Privacy Policy

Last updated: 5 October 2026

This Privacy Policy explains how DIY AI collects and uses personal information when you visit diyai.io, create an account, use DIY AI Studio, purchase a subscription or credits, leave a comment, or contact us.

Information we collect

Accounts, subscriptions and communications

We collect information you provide when registering or managing an account, including your name, email address, username, authentication information and account preferences. We also process membership status, introductory-offer eligibility, subscription records, credit balances, transaction history, billing information and correspondence with our support team.

If you subscribe to a newsletter or other marketing communications, we process your contact details, communication preferences and the record of your subscription or withdrawal.

Studio prompts, uploads and generated content

Depending on the feature you use, Studio processes text prompts, instructions, reference images, photographs, video, audio, voice samples and other material you submit. It also processes the resulting images, videos, music, speech, transcripts and other outputs.

Associated information can include your selected model, generation settings, project or asset details, job identifiers, processing status, timestamps, credit usage, download activity and error information. Where a voice-cloning feature creates a reusable voice profile, the processing also includes the reference recording and any derived voice data needed for that feature.

Uploads and outputs may contain personal information about you or someone else. Files can also contain metadata, such as filenames, creation dates and embedded location information. Remove unnecessary metadata and personal information before uploading.

Technical and usage information

When you use the website or Studio, our service providers and we may collect IP addresses, browser and device information, operating system, referring pages, pages visited, feature interactions, timestamps, cookie identifiers and diagnostic or security logs. An approximate location may be inferred from an IP address.

We receive information directly from you, from your interactions with our services, and from providers involved in payments, hosting, security, analytics and AI processing. Another user may also supply information about you in an upload or support request.

Why we use personal information and our lawful bases

Providing the service and performing our contract: We use account information, submitted content, generation records and payment information to register users, authenticate access, carry out requested Studio tasks, deliver results, administer subscriptions and credits, and provide related support. Without information necessary for these activities, we may be unable to provide the requested service.

Legitimate interests: We use proportionate information to maintain and secure the service, prevent fraud and misuse, investigate faults, moderate comments, resolve complaints and protect legal rights. We balance these interests against individuals’ rights and reasonable expectations. They do not override consent requirements for optional tracking.

Where a request contains personal information about someone other than the account holder, the account holder’s contract does not automatically provide a lawful basis for that other person’s information. Where appropriate, we rely on our legitimate interests in delivering the requested service, subject to that person’s rights and the nature of the information. Processing that requires consent or an additional legal condition must satisfy those requirements separately.

Consent: Where required, we obtain consent for optional cookies, session-replay tracking, marketing communications and any separately offered processing that relies on consent. You can withdraw that consent without affecting the lawfulness of earlier processing.

Legal obligations: We retain and use information where necessary to meet tax, accounting, regulatory and other legal requirements, or respond to a binding legal request.

How Studio uses third-party AI services

Studio is an online service. A generation, editing or transcription request may require us to send your prompt, relevant files or file-access links, settings and request metadata to external AI services. Those services can include a model provider, an API intermediary and the infrastructure provider hosting the model. The model’s brand name does not necessarily identify every organisation involved in processing the request.

When you choose a comparison or another workflow involving multiple models, relevant inputs may be sent to more than one provider to produce the results you requested.

Our staff and service providers may need access to relevant content or records to deliver a task, investigate a support issue, address suspected misuse or meet legal obligations. Access for those purposes is different from making your content public.

AI-provider details, training and secondary uses

Generating a result, creating a requested voice profile, retaining a security log and training a general-purpose AI model are different activities. You should not assume that using an API, paying for Studio or keeping a result out of a public gallery means that every provider offers zero retention or excludes all training and service-improvement uses.

Uploading content to complete a Studio task does not itself authorise us to publish that content in an article, testimonial, public dataset or marketing material. Any such use requires a separate appropriate permission or other lawful basis, with the relevant information provided to you.

