Legal
Privacy Policy
Last updated: October 1, 2026
This Privacy Policy explains which personal data Trustware FZCO ("we", "us") processes when you visit higgscheap.ai or use the higgscheap studio, why we do it and what rights you have.
1. Controller
Trustware FZCO, FZA Business Park, DDP, Makani Number A1 - 3641379065, Dubai, United Arab Emirates. Email: support@higgscheap.ai.
2. Data we process
- Account data: email address, a hash of your password (never the password itself), role, verification status and account settings.
- Payment data: amount, currency, credit pack, payment status and Stripe identifiers. Card details are entered at Stripe and never reach our servers.
- Content: your prompts, uploaded reference images and the images and videos generated for you, with their settings, cost and time.
- Credit history: purchases, charges and refunds of credits.
- Technical and security data: IP address, browser and device information, timestamps, login attempts and security events, kept in server logs.
- Communication: emails we send you (verification codes, password resets, receipts) and messages you send to support.
3. Purposes and legal bases
- Providing the Service, your account, generations and credits (performance of the contract, Art. 6(1)(b) GDPR).
- Payments, bookkeeping and tax records (legal obligation, Art. 6(1)(c) GDPR).
- Security, abuse and fraud prevention, rate limits and content policy enforcement (legitimate interests, Art. 6(1)(f) GDPR).
- Service emails needed to run your account (performance of the contract). We do not send marketing emails without your consent.
4. Service providers and recipients
We use processors that act on our instructions:
- Hosting and server infrastructure: Servers, Hong Kong.
- Cloudflare (content delivery, DNS, media storage in R2, bot protection with Turnstile).
- Stripe (payment processing; Stripe is also an independent controller for payment fraud prevention).
- Resend (sending transactional emails).
- AI model providers and API intermediaries that run your generations. They receive your prompts and reference images and return the results.
We do not sell your personal data and do not share it for advertising.
5. International transfers
We operate from outside the EU/EEA, and some providers process data in other countries, for example in the United States. Where the GDPR applies to such a transfer we rely on an adequacy decision (such as the EU-US Data Privacy Framework) or on standard contractual clauses.
6. Retention
- Account data, content and credit history: as long as your account exists. The image and video files of a deleted generation are removed from storage within 30 days of the deletion.
- Payment and booking records: as long as tax and commercial law requires (usually up to 10 years).
- Server and security logs: up to 90 days, longer only while needed to investigate a specific incident.
8. Your rights
You have the right to access your data, to correct it, to have it deleted, to restrict its processing, to data portability and to object to processing based on legitimate interests. Write to us at the address above to use these rights.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work.
9. Security
We protect your data with encryption in transit, hashed passwords, encrypted secrets and access controls. No system is completely secure, so we cannot guarantee absolute security.
10. Children
The Service is not meant for people under 18. We do not knowingly collect data of children.
11. Changes
We may update this Privacy Policy. The current version is always available on this page, with the date of the last update.