Your privacy matters. Learn how we collect, use, and protect your personal data.

1. Data Controller

Druid Cat is the data controller responsible for the personal data processed through our website, applications, and services.

This Privacy Policy explains, as the controller, what personal data we collect, why, and what rights you have. It describes the data we are responsible for — not the internal technical means by which our services operate.

2. What Data We Collect

Personal Information

  • Account Information: Email address, encrypted password, username
  • Purchase Information: Billing details and payment method (handled by our payment processor)
  • Communication Data: Messages sent through contact forms and support emails
  • Newsletter Subscriptions: Email address for marketing communications (with your consent)

Automatically Collected Data

  • Usage Analytics: Pages visited, time spent, and interaction patterns
  • Technical Data: IP address, browser type, device information
  • Cookies: Session cookies, preference cookies, and analytics cookies

Content You Provide and Generate

  • Prompts & Instructions: The text prompts and settings you submit to generate content
  • Uploaded Inputs: Any files you upload (such as images, audio, video, or documents) for processing
  • Generated Outputs: The images, videos, and other content created at your request
  • Usage Records: Generation history, account balance, subscription status, and payment history

3. How We Use Your Data

Service Delivery

  • Provide our AI image, video, and creative generation services
  • Process your orders and deliver purchased products
  • Manage your account, balance, and subscriptions
  • Deliver your generated outputs and send order confirmations

Communication

  • Respond to your inquiries and support requests
  • Send newsletter updates (with your consent)
  • Notify you of important service changes

Improvement, Security & Compliance

  • Analyze usage to improve and develop our services
  • Prevent fraud, abuse, and misuse, and ensure security
  • Comply with legal obligations, including the mandatory reporting of illegal content

4. Legal Basis for Processing (GDPR)

5. Data Sharing & Recipients

We share personal data only where necessary, and only with trusted third parties acting as processors on our behalf under appropriate data-processing agreements. We share data with the following categories of recipients:

  • Payment Processor: Secure, PCI-DSS-compliant processing of payments and billing
  • Infrastructure & Processing Providers: Hosting, cloud computing, and the technical processing required to deliver our services
  • Communication Providers: Delivery of transactional emails and newsletters
  • Analytics Providers: Aggregated, usage analytics to improve our services

External Platforms

Our website may link to or embed external platforms (for example YouTube, Patreon, Gumroad, and Instagram). When you interact with these, their own privacy policies apply.

We never sell your personal data, your prompts, or your generated content to third parties.

If you make a formal access request under Article 15 GDPR, we will, where legally required, provide you with the specific identity of recipients of your personal data.

6. Data Retention

Account & Content Data

  • Active Accounts: Data retained while your account exists and for legitimate business purposes
  • Deleted Accounts: Personal data removed within 30 days, except where retention is required by law
  • Uploaded Inputs & Generated Outputs: Retained only for a limited period to deliver the service, then deleted, unless you save them to your account

Transaction Data

  • Payment & Invoice Records: Retained for the period required by tax and accounting law (typically 5 years)
  • Support Communications: Retained for up to 3 years for service quality and dispute handling

7. Your Rights Under the GDPR

As a data subject, you have the following rights regarding your personal data:

Access

Request a copy of the personal data we hold about you

Rectification

Correct inaccurate or incomplete data

Erasure

Request deletion of your data ("right to be forgotten")

Restriction

Limit how we process your data in certain cases

Portability

Receive your data in a portable, machine-readable format

Objection

Object to processing based on legitimate interest or for marketing

Withdraw Consent

Withdraw consent at any time, without affecting prior processing

Automated Decisions

Not be subject to decisions with legal effect based solely on automated processing

To exercise any of these rights, contact us at aimusicpaws@gmail.com. We will respond within one month, as required by Article 12(3) GDPR.

Right to Lodge a Complaint: If you believe your data has been mishandled, you have the right to lodge a complaint with the Polish supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl — or with the supervisory authority in your country of residence.

8. International Transfers

Some of our service providers may process data outside the European Economic Area (EEA). Where we transfer your data internationally, we ensure an adequate level of protection through one or more of the following safeguards:

  • Adequacy Decisions: Transfers to countries recognised as adequate by the European Commission
  • Standard Contractual Clauses: EU-approved contractual safeguards
  • EU–US Data Privacy Framework: Where the recipient is certified under the framework

9. Cookies & Tracking

Essential Cookies

  • Session Cookies: Required for website functionality, login, and shopping cart
  • Security Cookies: Prevent fraud and ensure secure browsing

Analytics Cookies

  • Usage Analytics: Website usage statistics (requires your consent)
  • Performance Cookies: Monitor site speed and user experience

Marketing Cookies

  • Social Media & Advertising: Integration and conversion tracking (with your consent)

10. Data Security

Encryption

SSL/TLS encryption for all data transmission. Passwords stored using industry-standard hashing.

Secure Hosting

Data stored on secure infrastructure with regular security updates and monitoring.

Access Control

Strict access controls ensure only authorized personnel can access personal data. Administrator accounts are protected with mandatory two-step verification, and every user can enable optional two-step verification (email code) in My Account.

Breach Notification

In the event of a personal-data breach, we notify the supervisory authority within 72 hours as required by Article 33 GDPR.

11. Age Requirement

You must be at least 18 years old to use our services. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately and we will delete it.

12. AI-Generated Content & Automated Processing

Our services use artificial intelligence to generate content from the prompts and inputs you provide.

  • We do not sell your personal data, prompts, uploads, or generated content.
  • We do not use your prompts, uploads, or generated outputs to train our own AI models.
  • Generation may be carried out using third-party processing providers acting on our behalf; such providers process your content solely to produce the output you request.
  • AI outputs are produced automatically and may be inaccurate, unexpected, or resemble existing works. Please review the Terms & Conditions for details on AI-generated content.
  • You are not subject to decisions producing legal or similarly significant effects based solely on automated processing.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last Updated" date
  • Sending email notification for significant changes
  • Displaying a notice on our website