Soreal – a service of Soreal AI, LLC
Effective Date: May 19, 2025
Soreal AI, LLC ("Soreal," "we," "our," or "us") operates the Soreal website, API, and related services (collectively, the "Service"). This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use our Service. For purposes of data protection laws (e.g. GDPR), Soreal AI, LLC is the controller of your personal information.
Our Service is limited to users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you are under 18, you must not use the Service. If we become aware that a person under 18 has provided us with personal data, we will delete such data.
We collect various types of information in order to provide and improve the Service. The categories of data we collect include:
Category | Details & Examples | Source |
---|---|---|
Account Data | Name, email address, password hash, subscription level, payment status | Provided by you |
Payment Data | Billing name, card last 4 digits, billing ZIP/postal code. Note: Full payment card details are handled by Stripe; Soreal never stores your full card number. | Provided by you / via Stripe |
Prompt & Asset Data | Text prompts you enter, any reference images you upload, and the images generated by the Service ("Assets"), along with associated metadata (e.g. generation settings). | Provided by you; Assets are created by our models |
Device & Log Data | Technical information such as your IP address, browser type, operating system, referring URL, pages viewed, and timestamps of requests. | Collected automatically |
Analytics Data | Usage metrics about how you interact with our Service, e.g. feature usage, page views, button clicks, session length. Collected via Google Analytics 4 and our error/performance monitoring tool Sentry. | Collected automatically |
Cookie Data | Data collected through cookies or similar technologies. (See Section 5 below for details.) | Collected automatically |
Inferred Data | Derivations we make from other data – for example, an approximate location (city/country) inferred from your IP address, or product usage patterns inferred from how you use the Service. | Derived by us |
We use the collected information for the following purposes, relying on different legal bases as appropriate:
Purpose | Explanation & Legal Basis* |
---|---|
Provide the Service | To create and manage your account, authenticate you at login, render the website/app interface, process your prompts to generate images, and deliver responses via the API. (Legal basis: Contract – this processing is necessary to provide the Service you requested.) |
Improve & Secure | To debug and fix errors (using tools like Sentry for error monitoring), prevent fraud and abuse, analyze performance, and test new features. (Legal basis: Legitimate interests – we have a legitimate interest in maintaining and improving the security and quality of our Service.) |
Billing & Payments | To process subscription payments, manage billing (through Stripe), and detect fraudulent transactions. (Legal basis: Contract for payment processing, and legitimate interests for fraud prevention.) |
Communications | To send you service-related communications: account confirmations, invoices/receipts, technical or security alerts, and product updates or new feature announcements. We may also send marketing or promotional emails only if you have consented or if otherwise permitted by law. (Legal basis: Legitimate interests for essential communications; consent for marketing where required.) |
Model Training (Opt-out) | Paid-tier users: By default, we may use your prompts and generated images to improve our AI models and future versions of the Service. You have the choice to opt out if you do not want your data used for model training. (Legal basis: Consent – we treat your continued use without opting out as permission, where allowed by law.) |
Legal Compliance | To comply with applicable laws and regulations, respond to lawful requests by authorities, resolve disputes, and enforce our terms and policies. (Legal basis: Legal obligation.) |
**Where the GDPR/UK GDPR applies, we rely on the legal bases noted in parentheses above for the corresponding purposes.
We do not disclose your personal information to outside parties except in the following circumstances and with appropriate safeguards:
Importantly, we do not sell your personal information and we do not share your data with third parties for their own marketing or advertising purposes.
Soreal is based in the United States, and the data we collect is primarily stored and processed on servers located in the U.S. (for example, on Supabase and AWS infrastructure). This means that if you are located outside the U.S. (such as in the EEA, United Kingdom, or Switzerland), your personal data may be transferred to and processed in the United States or other jurisdictions that may not have the same data protection laws as your home country.
To ensure an adequate level of protection for personal data transferred internationally, we rely on the following safeguards:
If you have questions about our international data transfer practices, feel free to contact us (see Section 13 below).
We retain your personal information only for as long as necessary to fulfill the purposes described in this Policy, or as required by law. Our retention practices are:
After the applicable retention periods, or upon your verified request for erasure, we will either securely delete or anonymize your personal data so that it can no longer be linked to you. Please note that due to the nature of caching and distributed systems, there may be slight delays in removal from all systems. We will endeavor to complete the deletion process as promptly as possible and within any deadlines required by law.
Depending on your location and applicable privacy laws, you may have certain rights regarding your personal data. We honor all rights granted to users under relevant data protection laws:
Exercising Your Rights: You may exercise your privacy rights by contacting us at privacy@soreal.app or via the account Settings page (where available for certain requests like data export or deletion). We will need to verify your identity before processing certain requests (for example, by confirming control of your account or asking for additional information). We will respond to your request within the timeframe required by law (generally within 30 days for GDPR-related requests, and 45 days for CCPA requests, with extensions if permitted).
If you are in the EEA/UK/CH and believe we have not adequately addressed your concerns, you have the right to contact your local Data Protection Authority. California residents may contact the California Attorney General if they have concerns about how we handled a request. We encourage you to contact us first with any questions or concerns, and we will do our best to resolve them.
We take the security of your personal information very seriously. Soreal implements a variety of industry-standard security measures to protect your data from unauthorized access, use, or disclosure. These measures include, for example: the use of HTTPS encryption for all data in transit, encryption of sensitive data at rest, strict access controls following the principle of least privilege (only authorized staff with a need-to-know can access user data), and regular security audits and penetration testing of our systems. We also monitor for potential vulnerabilities and attacks, and we have incident response plans ready.
However, please understand that no security measure is 100% perfect. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach that affects your personal information, we will notify you and the relevant authorities as required by law, and we will take all necessary steps to mitigate the incident and prevent future occurrences.
Our Service may contain links to external websites or services that are not operated by Soreal. For example, our website might link to our social media pages, external resources, or third-party content. If you click on a third-party link, you will be directed to that third party's site. Note: This Privacy Policy does not apply to information collected on any third-party websites or services. Those sites have their own privacy policies, and we are not responsible for their content, security, or privacy practices. We recommend that you review the privacy policy of any external site you visit before providing any personal information.
We may update or revise this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. If we make material changes to the way we treat your personal information, we will provide you with advance notice. For example, we may notify you by email and/or by placing a prominent notice on our website or within the app at least 30 days prior to any significant changes taking effect. In some cases (for less substantive updates), we may simply update the "Effective Date" at the top of this Policy and post the revised Policy on our site. We encourage you to review this page periodically for the latest information on our privacy practices.
Your continued use of the Service after the updated Privacy Policy has become effective constitutes your acceptance of the changes. If you do not agree with any updates to the Policy, you should stop using the Service and, if you wish, delete your account or exercise other rights described above.
If you have any questions, concerns, or requests regarding this Privacy Policy or how Soreal handles your data, please do not hesitate to contact us:
Mailing Address:
Soreal AI, LLC
8 The Green, #18947
Dover, DE 19901, USA
Email: privacy@soreal.app
We will do our best to respond to your inquiry as soon as possible (typically within 5 business days for privacy-related requests).
Last revised: May 19, 2025