Privacy Policy

Effective date: September 2, 2026
Last updated: September 2, 2026

This Privacy Policy explains how Lightspeed Media Corp., an Arizona corporation doing business as PrivateCloud.ai and WOWify (“Lightspeed,” “PrivateCloud,” “WOWify,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal information in connection with PrivateCloud.ai, models.privatecloud.ai, the WOWify APIs made available through api.lightspeedcloud.ai, and related websites, dashboards, model catalogs, playgrounds, documentation, and services that link to this Policy (collectively, the “Services”).

This Policy should be read with our Terms of Service. It does not apply to a customer’s own products, websites, applications, or independent handling of personal information. When an API customer submits information about its end users, that customer ordinarily determines why and how the information is processed and is responsible for its own privacy notices, legal basis, and instructions.

1. Our Privacy Commitments for Customer Content

Our core rules are:

  1. We process customer prompts, uploads, and generations to provide the service requested by the customer.
  2. Lightspeed does not train or fine-tune AI models. Lightspeed operates the Services as an aggregator and accelerator of third-party models and does not use Customer Content for model training or fine-tuning. Upstream providers have their own retention and data-use practices, which may vary by model and processing route unless a separate written agreement states otherwise.
  3. We do not sell Customer Content or use it for advertising, marketing, publication, or unrelated product development.
  4. Studio customers control retention. PrivateCloud may store prompts, uploads, settings, and creations solely to serve them back to that customer through the account or Media Library. Customers can delete that content using available controls.
  5. API content is transient. WOWify API prompts, uploads, and outputs are processed to perform and deliver the requested result and are not maintained by Lightspeed as a permanent customer-content archive after delivery. Temporary processing or storage may be required for asynchronous generation, polling, callbacks, downloads, retries, requested support, security investigation, or legal compliance. Processing providers may temporarily retain generated media for service delivery and retrieval for up to seven days.
  6. Third-party processing is limited to what is needed. Model and infrastructure providers receive the content and technical information necessary to complete a request. Their retention and data-use practices may vary unless a separate written agreement states otherwise.
  7. No public use by default. Customer Content is not made public unless the customer deliberately uses a sharing, publishing, gallery, or other public feature and is told that the action will make the content public.

2. Definitions and Roles

“Customer Content” means prompts, instructions, messages, text, source and reference images, video, audio, documents, files, request metadata, and other material a customer or its end users submits, together with outputs generated specifically in response.

“Account Data” means information associated with a PrivateCloud or WOWify customer account, such as contact information, login records, access status, plan, and preferences.

“Operational Data” means content-free service records such as customer or API-key identifier, endpoint, model, timestamp, request identifier, status, latency, error code, approximate technical characteristics, credit usage, and security events.

For direct users of PrivateCloud, Lightspeed generally acts as the business or controller responsible for the personal information described in this Policy. For personal information submitted by a WOWify API customer about its end users, the API customer generally acts as the business or controller and Lightspeed acts as its service provider or processor, processing that information to provide the requested API service. The actual role depends on the circumstances and applicable law.

3. Information We Collect

3.1 Account and contact information

We may collect:

  1. name, business name, username, email address, telephone number, and business contact details;
  2. login credentials in protected form, access-token status, API keys, authentication events, and account-security information;
  3. age or adult-status confirmation and, when required for access, compliance, payments, or law, identity or business-verification information;
  4. communications, support requests, meeting records, feedback, and information you choose to provide; and
  5. account preferences, saved configuration, default settings, and communication choices.

3.2 Customer Content

Depending on the feature, Customer Content may include text prompts, conversations, images, faces and likeness references, video, audio, voice, documents, API payloads, generation settings, and resulting content. Some Customer Content may reveal sensitive information or intimate imagery. Do not submit information that is unnecessary for the selected function.

PrivateCloud features may technically analyze visual characteristics to perform image generation, editing, cloning, consistency, or compliance functions. Unless expressly stated for a separate product, the Services are not designed to identify a person from biometric data, authenticate identity by face, or create a general-purpose biometric identification database.

3.3 Payment and transaction information

We and our payment providers may collect billing contact information, payment method type, transaction amount, date, currency, invoice information, credit purchases and usage, subscription status, chargebacks, and payment identifiers. Payment-card numbers and some financial credentials are ordinarily collected and stored by the payment processor rather than by us.

3.4 Device, network, and usage information

We may collect IP address, browser and device type, operating system, referring page, pages or features used, timestamps, session identifiers, cookie identifiers, approximate location derived from IP address, language, and diagnostic information. We may collect API endpoint, model, request identifier, response status, latency, error code, credit usage, and rate-limit events without retaining the prompt or generated content in the operational log.

3.5 Information from third parties

We may receive information from payment processors, identity or access providers, model and infrastructure providers, fraud-prevention services, referral partners, and business customers that authorize an account or submit an API request. We may also receive information from publicly available sources when reasonably necessary for business verification, security, or legal compliance.

