新功能:Pro、Max 和 Studio 套餐支持无限图像生成。立省 20%

领取优惠

Vose

探索图像视频智能体社区价格

Privacy Policy

  • 1. Who is responsible for your data
  • 2. Personal data we collect
  • 3. Why we use data and our legal bases
  • 4. How creative content is processed
  • 5. AI providers and model training
  • 6. Who can receive personal data
  • 7. Cookies, marketing, and referral tracking
  • 8. International processing
  • 9. How long we keep data
  • 10. Security
  • 11. Your rights and choices
  • 12. Automated checks and decisions
  • 13. Children
  • 14. Additional information for US state residents
  • 15. Changes and contact

Vose AI Privacy Policy

Effective date: November 4, 2026

Last updated: October 5, 2026

This Privacy Policy explains how Vose AI collects and uses personal data when you visit vose.ai, create an account, use its creative tools, make purchases, or contact us. It also explains how to exercise your privacy rights. Personal data includes information that identifies you or can reasonably be linked to you.

Contents
  1. 1. Who is responsible for your data
  2. 2. Personal data we collect
  3. 3. Why we use data and our legal bases
  4. 4. How creative content is processed
  5. 5. AI providers and model training
  6. 6. Who can receive personal data
  7. 7. Cookies, marketing, and referral tracking
  8. 8. International processing
  9. 9. How long we keep data
  10. 10. Security
  11. 11. Your rights and choices
  12. 12. Automated checks and decisions
  13. 13. Children
  14. 14. Additional information for US state residents
  15. 15. Changes and contact

1. Who is responsible for your data

Vose Technologies S.L., established in Spain, is the controller for the personal data described in this Policy, except where we expressly act as a processor for an organization. Our registered address is Barrio San Pedro 31, 39193, Arnuero, Spain. Contact us about privacy at support@vose.ai, or by post at that address. General support is available at support@vose.ai.

When an organization engages us to process personal data solely under its instructions under a data processing agreement, that organization is the controller for that processing. Its privacy notice and our agreement with it apply to those activities. We still act as a controller for our own account administration, billing, security, and legal compliance. Simply using Vose for work does not, on its own, establish a processor relationship.

2. Personal data we collect

We collect the following categories where relevant to the features you use. We do not require every category from every user.

  • Account information: your email address, account identifier, display name, profile image, authentication information, language, and account settings. If you sign in through another service, we receive the identity and profile information that service is authorized to share.
  • Creative content: prompts, chat messages, instructions, uploaded files, images, video, audio, references, generated Outputs, project names, and associated metadata. This may include faces, voices, or other personal information appearing in the media. Files may contain location or device metadata even when you do not enter that information separately.
  • Transaction information: the plan and credit packs you buy, billing name and address, tax details where applicable, purchase and refund records, payment status, credit usage, and payment-provider identifiers. Full card details and security codes are collected by our payment provider rather than stored in Vose’s own systems; we may receive limited details such as card brand, last four digits, and expiry date.
  • Usage and technical information: IP address, approximate location inferred from IP, browser and device information, access times, pages or features used, selected models and settings, job identifiers and status, errors, security events, and diagnostic logs. Some logs may contain relevant prompt or content information when needed to investigate a problem.
  • Communications and preferences: support messages, feedback, complaint records, consent choices, and marketing preferences.
  • Referral information: referral codes, referring pages, campaign parameters, and related conversion records, where used for the referral or marketing activity described in Section 7.

We receive data directly from you and your device, from the sign-in and payment services you use, and from providers returning requested results or technical status. Other users may upload media that contains your personal data or invite you to a shared project if those features are available. An authorized connected tool supplies only the information within the permissions you grant. We do not obtain unrestricted access to external accounts merely because you connect them.

You can decline to provide optional information. We need certain account, content, or transaction data to provide the feature or purchase you request; without it, that feature may not work. Billing or tax information may also be required by law.

3. Why we use data and our legal bases

Where the GDPR applies, we use the legal bases below. “Legitimate interests” means a purpose we have assessed against your rights and reasonable expectations; it is not an unrestricted permission to use data.

Providing the Service

We use account data to create and authenticate your account, and your Inputs, relevant context, Outputs, settings, and job records to carry out the generation, editing, storage, and sharing you request. We use transaction data to manage payments, subscriptions, and credits, and communications to provide account support. The basis is performance of our contract with you or steps you request before entering it. For an organization user’s contact details, our basis may instead be the legitimate interest in managing the organization’s account.

