Privacy Policy
Hespera AI, LLC 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA
Version 1.0 · Effective from 26 September 2026
1. In short
Hespera is a creative studio for businesses and for individuals. Our customers — we call them clients — use Hespera to run a catalogue, generate images and video, talk to their own buyers, and sell.
That means we handle two very different kinds of information, and the rules differ for each:
- Information about our clients — the account you open with us. Here we decide why we hold it, and this policy governs it.
- Information our clients bring with them — their buyers' names, phone numbers, delivery addresses, chat messages. Here we act only on the client's instructions. We do not decide what happens to it, we do not use it for our own purposes, and we do not sell it. The client's own privacy notice governs that data; ours describes how we protect it. The terms of that arrangement are in our Data Processing Agreement.
If you are a buyer of one of our clients and want your data corrected or deleted, the fastest route is to ask that business directly. You can also write to us and we will pass the request on.
2. What we collect about our clients
To create and secure an account. Email address, password (stored only as a cryptographic hash — we never see it), and, if you enable it, two-factor authentication data.
To bill you. Subscription plan, credit balance, payment history. Card details never reach us — they go directly to our payment provider, Stripe, and we only ever see the last digits and the outcome of a charge.
To run the product. Your workspace: brand settings, catalogue, projects, generated images and video, and the prompts you write.
If you join the waiting list. Only your email address, plus whatever you choose to tell us about yourself in the optional second step.
Technical information. Your IP address is used to limit how often the waiting-list form can be submitted from one place. It is held in the memory of the server for a few minutes and is not written to our database. Where we operate advertising features, we store a hashed IP address in an abuse registry to stop banned accounts from returning under a new name. Our infrastructure providers keep their own access logs, which contain IP addresses — see section 8.
3. What we handle on behalf of our clients
When a client uses Hespera, information about their customers passes through us:
- contacts and companies in their CRM — names, email addresses, phone numbers, postal addresses;
- conversations in their chat widget, including anything a visitor types or uploads;
- appointment bookings — name and phone number;
- delivery details for orders — recipient name, phone number, city and pick-up point;
- their suppliers and staff records.
We hold this to provide the service, and for no other reason. We do not analyse it for our own ends, we do not build profiles from it, and we do not disclose it except to the sub-processors listed in section 8.
4. Why we are allowed to hold it
Under European data protection law we rely on the following grounds:
| What | Ground |
|---|---|
| Running your account and providing the service | Performance of our contract with you |
| Taking payment, keeping tax records | Contract, and our legal obligations |
| Keeping the service secure, preventing abuse | Our legitimate interest in a working service |
| Waiting list and product announcements | Your consent, withdrawable at any time |
| Data belonging to your customers | Your documented instructions, as our client |
5. Artificial intelligence
Generating an image, a video or a text means sending your request — the prompt, and any images you attached — to a model provider. Which providers we use is listed at Sub-processors.
We do not train models on your content, and we do not permit our providers to. We use these providers under commercial terms that exclude training on submitted data.
Providers do retain requests for a short period to detect abuse of their own systems. That is their retention, not ours, and it is described in their own terms.
Where the law requires it, we mark content as AI-generated and disclose when you are talking to a machine rather than a person. See AI Disclosure.
6. What we do not do
- We do not sell personal data, and we never have.
- We do not share it for anyone else's advertising.
- We do not use content our clients create to train models.
- We do not read client workspaces except when asked for support, or where we are legally compelled, or where an automated check flags abuse.
7. Where your data is
Our systems run in Europe:
| Where | |
|---|---|
| Database and sign-in | Frankfurt, Germany |
| Files, images and video | European Union |
| Application servers | Netherlands |
| Website and workspace | Stockholm, Sweden |
Some data does leave Europe, and these are the cases:
- requests to AI providers — the prompt, and any images you attached, when you generate something; most of these providers operate in the United States;
- payments — handled by Stripe, in Ireland and the United States;
- email, text messages and push notifications — sent through providers in the United States;
- sales measurement — when a purchase completes, our server reports it to Google Analytics in the United States.