4. How We Use Information

We use personal information and Customer Content only as reasonably necessary to:

  1. create, authenticate, administer, and secure accounts and API credentials;
  2. process prompts, uploads, model requests, customer-selected compliance checks, and generations;
  3. route requests to the selected or functionally appropriate model and infrastructure provider;
  4. return, store, organize, and display Studio content to the customer according to the customer’s retention choices;
  5. calculate prices, deduct credits, process payments, issue invoices, and maintain transaction records;
  6. operate, maintain, troubleshoot, test, secure, and support the Services;
  7. detect fraud, credential misuse, automated abuse, attacks, illegal content when reasonably detected, and violations affecting service security or legality;
  8. enforce rate limits, access restrictions, legal requirements, and binding upstream-provider rules;
  9. communicate about accounts, transactions, support, service changes, security, and features;
  10. analyze aggregated or content-free operational information to understand performance, capacity, reliability, and feature usage;
  11. establish, exercise, or defend legal claims and respond to lawful government process; and
  12. comply with tax, accounting, sanctions, recordkeeping, and other legal obligations.

We may use de-identified or aggregated statistics that cannot reasonably be linked to a person or reconstructed into Customer Content. We will not attempt to reidentify information maintained as de-identified except to test our de-identification safeguards.

5. Uses We Prohibit

We do not:

  1. train or fine-tune AI models or use Customer Content for model training or fine-tuning;
  2. sell Customer Content or personal information, or share it for cross-context behavioral advertising, as those terms are defined by applicable privacy law;
  3. use Customer Content for targeted advertising;
  4. use private Customer Content in demonstrations, galleries, marketing, social media, case studies, or promotional materials without specific permission;
  5. grant ourselves a perpetual or irrevocable content license;
  6. use a customer’s face, voice, likeness, confidential material, prompt, or generation for an unrelated purpose; or
  7. require API customers to send direct end-user identifiers when a pseudonymous reference is sufficient.

6. Automated Screening and Human Access

PrivateCloud does not routinely inspect or independently censor Customer Content. A request may nevertheless be screened or rejected by the selected upstream model provider under that provider’s rules. A request may also be screened when the customer selects a compliance service, or when screening is reasonably necessary for security, fraud prevention, or legal compliance.

API customers are expected to operate an appropriate compliance-filtering process, but they are not required to use the WOWify Compliance Filter. They may use WOWify’s filter, their own system, a third-party service, or an appropriate combination of automated and human review.

Authorized personnel may access Customer Content only when reasonably necessary to:

  1. provide support or investigate a generation at the customer’s request;
  2. investigate a security incident, suspected abuse, prohibited content, fraud, or a violation of the Terms;
  3. maintain or restore the Services; or
  4. comply with law or valid legal process.

Access is limited to personnel with a business need and is subject to confidentiality and security obligations. We do not conduct routine human review of Customer Content for censorship, model training, or advertising.

7. How Information Is Disclosed

We may disclose information in the following circumstances.

7.1 Model and infrastructure providers

We transmit only the portions of Customer Content and technical information needed by model, hosting, storage, content-delivery, and infrastructure providers to complete a request. These providers may change as models and features change. Their data practices may differ, and they may process or temporarily retain Customer Content for service operation, delivery, retrieval, security, support, or legal compliance.

We do not publicly disclose commercially sensitive provider identities, routing relationships, technical integrations, or commercial arrangements. Customers that need provider or subprocessor information for contractual, security, or regulatory review may request it under a written nondisclosure agreement or other written agreement. We will also disclose information when legally required.

7.2 Service providers

We may disclose Account Data, Operational Data, or payment information to vendors that provide payment processing, billing, identity and access management, hosting, security, email delivery, communications, customer support, analytics, professional services, and similar functions. They may process information only to provide services to us or as law permits.

7.3 The customer that controls the account

If an account or API key is provided by an employer, client, team administrator, or other organization, that organization may access account information, usage, billing, audit information, and Customer Content stored within the organization-controlled account, subject to its configuration and agreements. End users should direct questions about the organization’s practices to that organization.

We may preserve or disclose information when we reasonably believe it is necessary to comply with law, subpoena, court order, or lawful government request; protect a person from serious harm; investigate child exploitation, trafficking, fraud, attacks, or unlawful conduct; enforce agreements; or protect the rights, security, and integrity of customers, providers, Lightspeed, or others.

7.5 Business transactions

Information may be disclosed to professional advisers and a prospective or actual buyer, investor, lender, successor, or transaction counterparty in connection with due diligence, financing, merger, acquisition, reorganization, bankruptcy, or sale of assets. Any recipient remains subject to applicable confidentiality and privacy obligations.

