Privacy Policy

Last updated: August 4, 2026

1. Introduction and Data Controller

Protecting your personal data is important to us. This Privacy Policy explains what personal data we process in connection with our website and services, for what purpose, and to whom we disclose this data.

The data controller is:

DEMENO
Tino Bögli, Switzerland
Email: privacy@demeno.app
Postal address: see our Legal Notice

This Privacy Policy is governed by the Swiss Federal Act on Data Protection (FADP/DSG) and, where applicable, the EU General Data Protection Regulation (GDPR).

2. Personal Data We Process

2.1 Account Information

  • Email address (for account creation and communication)
  • Name (if provided via OAuth provider)
  • Profile picture (when signing in with Google)
  • Password hash (for email registration, stored encrypted)

2.2 Payment Data

  • Payment information is processed directly by our payment provider Stripe, Inc.
  • We do not store any credit card or bank account details ourselves
  • We only store your Stripe customer ID and subscription status

2.3 Usage Data

  • Images you upload (processed for AI generation and stored in your project library)
  • Rendering settings and prompts
  • Generated outputs (renderings, 3D models, CAD files, video clips)
  • Site addresses and map coordinates you enter for the site-context feature
  • Credit usage and history
  • Project data and configurations
  • Product usage events (pages visited, features used) — see Section 10 (Analytics)

2.4 Technical Data

  • IP address (for security and rate limiting)
  • Browser type and version
  • Operating system
  • Access timestamps
  • Referrer URL

3. Purpose of Data Processing

We process your personal data for the following purposes:

  • Providing and operating our platform and AI-powered services
  • Processing your requests (renderings, 3D models, CAD conversions)
  • Managing your account and subscription
  • Processing payments via Stripe
  • Communicating with you about your account and our services
  • Preventing abuse, fraud, and security threats
  • Complying with legal obligations
  • Improving our services and user experience

4. Legal Basis

We process your personal data based on the following legal grounds:

  • Contract performance: Processing necessary to provide our contractual services (Art. 31(2)(a) DSG)
  • Consent: Where you have given us consent, e.g. for newsletters (Art. 31(1) DSG)
  • Legitimate interests: Improving our services, fraud prevention, IT security (Art. 31(1) DSG)
  • Legal obligations: Compliance with accounting and tax retention requirements

5. Image Processing and AI

Important: Images you upload are transmitted to specialised AI providers to generate the requested outputs. Depending on the tool you use, this covers:

  • Image generation and editing: renderings, enhancement, upscaling, and prompt analysis
  • 3D generation: 3D models, scenes, and image segmentation
  • Video generation: short clips generated from a still frame

These providers act as our processors under a data processing agreement. They are located in the USA; see Section 7 on international transfers. We will name the providers used for a specific tool on request at privacy@demeno.app.

These services receive your images and prompts solely for the duration of processing your request. Images you upload and results you generate are stored in your project library on our storage infrastructure and count toward your plan's storage allowance; you can delete them at any time (see Section 9).

No model training: We do not use your uploaded content, your prompts, or your generated outputs to train AI models — neither our own nor anyone else's. Your content is transmitted to these providers solely to generate the output you requested.

No guarantee of results: AI-generated outputs are produced automatically and may vary between generations, even from identical inputs. We do not guarantee any specific result, nor the accuracy, completeness, originality, or fitness for a particular purpose of the generated content. Generated content serves as visualization only and does not constitute binding technical, planning, or architectural documentation. For full details, please refer to our Terms of Service.

6. Recipients and Data Processors

We work with carefully selected service providers who process personal data on our behalf, under a data processing agreement and only on our instructions. We disclose data to the following categories of recipients insofar as this is necessary to provide our services:

Category of recipientData concernedLocation
Hosting and content deliveryTechnical data, IP addressUSA / global edge network
Authentication, database, and file storageAccount data, projects, uploaded and generated filesUSA
Payment processingEmail address, billing details, subscription statusUSA / Ireland
AI processing (images, 3D, video)Images you upload, prompts, generated outputsUSA
Transactional email deliveryEmail address, message contentUSA
Product analytics and error trackingUsage events, technical data, error reportsEU
Cookieless web analyticsAggregated page views, no personal identifiersEU
Rate limiting and abuse preventionPseudonymised IP address, request countsUSA / EU
Maps and geocodingSite addresses and coordinates you enter, IP addressUSA

In addition, your browser may load technical resources (e.g. 3D decoder scripts and machine-learning models for on-device features) from third-party content delivery networks in the USA and the EU. These networks see your IP address and browser information but do not receive your images or account data — on-device features process your images locally in your browser.

