Nenis
Nenis

Privacy Policy

Last updated: September 13, 2026

Nenis is an AI image and video studio. This policy explains what we collect, who we send it to, and how long we keep it. It is written to be read, not skimmed past, so where something matters we have said it plainly.

The controller of your personal data is Nenis Inc. You can reach us at [email protected] for any question in this policy, including data requests.

1. What we collect

2. How we use it

We do not train AI models on your prompts, images, or videos, and we do not sell your personal data or use it for advertising.

Our lawful bases under the GDPR are: performance of a contract, for running the service and taking payment; legitimate interests, for security, fraud prevention, and error diagnosis; and legal obligation, for keeping financial records.

3. What we send to AI model providers

This is the most important disclosure in this policy. When you generate or edit media, the prompt you wrote and any reference image or video you uploaded are sent to the provider of the model you selected so it can produce a result. Which provider receives it depends entirely on which model you pick, and the model is always shown before you create.

These providers process your content under their own terms and privacy policies, and most of them are based outside the European Economic Area. We do not send them your email address, your name, or your payment details — only the content needed to produce your result.

Gemini Omni requires stored interaction state when a video is delivered by URI. By default, we retain that Google interaction and the files needed for follow-up editing for no longer than seven days. You can disable this for new videos in Settings or remove a video's edit history immediately from Gallery. Your copied result remains in Nenis. Uploaded-video Edit and Extend are unavailable in some regions; we use the country header supplied by our delivery provider to enforce that restriction and do not store it solely for this check.

4. Who else processes your data

We do not sell your personal data. We use the following processors to run the service:

ProcessorWhat it does
SupabaseDatabase and sign-in. Holds your account and gallery records.
Backblaze B2Stores your uploaded and generated image and video files.
ModalRuns the service that passes your prompt and images to the model provider you chose.
StripeTakes payment and handles refunds. Holds your card details.
BrevoSends account email such as verification and password resets.
VercelHosts the site, and provides aggregate traffic analytics.
CloudflareSits in front of the site for delivery and abuse protection.
UpstashRate limiting, to stop one account or address overloading the service.
SentryError reports. Session cookies, authorization headers, and tokens are stripped before anything is sent.

We may also disclose data where the law requires it, or to protect the rights and safety of our users and the service.

5. How long we keep things

6. Deleting your account

You can delete your account from your settings page at any time. When you do, your profile, gallery records, and credit balance are removed, and every image file you uploaded or generated is queued for permanent deletion from our storage. Any retained Gemini video interactions and files are also queued for deletion from Google.

Being specific about what does not go: we keep a small record of the deletion containing a one-way hash of your email address, your Stripe customer ID, and the totals of credits you purchased and held at the time. We keep it to meet our accounting obligations, to handle any later refund or chargeback on a purchase you already made, and to stop repeated deletion and re-registration being used to abuse the service. It does not contain your email address in readable form, your name, or anything you created.

7. Security

Your data is separated at the database level by Supabase Row Level Security, so one account cannot read another's records. Media files are private and served through short-lived signed links rather than public URLs. Every operation that moves credits runs inside the database as a single transaction, so a balance cannot be left in a half-changed state.

No system is perfectly secure, and we cannot guarantee that transmission over the internet is free of risk. If a breach affects your personal data we will notify you and the relevant supervisory authority as the GDPR requires.

8. International transfers

Several of our processors and all of our model providers operate outside the European Economic Area, mainly in the United States. Where we transfer personal data there, we rely on the safeguards those providers offer, including the European Commission's Standard Contractual Clauses where they apply.

9. Your rights

If you are in the EEA or the UK you have the right to access your data, correct it, delete it, restrict or object to how we use it, receive a portable copy, and withdraw consent where we relied on it. Most of this is available directly in your settings; for anything else, email [email protected] and we will respond within one month.

You also have the right to complain to your local data protection authority.

10. Age requirement

Nenis is for people aged 18 and over. We do not knowingly collect data from anyone younger. If we learn that an account belongs to someone under 18 we will delete the account and its data.

11. Changes to this policy

We may update this policy. The date at the top always reflects the current version, and we will give notice of significant changes before they take effect.

12. Contact

Questions, data requests, or anything else: [email protected].