HesperaLegal

Privacy Policy

Hespera AI, LLC 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA

Version 1.0 · Effective from 26 September 2026


1. In short

Hespera is a creative studio for businesses and for individuals. Our customers — we call them clients — use Hespera to run a catalogue, generate images and video, talk to their own buyers, and sell.

That means we handle two very different kinds of information, and the rules differ for each:

  • Information about our clients — the account you open with us. Here we decide why we hold it, and this policy governs it.
  • Information our clients bring with them — their buyers' names, phone numbers, delivery addresses, chat messages. Here we act only on the client's instructions. We do not decide what happens to it, we do not use it for our own purposes, and we do not sell it. The client's own privacy notice governs that data; ours describes how we protect it. The terms of that arrangement are in our Data Processing Agreement.

If you are a buyer of one of our clients and want your data corrected or deleted, the fastest route is to ask that business directly. You can also write to us and we will pass the request on.

2. What we collect about our clients

To create and secure an account. Email address, password (stored only as a cryptographic hash — we never see it), and, if you enable it, two-factor authentication data.

To bill you. Subscription plan, credit balance, payment history. Card details never reach us — they go directly to our payment provider, Stripe, and we only ever see the last digits and the outcome of a charge.

To run the product. Your workspace: brand settings, catalogue, projects, generated images and video, and the prompts you write.

If you join the waiting list. Only your email address, plus whatever you choose to tell us about yourself in the optional second step.

Technical information. Your IP address is used to limit how often the waiting-list form can be submitted from one place. It is held in the memory of the server for a few minutes and is not written to our database. Where we operate advertising features, we store a hashed IP address in an abuse registry to stop banned accounts from returning under a new name. Our infrastructure providers keep their own access logs, which contain IP addresses — see section 8.

3. What we handle on behalf of our clients

When a client uses Hespera, information about their customers passes through us:

  • contacts and companies in their CRM — names, email addresses, phone numbers, postal addresses;
  • conversations in their chat widget, including anything a visitor types or uploads;
  • appointment bookings — name and phone number;
  • delivery details for orders — recipient name, phone number, city and pick-up point;
  • their suppliers and staff records.

We hold this to provide the service, and for no other reason. We do not analyse it for our own ends, we do not build profiles from it, and we do not disclose it except to the sub-processors listed in section 8.

4. Why we are allowed to hold it

Under European data protection law we rely on the following grounds:

WhatGround
Running your account and providing the servicePerformance of our contract with you
Taking payment, keeping tax recordsContract, and our legal obligations
Keeping the service secure, preventing abuseOur legitimate interest in a working service
Waiting list and product announcementsYour consent, withdrawable at any time
Data belonging to your customersYour documented instructions, as our client

5. Artificial intelligence

Generating an image, a video or a text means sending your request — the prompt, and any images you attached — to a model provider. Which providers we use is listed at Sub-processors.

We do not train models on your content, and we do not permit our providers to. We use these providers under commercial terms that exclude training on submitted data.

Providers do retain requests for a short period to detect abuse of their own systems. That is their retention, not ours, and it is described in their own terms.

Where the law requires it, we mark content as AI-generated and disclose when you are talking to a machine rather than a person. See AI Disclosure.

6. What we do not do

  • We do not sell personal data, and we never have.
  • We do not share it for anyone else's advertising.
  • We do not use content our clients create to train models.
  • We do not read client workspaces except when asked for support, or where we are legally compelled, or where an automated check flags abuse.

7. Where your data is

Our systems run in Europe:

Where
Database and sign-inFrankfurt, Germany
Files, images and videoEuropean Union
Application serversNetherlands
Website and workspaceStockholm, Sweden

Some data does leave Europe, and these are the cases:

  • requests to AI providers — the prompt, and any images you attached, when you generate something; most of these providers operate in the United States;
  • payments — handled by Stripe, in Ireland and the United States;
  • email, text messages and push notifications — sent through providers in the United States;
  • sales measurement — when a purchase completes, our server reports it to Google Analytics in the United States.