Security and preventing abuse

We use account, technical, transaction, and relevant content data to protect accounts, prevent fraud, detect prohibited use, investigate incidents, and enforce fair use. Our basis is the legitimate interest in maintaining a secure and lawful service, or a specific legal obligation where one applies. We limit access and use to what the purpose requires.

Legal and business records

We retain invoices and tax information to meet legal obligations. We use relevant account, transaction, support, and incident records to handle claims and establish, exercise, or defend legal rights, based on legal obligations or our legitimate interest in resolving disputes. We use necessary business records for accounting, audit, and properly safeguarded business transactions on those same bases as applicable.

Reliability and product improvement

We use technical performance, feature usage, and feedback to identify bugs, understand demand, and improve functionality, based on our legitimate interest in operating a useful and reliable service. Non-essential tracking technologies require consent where applicable. Model training on private creative content is governed separately by Section 5; describing improvement here does not authorize it.

Marketing and referral attribution

We use contact details and preferences to send marketing when you consent or when a limited existing-customer exception lawfully applies, with an opt-out at collection and in each message. Related processing relies on consent or, for the permitted exception, our legitimate interest in communicating about our own similar services. Optional analytics, advertising tracking, and cookie-based affiliate attribution require consent where applicable. Essential contractual referral accounting, such as applying a code you enter, may rely on contract performance or our legitimate interest in administering the referral arrangement.

Optional sensitive processing

Where a feature lawfully requires special-category data or consent under biometric laws, we will identify the purpose, data, legal condition, and relevant providers before collection and obtain separate explicit consent when required. General acceptance of the Terms or this Policy is not a substitute. We do not rely on a customer’s contract as the legal basis for processing an unrelated person’s data; for data in user uploads, we assess our role and the relevant legal basis, including any additional sensitive-data condition.

4. How creative content is processed

Providing a requested feature can involve uploading and temporarily processing files, extracting frames or audio, converting formats, generating embeddings or other technical representations, applying safety checks, and sending relevant material to an AI provider. An assistant may process conversation context and call tools you have authorized. The information sent depends on the feature and the model used.

An identifiable face or voice in a file is personal data. Whether processing also constitutes biometric data, or special-category biometric data used for unique identification, depends on the technical processing, its purpose, and the applicable law. Creative editing should not be assumed to be exempt from biometric rules.

Vose does not use your media for biometric identification or authentication, or to infer sensitive traits about identifiable people. If a supported creative feature creates or stores a face representation, voice representation, or reusable identity asset, its specific notice will describe the data, provider, purpose, retention, deletion, and consent requirements before you use it. [INSERT CHARACTER FEATURE NOTICE: what reference media is stored for a character, which provider processes it, how long it is kept, and how to delete it.]

If another user uploads your personal data, contact support@vose.ai with information that helps locate it. We will assess the request and our obligations, including applicable notice requirements for indirectly collected data. The uploader’s obligations do not replace ours.

5. AI providers and model training

We do not use your private Inputs or Outputs to train or fine-tune general-purpose AI models, and we do not authorize our service providers to do so, unless you separately opt in. Processing content to generate the result you requested, enforce safety rules, or diagnose a specific failure is distinct from general-purpose model training.

If a feature lets you deliberately train or personalize a model, create a voice, or register a character using selected material, we process that material for the feature you request under its specific notice. It does not automatically authorize unrelated model development. Any optional broader training program will explain the data used, providers involved, legal basis, withdrawal process, and practical limits before you decide whether to join.

Depending on the model or feature you select, requests may be processed by OpenAI, Google (Gemini), Anthropic, Black Forest Labs (FLUX), BytePlus (Seedance), MiniMax, and fal.ai. Provider routes may retain information for generation delivery, safety, and abuse prevention for the periods disclosed for the route. We do not promise that every provider has zero retention. [INSERT VERIFIED AI PROVIDER DETAILS: roles, countries, training restrictions, and retention periods for each enabled provider.]

Where a provider acts on our behalf, it must process personal data under an appropriate agreement and our instructions. If a particular feature instead involves a provider acting as a separate controller for a defined purpose, we identify that provider and purpose before processing. Merely naming a model brand does not identify every company receiving the request.

