1. What data do we collect?
- Account information: name, email address, and account identifier.
- The product images you upload for generation.
- The generated images produced by AI processing.
- Anonymised technical data used for performance and service improvement.
2. How are your product images processed?
Your product images are uploaded directly to secure storage on Supabase Storage through short-lived signed URLs. The image is passed to the generation model to produce the advertising version, then returned to you through a link tied to your account only. Images are not stored with any public identifying data, and no other user can access them.
3. Encryption and security
- All communication with the platform goes over HTTPS/TLS 1.3.
- Data in the database is protected by strict row-level RLS policies.
- Sensitive access keys (API keys) are never exposed on the front end.
- External webhooks are signed with HMAC-SHA256 using a timing-safe comparison.
4. Data sharing and technical service providers
We do not sell, rent, or share your personal information or your product images with any third party for marketing or analytics purposes.
We rely on technical service providers strictly necessary to operate the platform:
- Supabase Inc. (United States) — database, authentication, and image storage.
- Google LLC — Gemini models for image processing and generation (processing on United States servers).
- fal.ai / Features and Labels Inc. (United States) — running image generation and enhancement models.
- PayPal (Europe) S.à r.l. — payment and subscription processing.
This means your images may be processed outside your country of residence, including in the United States, solely for the purpose of fulfilling your request, and under the contractual data protection terms agreed with each provider.
None of your content is used to train AI models, and all of these providers are contractually bound to protect the data.
5. Your rights
- Access your data at any time from the dashboard.
- Edit your account information directly.
- Delete your account and all images associated with it from the “Delete account” button. Images and personal data are deleted, while invoice and payment records alone are retained for the period required by accounting law.
- Request a full copy of your data by email at contact@vilabs360.com within 7 business days.
6. Cookies
We use only cookies that are necessary to run the session and remember language and dark mode preferences. We do not use third-party advertising trackers.
7. Data retention period
Your uploaded images and generated images are kept for as long as your account is active, and you can delete any of them at any time from the library. When the account is deleted, images are removed from operational storage within 7 days, and from backups within 30 days at most. Invoice and payment records are kept for 10 years in accordance with accounting and legal obligations, and contain no images.
8. Contact
For any privacy question or data deletion request, write to us at contact@vilabs360.com. We reply within 24 hours.
9. Salla store integration
When you connect your Salla store to your Vilabs360 account, we apply the principle of least data: we read only product data, images, and the basic information needed to pick a product and turn it into AI-generated advertising content. We do not collect any sensitive data, we do not access your customers, orders, or payments, and we never modify any product in your store.
- What we access only: the store name and identifier, and the product list (name, description, images) through these scopes only: offline_access, products.read and settings.read. These are read-only scopes and we never write anything to your store.
- What we never access: customers, orders, invoices, payments, financial inventory, or any personal data belonging to your store's shoppers.
- No modification to your products: our scopes are read-only. We do not modify prices, stock, descriptions, or any product data in your store, and we do not publish or delete any product.
- We do not store your catalogue: products are fetched from Salla on demand and displayed to you without being saved in our database. The only thing stored is the single product image you choose for generation, inside your own private storage space.
- AI processing of images: the image you pick may be processed by our AI providers (Google Gemini and fal.ai) to produce the advertising content at your request only. Your images are never used to train any AI model.
- Token encryption: your store access and refresh tokens are stored encrypted in the database, are never returned to the browser, and cannot be accessed by any other user.
- Data use: product data is used exclusively to generate advertising images and copy at your request. It is never sold, never shared with third parties for marketing, and never used to train AI models.
- Disconnecting or uninstalling the app: when you disconnect the store from your account page, or remove the app from your Salla dashboard, we receive the uninstall notification and immediately delete the access and refresh tokens and all authentication data, and stop all access to your store. Images you already imported remain yours in your library and can be deleted at any time.
For any question about the Salla integration or to request deletion of connection data, contact us at contact@vilabs360.com. Full details on connecting, disconnecting, and common questions are available on the Salla integration page.
10. Zid store integration
When you connect a Zid store we use Zid's official OAuth authorization with the products read scope only.
- OAuth: the connection goes through Zid's official authorization page; we never ask for your store password.
- Token encryption: access and refresh tokens are stored encrypted in our database and never reach the browser.
- Data usage: product name, description, images, and URL are used solely to generate the ad content you request.
- No sharing: we never sell or share your store data with third parties, and it is never used to train models.
- Data deletion: when you disconnect the store, tokens and authentication data are deleted immediately and all access stops.
Full details are on the Zid store integration page.
11. Shopify store integration
When you connect a Shopify store we use Shopify's official OAuth authorization with the products read scope only (read_products).
- OAuth: the connection goes through Shopify's official authorization page; we never ask for your store password.
- Token encryption: access tokens are stored encrypted in our database and never reach the browser.
- Data usage: product name, description, images, and URL are used solely to generate the ad content you request.
- No customer or order access: our scope does not allow access to customer, order, or payment data.
- No sharing: we never sell or share your store data with third parties, and it is never used to train models.
- Data deletion: when you disconnect the store or uninstall the app, access tokens are deleted and all access stops.
Full details are on the Shopify store integration page.