Legal
Privacy Policy
Updated 1 October 2026
In short: we collect what Imaginifera needs to work: your account, what you create, your credits and payments, and a little technical data to keep the service safe.
We don’t sell your data, we don’t show ads, and we use no tracking or analytics cookies.
Who we are
Imaginifera, at imaginifera.com and in the Imaginifera Android app, is run by TANYA BAL PR, Trg Nikole Pašića 5, 11103 Beograd (Stari Grad), Serbia. We are the controller of the personal data described here. Write to us any time at contact@tanyalabs.com.
What we collect
Your account
Your email address, your name if you add one, and your password, stored only as a one-way hash we can’t read. If you sign in with Google, we receive your Google account ID, email address and name.
What you create
Your prompts and settings (format, style, quality, length), any starting images you upload, and the images and videos Imaginifera makes for you.
Credits and purchases
Your plan, credit balance and credit history, and the status, amount and date of your payments as reported by Paddle or Google Play. We never see or store your card details.
Safety
Prompts our safety filter stops, and the reports you send about a creation, together with that creation’s prompt.
Technical data
Your IP address and basic browser information, used to protect the service (for example, limiting repeated sign-in attempts). They may appear in server logs that are kept for a short time.
Cookies and storage on your device
We use only cookies Imaginifera needs to work:
- gaia_session keeps you signed in, for up to 30 days.
- gaia_oauth protects Google sign-in, for a few minutes.
- gaia_claim finishes a purchase made before you have an account, for up to two hours.
Your browser also keeps your unfinished prompt and settings on your device so they’re still there when you come back. Paddle’s checkout window may set its own cookies when you open it.
Why we use it
- To run Imaginifera for you: your account, making your creations, keeping your library, credits and plan. This is needed for our contract with you.
- To take payments and keep accounts, as our contract and accounting law require.
- To keep Imaginifera safe and lawful: filtering prompts, reviewing reports, and preventing abuse and fraud. This is our legitimate interest and, in some cases, a legal obligation.
- To email you about your account: confirming your email, password resets and important changes. We don’t send marketing emails unless you ask for them.
Who helps us
These companies process data for us, only to provide their part of the service:
- DigitalOcean hosts the website, the database and your files on servers in Frankfurt, Germany.
- RunPod runs the engines that make your images and videos. For each creation it receives your prompt, settings and starting image, and keeps the result in its storage until Imaginifera collects it.
- Paddle (Paddle.com Market Ltd) sells plans on the website as our reseller. It handles your payment details, invoices and VAT under its own privacy policy.
- Google provides Google sign-in, if you choose it, and payments in the Android app through Google Play, under Google’s privacy policy.
- An email delivery provider sends account emails.
Some of these companies work outside Serbia and the EU, for example in the United States. Where they do, the transfer is protected by safeguards such as the European Commission’s standard contractual clauses or an adequacy decision.
We share data with others only when the law requires it, for example to answer a valid order from an authority or to report child sexual abuse material.
How long we keep it
- Your account, library and credits: until you delete them or your account.
- Creations and uploads you delete: removed from our server straight away.
- Safety records: up to 12 months, or until your account is deleted.
- Sign-ins: end after 30 days without use.
- Payment records: kept without your account details for accounting, as the law requires. Paddle and Google keep their own records.
- Server backups: overwritten within about a month.
Your rights
Under Serbia’s Law on Personal Data Protection and the EU General Data Protection Regulation, you can ask to see, correct, delete or take a copy of your data, and object to or restrict how we use it. You can change your name and password and delete creations or your whole account yourself in the studio, under Account and credits. For anything else, write to contact@tanyalabs.com from the email address on your account. We answer within 30 days.
You can also complain to Serbia’s Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs) or to the data protection authority where you live.
Adults only
Imaginifera is for people aged 18 and over. We don’t knowingly collect data from anyone younger. If you believe someone under 18 has an account, tell us and we’ll delete it.
Security
Connections are encrypted, passwords are stored only as hashes, your files are private to your account, and access to the server is limited and protected with keys.
Changes
When this policy changes, we update this page and its date. If a change is important, we tell you by email or in the studio first.