Burning AI Privacy Policy

This Privacy Policy applies to the Burning AI mobile application, the Burning AI website, customer-support channels, and related services that display or link to this Policy (collectively, the “Services”).

📅 Effective date: April 15, 2026 🔄 Last updated: July 27, 2026 📧 [email protected]

1. Who We Are

Burning AI is an AI-powered creative application that transforms photos selected by users into stylized images, animations, and videos.

The controller responsible for the personal data described in this Policy is:

EVERLUU TECHNOLOGY COMPANY LIMITED

Registered address: 1st Floor, No. 95 Nguyen Cong Tru Street, Saigon Ward, Ho Chi Minh City, Vietnam

Privacy email: [email protected]

Data Protection Officer (DPO): Marnie

DPO email: [email protected]

This Policy explains our data practices. Merely downloading, opening, or continuing to use the Services does not constitute blanket consent to every type of processing. Where applicable law requires consent, we will provide a separate explanation and request an affirmative choice before the relevant processing begins.

2. Age Requirement

The Services are intended only for users who are at least 18 years old. We do not knowingly offer the Services to, or collect personal data from, anyone under 18.

If we learn that a person under 18 has submitted personal data, we will take reasonable steps to close the relevant account and delete the associated information, unless a legal obligation requires limited retention.

A parent or guardian who believes that a minor has used the Services may contact the DPO at [email protected]. We may request limited information needed to locate the relevant account or content, but we will not request unrelated documents.

3. Information We Process

We process only information reasonably needed to provide, secure, and maintain the features you choose to use.

3.1 Account information

Where account functionality is available, we may process your email address, username, internal user ID, and encrypted password-verification data.

We use this information to create and authenticate your account, maintain account security, synchronize supported settings, restore access, and respond to account requests.

We do not store passwords in readable plain text. Account information is retained while your account remains active. After a verified account-deletion request, it is deleted or irreversibly de-identified within seven days, except where limited retention is required by law.

3.2 Uploaded photos and creative inputs

This includes photos that you deliberately select, prompts, selected styles, motion settings, output duration, aspect ratio, music or sound presets, and similar generation instructions.

We use this information only to perform the creative task you request, return the result, investigate a failed task, or provide support at your request.

Uploaded source photos are removed from the active generation environment within 48 hours after a task succeeds or fails. A narrow exception may apply where temporary retention is required to complete a support request, investigate unlawful activity, or comply with a binding legal obligation.

3.3 Generated content and project information

This may include generated images, animations or videos, project records, favorites, regeneration history, generation IDs, timestamps, model versions, task status, retry information, and basic error information.

Generated content and project information held by us is normally deleted within seven days after creation. You should save any result you wish to keep to your device before that period expires.

Content saved only on your device remains under your control. We do not continuously access files merely because they were created with Burning AI.

3.4 Device, application, and network information

This may include device model, operating-system version, application version, language, time zone, app-instance identifier, IP address, request time, response status, and country or general region inferred from the IP address.

We use this information to establish a connection, maintain compatibility, diagnose technical problems, apply request limits, prevent abuse, and protect our systems.

We do not use this information to obtain precise GPS location. We do not collect persistent hardware identifiers such as IMEI, SIM serial number, or device serial number.

Information in this category is normally deleted or irreversibly de-identified within seven days.

3.5 Usage and diagnostic information

This may include features viewed or used, session events, generation counts, page interactions, crashes, error codes, response time, and performance information.

We use this information to operate the Services, identify errors, maintain reliability, and improve performance. We do not use this information for behavioral advertising or cross-application tracking.

Usage and diagnostic information is normally deleted or irreversibly de-identified within seven days.

3.6 Notifications

If you enable notifications, we may process a push token and notification settings to send generation-completion, account-security, or service-status notices.

You may disable notifications through your device settings. Push tokens and related settings are deleted when no longer needed and, in any event, within seven days after account deletion or token invalidation.

