Privacy Policy

What we collect when you use Fimuro, why, how long we keep it, and your rights.

Last updated: 16 September 2026 · Effective immediately for new users; 30 days after posting for existing users.

1. Introduction

Fimuro ("Fimuro", "we", "us") respects your privacy. This policy explains what personal data we collect when you use fimuro.com and fimuro.com (the "Service"), why we collect it, how long we keep it, who we share it with, and the choices you have. It is written to comply with the laws of Bangladesh and, where applicable, the EU General Data Protection Regulation (GDPR) for users located in the European Economic Area.

Data controller: Fimuro, Ullapara, Sirajganj, Bangladesh. Privacy contact: [email protected].

2. Data we collect

CategoryExamplesSource
Account dataName, email address, mobile number, password (hashed), company name and BIN if you add them for invoicesYou
Payment dataAmount, currency (BDT or USD), pack purchased, payment method type (e.g. bKash, Visa, PayPal), gateway transaction ID, masked identifiers such as the last 4 digits of a card or a partially masked wallet number, invoice historyYou, EPS payment gateway
Content dataPrompts you type, images and videos you upload, generated outputs, edits, project namesYou
Usage dataPages viewed, features used, credits spent, timestamps, error logsAutomatically
Device dataIP address, browser type and version, operating system, screen size, approximate location derived from IP, cookie identifiersAutomatically
Support dataMessages you send us by email, form, phone or WhatsApp, and our repliesYou

We do not collect full card numbers, CVV codes, bKash/Nagad/Rocket PINs or internet-banking passwords. These are entered only on the payment gateway's secure pages and never reach our servers.

3. Why we use your data and legal bases

  • To provide the Service — creating your account, generating content from your prompts, storing your library, delivering credits (performance of a contract).
  • To process payments and issue invoices — confirming transactions with the gateway, preventing fraud, keeping tax records (contract and legal obligation).
  • To support you — answering questions, investigating payment or generation problems (contract and legitimate interest).
  • To keep the Service safe — detecting abuse, enforcing acceptable-use rules, securing accounts (legitimate interest and legal obligation).
  • To improve the Service — analysing aggregated usage to fix bugs and prioritise features (legitimate interest). We do not use your private uploads or outputs to train AI models.
  • To send service messages — payment receipts, credit-expiry reminders, security alerts, changes to terms (contract). Marketing emails are sent only with your consent and every one has an unsubscribe link.

4. Who we share data with

We share personal data only with the following categories of recipients, and only as needed:

  • Payment gateways — EPS (Easy Payment System Ltd., Dhaka) for BDT, our international card/PayPal gateway for USD, and the bank, card network or mobile financial service you choose, to process your payment. They act under their own privacy policies.
  • AI model and cloud providers — the servers that run generation and store files. Prompts and uploads are transmitted to these providers solely to produce your output; contractual terms prohibit them from using your data for other purposes.
  • Email and messaging providers — to send receipts, notifications and support replies.
  • Analytics providers — to understand aggregated usage (see the Cookie Policy).
  • Professional advisers and authorities — accountants, lawyers, regulators, law-enforcement or courts where required by Bangladeshi law or to protect our rights.
  • A successor business — if Fimuro is sold or merged, under the same protections as this policy.

We do not sell personal data, and we do not share it with advertisers for their own marketing.

5. International transfers

Some providers listed above host data outside Bangladesh (for example in Singapore, the EU or the United States). Where we transfer data internationally we use providers with recognised security certifications and, for EEA data, standard contractual clauses or an adequacy decision.

6. How long we keep data

DataRetention
Account dataWhile your account is open, then 30 days after deletion (to allow reactivation), unless a longer period is required below
Payment and invoice records6 years after the transaction, as required by Bangladeshi tax and VAT law
Prompts, uploads and generated filesUntil you delete them or your account is deleted; deleted files are purged from backups within 30 days
Usage and device logs12 months
Support conversations24 months after the last message

7. Security

All traffic to the Service is encrypted with TLS. Passwords are stored as salted hashes. Access to production systems is limited to staff who need it, protected by multi-factor authentication and logged. Payments are handled by a PCI-DSS-compliant gateway; card data never touches our servers. No system is perfectly secure, so if we learn of a breach affecting your data we will notify you and any required regulator without undue delay.

8. Your rights and choices

Subject to applicable law, you can:

  • access a copy of the personal data we hold about you;
  • correct inaccurate data (most fields can be edited in Settings);
  • delete your account and content (Settings → Account → Delete, or email us);
  • export your generated files from your library at any time;
  • object to or restrict certain processing, and withdraw consent for marketing at any time;
  • complain to a supervisory authority. In Bangladesh, consumers may contact the DNCRP; EEA users may contact their local data-protection authority.

To exercise any right, email [email protected] from your account email. We respond within 30 days and may ask you to verify your identity.

9. Cookies

We use strictly necessary cookies to keep you logged in and protect against cross-site request forgery, and optional analytics cookies to understand how the Service is used. Details, and how to opt out, are in our Cookie Policy.

10. Children

The Service is not directed to anyone under 18 and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

11. Changes to this policy

We may update this policy. The date at the top shows the latest version. If changes are material, we will notify you by email or in the studio before they take effect.

12. Contact

Privacy questions or requests: [email protected]
Fimuro, Ullapara, Sirajganj, Bangladesh
Phone: +880 1790-648132