6. Who can receive personal data

We disclose relevant data to the following recipients only where necessary for the purposes in this Policy:

  • Infrastructure and authentication providers that host data, deliver files, protect traffic, maintain backups, and support account sign-in.
  • AI model, inference, routing, and content-safety providers that process the material required for your selected feature, with the safeguards described in Section 5.
  • Payment providers, currently Stripe, that process transactions and may act as separate controllers for activities such as fraud prevention and legal compliance. Their own notice is available at stripe.com/privacy.
  • Support, email, diagnostics, analytics, and consent-management providers that perform the relevant operational tasks under appropriate restrictions.
  • Referral or advertising partners only to the extent described in Section 7 and subject to the required choices. We do not give these partners access to private creative content for advertising.
  • People you choose to share with. Where an organization workspace exists, authorized administrators and collaborators may access data within the permissions and notices for that workspace. Public sharing can make selected content accessible to anyone.
  • Professional advisers, regulators, courts, or law enforcement when a lawful and necessary disclosure is required, or to establish or defend rights. We assess requests and disclose only what is appropriate.
  • Prospective or actual parties to a merger, acquisition, financing, or asset transfer, and their advisers, subject to confidentiality, data minimization, and applicable legal safeguards. A business transfer does not authorize unrelated uses without the necessary notice and legal basis.

Current provider information is available by contacting support@vose.ai. This information identifies the relevant service, contracting entity, purpose, location, and safeguards.

Within Vose, access is limited to personnel who need it for authorized tasks. We may inspect relevant content to investigate support requests, security incidents, or abuse; visibility restrictions do not mean that no human can ever access it.

7. Cookies, marketing, and referral tracking

We use cookies and similar technologies for essential functions such as authentication, session security, and remembering privacy choices. These functions may operate without consent where the law permits. Optional preference, analytics, referral-attribution, and advertising technologies are used only in accordance with the choices and legal requirements that apply to them.

In the EEA and other places requiring prior consent, we do not activate non-essential technologies before your choice. You can accept, reject, or choose categories and later change your choice through . Rejecting optional cookies does not prevent basic account use. Browser controls are additional to, rather than a replacement for, the consent controls we provide.

The cookie settings panel identifies the technologies actually used, their providers, purposes, duration, and whether they involve third-party access. Optional third-party embeds are subject to the same consent requirements where applicable.

If you arrive through an affiliate link or use a referral code, attribution may connect the referral with a sign-up or purchase so commission can be calculated. We minimize information provided to affiliates. [INSERT AFFILIATE DISCLOSURE: state whether affiliates receive only aggregate or pseudonymous conversion data or also identifiable customer information.]

We do not sell personal data or share it for cross-context behavioral advertising, and we do not process it for targeted advertising as those terms are defined under applicable US state privacy laws. Ordinary service-provider disclosures are subject to appropriate contractual restrictions.

You can unsubscribe from marketing through the link in a message or by contacting us. We may still send necessary account, billing, security, and legal notices. Where applicable law requires us to honor an opt-out preference signal such as Global Privacy Control, we do so. A privacy signal does not itself sign you out or erase your account.

8. International processing

Vose operates from Spain, but providers may process personal data outside the EEA. Our backend and databases are hosted with Google Cloud and Firebase in the United States, media files are stored and delivered through Cloudflare’s global network, and AI providers may process requests in the United States, Singapore, or other countries depending on the model you select. Remote support access from another country can also be a transfer.

Where a transfer requires safeguards under the GDPR, we use an applicable adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses, with transfer assessments and supplementary measures where necessary. UK or Swiss data receives the corresponding protections where those laws apply. We rely on a certified transfer framework only for a recipient and processing covered by a currently valid certification.

You may ask support@vose.ai for information or a copy of the relevant safeguards, subject to necessary redactions. Using Vose does not constitute blanket consent to an unprotected international transfer. Provider selection and feature availability must respect these requirements.

9. How long we keep data

We keep identifiable data only as long as needed for the stated purpose, taking account of your choices, the service you request, legal duties, and proportionate dispute or security needs. The following rules apply, subject to necessary legal holds.

Account and creative content

We keep active account information while you maintain an account. Content and project history remain available according to your plan and until you delete them, subject to the retention limits disclosed in the Service. [INSERT PLAN-SPECIFIC RETENTION: describe free accounts, active subscriptions, canceled subscriptions, and inactive accounts if their rules differ.]

After a valid deletion request, we remove or anonymize the relevant account or content data from active systems within [INSERT ACTIVE-SYSTEM DELETION PERIOD]. Residual backups are overwritten or expire within [INSERT MAXIMUM BACKUP PERIOD]. Backup data retained during that period is isolated from ordinary use, and deletion requests are reapplied if a backup is restored. Provider copies are handled under the verified schedules in Section 5.

Other operational records

Technical and security logs are retained for [INSERT LOG RETENTION PERIOD], unless a specific incident requires relevant records to be kept longer. Support records are retained for [INSERT SUPPORT RETENTION PERIOD AFTER CASE CLOSURE] where needed to resolve the issue and related claims. Financial records are kept for the applicable statutory accounting and tax period, as set out in [INSERT CONFIRMED FINANCIAL RETENTION RULE].