We may disclose information when the customer directs us to do so, activates a public or sharing feature, connects a third-party service, or otherwise provides valid consent.

We do not make Customer Content public merely because it was submitted to a generation or testing feature.

8. Retention and Customer Control

8.1 PrivateCloud Studio

Studio prompts, uploads, configurations, and creations may be retained in the customer’s account or Media Library solely to serve them back to that customer. The customer determines how long to keep that content by using the available save and delete controls. A customer may also export content using available download functions.

When a customer deletes Studio content, we remove it from active customer access and delete or de-identify it from active systems as soon as reasonably practicable. Temporary working copies, cached copies, and disaster-recovery backups may persist for a limited period until overwritten through ordinary system cycles. We may preserve a limited copy when required by law, necessary to investigate abuse or a security incident, or reasonably necessary to resolve a billing or legal dispute. Preserved content is restricted to that purpose and is not used for training or marketing.

8.2 WOWify API

WOWify API prompts, uploads, and generated outputs are processed to perform and deliver the request. They are not maintained by Lightspeed as a permanent customer-content archive after successful delivery unless:

  1. the customer uses an API feature that expressly provides customer-controlled storage;
  2. temporary storage is required for asynchronous processing, polling, retries, callback delivery, or download;
  3. the customer requests support requiring access to the affected request;
  4. temporary preservation is reasonably necessary for security, fraud, abuse, or legal investigation; or
  5. law requires retention.

Temporary request and output files under Lightspeed’s control are removed through ordinary automated deletion cycles after delivery and completion of the processing workflow. Processing providers may retain generated media for service operation, delivery, retrieval, security, or support for up to seven days. Lightspeed-held, content-free API usage records follow the periods in Section 8.3. Provider-held technical metadata follows the provider practices described in Section 7.1 and is not used by Lightspeed as a permanent Customer Content archive. Customers should promptly download and securely retain outputs they wish to preserve.

8.3 Operational and billing records

We generally retain content-free operational records for approximately thirty days to monitor service health, investigate errors, provide support, secure accounts, and reconcile usage. These records may include customer or API-key identifier, endpoint, model, timestamp, request identifier, response status, latency, error code, and credit usage, but not the prompt, upload, or generated output.

We generally retain billing and transaction records for one year. Certain tax, accounting, fraud, chargeback, contract, or legal records may be retained longer when reasonably necessary or legally required.

Account information is retained while the account is active and for a reasonable period afterward for closure, security, fraud prevention, dispute resolution, and legal compliance. Support communications are retained for as long as reasonably necessary to resolve and document the issue.

8.4 Provenance records

Certain Services may organize workflow information into a customer-accessible provenance or generation record. Depending on the feature, the record may contain Customer Content, settings, timestamps, request or job identifiers, Lightspeed model or internal route identifiers, processing status, billing or credit information, compliance events, intermediate outputs, outputs, and analyses. Non-public provider names and routing details are included only when disclosed under a written nondisclosure agreement or as legally required.

Studio provenance follows the customer’s retention choices and may be removed when the associated creation is deleted. API provenance may be returned with a response, made available through a documented retrieval method, or stored only when the customer selects a storage feature. The existence of provenance does not convert transient API content into a permanent archive. Customers are responsible for exporting and protecting records they wish to retain. We do not use provenance records for model training, advertising, marketing, or an unrelated purpose.

8.5 Adult-oriented and sensitive content

The Services are designed in substantial part for lawful use by the adult entertainment industry. Customer Content may therefore contain explicit, intimate, or otherwise sensitive material. We process such content only as described in this Policy to provide, secure, support, and legally operate the Services.

Customers should not submit government identification, performer records, releases, or other sensitive personal information unless a particular Service expressly requires it. Lightspeed is not a performer-verification or legally required records-custodian service and does not assume a customer’s duties concerning age verification, consent, releases, recordkeeping, labeling, access controls, or lawful distribution. API customers are responsible for providing notices, obtaining consent, restricting access to adults, and establishing appropriate compliance processes for their applications.

9. Cookies and Similar Technologies

We may use cookies, local storage, and similar technologies to maintain sessions, authenticate users, remember preferences, protect accounts, measure service performance, and understand use of the Services. We may use limited analytics providers for those purposes.

We do not use Customer Content for behavioral advertising. We do not authorize third-party advertisers to place tracking technologies inside private generation payloads or the API. Browser settings may block or delete cookies, but essential account or security features may stop working.

Where legally required, we will provide a cookie notice or consent controls for nonessential technologies.

10. Payments

Payment processors handle payment-card, bank, wallet, or cryptocurrency transaction information under their own privacy notices and security obligations. We receive information needed to confirm payment, credit the account, address disputes, and maintain billing records. Do not send payment-card numbers or wallet private keys through prompts, support messages, or API payloads.

11. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information, including access controls, authentication, logging, network protections, and restrictions on personnel and providers. No internet transmission, storage system, or AI provider can be guaranteed completely secure.

Customers are responsible for protecting their passwords, API keys, access tokens, downloaded content, and applications. Notify us promptly at sjones@wowify.ai if you suspect unauthorized access or a security incident involving the Services.

12. International Processing

The Services are operated from the United States and may use providers located in the United States and other countries. As a result, information may be processed in jurisdictions with privacy laws different from those where the customer or end user resides.

Where applicable law requires a transfer mechanism, we will use an appropriate mechanism such as contractual protections or another legally recognized safeguard. API customers that require particular data-location, subprocessor, or transfer terms should contact us before submitting regulated data.

13. Privacy Rights and Choices

Depending on location and applicable law, a person may have the right to:

  1. request confirmation of whether we process personal information;
  2. access or receive a copy of personal information;
  3. correct inaccurate personal information;
  4. delete personal information;
  5. restrict or object to certain processing;
  6. receive portable information provided to us;
  7. withdraw consent where processing relies on consent;
  8. opt out of marketing communications;
  9. opt out of sale, sharing, or targeted advertising; and
  10. appeal a decision concerning a privacy request.

We do not sell personal information or share it for cross-context behavioral advertising as those terms are commonly defined under U.S. state privacy laws. We therefore do not offer a sale or targeted-advertising opt-out for Customer Content.

To exercise a right, email sjones@wowify.ai and describe the request. We may verify identity and authority before acting. If we process the information solely for an API customer, we may direct the requester to that customer and assist the customer as required by contract and law.

Rights are subject to legal exceptions. We will not discriminate against a person for exercising an applicable privacy right.

14. U.S. State Privacy Disclosures

For residents of states with comprehensive privacy laws, the categories of personal information we may have collected during the preceding twelve months are:

  1. identifiers and account information;
  2. commercial and transaction information;
  3. internet, device, and network activity;
  4. approximate geolocation derived from IP address;
  5. audio, visual, and electronic information submitted as Customer Content;
  6. professional or business information provided by a customer;
  7. inferences limited to security, fraud, service configuration, and use; and
  8. sensitive information voluntarily submitted as Customer Content or required for account, payment, age, identity, or compliance purposes.

We collect these categories from customers, their authorized users and end users, devices and browsers, payment and access providers, service providers, and business partners. We use and disclose them for the purposes and to the recipients described in this Policy. We do not sell these categories or share them for cross-context behavioral advertising.

We use sensitive personal information only to provide requested services, secure accounts, process transactions, comply with law, and perform other purposes permitted without a right to limit under applicable law. Customer Content should not contain sensitive information unnecessary for the selected service.

15. API Customers and End-User Information

An API customer is responsible for determining whether it may lawfully send end-user information to the WOWify API. The customer must:

  1. provide all required privacy notices and obtain required consents;
  2. limit requests to information reasonably necessary for the function;
  3. avoid direct identifiers when a pseudonymous reference is sufficient;
  4. respond to end-user requests and provide us instructions when our assistance is needed;
  5. maintain appropriate security and retention controls in its own systems; and
  6. comply with laws governing intimate imagery, biometric data, likeness rights, consumer privacy, employment, health, financial, and children’s information.

The WOWify API is not intended to receive protected health information subject to HIPAA, payment-card data subject to PCI DSS, government identification numbers, financial-account credentials, or children’s data unless a separate written agreement expressly authorizes and governs that processing.

16. Children and Minors

The Services are restricted to adults eighteen and older. We do not knowingly permit individuals under eighteen to create accounts or use the Services, and we do not permit Customer Content depicting, sexualizing, exploiting, or presenting a minor or a person presented as a minor in a sexual context. If we discover that a minor has used the Services or that Customer Content unlawfully involves a minor, we may remove or restrict the content, suspend the applicable account, preserve information when legally required, and report the matter to appropriate authorities. If you believe a minor’s information or prohibited content has been submitted, contact sjones@wowify.ai immediately.

17. Third-Party Sites and Customer Integrations

The Services may link to third-party sites or allow customers to connect third-party tools. This Policy does not govern a third party’s independent services or a customer’s own application. Review their privacy terms before providing information. Activating an integration authorizes us to exchange the information necessary to perform the requested connection.

18. Changes to This Policy

We may update this Policy to reflect changes in the Services, providers, law, or practices. We will post the revised version and update the date above. If a change materially reduces protections for previously collected Customer Content, we will provide reasonable advance notice and apply the change prospectively unless law requires otherwise. We will not retroactively convert private Customer Content into training or marketing material.

19. Contact

Questions, requests, complaints, and security concerns: Lightspeed Media Corp., Phoenix, Arizona, United States; sjones@wowify.ai. For a permitted privacy appeal, use the subject “Privacy Appeal.”