Contact us before submitting confidential business material or using Studio for processing that requires a data-processing agreement, a particular storage location or specific privacy controls. This public policy is not itself a business data-processing agreement.

Information about other people, faces and voices

Only upload personal information that you are entitled to provide for the requested purpose. Explain the intended use to the people concerned and obtain any necessary permissions. Permission to possess a photograph or recording does not necessarily include permission to create a synthetic likeness, clone a voice or publish the result.

Do not submit passwords, private keys, payment-card details, identity documents or unnecessary sensitive information in a prompt or upload. Do not use Studio to process health records, intimate material or other specially protected information unless the relevant feature expressly supports that use and the required legal conditions and safeguards have been established.

If you believe that someone has uploaded your personal information, image or voice without proper authority, contact info@diyai.io. Include enough information to help us locate the material, but do not send additional sensitive documents unless we request them through an appropriate channel.

Payments and billing

Studio payments are processed through Stripe. Stripe collects payment details through its payment interface and processes information needed to complete transactions and carry out its payment, security and fraud-prevention functions.

We receive the billing and transaction information needed to administer your purchase, such as customer and subscription identifiers, payment status, amount, currency and invoice information. Stripe explains its handling of personal information in the Stripe Privacy Policy.

Cancelling a subscription does not automatically erase account information, generation history or records we must retain. Contact us to request account closure and deletion, and identify any active subscription so we can handle cancellation and closure together.

Cookies, analytics and session replay

We use cookies and similar technologies for account access, security, preferences, analytics and referral attribution. Some are necessary to provide a service you request; others are optional and require consent where applicable.

Our website uses Google Analytics 4 to understand traffic sources, page use and interactions with the service. We also use Microsoft Clarity for behavioural measurements, heatmaps and session replay to understand navigation problems and improve usability.

Session replay can reconstruct interactions such as clicks and scrolling and may capture visible page content, depending on the implementation and masking settings. Do not treat it as inherently anonymous. Google and Microsoft describe their processing in the Google Privacy Policy and Microsoft Privacy Statement.

Where consent is required, optional tracking is enabled only after you make the relevant choice. You can reject optional tracking or withdraw consent through the cookie controls without losing access to functionality that does not require it. Continuing to browse is not treated as consent. Browser settings can also remove or block cookies, although blocking necessary cookies may prevent login or checkout from working.

Cookies

If you choose to save your details when commenting, the site can remember your name, email address and website for one year. A temporary cookie used to check browser cookie support is discarded when you close the browser.

Standard login cookies normally last two days, or two weeks when “Remember Me” is selected. Screen-preference cookies normally last one year. Logging out removes the login cookies. An article-editing cookie records the post ID and normally expires after one day.

Comments, public content and embedded media

When you leave a comment, we collect the information entered in the comment form, along with your IP address and browser user agent, to publish and moderate comments and help detect spam. Comments may be checked by an automated spam-detection service.

A hashed identifier derived from your email address may be sent to Gravatar to check whether you use that service. A hash is not necessarily anonymous. After approval, your comment and associated profile image may be publicly visible. See Automattic’s Privacy Policy.

Content you publish publicly or share with others can be copied and redistributed. Public images may expose embedded location metadata. A file or download link may also allow access to anyone who has that link, depending on the feature and storage arrangement; an account login does not necessarily make every asset link access-restricted.

Articles may contain third-party videos, images or other embedded content. When loaded, those services may receive technical information and use tracking technologies, including recognising you if you are logged into their service. Their own privacy notices apply to their processing, alongside any choices available through our cookie controls.

Who receives personal information?

We share relevant information with providers involved in hosting, content delivery, file storage, security, email delivery, account and membership administration, payments, analytics and AI processing. Our infrastructure includes Cloudflare for website delivery and protection. The specific AI-processing arrangements are identified above.

Referral and affiliate systems may process referral identifiers, clicks, signups and attributed transaction information to measure referrals and administer commissions. Affiliate attribution does not itself give an affiliate permission to access your Studio prompts or files.

