Privacy Policy
What we collect when you use Fimuro, why, how long we keep it, and your rights.
1. Introduction
Fimuro ("Fimuro", "we", "us") respects your privacy. This policy explains what personal data we collect when you use fimuro.com and fimuro.com (the "Service"), why we collect it, how long we keep it, who we share it with, and the choices you have. It is written to comply with the laws of Bangladesh and, where applicable, the EU General Data Protection Regulation (GDPR) for users located in the European Economic Area.
Data controller: Fimuro, Ullapara, Sirajganj, Bangladesh. Privacy contact: [email protected].
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, mobile number, password (hashed), company name and BIN if you add them for invoices | You |
| Payment data | Amount, currency (BDT or USD), pack purchased, payment method type (e.g. bKash, Visa, PayPal), gateway transaction ID, masked identifiers such as the last 4 digits of a card or a partially masked wallet number, invoice history | You, EPS payment gateway |
| Content data | Prompts you type, images and videos you upload, generated outputs, edits, project names | You |
| Usage data | Pages viewed, features used, credits spent, timestamps, error logs | Automatically |
| Device data | IP address, browser type and version, operating system, screen size, approximate location derived from IP, cookie identifiers | Automatically |
| Support data | Messages you send us by email, form, phone or WhatsApp, and our replies | You |
We do not collect full card numbers, CVV codes, bKash/Nagad/Rocket PINs or internet-banking passwords. These are entered only on the payment gateway's secure pages and never reach our servers.
3. Why we use your data and legal bases
- To provide the Service — creating your account, generating content from your prompts, storing your library, delivering credits (performance of a contract).
- To process payments and issue invoices — confirming transactions with the gateway, preventing fraud, keeping tax records (contract and legal obligation).
- To support you — answering questions, investigating payment or generation problems (contract and legitimate interest).
- To keep the Service safe — detecting abuse, enforcing acceptable-use rules, securing accounts (legitimate interest and legal obligation).
- To improve the Service — analysing aggregated usage to fix bugs and prioritise features (legitimate interest). We do not use your private uploads or outputs to train AI models.
- To send service messages — payment receipts, credit-expiry reminders, security alerts, changes to terms (contract). Marketing emails are sent only with your consent and every one has an unsubscribe link.
4. Who we share data with
We share personal data only with the following categories of recipients, and only as needed:
- Payment gateways — EPS (Easy Payment System Ltd., Dhaka) for BDT, our international card/PayPal gateway for USD, and the bank, card network or mobile financial service you choose, to process your payment. They act under their own privacy policies.
- AI model and cloud providers — the servers that run generation and store files. Prompts and uploads are transmitted to these providers solely to produce your output; contractual terms prohibit them from using your data for other purposes.
- Email and messaging providers — to send receipts, notifications and support replies.
- Analytics providers — to understand aggregated usage (see the Cookie Policy).
- Professional advisers and authorities — accountants, lawyers, regulators, law-enforcement or courts where required by Bangladeshi law or to protect our rights.
- A successor business — if Fimuro is sold or merged, under the same protections as this policy.
We do not sell personal data, and we do not share it with advertisers for their own marketing.
5. International transfers
Some providers listed above host data outside Bangladesh (for example in Singapore, the EU or the United States). Where we transfer data internationally we use providers with recognised security certifications and, for EEA data, standard contractual clauses or an adequacy decision.
6. How long we keep data
| Data | Retention |
|---|---|
| Account data | While your account is open, then 30 days after deletion (to allow reactivation), unless a longer period is required below |
| Payment and invoice records | 6 years after the transaction, as required by Bangladeshi tax and VAT law |
| Prompts, uploads and generated files | Until you delete them or your account is deleted; deleted files are purged from backups within 30 days |
| Usage and device logs | 12 months |
| Support conversations | 24 months after the last message |
7. Security
All traffic to the Service is encrypted with TLS. Passwords are stored as salted hashes. Access to production systems is limited to staff who need it, protected by multi-factor authentication and logged. Payments are handled by a PCI-DSS-compliant gateway; card data never touches our servers. No system is perfectly secure, so if we learn of a breach affecting your data we will notify you and any required regulator without undue delay.
8. Your rights and choices
Subject to applicable law, you can:
- access a copy of the personal data we hold about you;
- correct inaccurate data (most fields can be edited in Settings);
- delete your account and content (Settings → Account → Delete, or email us);
- export your generated files from your library at any time;
- object to or restrict certain processing, and withdraw consent for marketing at any time;
- complain to a supervisory authority. In Bangladesh, consumers may contact the DNCRP; EEA users may contact their local data-protection authority.
To exercise any right, email [email protected] from your account email. We respond within 30 days and may ask you to verify your identity.
9. Cookies
We use strictly necessary cookies to keep you logged in and protect against cross-site request forgery, and optional analytics cookies to understand how the Service is used. Details, and how to opt out, are in our Cookie Policy.
10. Children
The Service is not directed to anyone under 18 and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
11. Changes to this policy
We may update this policy. The date at the top shows the latest version. If changes are material, we will notify you by email or in the studio before they take effect.
12. Contact
Privacy questions or requests: [email protected]
Fimuro, Ullapara, Sirajganj, Bangladesh
Phone: +880 1790-648132