Each provider is named at Sub-processors. These transfers rely on the European Commission's Standard Contractual Clauses, or on another safeguard recognised by European data protection law.
Hespera AI, LLC is a company registered in the United States, so our own staff access to data constitutes a transfer as well, covered by the same clauses.
8. Who else touches the data
We use other companies to run Hespera — hosting, storage, payments, email, AI models. Each of them acts under a written contract that binds them to the same protections we offer you.
The full list, with what each one does and where, is published and kept current at Sub-processors. We announce changes to that list 30 days before they take effect, so that clients have time to object.
Some of these providers keep access logs containing IP addresses, as any hosting provider does.
9. Apps written by other people
The editor can run small apps written by developers outside our company. They are not sub-processors: they act for you, at the moment you use them, and only with what you allow.
An app receives nothing until you use it, and then only what you allowed. It never receives your login, your payment details, or anything you have not selected. It runs in an isolated sandbox, served from a separate domain, with no access to your account.
An app may reach the internet only at the addresses it declared, and only if it declared any. That restriction is enforced by your browser, not by the developer's promise. Beside the developer's name you are shown those addresses and a sentence, written by the developer, saying what is sent there and why.
Where an app both reads your work and has a declared address, we tell you before it runs the first time. In that case the developer becomes an independent controller of what they receive, under the App Developer Terms: they must not use it to train models or build profiles, they must delete it on request, and they must tell us of any breach within 72 hours. That is a contract, not a technical guarantee — an app given a photograph has seen it.
We keep a record, for 12 months, of what each app did in your workspace: which requests it made and which were refused. You can read it in your settings, where you can also switch any app off. We can switch an app off for everyone at once, and do so where we see a risk.
10. How long we keep it
| What | How long |
|---|---|
| Account and workspace | While your account is open |
| After you delete your account | 30 days in a recoverable state, then permanently erased |
| Backups | Up to a further 30 days, after which they roll off |
| Conversations in the chat widget | 90 days of inactivity, then 30 days recoverable, then erased |
| Billing records | As long as tax law requires us to keep them |
| Abuse registry (hashed) | Until the reason for the entry no longer applies |
Deleting your account is described at Delete Your Account.
11. Your rights
Wherever you live, you may ask us to show you what we hold, correct it, delete it, export it in a portable form, restrict what we do with it, or object to processing we base on legitimate interest. Where we rely on consent, you may withdraw it at any time.
Residents of California and other US states with comparable laws have equivalent rights, including the right not to be discriminated against for exercising them.
Write to support@hespera.ai or use Data Requests. We answer within 30 days. We do not charge for this, and we will not ask you for anything beyond what we need to be sure it is really you.
If we get it wrong, you may complain to your national data protection authority. We would rather you told us first.
12. Cookies
We use only the cookies the product needs to work, or that remember a choice you made: they keep you signed in, remember your workspace and language, and whether you collapsed the sidebar. If you arrive through someone's invitation link, a cookie remembers who invited you for 90 days.
We use no analytics cookies and no advertising tags, and nothing that follows you across other websites. If we ever add analytics, it will load only if you agree, and refusing will cost you nothing.
Separately, when a purchase completes our server reports the sale to Google Analytics directly, server to server, without placing anything on your device.
The detail is at Cookie Policy.
13. Age
Hespera is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will remove it.
14. Security
Access to production data is limited to the founder of the company; no one else has it. Data is encrypted in transit, and our database and file storage encrypt it at rest. Credentials you give us for other services are encrypted once more, with a key kept outside the database. Access between our own services is authenticated and every request is traceable. Passwords are stored as hashes and cannot be read, by us or by anyone else.
We publish how to report a vulnerability at Security.
If a breach puts your rights at risk, we will notify the relevant authority within 72 hours and tell you without undue delay.
15. Changes
When we change this policy we update the version and date at the top and keep the previous version available. If a change materially affects your rights, we will tell you before it takes effect — by email, or in the product.
16. Talk to us
support@hespera.ai Hespera AI, LLC, 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA
This policy is governed by the laws of the State of Delaware, without prejudice to rights you hold under the mandatory law of the country you live in.