3.7 Customer support and privacy requests

When you contact us, we may process your email address, account identifier, message, screenshots, attachments, request type, and the record of our response.

We use this information to provide support, investigate problems, process account-deletion and privacy requests, and resolve complaints.

Support and privacy-request records are normally deleted within seven days after the matter is closed, unless a binding legal obligation or unresolved legal claim requires limited retention.

3.8 Security and content-enforcement information

This may include suspicious login or request signals, automated or high-volume generation patterns, reported content, violations of our rules, security incidents, and investigation results.

We process this information to protect users and our systems, prevent fraud or abuse, enforce our terms, and investigate unlawful or seriously harmful activity.

Ordinary security records are normally deleted or irreversibly de-identified within seven days. Records that are directly relevant to an unresolved security incident or legal claim may be retained only for the period reasonably necessary to resolve that matter.

4. Device Permissions

We request a device permission only when it is relevant to a feature you choose to use.

Photos and media. Burning AI uses the system photo picker or a limited media-access method so that you can choose a particular photo. We do not automatically scan, copy, or upload your entire photo library.

Saving results. Burning AI uses the system media library or file interface to save generated results to your device. We do not request broad access to all files unless a genuine compatibility requirement exists and the access is permitted by the operating system.

Notifications. Notification permission is optional and is used only for generation, account-security, or service-status notices.

Network access. A network connection is required to upload content you select, process a generation task, return the result, synchronize supported account functions, and protect the Services.

You can withdraw permissions through system settings. Withdrawing a permission may prevent the specific feature that depends on it from working, but it does not authorize any collection outside the permissions that remain enabled.

5. Image and AI Processing

5.1 How generation works

When you submit a task:

  1. You select a photo and choose generation settings.
  2. The selected photo and necessary task data are transmitted through an encrypted connection to our processing environment.
  3. Our systems run the selected AI model.
  4. The result is returned to the Services for you to view or save.
  5. The uploaded source photo is removed within 48 hours after the task succeeds or fails.
  6. Other task records and generated content held by us are removed within seven days.

5.2 Model training

We do not use uploaded source photos or private generated content to train or fine-tune a general-purpose model for other users unless we first provide a separate explanation and obtain a specific, affirmative, and withdrawable consent where required.

If a voluntary model-improvement program is introduced, the separate notice will explain the information used, the purpose, the retention period, how to decline or withdraw, and the effect of withdrawal on processing already completed.

Information that has been irreversibly de-identified so that it is no longer personal data may be used to evaluate system performance.

5.3 Facial features

The Services may analyze visual structure and facial features in a selected photo to create the requested effect. Burning AI does not use facial recognition to verify identity and does not create a biometric identity database or template for identifying users.

5.4 Human access

Our personnel do not ordinarily review uploaded content. Limited access may occur only when:

  • you deliberately provide content in a support request;
  • access is reasonably necessary to investigate fraud, unlawful activity, a security incident, or a serious violation of our rules; or
  • access is required by valid legal process.

Access is limited to authorized personnel and is logged where reasonably practicable.

5.5 Your responsibility

You must have the rights or permission needed to upload the content you submit. Rules concerning ownership, prohibited content, and intellectual property are addressed in our Terms of Service and do not reduce the privacy commitments in this Policy.

6. Why We Use Information

We use information to:

  • create, authenticate, maintain, and protect accounts;
  • process selected photos and provide requested images, animations, or videos;
  • temporarily maintain projects and generation results;
  • respond to support, deletion, and privacy requests;
  • send generation, account-security, and service-status notices;
  • diagnose crashes and maintain performance;
  • detect fraud, automated requests, account compromise, abuse, and security incidents;
  • enforce our terms and resolve disputes; and
  • comply with binding legal obligations.

Where GDPR or a similar framework applies, our legal bases may include:

Contract. Processing needed to provide a feature, account, or support service you request.

Legitimate interests. Protecting users and our systems, preventing fraud, resolving technical problems, enforcing our terms, and improving reliability after balancing those interests against your rights.