Each provider is named at Sub-processors. These transfers rely on the European Commission's Standard Contractual Clauses, or on another safeguard recognised by European data protection law.

Hespera AI, LLC is a company registered in the United States, so our own staff access to data constitutes a transfer as well, covered by the same clauses.

8. Who else touches the data

We use other companies to run Hespera — hosting, storage, payments, email, AI models. Each of them acts under a written contract that binds them to the same protections we offer you.

The full list, with what each one does and where, is published and kept current at Sub-processors. We announce changes to that list 30 days before they take effect, so that clients have time to object.

Some of these providers keep access logs containing IP addresses, as any hosting provider does.

9. Apps written by other people

The editor can run small apps written by developers outside our company. They are not sub-processors: they act for you, at the moment you use them, and only with what you allow.

An app receives nothing until you use it, and then only what you allowed. It never receives your login, your payment details, or anything you have not selected. It runs in an isolated sandbox, served from a separate domain, with no access to your account.

An app may reach the internet only at the addresses it declared, and only if it declared any. That restriction is enforced by your browser, not by the developer's promise. Beside the developer's name you are shown those addresses and a sentence, written by the developer, saying what is sent there and why.

Where an app both reads your work and has a declared address, we tell you before it runs the first time. In that case the developer becomes an independent controller of what they receive, under the App Developer Terms: they must not use it to train models or build profiles, they must delete it on request, and they must tell us of any breach within 72 hours. That is a contract, not a technical guarantee — an app given a photograph has seen it.

We keep a record, for 12 months, of what each app did in your workspace: which requests it made and which were refused. You can read it in your settings, where you can also switch any app off. We can switch an app off for everyone at once, and do so where we see a risk.

10. How long we keep it

WhatHow long
Account and workspaceWhile your account is open
After you delete your account30 days in a recoverable state, then permanently erased
BackupsUp to a further 30 days, after which they roll off
Conversations in the chat widget90 days of inactivity, then 30 days recoverable, then erased
Billing recordsAs long as tax law requires us to keep them
Abuse registry (hashed)Until the reason for the entry no longer applies

Deleting your account is described at Delete Your Account.

11. Your rights

Wherever you live, you may ask us to show you what we hold, correct it, delete it, export it in a portable form, restrict what we do with it, or object to processing we base on legitimate interest. Where we rely on consent, you may withdraw it at any time.

Residents of California and other US states with comparable laws have equivalent rights, including the right not to be discriminated against for exercising them.

Write to support@hespera.ai or use Data Requests. We answer within 30 days. We do not charge for this, and we will not ask you for anything beyond what we need to be sure it is really you.

If we get it wrong, you may complain to your national data protection authority. We would rather you told us first.

12. Cookies

We use only the cookies the product needs to work, or that remember a choice you made: they keep you signed in, remember your workspace and language, and whether you collapsed the sidebar. If you arrive through someone's invitation link, a cookie remembers who invited you for 90 days.

We use no analytics cookies and no advertising tags, and nothing that follows you across other websites. If we ever add analytics, it will load only if you agree, and refusing will cost you nothing.

Separately, when a purchase completes our server reports the sale to Google Analytics directly, server to server, without placing anything on your device.

The detail is at Cookie Policy.

13. Age

Hespera is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will remove it.

14. Security

Access to production data is limited to the founder of the company; no one else has it. Data is encrypted in transit, and our database and file storage encrypt it at rest. Credentials you give us for other services are encrypted once more, with a key kept outside the database. Access between our own services is authenticated and every request is traceable. Passwords are stored as hashes and cannot be read, by us or by anyone else.

We publish how to report a vulnerability at Security.

If a breach puts your rights at risk, we will notify the relevant authority within 72 hours and tell you without undue delay.

15. Changes

When we change this policy we update the version and date at the top and keep the previous version available. If a change materially affects your rights, we will tell you before it takes effect — by email, or in the product.

16. Talk to us

support@hespera.ai Hespera AI, LLC, 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA

This policy is governed by the laws of the State of Delaware, without prejudice to rights you hold under the mandatory law of the country you live in.

Back to hespera.ai