Last updated 2026-10-03
Privacy Policy
Genaro (“we,” “us,” or “our”) operates Genaro (the “Service”) at https://genaro.ai, including its application programming interface (“API”), console and documentation. This Privacy Policy explains how we collect, use, disclose and protect information when you use the Service. Capitalized terms not defined here have the meanings given in our Terms of Service. By using the Service, you acknowledge the practices described in this policy.
1. Information We Collect
1.1 Account Information
When you create an Account, we collect your name, email address and profile information, including a profile photograph where you sign in through a social login provider, through our third-party authentication provider. We do not receive or store your password.
1.2 Content You Create
We store the media files you upload and the media generated for you, together with the derived versions we create of them, such as thumbnails and previews. We also store records of your generation requests, including the model selected, your prompts and other parameters, the inputs you reference, the status and outcome of the request, any error, the associated charge, and the resulting output. If you use agent or conversation features, we store the messages, tool calls and results of your conversations.
1.3 API Keys
We store API Keys only in a one-way hashed form. We cannot retrieve or display an API Key after it has been issued.
1.4 Destinations You Configure
If you configure webhook or telemetry destinations, we store the addresses of those destinations and any authentication details you supply for them.
1.5 Automatically Collected Information
When you access the Service, we automatically collect:
- Device and connection information: IP address, browser or client type and similar information transmitted with your requests;
- Log data: access times, requests made, response status and the Account or API Key used; and
- Usage data: generation requests, models used, usage totals, and diagnostic and performance information, including error reports from which credentials and personal identifiers are removed before transmission to our error-monitoring provider.
1.6 Payment and Billing Information
Payments are processed by a third-party payment processor. We do not store your full payment card number or banking details. We receive and store a processor customer reference, transaction identifiers, amounts, and a ledger of every credit, charge and refund applied to your Balance.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, maintain and secure the Service;
- Process and fulfill your storage and generation requests;
- Manage your Account, authentication and API Keys;
- Process payments and maintain your Balance;
- Send you transactional communications, including receipts, balance and Account-status notices, security notices and service updates;
- Monitor usage to maintain performance and reliability and to apply limits;
- Detect, investigate and prevent fraud, abuse and violations of our policies;
- Enforce our Terms of Service and Acceptable Use Policy; and
- Comply with legal obligations and respond to lawful requests.
2.1 No Sale of Personal Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
2.2 No Training on Your Content
We do not use Your Content, including your media, prompts and Generated Content, to train or fine-tune any artificial intelligence model, and we do not provide it to any third party for that purpose. We use Your Content only to provide the Service to you and as otherwise described in this policy.
3. Third-Party Service Providers
We use third-party service providers to operate, maintain and secure the Service. Each receives only the information necessary to perform its function and processes it on our behalf. Those providers include:
- Clerk, for authentication and account sign-in;
- Stripe, for payment processing;
- Cloudflare R2, for storage of media;
- Modal, WaveSpeed, Kie.ai and Fal, as Providers that run the image and video generation models;
- OpenRouter, for the language models used by agent features;
- Sentry, for error monitoring;
- An email delivery provider, for transactional email; and
- Our infrastructure and hosting providers, which run the Service and its database.
When you request a generation, your prompts, parameters and any input media you reference are transmitted to the Provider that runs the selected model. Which Provider processes a request depends on the model selected and on our routing. Each Provider has its own privacy policy and retention practices, which we do not control and which govern the data transmitted to it.
Payment transactions are processed by a payment processor that maintains Payment Card Industry compliance; we do not have access to your full payment card details. Third-party providers may set cookies, collect access logs including IP addresses, or process data in locations outside your country of residence.
Webhook and telemetry destinations that you configure receive the events and telemetry you direct to them, and we are not responsible for their handling of that data. We may also disclose information where required by law or valid legal process, to protect the rights, safety or property of any person, or in connection with a merger, acquisition or sale of assets, including reports to authorities as described in Section 8.4 of the Acceptable Use Policy.
5. Data Security
We implement security measures designed to protect your information, including:
- Encryption of data in transit;
- One-way hashing of API Keys;
- Logical isolation of each Workspace from every other Workspace;
- Time-limited, signed access links for the upload and download of media;
- Access controls limiting personnel and system access to personal data on a need-to-know basis; and
- Authentication through a specialist third-party provider.
Despite these measures, no method of electronic transmission or storage is completely secure, and we cannot guarantee the absolute security of your data. You are responsible for maintaining the confidentiality of your sign-in credentials and API Keys.
6. Data Retention
We retain your information for as long as your Account is active and as needed to provide the Service. Specifically:
- Account data: retained while your Account is active and for a reasonable period afterwards to comply with legal obligations;
- Content and generation records: retained until you delete them or your Account is erased, subject to the lifecycle described on the Data Deletion page;
- API Keys and configured destinations: retained until you delete them or your Account is erased;
- Server logs: retained for up to thirty (30) days for security and diagnostic purposes;
- Financial records: retained as required by applicable tax and accounting laws; and
- Backups: deleted data may persist in backups for a limited period, as described on the Data Deletion page.
Notwithstanding the foregoing, we may retain information where required by law, where necessary to resolve disputes, enforce our agreements or protect any person, and, as described in the Acceptable Use Policy, where it relates to suspected unlawful content.
7. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. Our third-party service providers may process data in various locations globally. By using the Service, you acknowledge the transfer of your information to those locations, where data protection laws may differ from those in your jurisdiction.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: to request a copy of the personal data we hold about you;
- Correction: to request correction of inaccurate or incomplete data;
- Deletion: to request deletion of your Account and associated data;
- Portability: to request a machine-readable copy of your data;
- Restriction: to request that we limit processing of your data in certain circumstances;
- Objection: to object to processing of your data for certain purposes; and
- Withdrawal of consent: where processing is based on consent, to withdraw it at any time.
You may list, retrieve and delete much of your data yourself through the Service. To exercise any of these rights, or to request erasure of your Account, contact us at support@genaro.ai. We will respond within thirty (30) days and may ask you to verify your identity before processing your request. The consequences of deletion are described on the Data Deletion page.
9. California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (“CCPA”):
- The right to know what personal information we collect, use and disclose;
- The right to request deletion of your personal information;
- The right to correct inaccurate personal information;
- The right to opt out of the sale or sharing of your personal information (we do not sell or share your personal information); and
- The right to non-discrimination for exercising your CCPA rights.
10. European Residents (GDPR)
If you are located in the European Economic Area, the United Kingdom or Switzerland, our legal bases for processing your data include:
- Contract performance: processing necessary to provide the Service you requested;
- Legitimate interests: processing for fraud prevention, security, enforcement of our policies and the operation of the Service, balanced against your rights;
- Consent: where you have given consent; and
- Legal obligation: processing required by applicable law.
You may lodge a complaint with your local data protection authority if you believe your rights have been violated.
11. Children’s Privacy
The Service is not intended for persons under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal data from a minor, we will take steps to delete that information promptly, subject to our reporting and preservation obligations under applicable law. If you believe that a minor has provided us with personal data, please contact us at support@genaro.ai.
12. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify affected users and relevant authorities as required by applicable law. The notice will describe the nature of the breach, the data affected and steps you can take to protect yourself.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. We will notify you of material changes by posting the updated policy on this page with a new “Last updated” date and, for significant changes that affect how we handle your data, by notifying the owner of your Account by email. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
14. Contact Us
If you have questions, concerns or requests regarding this Privacy Policy or our data practices, contact us at: Genaro, Email: support@genaro.ai, Website: https://genaro.ai.