Consent. Processing for which we request a specific, affirmative choice. You may withdraw consent at any time. Withdrawal does not affect processing lawfully completed before withdrawal.

Legal obligation. Processing necessary to comply with a binding regulatory, court, tax, accounting, or other legal requirement.

Legal claims and safety. Processing reasonably necessary to establish, exercise, or defend legal claims or protect a person’s safety.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects on users.

7. Website Technologies

The native mobile application does not use browser cookies.

Our website may use essential technical storage and limited server logs to deliver pages, prevent attacks, and remember necessary settings. We do not use behavioral advertising pixels, cross-site tracking, or non-essential analytics on the website.

Technical website logs may include an IP address, browser type, request time, requested page, and security signals. We use them only for delivery, security, and reliability, and delete or irreversibly de-identify them within seven days.

You may use browser controls to block or delete local website data. Doing so may affect functions that depend on essential settings.

“Do Not Track” signals do not have a single agreed legal or technical meaning. Because we do not conduct behavioral advertising or cross-site tracking, there is no advertising profile to opt out from through this signal.

8. Disclosure of Information

We do not sell, rent, trade, or disclose personal data for advertising, profiling, or another company’s independent commercial purposes.

Information may be disclosed only in the following limited situations:

At your direction. If you choose to save or share generated content using a device function, the content is handled according to the destination you select.

Legal and safety requirements. We may disclose limited information when reasonably necessary to comply with applicable law, a court order, or a valid government demand; protect a person’s safety; investigate fraud or unlawful activity; enforce our agreements; or protect our rights and systems.

Corporate changes. If our business is reorganized, merged, or transferred, information may be included in the transaction only under confidentiality and data-protection obligations. We will provide notice if the responsible controller or processing purposes materially change.

We do not disclose uploaded source photos or private generated content for advertising or commercial reuse.

9. International Processing

Information may be processed outside the country or region where you live when necessary to operate the Services.

Where GDPR applies to a transfer outside the European Economic Area, we use a lawful mechanism appropriate to the actual transfer, such as an adequacy decision, approved contractual safeguards, or another recognized legal basis. Where required, we assess transfer risks and apply supplementary protections.

Transfers governed by United Kingdom or Swiss law use the corresponding legally recognized safeguards.

You may contact the DPO to ask about the principal processing locations or the safeguards applicable to your information.

10. Retention and Deletion

We minimize retention and apply the following general limits:

  • uploaded source photos: deleted from the active generation environment within 48 hours after the task succeeds or fails;
  • generated images, animations, videos, project records, generation IDs, and task metadata: deleted within seven days;
  • device, application, network, usage, diagnostic, notification, and ordinary security information: deleted or irreversibly de-identified within seven days;
  • customer-support, complaint, and privacy-request information: deleted within seven days after the matter is closed;
  • website technical logs: deleted or irreversibly de-identified within seven days;
  • protected backup copies: automatically overwritten or deleted within seven days; and
  • account information: retained while the account is active and deleted or irreversibly de-identified within seven days after a verified account-deletion request.

You should save generated content to your device before the seven-day period expires if you want to keep it.

A narrowly limited record may be kept longer only when required by a binding legal obligation, an unresolved security investigation, or the establishment, exercise, or defense of a legal claim. Such information is isolated from ordinary product use and deleted when the reason for retention ends.

11. Account and Data Deletion

Where Burning AI permits account creation, you may request deletion in either of the following ways:

In the App: Profile or Account Settings → Delete Account.

Outside the App: email [email protected] with the subject “Burning AI Account Deletion Request” and include the user ID or registered email needed to locate the account.

We use proportionate verification to prevent unauthorized deletion. We will not request your password, complete financial information, or unrelated identity documents.

After verification, the account and associated information are deleted or irreversibly de-identified within seven days, subject only to the narrow legal exceptions described in Section 10.

You do not need to reinstall the application to submit an external deletion request.

