Privacy Policy
Effective Date: 10.03.2026
Keilascom OÜ ("Company", "we", "us", or "our"), a company registered in the Republic of Estonia (Harju maakond, Tallinn, Lasnamäe linnaosa, Lõõtsa tn 2a, 11415, D-U-N-S® Number: 565746865), respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website https://allnight.ai and use our artificial intelligence media generation services (the "Service" or "Platform").
This Privacy Policy is designed to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws. Due to the mature nature of the content generated on this Platform, we implement stringent data minimization and security practices.
1. Information We Collect
We collect personal data that you voluntarily provide to us when you register on the Platform, express an interest in obtaining information about us or our products, or otherwise contact us.
- Account Information: Name, email address, password, and communication preferences.
- Age Verification Data: Because the Service is strictly limited to users aged 18 and older, we may collect your date of birth or utilize secure third-party age verification services to ensure legal compliance. We do not store biometric IDs permanently unless required by law.
- Financial Data: We do not store your full credit card details. All payments are processed by secure, PCI-DSS compliant third-party payment processors. Payments may be processed via major credit and debit cards (including, but not limited to, Visa and Mastercard), supported cryptocurrencies, and other authorized gateways (e.g., Stripe, Crypto.com). We only receive billing confirmations and partial payment details (e.g., the last 4 digits of a card) necessary to manage your subscription.
- AI Input Data: Text prompts, images, video files, audio files, and parameters you submit to the Service to generate Output. Given the nature of the Service, we urge Users not to submit personally identifiable information or non-consensual images as Input, in strict accordance with our Terms of Service.
- Automatically Collected Data: IP addresses, browser types, operating systems, device information, and usage metrics (such as timestamps and interaction with the Platform) collected via cookies and tracking technologies.
2. How We Use Your Information
We process your personal information for a variety of legitimate business purposes, including:
- To Provide and Maintain the Service: Creating your account, verifying your age eligibility, processing your inputs through our AI models, and delivering the generated Output.
- To Process Payments: Managing subscriptions, processing transactions in supported currencies (including Euros, USD, and cryptocurrencies), and preventing fraudulent transactions or chargebacks.
- To Improve the AI Models: We may use aggregated and anonymized Input and Output data to improve the performance of our Service. If we use third-party AI API providers, we ensure their enterprise agreements prohibit the use of your private data to train their foundational models without our explicit consent.
- For Customer Support: Responding to your inquiries, troubleshooting technical issues, and resolving disputes.
- For Legal Compliance: Complying with applicable laws, enforcing our Acceptable Use Policy, and responding to lawful requests from authorities.
3. How We Share Your Information
We do not sell your personal data. We only share your information with the following categories of third parties under strict confidentiality agreements:
- Service Providers & Sub-processors: Cloud hosting providers, AI infrastructure providers (third-party APIs), age verification partners, and database management services required to run the Platform.
- Payment Gateways: Entities like Stripe or Crypto.com to securely facilitate your transactions.
- Legal Obligations: If required by law, court order, or governmental request to protect our rights, your safety, or the safety of others.
4. International Data Transfers
Our servers and primary processing operations are located within the European Economic Area (EEA). However, some of our third-party service providers may process data outside the EEA. In such cases, we ensure that appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs), are in place to guarantee an adequate level of data protection.
5. Data Retention
We keep your personal information only for as long as necessary for the purposes set out in this Privacy Policy, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). Generative Assets (Input and Output) may be temporarily stored on our servers to allow you to access your history, but you are strongly encouraged to delete sensitive assets from your account dashboard. Deleted assets are permanently purged from our active servers.
6. Your Privacy Rights (GDPR)
If you are a resident of the European Economic Area (EEA) or the UK, you have specific rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request that we correct any inaccurate or incomplete data.
- Right to Erasure (Right to be Forgotten): You can request the deletion of your personal data, subject to certain legal exceptions.
- Right to Restrict Processing: You can ask us to suspend the processing of your data under specific circumstances.
- Right to Data Portability: You can request your data in a structured, commonly used, and machine-readable format.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
7. Data Security
We implement robust organizational and technical security measures (including encryption, SSL, and access controls) designed to protect your personal data from unauthorized access, loss, or alteration. Due to the sensitive nature of the Platform, we utilize strict access limitations. However, no electronic transmission over the internet can be guaranteed to be 100% secure.
8. Strict Age Restriction and Children's Privacy
Our Service is strictly limited to individuals who are at least eighteen (18) years of age, or the age of legal majority in their jurisdiction. The Platform may contain mature content, and we do not knowingly collect personal information from individuals under 18. If we become aware that we have collected personal data from a minor, we will take immediate steps to terminate the account and permanently delete that information.
9. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Effective Date".
10. Contact Us
If you have questions, comments, or concerns about this Privacy Policy or our data practices, or if you wish to contact our Data Protection Officer (DPO), please reach out to us at:
Keilascom OÜHarju maakond, Tallinn, Lasnamäe linnaosa, Lõõtsa tn 2a, 11415, Estonia
[email protected]