Privacy Policy
Effective 2026-08-07
Who we are
Aspaceai International Limited operates ASpaceAI from United States and provides an AI home design visualization service. Aspaceai International Limited is the controller of the personal data described below.
For any question about this policy or about your data, contact service@aspaceai.com.
What we collect
Account data: your email address, your name if you provide one, your authentication method, and — if you enable two-factor authentication — the fact that it is enabled. We never store your password in readable form.
Organisation data: the workspaces you belong to, your role in each, and invitations you send or receive.
Billing data: your subscription tier, plan history, orders, and credit ledger. Card details are handled by our payment processor and never reach our servers.
Design content: room photos, furniture reference images, generated images, prompts, and any text you submit to describe a home design change. These are private to your organisation by default.
Share interaction data: when a public design link is created, successfully copied, handed off to the browser share sheet according to the browser client's completion result, or its public page is visibly opened, we record the share, originating asset and organisation, event type, and time. A share-sheet handoff does not prove that a recipient received or opened the link. Copy and share-sheet actions include the signed-in actor; a page open includes an account identifier only when that viewer is already signed in. Signed-out page opens remain anonymous and are not assigned a visitor identifier. These first-party records contain no public token, IP address, user agent, referrer, cookie, or device fingerprint.
Catalog interaction data: when you open a furniture or painting merchant link, we record the product and variant, price, currency, quantity, store, originating task or design, placement surface, and time. Signed-in in-app clicks may include account and organisation attribution. Clicks from public-share pages are always viewer-anonymous, even if the visitor has a signed-in session, but remain linked to the shared task and its creator. This first-party server event sets no new cookie, and its analytics record contains no IP address or user agent.
Technical data: IP address, user agent, and authentication events such as sign-ins and password resets. We keep these to detect abuse and to answer 'was this me?'
Cookies and similar technologies: see the cookies section below.
Why we process it, and on what basis
To provide the service you asked for, including authentication, uploads, AI room edits, generated results, and downloads — performance of our contract with you.
To take payment and keep financial records — performance of our contract, and compliance with a legal obligation for records we must retain.
To keep the service secure and to investigate abuse — our legitimate interest in a service that is not being attacked.
To send transactional email such as verification, password resets, and receipts — performance of our contract.
To measure whether shared designs are distributed, viewed, and lead to useful product interactions — our legitimate interest in evaluating and improving the service, using the first-party share interaction data described above.
To measure whether furniture and painting recommendations are useful and improve their placement — our legitimate interest in evaluating and improving the service, using the first-party catalog interaction data described above.
For third-party analytics or advertising, where enabled — your consent, which you may give or withdraw at any time.
Cookies and similar technologies
Strictly necessary cookies keep you signed in, protect forms against cross-site request forgery, and remember your cookie choice. These are required for the service to function and are set without consent.
Analytics and advertising technologies, where enabled, are set only after you accept them. Nothing in those categories loads before you make a choice, and rejecting them is a single click with the same prominence as accepting.
You can change your decision at any time from the cookie settings link in the site footer. Withdrawing consent stops future collection; it does not undo processing that already, lawfully, happened.
Who we share it with
We do not sell personal data.
Depending on the features you use and the services enabled on the deployment, we use these providers to operate ASpaceAI: Vercel — Application hosting, content delivery, and request logs; Managed PostgreSQL infrastructure — Account, organisation, billing, task, and audit records; Managed Redis infrastructure — Abuse prevention and distributed request rate limiting; Stripe — Payment processing, subscription billing, and receipts; Resend — Account verification, password reset, and transactional email; Kie.ai and its model providers — AI image editing and generation requested in Studio; Configured private object-storage provider (Amazon S3, Cloudflare R2, or compatible) — Storage and delivery of uploaded and generated files; Cloudflare Turnstile — Bot and abuse prevention on authentication forms; Google — Optional Google account sign-in; consent-gated Google Analytics and AdSense when configured.
When you ask ASpaceAI to generate or edit an image, the uploaded images and prompt needed for that request are sent to the AI provider so it can produce the result.
When you choose Google sign-in, Google receives the information necessary to authenticate you. Google Analytics and advertising services are contacted only after the relevant consent is given and only when those services are configured.
We may disclose data where we are legally required to, or to establish or defend legal claims.
International transfers
Our providers may process data outside your country, including outside the EEA or the UK. Where that happens, we rely on legally recognized transfer safeguards such as standard contractual clauses or equivalent measures provided by the relevant vendor.
How long we keep it
Account and organisation data: while the account is active and afterward only for as long as reasonably needed to handle a closure request, prevent fraud, resolve disputes, or meet legal obligations.
Financial records, including orders and subscription history: retained after account closure for the period our tax and accounting obligations require.
Authentication, credit-ledger, task, and administrative audit records: these records are append-only or retained as service and security history. We keep them while needed for account security, fraud prevention, support, accounting, dispute resolution, and legal compliance.
Uploaded source files: active files remain available to your account until you delete them. Deletion removes the stored object, while limited database metadata and audit references may remain for security, accounting, or dispute-resolution purposes.
Generated outputs and Studio task records: task and result references remain in account history unless we delete or de-identify them in response to a valid request. Copies held temporarily by AI or infrastructure providers follow those providers' operational deletion cycles.
Share interactions: retained as append-only product-usage analytics while reasonably needed to evaluate sharing. A matching account export describes actors relative to the requesting account rather than revealing another member's identifier; erasure replaces creator and signed-in actor identifiers with an irreversible pseudonym while retaining non-identifying aggregate event facts.
Catalog merchant-link clicks: retained as append-only product-usefulness analytics while reasonably needed to evaluate recommendations. A matching account export includes them, and account erasure replaces clicker and task-creator identifiers with an irreversible pseudonym while retaining the non-identifying product and aggregate click facts.
Backups and deletion processing: deleted data may persist temporarily in restricted backups or queues until the normal backup rotation or deletion process completes.
Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, receive a portable copy, object to processing based on legitimate interests, or withdraw consent you have given.
There is currently no in-product control for closing an account or deleting all personal data. To close an account, request deletion, or exercise another privacy right, contact service@aspaceai.com. We will verify the request and respond within the period the applicable law requires.
If you believe we have handled your data improperly, you may complain to your local supervisory authority. We would rather you told us first.
Security
Access to your data is scoped to your organisation, uploaded files are private by default and served through expiring links, and administrative accounts require two-factor authentication.
No service is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority where the law requires it.
Children
The service is not directed to children under 13, and we do not knowingly collect their personal data.
Changes to this policy
We will post any change here and update the effective date above. If a change materially affects your rights, we will tell you before it takes effect.