Privacy & Data Security Center
We are committed to providing the highest standards of data privacy, ensuring the absolute security of your creative assets and personal info.
1. Introduction & Scope
Welcome to the AlphaVow Privacy & Data Security Center. We understand that your creative files and personal data are critical to you. This Privacy Policy is designed to detail in a transparent and thorough manner how we handle, collect, and store your data when you use our desktop software (such as AlphaVow Photo RAW and Photo RAW MAX) and our online web services.
This policy is fully compliant with strict global user privacy protections, including the EU General Data Protection Regulation (GDPR), the EU ePrivacy Directive, the California Consumer Privacy Act (CCPA/CPRA), and the Personal Information Protection Law of China (PIPL).
AlphaVow Core Promise: We absolutely do not sell, rent, or lease your personal information to any third parties. All data collection is strictly dedicated to improving and optimizing your creative design workflow.
2. Types of Data We Collect
To provide high-quality services, we may collect the following categories of information:
- Basic Account & License Info: When you license products or register a Team account, we collect your name, email address, and country/zip code to verify and activate product licenses.
- Billing & Subscription Data: Transactions are securely managed by contracted billing processors (e.g. Stripe, FastSpring). This includes billing address and payment tokens. We do not store unencrypted raw credit card numbers.
- Device & Diagnostic Logs (Anonymous): To resolve stability issues, our desktop applications can send crash diagnostics (such as CPU/GPU specs). This diagnostic log never references your personal photo files or private content.
- Cookies & Identifiers: We utilize cookies on our website. Strictly necessary cookies are vital for session validation and security shields, whereas analytical and marketing cookies (activated only after your opt-in) help improve pages.
3. How We Use Your Data
We process your data not just for compliance, but to fully empower your creative workflow. The legal grounds include:
- Contract Fulfillment: Verifying software license keys, activating Dynamic Team Plan seats, and completing financial checkout transactions.
- Software Updates & SLA Support: Delivery of core AI model algorithms (e.g. NoNoise AI, Portrait AI engine updates) and answering submitted technical support tickets.
- Legitimate Interests (Anonymous): Evaluating tutorial video popularity, page loading velocities, and polishing responsive UI layouts.
- Legal Compliance: Collecting transaction metadata to fulfill international VAT/sales tax audits and compliance obligations.
5. Your Global Rights (GDPR/PIPL)
Regardless of your geographic location, we respect and empower your rights to control your private data:
- EU / UK Citizens (GDPR / ePrivacy): You have the right to access, rectify, restrict processing, port your data, withdraw cookie consent, and enforce the "Right to be Forgotten" (complete account deletion).
- California Residents (CCPA/CPRA): You have the right to know what personal info is collected, request data lists, and demand deletion. We do not sell data; hence, we do not require a "Do Not Sell My Info" toggle.
- Chinese Citizens (PIPL): We disclose all cookie details clearly. You possess full rights to correct personal info, withdraw processing consent, restrict processing, and close accounts to wipe associated data.
To exercise any of the rights listed above, please submit a request to our DPO. We commit to responding to all valid compliance requests within 30 days.
6. Security & Encryption
AlphaVow deploys rigorous safeguards across transit and storage nodes to ensure your data is protected against unauthorized access, tampering, or leaks:
🔒 In-Transit Encryption (SSL/TLS)
All account settings, passwords, and billing metadata transferred from your browser are securely routed via highly encrypted endpoints.
🛡️ Storage Encryption (AES-256)
Sensitive identifiers and billing details stored inside our secure cloud databases are encrypted at rest using industry-standard AES-256 algorithms.
We conduct routine penetration testing and static vulnerability scans on our hosting networks to detect and block configuration exploits.
7. Retention, Deletion & Contact
Data Retention Policy: We retain your personal information only as long as your account is active or needed to deliver service workflows. If you request account closure, we will fully wipe your records from our active databases upon verification, except as required to fulfill legal tax audit compliance rules (typically 5 to 7 years for transaction records).
If you have any questions regarding this policy or wish to exercise your privacy rights, please contact our Data Protection Officer (DPO):

