AI Devote · Privacy

Zentix Solutions Co., Ltd.

Privacy Policy

This document sets out how AI Devote treats personal information from collection through deletion — written for transparency, Google Play review, and multi-region privacy compliance.

Updated August 13, 2026 Adults 18+ Controller: Zentix Solutions

AI Devote (the “App”) is operated by Zentix Solutions Co., Ltd. (“we,” “us,” or “our”). Before you continue, review this Policy and the Terms of Service. Acceptance plus use of the App means you understand how we handle personal data as described here. If you disagree, please leave the App unused.

Age gate: AI Devote is built exclusively for users 18 and older. We do not market to minors and do not knowingly collect personal information from anyone under 18.
01

Who decides how data is processed

Zentix Solutions Co., Ltd. is the independent data controller for processing carried out through AI Devote and accepts the corresponding duties under applicable privacy law.

Legal entity Zentix Solutions Co., Ltd.
Registered office 462 Phan Xich Long Street, Cau Kieu Ward, Ho Chi Minh City, Vietnam

Privacy rights requests, compliance questions, and processing inquiries should go to the email above. We reply inside the window required by the law that applies to your request.

02

Where this Policy reaches

Coverage

It applies to every download, install, and in-App session of AI Devote distributed on Google Play — free tools, optional paid unlocks, AI image generation, and related in-product actions.

What the product does

AI Devote helps you restyle personal photos with AI. Pick media from your device, choose a creative direction, and receive generated visuals without needing studio-level editing skills.

Paid extras

If in-app purchases are offered, they may unlock premium looks, higher export fidelity, or similar add-ons. Order-related data is used only to validate transactions, unlock entitlements, and support after-sales care.

03

Data inventory and purposes

We collect the least data reasonably needed to run the App, keep it stable, refine quality, and complete purchases. Unrelated data is out of scope.

A. Runtime and device signals

How obtained

INTERNET permission enables connectivity. Where authorization frameworks apply, we may receive model and OS details, device identifiers, install metadata, operation logs, connectivity state, and hardware parameters that support operation.

Those signals are not pulled outside the applicable permission rules. Connectivity exists so the App can transmit data and deliver AI features.

Why kept

  • Boot and operate core functions
  • Match features to device capability
  • Trace crashes, freezes, and performance faults
  • Strengthen stability and resist abusive or abnormal clients
  • Protect end users and the App itself

We do not recycle this telemetry for hidden commercial dossiers.

B. Media you deliberately pick

How obtained

With permissions such as READ_EXTERNAL_STORAGE, READ_MEDIA_IMAGES, and/or READ_MEDIA_VIDEO (as applicable), the App may open images or videos you actively select. It does not quietly inventory your entire library.

Without media access, upload-driven creation may be unavailable because those permissions underpin the core workflow.

Why kept

  • Transmit selected assets for generation
  • Produce and preview AI outputs
  • Allow local save or export

Cloud buffers used mid-generation are cleared when the job finishes. Original creative files are not warehoused in long-term cloud storage.

C. Interaction & commerce signals (If present)

How obtained

Feature use, style choices, creation history, order references, payment confirmations, and session length may be logged automatically when you use tools or buy unlocks.

Extra consent prompts are not always required when processing is necessary to deliver what you asked for.

Why kept

  • Personalize creative defaults
  • Tune styles and generation quality
  • Unlock paid benefits and reconcile orders
  • Answer support tickets and review aggregate usage

These logs are not fuel for unrelated marketing campaigns.

D. Messages you initiate

Email you send to us contains whatever content and contact details you choose to include. We receive it only after you send it. Use is limited to replies, complaint handling, privacy requests, support, and issue resolution.

04

Legal grounds we rely on

  • Consent — Policy acceptance, permission grants, voluntary uploads, and purchase initiation.
  • Contract — steps needed to deliver creation features and paid benefits you request.
  • Legitimate interests — security, fraud resistance, reliability, and measured product improvement, where allowed and balanced against your rights.
  • Legal duty — retention or disclosure compelled by accounting, audits, regulation, or lawful authority requests.
05

Disclosures, vendors, and opt-out routes

Personal data is not circulated freely. Sharing is limited to the cases below. Recipients are expected to safeguard data and stay inside authorized purposes; confidentiality and data-protection terms apply where appropriate.

Infrastructure partners

Hosting, compute, and storage vendors see only what is required to keep AI Devote online. They may not repurpose that data for unrelated ventures.

Payment rails

Store billing partners process transaction fields needed to complete and verify purchases. Creative media is not sent to them unless a separate, lawful disclosure says so.

Compulsory legal access

Courts, regulators, or law enforcement may receive data when a lawful demand or other legal duty requires it. We limit such releases to what is reasonably necessary.