12. Your Privacy Rights

Depending on your location and applicable law, you may have the right to:

  • confirm whether we process personal data about you;
  • obtain access to or a copy of relevant personal data;
  • correct inaccurate or incomplete information;
  • request deletion;
  • request restriction of processing;
  • object to processing based on legitimate interests or direct marketing;
  • receive eligible information in a structured, commonly used, machine-readable format;
  • withdraw consent;
  • opt out of sale, targeted advertising, or certain profiling where those rights apply;
  • limit certain uses of sensitive personal information where applicable;
  • appeal a denied request where applicable law provides an appeal;
  • not receive unlawful discriminatory treatment for exercising a privacy right; and
  • complain to a competent data-protection or consumer-protection authority.

We do not sell personal data, conduct targeted advertising, or use personal data for cross-application profiling.

These rights are subject to legal conditions and exceptions. For example, portability generally applies only to eligible information provided by the user and processed automatically on the basis of consent or a contract. Deletion may be limited by binding legal obligations and unresolved legal claims.

To submit a request, email the DPO at [email protected] and describe the right you wish to exercise. Provide only the limited information needed to locate your account. We may reasonably verify your identity. An authorized representative may be required to provide valid authorization.

Do not send a password, complete financial information, or unnecessary identity document by email.

Deleting an account necessarily ends features that depend on that account or its temporary project history. This consequence is not discriminatory treatment.

12.1 European Economic Area, United Kingdom, and Switzerland

Where GDPR or equivalent law applies, we generally respond within one month. For a complex or numerous request, the period may be extended by up to two additional months where legally permitted, and we will explain the extension within the initial month.

You may complain to the supervisory authority where you habitually live, work, or believe an infringement occurred. Contacting us first is not a condition of filing a complaint.

12.2 California

Where CCPA/CPRA applies, California residents may request information about the categories and specific pieces of personal information collected in the applicable lookback period, the sources, purposes, and categories of recipients, and may request correction or deletion.

We generally respond to a verifiable request within 45 days. If the law permits an extension, we will notify you and explain the reason.

We do not sell personal information or share it for cross-context behavioral advertising.

12.3 Other applicable US states

Where a relevant state privacy law applies, residents may have rights to access, correct, delete, obtain a copy, and opt out of sale, targeted advertising, or profiling that produces legal or similarly significant effects.

If we deny an eligible request, you may email [email protected] with the subject “Burning AI Privacy Appeal.” We will review the decision and explain any further complaint route required by applicable law.

13. Security and Incident Response

We maintain technical and organizational safeguards appropriate to the information and risk. These measures include encrypted transmission, access controls, least-privilege access, authentication, audit logging, protected backups, confidentiality obligations, and incident-response procedures.

No transmission or storage method can guarantee absolute security. If a security incident affects personal data, we will investigate, contain, and remediate it and notify affected users and regulators within the periods required by applicable law.

If you believe your account or information has been accessed without authorization, contact the DPO at [email protected] promptly.

14. Changes to This Policy

We may update this Policy to reflect changes in features, processing, law, or operations. The revised version will be posted at the privacy-policy URL and will display a new “Last updated” date.

If a change materially affects user rights or introduces a materially different use of personal data, we will provide advance notice through the application, account email, or another prominent method where required.

Continued use does not replace consent where the law requires a new affirmative choice. We will obtain that choice before beginning the new consent-based processing.

15. Contact and Complaints

Questions, privacy requests, account-deletion requests, appeals, or complaints may be sent to:

Data controller: EVERLUU TECHNOLOGY COMPANY LIMITED

Registered address: 1st Floor, No. 95 Nguyen Cong Tru Street, Saigon Ward, Ho Chi Minh City, Vietnam

Application: Burning AI

Data Protection Officer (DPO): Marnie

DPO and privacy email: [email protected]

If you are dissatisfied with our response, you may complain to a data-protection, consumer-protection, or other authority with jurisdiction. You may contact us first so that we can investigate, but doing so does not limit your right to approach an authority directly.