.
- Closing an account and further erasure
- Request account closure or erasure by email. We assess which data can be erased, which providers must be notified, and any narrowly applicable legal exceptions. Expiring a download link is not the same as erasing the underlying file.
Access and security
Your personal library requires authentication. The application checks ownership of creations and references, uses private storage and issues temporary access links. Administrative access is restricted to authorised accounts. These safeguards reduce the risk of unauthorised access; they do not make an online service immune to incidents.
Keep your sign-in information confidential. Anyone who receives a valid signed download link may be able to use it until it expires. Copies you download, publish or send to others are outside the private library and cannot be withdrawn from third parties merely by deleting a studio item.
Report suspected unauthorised access or a personal-data incident to hello@unspecified.ai, with the information needed to investigate and without including passwords.
Other people’s data and professional use
If your prompt or reference identifies someone else, establish the appropriate legal basis, provide any required information and obtain the rights or permissions needed for the intended use. Avoid submitting personal data that is not necessary for the task. These user obligations do not release us from our own data protection duties.
Where a professional customer determines the purposes and means of processing personal data entrusted to the studio, the customer may be the controller and NEW GAME its processor for that processing. Our separate account, security and administration activities may remain controller activities. The actual roles depend on the processing concerned.
This privacy policy is not an Article 28 data processing agreement. Before entrusting client, employee or other third-party personal data to us under such an arrangement, contact hello@unspecified.ai to establish the required agreement, instructions, authorised subprocessors, transfer arrangements and deletion terms.
Your rights and how to use them
Write to hello@unspecified.ai, preferably from the address associated with your account, stating the right you wish to exercise and the information needed to locate the data. If we have reasonable doubts about your identity, we may request proportionate additional information; an identity document is not systematically required.
We respond without undue delay and, in principle, within one month of receiving the request. This period may be extended by two further months where necessary because of the complexity or number of requests; we will inform you within the first month and explain why. Rights are exercised free of charge, subject to the GDPR’s narrowly defined exceptions for manifestly unfounded or excessive requests. Any refusal must be explained, together with the available remedies.
You may complain to the CNIL without contacting us first: Commission nationale de l’informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
- Ask for access to your personal data and a copy, and have inaccurate information corrected.
- Request erasure or restriction of processing under the conditions set by the GDPR.
- Object, for reasons relating to your situation, to processing based on legitimate interests. An objection is assessed against any compelling legitimate grounds or legal-claim requirements. You can object to direct marketing at any time.
- Request portability of data you provided where processing is automated and based on consent or a contract.
- Withdraw consent at any time for processing that actually relies on consent, without affecting the lawfulness of earlier processing.
- Give instructions about the handling of your personal data after your death under applicable French law, and lodge a complaint with the CNIL or your competent supervisory authority.
Browser storage and policy updates
Authentication cookies, interface preferences and local studio drafts support the studio. Drafts may include imported media and can be restored on this device for 30 days after the last save. The separate cookies policy lists their purposes, lifetimes and the controls available in your browser.
This policy may change when the service, its providers or legal requirements change. The date above identifies this version. Where a change requires renewed information or consent, simply updating this page is not a substitute for taking that step.
Character collections
Collections group a name and several private photos from your library. You confirm that you hold the rights and the depicted people’s permission before saving them. Selecting a character adds its photos to the prompt references; they are sent to the provider when you start a generation. For Seedance 2.5, this connection may use Higgsfield when enabled.
Removing a collection archives it; this does not remove references already attached to a request or delete existing creations. Contact support to withdraw permission or request erasure. This organizational shortcut is not identity verification and does not replace the necessary permissions. The invitations described below remain a separate process.
Invitations and portraits
The account holder names the invitation beneficiary. The invited person reviews that name, declares their own name and adult status and accepts the displayed text. The account name is self-declared, not identity-certified. The private link provides access to the invitation and withdrawal of permission: keep it confidential.
We record declared names, the beneficiary, the accepted text and version, dates, expiry, withdrawals and identifiers needed to evidence and secure the process. Permission lasts three months from acceptance; an unaccepted invitation expires after seven days. Optional portrait use relies on consent (GDPR Article 6(1)(a)). Records needed for evidence and abuse prevention rely on our legitimate interests (Article 6(1)(f)), within the limits of their purpose.
Portrait uploads and generation remain subject to BytePlus activation. When available, identity verification takes place in BytePlus’s interface, which presents its information about the data collected. Unspecified receives verification and asset identifiers and statuses, then sends the approved photo and necessary instructions to BytePlus ModelArk for private portrait storage and generation. Do not upload identity documents into the composer.
Withdrawal or expiry blocks new uses. Withdrawal also requests cleanup of associated resources; errors may require further attempts. Evidence of permission, withdrawal or disputes is not automatically erased: retention must remain limited to evidence needs and applicable periods. Videos already created, downloaded or published are not automatically deleted. Our privacy contact can handle requests for review or data erasure.
Reports and restrictions
A report may contain the reporter’s contact details, the relevant content or account, its category, facts and supporting information. We retain its status, review requests, reasoned decisions and history. Only authorised staff can handle cases; signed-in reporters can view their own reports.
This processing protects people, enforces rules and handles challenges, based on our legitimate interests and, where applicable, a legal obligation. A decision may restrict content or suspend new generations for an account. Information is kept while a case is handled, then according to limited evidence and security needs and applicable obligations. You can request human review through our contact email.