Privacy Policy

Last updated: April 16, 2026

Company: LuTa Tech

Website: https://www.squarefacegenerator.ai

Contact: support@luta-tech.com

Privacy: privacy@squarefacegenerator.ai

1. Introduction

This Privacy Policy outlines how LuTa Tech ("Company," "we," "us," or "our") collects, uses, stores, and shares your data when you use our Square Face Generator service ("Service") and website (the "Site"). This policy also informs you of your legal privacy rights and how we comply with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

By using the Site and our Service, you consent to the collection and use of your Personal Data as described herein. If you do not agree with this policy, please discontinue use of the Service.

Key Definitions:

  • Personal Data: Any information that can identify an individual, such as name, email, and IP address.
  • Cookies: Small files placed on your device that store browsing information.
  • Service: Our AI-powered square face avatar and icon generation tools, account management, and related features.
  • Data Controller: LuTa Tech is the data controller responsible for your Personal Data.

2. Information We Collect

2.1 Account Information

  • Email address and name — collected via Google OAuth when you create an account.
  • Account preferences — subscription tier, language, and settings.

2.2 Payment Information

Payment details are processed securely through Creem, our payment processor. We do not store your credit card or bank information on our servers. We only retain transaction records (amount, date, plan type) for billing and legal purposes.

2.3 Uploaded Images and Face Data

Images you upload for avatar generation may contain human faces. These images are used solely to generate avatars using our AI effects and are automatically deleted after processing is complete. We process images only for avatar rendering purposes and do not use them for facial recognition, identification, or profiling.

In some cases, images may be temporarily shared with trusted third-party rendering providers who are contractually bound to not retain or misuse your data. Your use of these features indicates your consent to this limited processing.

2.4 Generated Avatars

Avatars you generate are accessible via links provided by our AI processing providers. We do not control the availability of these links and cannot guarantee permanent access. We recommend downloading your avatars promptly. You retain ownership of all content you create.

2.5 Usage Data

We automatically collect anonymized usage analytics including device type, browser type, pages visited, features used, and general geographic location to improve our service. We do not track individual users across sessions for advertising purposes.

3. How We Use Your Information

  • Service Delivery: To provide, maintain, and improve our avatar generation service
  • Payment Processing: To process payments and manage your subscription via Creem
  • Communication: To respond to support requests and send service-related notifications
  • Security: To prevent fraud, abuse, and unauthorized access
  • Analytics: To analyze usage patterns and improve our service using aggregated, non-identifiable data
  • Legal Compliance: To comply with tax, accounting, and applicable legal obligations

We may use aggregated, non-identifiable data for service improvement and model training. Personal data is never used to train third-party AI models without your explicit consent.

4. Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), we process your Personal Data based on the following legal grounds:

  • Performance of Contract: To provide the avatar generation service you requested (Art. 6(1)(b) GDPR)
  • Legitimate Interests: For security, fraud prevention, and service improvement (Art. 6(1)(f) GDPR)
  • Consent: For optional analytics and communications beyond what is necessary for the service (Art. 6(1)(a) GDPR)
  • Legal Obligation: To comply with tax, accounting, and other legal requirements (Art. 6(1)(c) GDPR)

5. Third-Party Services and Data Sharing

We share data with the following service providers to operate our Service:

  • Supabase — Database and authentication. Shares: account data, usage data.
  • Creem — Payment processing. Shares: email, transaction amounts, billing cycle.
  • our AI processing provider — AI image processing API. Shares: uploaded images (temporarily, for rendering only).
  • Google OAuth — Account authentication. Shares: email and name upon sign-in.

These third-party services have their own privacy policies. We select partners that maintain appropriate security standards. We are not responsible for the privacy practices of these third parties.

6. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States and China, where our service providers (e.g., Supabase) operate. Where required by applicable law, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) and data processing agreements to ensure your data is adequately protected.

7. Cookies and Tracking

We use the following cookies:

  • Essential Cookies — Required for authentication and session management (e.g., supabase.auth.token)
  • Analytics Cookies — Used to understand how visitors interact with our website (e.g., Google Analytics _ga, _gid)

You can set your browser to reject cookies, but this may affect the functionality of the Site. You may opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on. We do not use cookies for advertising or cross-site tracking.

8. Data Storage and Security

Your data is stored on secure servers and encrypted in transit using TLS/SSL. We use industry-standard security measures to protect your information. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security. It is your responsibility to secure your device and login credentials.

Data Breach Notification

In the event of a data breach that affects your Personal Data, we will notify affected users and relevant supervisory authorities within 72 hours as required by applicable law.

9. Content Restrictions

The following restrictions apply to all content generated, uploaded, or shared:

  • Illegal Content: Promotes or facilitates illegal activities
  • Harmful Content: Promotes hatred, violence, or discrimination against protected groups
  • Explicit Content: Pornographic or excessively violent material
  • IP Infringement: Violates copyrights, trademarks, or other intellectual property rights
  • False Content: Intentionally false or deceptive material
  • Privacy Violations: Discloses personal information without consent
  • Hate Speech: Promotes hatred or hostility
  • Harassment: Targets individuals with intent to harass, bully, or intimidate
  • Self-Harm: Promotes or glorifies self-harm or suicide
  • Spam and Malware: Spam or content containing malicious code
  • Impersonation: Deceptive impersonation of individuals or organizations

AI-Specific Rules:

  • Do not present AI-generated content as real footage without proper disclosure
  • Do not input sensitive personal data (e.g., race, beliefs, health data) into our AI tools
  • Do not use our AI tools to generate content that violates the prohibitions listed above

We reserve the right to remove violating content and take appropriate action, including account suspension or termination.

10. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your Personal Data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure ("Right to be Forgotten"): Request deletion of your data (subject to legal retention periods)
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: For activities based on consent (e.g., analytics cookies)

To exercise any of these rights, please email us at privacy@squarefacegenerator.ai. We will respond to your request within 30 days as required by applicable law.

11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the CCPA:

  • Right to Know: You may request information about the Personal Data we have collected, used, and disclosed in the past 12 months.
  • Right to Delete: You may request that we delete your Personal Data, subject to certain exceptions.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

We do not sell your Personal Information. To exercise CCPA rights, contact us at privacy@squarefacegenerator.ai.

12. Data Retention

  • Uploaded images: Deleted after avatar generation processing is complete.
  • Generated avatars: Availability depends on our AI processing providers. We recommend downloading your avatars promptly. We do not control third-party link expiration.
  • Account data: Retained until you request deletion or close your account.
  • Payment records: Retained for the duration required by applicable tax and accounting laws.
  • Anonymized usage data: May be retained indefinitely for analytics and service improvement.

13. Children's Privacy

Our service is not intended for children under 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected data from a child under 18, we will delete it promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Major updates may also be communicated via email or notices on the Website.

15. Contact Us

For questions about this Privacy Policy or to exercise your data rights, contact us at:

General Support: support@luta-tech.com

Privacy Inquiries: privacy@squarefacegenerator.ai

By using Square Face Generator, you acknowledge that you have read, understood, and agree to this Privacy Policy and our Terms of Service.