Legal

Privacy Policy

Last updated: October 1, 2026

This Privacy Policy explains which personal data Trustware FZCO ("we", "us") processes when you visit higgscheap.ai or use the higgscheap studio, why we do it and what rights you have.

1. Controller

Trustware FZCO, FZA Business Park, DDP, Makani Number A1 - 3641379065, Dubai, United Arab Emirates. Email: support@higgscheap.ai.

2. Data we process

  • Account data: email address, a hash of your password (never the password itself), role, verification status and account settings.
  • Payment data: amount, currency, credit pack, payment status and Stripe identifiers. Card details are entered at Stripe and never reach our servers.
  • Content: your prompts, uploaded reference images and the images and videos generated for you, with their settings, cost and time.
  • Credit history: purchases, charges and refunds of credits.
  • Technical and security data: IP address, browser and device information, timestamps, login attempts and security events, kept in server logs.
  • Communication: emails we send you (verification codes, password resets, receipts) and messages you send to support.

3. Purposes and legal bases

  • Providing the Service, your account, generations and credits (performance of the contract, Art. 6(1)(b) GDPR).
  • Payments, bookkeeping and tax records (legal obligation, Art. 6(1)(c) GDPR).
  • Security, abuse and fraud prevention, rate limits and content policy enforcement (legitimate interests, Art. 6(1)(f) GDPR).
  • Service emails needed to run your account (performance of the contract). We do not send marketing emails without your consent.

4. Service providers and recipients

We use processors that act on our instructions:

  • Hosting and server infrastructure: Servers, Hong Kong.
  • Cloudflare (content delivery, DNS, media storage in R2, bot protection with Turnstile).
  • Stripe (payment processing; Stripe is also an independent controller for payment fraud prevention).
  • Resend (sending transactional emails).
  • AI model providers and API intermediaries that run your generations. They receive your prompts and reference images and return the results.

We do not sell your personal data and do not share it for advertising.

5. International transfers

We operate from outside the EU/EEA, and some providers process data in other countries, for example in the United States. Where the GDPR applies to such a transfer we rely on an adequacy decision (such as the EU-US Data Privacy Framework) or on standard contractual clauses.

6. Retention

  • Account data, content and credit history: as long as your account exists. The image and video files of a deleted generation are removed from storage within 30 days of the deletion.
  • Payment and booking records: as long as tax and commercial law requires (usually up to 10 years).
  • Server and security logs: up to 90 days, longer only while needed to investigate a specific incident.

7. Cookies

We only use cookies that are needed for the website to work: a session cookie that keeps you signed in, security cookies of the login system, and a cookie that remembers that you closed the announcement bar. We do not use advertising or analytics cookies.

8. Your rights

You have the right to access your data, to correct it, to have it deleted, to restrict its processing, to data portability and to object to processing based on legitimate interests. Write to us at the address above to use these rights.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work.

9. Security

We protect your data with encryption in transit, hashed passwords, encrypted secrets and access controls. No system is completely secure, so we cannot guarantee absolute security.

10. Children

The Service is not meant for people under 18. We do not knowingly collect data of children.

11. Changes

We may update this Privacy Policy. The current version is always available on this page, with the date of the last update.