This Privacy Policy explains how Review Spaces L.P. ("Review Spaces," "we," "our," or "us") collects, uses, shares, and protects personal data when you use our website, account portal, Photoshop plugin, AI tools, credit system, support, and related services (the "Service").
The Service is designed for visual creatives, architects, designers, studios, and teams using Review Spaces AI Tools for Photoshop. Because the Service provides AI image generation, editing, reference-image workflows, camera/view control, upscaling, prompt enhancement, image description, history, presets, preferences, and related creative tools, prompts, images, reference images, Outputs, metadata, and job parameters may be processed by Review Spaces and Third-Party Services as described below.
Controller identity
Review Spaces L.P. is the controller for account data, billing metadata, website data, support communications, and most Service usage data. You can contact us about privacy matters at [email protected].
Where a business customer uses the Service for its own team or clients, that customer may be a separate controller or, in some cases, Review Spaces may act as a processor for that customer. The exact role depends on the customer relationship, configuration, and any separate written agreement.
Data we collect
Depending on how you use the Service, we may collect the following categories of information:
Account data: name, display name, email address, company or studio information where provided, password hash, account settings, account status, and workspace key metadata.
Billing data: Stripe customer ID, invoices, billing address, VAT or tax IDs, payment status, purchase history, credit purchases, credit balances, and billing communications. Full payment card details are processed by Stripe or another payment processor and are not stored by Review Spaces.
Plugin and Service data: prompts, input images, reference images, generated Outputs, selected tools, models, settings, resolution, masks, job status, credit usage, timestamps, presets, preferences, and history where enabled.
Technical data: IP address, device and browser information, computer name where provided, plugin version, Photoshop version if collected, operating system, authentication and session data, two-factor authentication status, logs, error reports, crash reports, debug data, and security events.
Usage data: pages visited, links clicked, actions taken, feature usage, model usage, analytics events, performance information, and interaction patterns.
Referral data: referral codes and links, referrer and referred account identifiers, sign-up dates, qualifying purchases, referral status, rewards issued, and related program activity.
Support data: messages, attachments, screenshots, files, account identifiers, communications, and notes related to support requests.
Cookies and local storage: session data, preferences, authentication state, analytics identifiers, security data, and similar technologies.
Purposes and legal bases
Where GDPR or similar laws apply, we rely on the following legal bases:
- Provide the Service and perform our contract: create and manage accounts, authenticate users, operate the Plugin, process prompts and images, generate or edit Outputs, manage Credits, provide downloads, and deliver purchased functionality.
- Process payments and billing: manage purchases, invoices, taxes, VAT, payment status, fraud checks, refunds where applicable, and payment disputes.
- Referral program: operate referral links, determine reward eligibility, issue referral credits, track referral activity, and prevent misuse or fraud.
- Customer support: respond to questions, diagnose issues, investigate failed jobs, and provide operational assistance.
- Security and fraud prevention: protect accounts, keys, payments, systems, providers, users, and the Service from misuse, compromise, abuse, or unlawful activity. This is based on contract performance, legitimate interests, and legal obligations where applicable.
- Analytics and product improvement: understand usage, improve features, fix bugs, evaluate model performance, improve reliability, and prioritise development. This is based on legitimate interests or consent where required.
- Legal compliance: comply with tax, accounting, consumer protection, sanctions, legal process, and other legal obligations.
- Communications: send service notices, account messages, security alerts, billing messages, and support communications. Marketing communications are sent only where permitted by law or with consent where required.
AI provider processing
To provide AI image generation, editing, upscaling, image description, prompt enhancement, reference-image workflows, and related features, we may send prompts, input images, reference images, Outputs, metadata, selected settings, job parameters, and technical information to AI Providers and infrastructure providers.
Examples of providers or services we may use include Google/Gemini, OpenAI, xAI/Grok, Freepik/Magnific, ByteDance/Seedream, Unsplash, Stripe, analytics providers, hosting and storage providers, email providers, support providers, and Adobe-related distribution channels.
- AI Providers may process data in countries different from your country, including outside Greece, the EU, or the EEA.
- AI Provider processing may be governed by their own terms, privacy policies, data processing terms, and safety policies.
- AI Providers may return refusals, safety blocks, errors, no-content responses, or unexpected results, and their models, policies, infrastructure, and data handling practices may change.
Data sharing
We do not sell your personal data. We may share information with:
- AI/model providers to generate, edit, upscale, describe, enhance, or otherwise process images and related content.
