Janubeus LogoJanubeus

Privacy Policy

Your privacy matters to us. This policy explains how we collect, use, and protect your personal information.

Privacy Policy (Datenschutzerklärung)

Last Updated: August 29, 2025

This Privacy Policy serves to inform Users about the nature, scope, and purpose of the processing of personal data (hereinafter "Data") in connection with our online service "Janubeus" and its associated websites, features, and content (hereinafter collectively referred to as the "Service").

With respect to the terminology employed herein, such as "processing" or "Controller," reference is made to the definitions provided in Article 4 of the General Data Protection Regulation (GDPR).

1. Controller (Verantwortlicher)

The controller, as defined by the General Data Protection Regulation (GDPR), responsible for the processing of personal data in connection with this Service is:

Janubeus by Daniel Wilmes
Daniel Wilmes
Kleine Penzlinger Straße 10
33102 Paderborn
Germany

Email: privacy@janubeus.com
Phone: +49 151 59848556
Link to Legal Notice (Impressum): Legal Notice (Impressum)

3. Overview of Processing Activities

This section provides a comprehensive overview of the categories of data processed, the classes of data subjects affected, and the corresponding purposes for which the data are processed.

  • Types of Data Processed: Inventory Data, Contact Data, Content Data, Contractual Data, Usage Data, Metadata and Communication Data.
  • Categories of Data Subjects: Visitors, Users, Customers, and prospective customers of our Service.
  • Purposes of Processing: Provisioning of the Service, processing inquiries, security measures, audience measurement, marketing, and fulfillment of contractual obligations.
  • Applicable Legal Bases for Processing: Our processing activities are based on Consent (Art. 6(1)(a) GDPR), Performance of a contract (Art. 6(1)(b) GDPR), Compliance with a legal obligation (Art. 6(1)(c) GDPR), and our Legitimate interests (Art. 6(1)(f) GDPR).

4. Data Processing in Detail

4.1. Accessing Our Website and Service (Server Log Files)

During the purely informational use of our website, certain information is automatically collected in server log files. This data includes browser type, operating system, referrer URL, hostname, time of request, and IP address. The legal basis for this processing is our legitimate interest in maintaining the security and stability of our Service (Art. 6(1)(f) GDPR). These logs are retained for 7 days.

4.2. Registration and User Account

Utilization of the core functionalities of Janubeus necessitates the creation of a user account. We process your email address, a hashed password, and a display name. This processing is indispensable for the performance of our contract with you (Art. 6(1)(b) GDPR).

4.3. Core Service Functionality: AI-Powered 3D Model Generation

The Janubeus service processes user-provided content (images and text prompts) to generate 3D models. This processing is performed exclusively to fulfill our contractual obligations (Art. 6(1)(b) GDPR).

Important Note on AI Model Training: User-uploaded content is not utilized for training our general AI models.

4.4. Contacting Us

Information provided when you contact us will be processed to address your inquiry, based on either contractual necessity (Art. 6(1)(b) GDPR) or our legitimate interest in effective communication (Art. 6(1)(f) GDPR).

5. Third-Party Services and Data Transfers

We engage specialized service providers to operate our platform, including Vercel (Hosting), Supabase (Backend/Database), Stripe (Payment Processing), and Google Analytics (Web Analytics). We have concluded Data Processing Agreements (DPAs) with all providers. Data transfers outside the EU/EEA are secured through appropriate safeguards such as Standard Contractual Clauses (SCCs).

6. Cookies and Consent Management

Our Service utilizes different types of cookies to provide you with the best possible experience:

6.1. Technically Necessary Cookies

These cookies are essential for the website to function properly and are processed based on our legitimate interest (Art. 6(1)(f) GDPR):

  • Authentication Cookies (Supabase): Enable secure login and session management
  • Payment Security Cookies (Stripe): Ensure secure payment processing and fraud prevention
  • Language Preference Cookie: Remember your preferred language setting

6.2. Optional Cookies

These cookies are only activated with your explicit consent (Art. 6(1)(a) GDPR):

  • Analytics Cookies (Google Analytics): Help us understand how visitors interact with our website
  • Marketing Cookies: Enable personalized advertising and retargeting (when implemented)

You can manage your cookie preferences at any time by:

  • Adjusting your settings in the cookie banner when it appears
  • Visiting our dedicated Cookie Settings page
  • Using the cookie preferences modal accessible throughout our website

Important: Withdrawing consent for optional cookies will not affect the functionality of our core services, but may limit some features like analytics-driven improvements.

7. Data Retention

We store personal data only as long as necessary for the specified purposes or as required by law. User account data is erased within 30 days of account deletion, unless subject to legal retention obligations (e.g., invoices for 10 years under German law).

8. Your Rights as a Data Subject

You have the right to access, rectify, erase, restrict processing of, and port your personal data. You also have the right to object to processing, withdraw consent, and lodge a complaint with a supervisory authority. To exercise these rights, please contact us using the details provided in Section 1.


Jurisdiction-Specific Provisions

Residents of the United Kingdom (UK)

For residents of the United Kingdom, we process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Your rights as a data subject under the UK GDPR are analogous to those under the EU GDPR.

Residents of the United States

This section provides additional details for residents of certain U.S. states with comprehensive privacy laws, such as California (California Consumer Privacy Act or "CCPA"), Virginia, Colorado, and others. We have adopted a unified approach to U.S. privacy rights for simplicity and to provide strong privacy protections to all our U.S. users.

You have the following rights:

  • Right to Know and Access: The right to request information about the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: The right to request the deletion of your personal information. This right is not absolute and is subject to certain exceptions. For instance, pursuant to laws such as the California Civil Code § 1798.105(d), we are not required to delete information that is necessary to complete a transaction, detect security incidents, comply with a legal obligation, or for other internal and lawful uses.
  • Right to Correct: The right to request the correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: You have the right to direct us not to "sell" or "share" your personal information. We do not sell your personal data for monetary consideration. As our Service operates on an opt-in basis for any data use beyond core service delivery (such as for analytics cookies), we inherently comply with the spirit of this right.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

To exercise these rights, please contact us through the methods described in Section 1.

We reserve the right to amend this privacy policy at any time to ensure its compliance with current legal requirements or to reflect changes in our service or data processing activities.

legal.lastUpdatedLabel: January 15, 2024