Consent records and a minimal suppression record may be retained to show and honor your choices. Information needed for a specific legal claim is restricted and kept only for the relevant limitation or proceedings period. We may retain statistics after irreversible anonymization; removing a name alone does not make data anonymous.

Deleting Vose content cannot erase independent copies previously downloaded by people you shared it with. If we lawfully retain some data after deletion, we restrict its use to the reason for retention and delete it when that reason ends.

10. Security

We use technical and organizational measures appropriate to the risks, including access restrictions and safeguards for storage and transmission. The specific controls depend on the system and data involved. No service can guarantee absolute security. We will meet applicable personal-data breach assessment and notification obligations.

Project visibility and direct file access may differ. Media files and share links can be opened by anyone who has the link, without signing in, and remain accessible until you delete the content. Avoid publicly sharing links to confidential or personal media. We do not promise end-to-end encryption or exclusive EEA hosting unless a separate agreement expressly provides it.

11. Your rights and choices

Depending on applicable law and the circumstances, you may request access to your personal data, correction, deletion, restriction, a portable copy, and information about recipients or sources. You may object to processing based on legitimate interests, and you may object to direct marketing at any time. Where processing relies on consent, you may withdraw it as easily as you gave it; this does not affect lawful processing before withdrawal.

Contact support@vose.ai to exercise a right. You do not need a paid subscription. We may request proportionate information to verify your identity or authority, but will not require unnecessary identity documents. We generally respond to GDPR requests within one month. A complex or numerous request may require up to two additional months; if so, we will explain the extension within the first month. Requests are normally free, subject only to lawful exceptions.

You may complain to the Spanish Data Protection Agency, Agencia Española de Protección de Datos, at www.aepd.es, or to another competent supervisory authority, including in the EEA country where you live or work. You do not have to contact us first. Where applicable, UK residents may contact the Information Commissioner’s Office at ico.org.uk.

If we process the relevant data solely for an organization as its processor, we will direct or forward your request to that organization and assist it as required. We remain responsible for requests about processing for which Vose is the controller.

12. Automated checks and decisions

We use automated systems to generate content and may use automated fraud and safety checks to flag, refuse, or pause requests and activity. Their purpose is to enforce content restrictions, protect accounts, and prevent payment abuse; errors are possible. You may ask for human review through support@vose.ai.

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects without a lawful basis and the safeguards required by applicable law. If we introduce such a decision process, we will first provide the required information about its operation, consequences, and your rights.

13. Children

The Service is intended for adults who meet the eligibility requirements in our Terms. We do not knowingly allow people under 18 to create accounts. If you believe a child has provided personal data through an unauthorized account, contact support@vose.ai so we can investigate and take appropriate action.

An adult may submit media containing a child only where lawful, authorized, and permitted by our content rules. The child’s data remains protected by applicable law. An adult account does not remove the need for appropriate permissions or special safeguards, and all sexual or exploitative depictions of children are prohibited.

14. Additional information for US state residents

This section applies where a US state privacy law covers you and our processing. The categories of data and sources are described in Section 2, purposes in Section 3, recipients in Section 6, retention in Section 9, and our sale, sharing, and targeted-advertising position in Section 7.

Subject to the applicable law, you may have rights to know or confirm processing, access, correct, delete, and obtain a portable copy of personal data, to opt out of sale, sharing, targeted advertising, or certain profiling, and to limit qualifying uses of sensitive information. We will not unlawfully discriminate against you for exercising a right. Sensitive information is handled for the purposes described in this Policy and subject to any additional consent or limitation requirements.

Submit requests to support@vose.ai. An authorized agent may submit a request where permitted; we may verify the agent’s authority and your identity where lawful. Opt-out requests will not be subjected to verification that the law prohibits. We honor legally required browser opt-out signals as described in Section 7.

If we deny a request, we explain the reason and any available appeal process. Where state law grants an appeal, email support@vose.ai with “Privacy appeal” and the request reference. We will respond within the applicable deadline and provide information about contacting the relevant state authority if the appeal is denied. California and other state response periods apply where they require a different procedure from the GDPR process above.

15. Changes and contact

We will update this Policy when our practices or legal requirements change and revise the date above. We will give appropriate notice of material changes before they take effect and obtain new consent where required. Continued use does not replace any consent that the law requires us to obtain separately.

For questions about this Policy or your data, contact support@vose.ai or write to Vose Technologies S.L., Barrio San Pedro 31, 39193, Arnuero, Spain.

© 2026 Vose Technologies S.L. 保留所有权利。

帮助中心Cookie 声明条款隐私