Nenis is an AI image and video studio. This policy explains what we collect, who we send it to, and how long we keep it. It is written to be read, not skimmed past, so where something matters we have said it plainly.
The controller of your personal data is Nenis Inc. You can reach us at [email protected] for any question in this policy, including data requests.
We do not train AI models on your prompts, images, or videos, and we do not sell your personal data or use it for advertising.
Our lawful bases under the GDPR are: performance of a contract, for running the service and taking payment; legitimate interests, for security, fraud prevention, and error diagnosis; and legal obligation, for keeping financial records.
This is the most important disclosure in this policy. When you generate or edit media, the prompt you wrote and any reference image or video you uploaded are sent to the provider of the model you selected so it can produce a result. Which provider receives it depends entirely on which model you pick, and the model is always shown before you create.
These providers process your content under their own terms and privacy policies, and most of them are based outside the European Economic Area. We do not send them your email address, your name, or your payment details — only the content needed to produce your result.
Gemini Omni requires stored interaction state when a video is delivered by URI. By default, we retain that Google interaction and the files needed for follow-up editing for no longer than seven days. You can disable this for new videos in Settings or remove a video's edit history immediately from Gallery. Your copied result remains in Nenis. Uploaded-video Edit and Extend are unavailable in some regions; we use the country header supplied by our delivery provider to enforce that restriction and do not store it solely for this check.
We do not sell your personal data. We use the following processors to run the service:
| Processor | What it does |
|---|---|
| Supabase | Database and sign-in. Holds your account and gallery records. |
| Backblaze B2 | Stores your uploaded and generated image and video files. |
| Modal | Runs the service that passes your prompt and images to the model provider you chose. |
| Stripe | Takes payment and handles refunds. Holds your card details. |
| Brevo | Sends account email such as verification and password resets. |
| Vercel | Hosts the site, and provides aggregate traffic analytics. |
| Cloudflare | Sits in front of the site for delivery and abuse protection. |
| Upstash | Rate limiting, to stop one account or address overloading the service. |
| Sentry | Error reports. Session cookies, authorization headers, and tokens are stripped before anything is sent. |
We may also disclose data where the law requires it, or to protect the rights and safety of our users and the service.
You can delete your account from your settings page at any time. When you do, your profile, gallery records, and credit balance are removed, and every image file you uploaded or generated is queued for permanent deletion from our storage. Any retained Gemini video interactions and files are also queued for deletion from Google.
Being specific about what does not go: we keep a small record of the deletion containing a one-way hash of your email address, your Stripe customer ID, and the totals of credits you purchased and held at the time. We keep it to meet our accounting obligations, to handle any later refund or chargeback on a purchase you already made, and to stop repeated deletion and re-registration being used to abuse the service. It does not contain your email address in readable form, your name, or anything you created.
Your data is separated at the database level by Supabase Row Level Security, so one account cannot read another's records. Media files are private and served through short-lived signed links rather than public URLs. Every operation that moves credits runs inside the database as a single transaction, so a balance cannot be left in a half-changed state.
No system is perfectly secure, and we cannot guarantee that transmission over the internet is free of risk. If a breach affects your personal data we will notify you and the relevant supervisory authority as the GDPR requires.
Several of our processors and all of our model providers operate outside the European Economic Area, mainly in the United States. Where we transfer personal data there, we rely on the safeguards those providers offer, including the European Commission's Standard Contractual Clauses where they apply.
If you are in the EEA or the UK you have the right to access your data, correct it, delete it, restrict or object to how we use it, receive a portable copy, and withdraw consent where we relied on it. Most of this is available directly in your settings; for anything else, email [email protected] and we will respond within one month.
You also have the right to complain to your local data protection authority.
Nenis is for people aged 18 and over. We do not knowingly collect data from anyone younger. If we learn that an account belongs to someone under 18 we will delete the account and its data.
We may update this policy. The date at the top always reflects the current version, and we will give notice of significant changes before they take effect.
Questions, data requests, or anything else: [email protected].