We may also disclose information to professional advisers, authorities or other parties where necessary to meet legal obligations, investigate fraud, protect rights or handle a dispute. If the business is sold or reorganised, relevant records may be disclosed to advisers and a prospective or new operator, subject to appropriate safeguards and notice where required.

Some recipients process information on our instructions; others are responsible for particular processing purposes of their own. Sharing information with a provider does not remove DIY AI’s responsibility for its own processing.

International processing

Our providers may process personal information outside the United Kingdom, including in the United States and other countries. The processing locations and safeguards for Studio content are identified in the AI data-handling information above.

Where a transfer requires a legal safeguard, the applicable arrangement must meet UK data-protection requirements. Depending on the recipient, this may involve an applicable adequacy arrangement, approved contractual safeguards, and the necessary transfer assessment. Contact us for information about the arrangement relevant to your data and how to obtain a copy of the applicable safeguards.

How long we keep information

We retain personal information only for as long as necessary for the relevant purpose. The criteria depend on the type of record, the service requested, account settings, support needs and any applicable legal obligations.

Account records: We keep information needed to administer an active account and, after closure, any records still needed for outstanding transactions, disputes, security or legal requirements.

Studio content and job records: Retention depends on completing and delivering the task, any saved-history or project functionality you use, applicable storage limits and deletion requests. Operational job and credit records may need to remain after an associated file has been deleted. Provider-specific retention is described in the AI data-handling information above.

Billing records: We keep invoices and transaction records for the periods required by applicable tax and accounting law and as necessary to resolve payment disputes.

Comments: Published comments and their metadata may remain while the discussion is available, potentially indefinitely, subject to moderation and applicable deletion rights.

Support, security, and analytics: Retention takes into account resolving the issue, the investigation period needed for a security event, and the configured analytics retention period. Marketing contact information is retained while the subscription remains active; a limited suppression record may remain to respect an unsubscribe request.

Deleting a file from a visible history does not necessarily remove related billing records, security logs or provider-held copies. Backup copies may take longer to be overwritten and remain subject to retention and security controls. We assess deletion requests across the systems concerned and explain any applicable legal exceptions.

Security and automated checks

We take reasonable technical and organisational steps to protect personal information. However, no website or online service can guarantee absolute security. Keep your account credentials secure and contact us promptly if you suspect unauthorised access.

Studio uses automated processing to generate outputs and manage functions such as membership eligibility, credit availability and processing status. Security and provider moderation checks may reject a request or flag activity for investigation. Contact us to request a review if you believe an automated action has incorrectly affected your access or content.

Your privacy rights

Depending on the circumstances and applicable law, you can request access to your personal information, correction of inaccurate information, deletion, restriction of processing, and a portable copy of information you provided where that right applies. You can also withdraw consent for processing that relies on it.

Your right to object: You can object to processing based on legitimate interests on grounds relating to your situation. You can object to direct marketing at any time.

Some profile information can be edited through your account. Contact info@diyai.io for an access, correction, deletion or other rights request, including one relating to information uploaded by another user. We may request proportionate information to verify your identity and locate the relevant records.

We normally respond within one month, subject to any extension or pause permitted by law. Some rights have exceptions; for example, deletion may not apply to information we must retain by law or need for a legal claim. We will explain any relevant restriction.

You can complain to the UK Information Commissioner’s Office through its complaints service. You may also have the right to contact your local data-protection authority. You do not have to complain to us first to exercise your right to contact a regulator.

Children’s information

Studio is designed for adult use rather than as a children’s service. This does not mean that a child’s personal information cannot appear in material uploaded by an adult. Anyone submitting permitted material involving a child must have the necessary authority, minimise the information included and take particular care over the child’s privacy and welfare.

If you are a parent or guardian concerned about an account, upload or generated content involving a child, contact us so that we can investigate and address the concern.

Changes to this policy

We may update this policy to reflect changes to our services, processing practices or legal obligations. The date at the top identifies the latest revision. Where a change requires additional notice or fresh consent, updating this page alone will not replace that requirement.