- Hosting, storage, infrastructure, monitoring, and security providers to operate, secure, back up, and maintain the Service.
- Payment processors such as Stripe to process payments, invoices, taxes, fraud checks, refunds, and billing disputes.
- Analytics providers to understand website, Plugin, and Service usage and improve the Service.
- Email, support, and communications providers to send account messages and respond to support requests.
- Adobe-related distribution channels or integrations where needed for Plugin distribution, compatibility, or related workflows.
- Professional advisers such as lawyers, accountants, auditors, insurers, and consultants.
- Authorities, courts, regulators, or third parties where required by law, legal process, safety, security, fraud prevention, or protection of rights.
- Business transfer parties in connection with a merger, acquisition, financing, reorganisation, sale of assets, insolvency, or similar transaction.
International transfers
Review Spaces is based in Greece, but the Service and our providers may process data in other countries, including countries outside the EU or EEA. Where required, we use safeguards such as adequacy decisions, Standard Contractual Clauses, data processing agreements, provider contractual safeguards, or other lawful transfer mechanisms.
Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law. Retention periods may vary by data type:
- Account data: while your Account is active and for a reasonable period after closure for security, backup, dispute, and legal purposes.
- Billing and tax records: for the period required by tax, accounting, payment, and legal obligations.
- Uploaded and generated image files: automatically removed after 24 hours.
- Prompts, job metadata, selected tools and models, settings, timestamps, activity history, and related operational records: for the period needed to provide history, support, debugging, security, legal compliance, or dispute resolution, or until deleted where deletion tools are available.
- Logs and security data: for a limited period appropriate to security, abuse prevention, debugging, and operational monitoring.
- Support tickets: for a reasonable period needed to provide support, maintain business records, and resolve disputes.
- Backups: retained until overwritten or deleted through backup rotation.
Security
We use administrative, technical, and organisational measures designed to protect personal data, including encryption in transit, password hashing, two-factor authentication, session or token controls, access controls, credential management, limited production access, monitoring or logging, backups, and provider security controls where appropriate.
No system is 100% secure. We cannot guarantee that unauthorised access, disclosure, loss, misuse, or alteration will never occur. You are responsible for keeping your Account credentials, Account Key, API Key, and devices secure.
Your rights
Depending on your location and applicable law, you may have rights to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- delete personal data;
- restrict or object to certain processing;
- receive a portable copy of certain data;
- withdraw consent where processing is based on consent;
- complain to a supervisory authority, including your local data protection authority.
To exercise your rights, contact [email protected]. We may need to verify your identity or authority before responding. Some rights are subject to legal limits, including where we must retain data for billing, tax, security, legal claims, or compliance purposes.
Cookies and local storage
We remember your analytics choice in local storage and ask you to choose again after 180 days. With your consent, we use Google Analytics 4 to understand visits and interactions with this website, including pages viewed, approximate location, and device and browser information. Google Analytics may set identifiers such as _ga for up to six months. Google Analytics event-level data is retained for two months. We do not load Google Analytics or send analytics data to Google before you accept, and we keep advertising storage, ad user data, and ad personalisation disabled.
Consent is the legal basis for this optional analytics processing. You can accept or reject analytics with equal ease and can change your choice at any time using “Cookie settings”. Rejecting analytics does not limit the website. When you withdraw consent, we stop Google Analytics and remove its first-party analytics cookies from this site where the browser permits. See Google’s Privacy Policy for details about its processing and international data transfers.
Children
The Service is not intended for anyone under 18. We do not knowingly collect personal data from children. If we learn that a child has provided personal data, we will take reasonable steps to delete it.
Marketing communications
We may send marketing communications where permitted by law or where you have consented. You can unsubscribe from marketing emails by using the unsubscribe link in the email or contacting us. We may still send non-marketing messages such as account, billing, support, security, and legal notices.
Automated decision-making
Review Spaces does not use personal data to make automated decisions that produce legal or similarly significant effects about you. The Service uses AI systems to generate, edit, upscale, describe, or enhance creative content based on your Inputs, but those creative outputs are not used by Review Spaces to make legal or similarly significant decisions about you.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We may notify you of material changes by email, website notice, account notice, in-service notification, or by updating the date above. Your continued use of the Service after an updated Privacy Policy becomes effective means you acknowledge the updated policy.
Contact
For privacy and legal questions, contact [email protected]. For support, contact [email protected].