We name categories rather than individual companies here because our providers change as the service evolves, and an outdated list would be less accurate than none. We will name the specific providers, their locations, and the safeguards in place on request at privacy@demeno.app, and we will name the actual recipients of your personal data whenever you exercise your right of access under Section 15.

7. International Data Transfers

Some of our data processors are located in the USA. Since September 15, 2024, Switzerland has issued an adequacy decision for the USA (for companies participating in the Swiss-U.S. Data Privacy Framework). Where no adequacy decision applies, we rely on Standard Contractual Clauses (SCCs) or other appropriate safeguards pursuant to Art. 16 DSG.

8. Data Security

We take appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, misuse, or destruction. These include:

  • Encrypted data transmission (TLS/HTTPS)
  • Secure authentication via OAuth 2.0 and managed session handling
  • Rate limiting to protect against abuse
  • Access controls and role-based permissions
  • Regular review of our security measures

Generated content is stored under long, randomly generated URLs. Only someone who has the exact link can access a file; the links are not listed or indexed anywhere. Please treat links to confidential work accordingly and do not share them publicly.

Despite these measures, no data transmission over the internet can be guaranteed to be completely secure.

9. Data Retention

  • Account data: Retained while your account is active; deleted when you delete your account (within 30 days at the latest)
  • Uploaded images and generated content: Stored in your project library until you delete them or delete your account; storage limits per plan apply
  • Video clips: Automatically deleted 7 days after generation — download clips you want to keep
  • Content from anonymous use (no account): Automatically deleted 7 days after upload or generation
  • Payment records: Retained as required by law (up to 10 years)
  • Technical logs: Rate-limiting counters expire within minutes. IP records used to enforce anonymous free-usage limits are stored only in pseudonymized (hashed) form and deleted after 12 months at the latest; our hosting providers keep their own short-term access logs

10. Analytics

We use PostHog for product analytics and error tracking. Our PostHog instance runs on PostHog's EU Cloud (Frankfurt, Germany), so analytics data is processed within the EU. Analytics cookies and behavioral tracking (usage events, anonymized session replays) are only activated after you accept them via the cookie banner; before that, only cookieless page-view statistics are collected, and if you decline, analytics is disabled entirely. For signed-in users who have accepted analytics, usage events are linked to the account to help us understand and improve the product.

We may additionally use Plausible Analytics, a cookieless, privacy-focused web analytics service operated from the EU, which stores nothing on your device and creates no persistent identifiers. We do not use advertising or cross-site tracking of any kind.

11. Cookies

We use technically necessary cookies for authentication, session management, and payment, and — only with your consent — analytics cookies as described in Section 10. We do not use any advertising cookies. For details, including how to change your consent choice, please refer to our Cookie Policy.

12. Email Communications

We send transactional emails that are necessary to operate your account: welcome messages, subscription and payment confirmations, failed payment notices, credit-usage warnings, and account-deletion confirmations. These are part of the service and cannot be disabled while your account exists.

Marketing emails (e.g. newsletters or product announcements) are only sent with your consent, and every such email contains an unsubscribe link. You can withdraw your consent at any time without affecting the service. We never share your email address with third parties for their own marketing.

13. Children's Privacy

Our services are directed at professionals and are not intended for persons under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have collected personal data from a person under 18 without valid consent, we will delete it. If you believe a minor has provided us with personal data, please contact us at privacy@demeno.app.

14. Data Breach Notification

If a data security breach occurs that is likely to result in a high risk to your personality or fundamental rights, we will notify the Swiss Federal Data Protection and Information Commissioner (FDPIC) as required by Art. 24 DSG and, where necessary for your protection, inform you directly and without undue delay about the nature of the breach and the measures taken.

15. Your Rights

Under the DSG and, where applicable, the GDPR, you have the following rights:

  • Right of access: You may request information about your personal data stored by us (Art. 25 DSG)
  • Right to rectification: You may request correction of inaccurate data (Art. 32(1) DSG)
  • Right to erasure: You may request deletion of your data, unless statutory retention obligations apply
  • Right to data portability: You may request your data in a commonly used format (Art. 28 DSG)
  • Right to object: You may object to the processing of your data
  • Right to withdraw consent: You may withdraw any consent given at any time

To exercise your rights, please contact us at privacy@demeno.app. You can also delete your account and all associated data at any time in your account settings, or request a data export.

You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC):
www.edoeb.admin.ch

16. Changes to This Privacy Policy

We may update this Privacy Policy at any time. The current version is always available on this page. We will notify you of material changes through appropriate channels. The date of the last update can be found at the top of this policy.

17. Contact

For privacy-related inquiries or to exercise your rights, contact us at:
Email: privacy@demeno.app