Embedded SDKs and AI endpoints

Third-party kits or AI services may support generation, payments, stability, or optimization. We take reasonable care that their processing tracks this Policy, applicable law, and Google Play rules.

  • Vendors are screened for compliance posture.
  • Transfers stay minimized and purpose-bound whether data leaves via on-device code or remote APIs.
  • AI vendors should process inputs only to fulfill your generation request — not for independent model training or promotion — unless you are clearly told and a valid legal basis exists.
  • Overreach can lead to cut-off access, remediation demands, and protective measures for users.

No commercial data sales

We do not sell, rent, or barter personal data. If a regional statute labels certain transfers or ad uses as a “sale” or “share,” you may opt out.

  • Permissions panel — revoke media, storage, or device access. Dependent features may stop. Uninstall ends future local capture but may leave lawfully retained server records intact.
  • Email opt-out — write to [email protected] with “Terminate Data Sharing/Opt Out of Data Transfers” and enough detail to verify you. Verified asks are handled within 15 business days or another statutory deadline.
06

Rights that may travel with your location

Available tools differ by jurisdiction. Eligible requests are free unless an exception applies.

EU / EEA — GDPR

Access, correction, erasure, restriction, objection, portability, consent withdrawal, and complaints to a supervisory authority may be available. Withdrawal does not unwind earlier lawful processing.

Brazil — LGPD

Confirmation of processing, access, correction, anonymization/blocking/deletion of improper data, transparency about recipients, portability where applicable, and consent withdrawal or objection (where allowed) may apply.

California — CCPA / CPRA

Know, access, delete, correct, opt out of sale/sharing, limit certain sensitive uses where applicable, and exercise rights without unlawful discrimination.

Virginia — VCDPA

Access, correct, delete, obtain portable copies, opt out of targeted ads / sale / certain profiling, and appeal denied privacy decisions.

Other places

Local statutes may add further rights. We apply the regime that governs the relevant user and processing.

07

How long data stays and how we guard it

Creative assets

Uploads and outputs often live on your device. Cloud hops for live generation use short-lived caches that are wiped or anonymized when no longer needed, subject to technical, security, and legal constraints. Originals are not parked in long-term cloud vaults unless you are told and authorize that retention.

Ops and commerce logs

Operation logs, interaction history, and order records remain only while needed for delivery, disputes, fraud controls, and compliance. After a verified deletion ask, eligible data is erased or anonymized inside the legally required window unless retention must continue.

Forced retention windows

Tax, audit, accounting, security, or regulatory duties may freeze certain records for a minimum period. When that clock ends and no further need remains, the data is securely removed or anonymized.

Protective controls

Reasonable administrative, technical, and organizational safeguards — including encrypted transit, access limits, and isolation practices — reduce unauthorized access, change, or loss. Only people and vendors with a legitimate need get access, under confidentiality expectations.

Absolute security does not exist online. Device hygiene, credentials, and permission choices remain partly in your hands.

08

In-App purchase data (If present)

Full card numbers and payment passwords are not collected by us. Authorized processors run checkout. We usually see only order IDs, payment state, and entitlement flags needed to manage the buy.

Those fields support entitlement delivery, support, fraud checks, accounting, and legal compliance — not unrelated marketing or unauthorized resale.

You may ask to access or delete eligible purchase records. Some must linger for tax, accounting, fraud, dispute, or regulatory reasons and cannot vanish on demand.

09

When this Policy is rewritten

Feature launches, operational shifts, legal updates, Google Play rule changes, or new processing practices may force revisions. Material updates can surface in-App or through another suitable channel. The new text governs from its stated effective date. Fresh consent is requested when the law demands it before new processing starts. Disagreement means you should stop and uninstall.

10

Boundaries of our responsibility

To the extent the law allows, we are not liable for privacy incidents caused solely by you revealing data to others, authorizing unrelated third parties, or neglecting device security. Non-waivable liability stays intact.

Binding legal changes or events beyond reasonable control may force processing adjustments, handled with required notice or consent.

Anyone under 18 is outside the product’s audience. If a minor’s data surfaces, we take reasonable deletion steps as the law allows. Guardians who suspect a minor submitted data should write to us below.

11

Raising a complaint

Suspect processing that conflicts with this Policy or the law? Contact us first. You may also escalate to your local data-protection authority where that path exists. We cooperate with lawful probes and fix confirmed gaps.

12

Reach the controller

Questions on this Policy, processing, rights requests, complaints, or suggestions:

Company Zentix Solutions Co., Ltd.
Address 462 Phan Xich Long Street, Cau Kieu Ward, Ho Chi Minh City, Vietnam

Verified requests receive a response within 15 business days, or within any different window the applicable law sets.

© 2026 Zentix Solutions Co., Ltd. · AI Devote