1. Who controls your data
Poiema is the controller of personal data processed to provide this service. Questions, access requests, and privacy concerns can be sent to support@poiema.pro.
2. Data we collect
- Account data, including your email address, name, profile image, authentication method, and workspace membership.
- Project data, including briefs, prompts, scripts, uploaded files, generated assets, feedback, and workflow history.
- Service data, including feature usage, generation parameters, charges, task status, diagnostic logs, device information, and security events.
- Billing data, including subscription status, invoices, credit purchases, and payment references. Payment-card details are handled by the payment provider and are not stored by Poiema.
- Support communications and any information you choose to include in them.
3. Google sign-in data
If you choose Google sign-in, Poiema uses your Google email address, display name, and profile image, when available, solely to authenticate you, create your account, and show your identity inside Poiema. We do not request access to Gmail, Google Drive, contacts, calendars, or other Google content. We do not sell Google user data or use it for advertising.
4. Why we use personal data
We process data to provide and secure the service, fulfil subscriptions and generation requests, maintain project history, prevent abuse, answer support requests, comply with law, and improve reliability.
Depending on the activity, our lawful bases are performance of a contract, legitimate interests in operating and securing Poiema, compliance with legal obligations, and consent where the law requires it. You can withdraw consent without affecting earlier lawful processing.
5. How data is shared
We share data only when needed with infrastructure, authentication, storage, monitoring, payment, email, and AI-generation providers acting for Poiema; when you direct us to do so; or when law requires it. Project content sent to an AI provider is limited to what is needed to perform the generation you request.
We do not sell personal data. Providers are required to protect data and use it only for the contracted service.
6. International transfers
Some providers may process data outside the United Kingdom or European Economic Area. Where required, we rely on adequacy regulations, approved contractual safeguards, or another lawful transfer mechanism.
7. Retention and deletion
Account and project data is kept while your account is active. When you request account deletion, access is disabled and the account enters a 30-day recovery period before project and storage records are purged, subject to legal, fraud-prevention, dispute, and backup-retention requirements. Billing and audit records may be retained for the period required by law. Temporary operational logs and cached worker data are retained only as long as needed for security and reliable delivery.
8. Security and cookies
Poiema uses access controls, encrypted transport, private storage, scoped worker permissions, and audit records to protect data. No system can guarantee absolute security. We use essential cookies and browser storage for authentication, session continuity, security, and preferences; Poiema does not use them for third-party behavioural advertising.
9. Your rights
Depending on where you live, you may have rights to access, correct, erase, restrict, port, or object to processing of your personal data, and to complain to your local data-protection authority. UK users may complain to the Information Commissioner’s Office. Contact us first if you would like us to act on a request.
10. Changes
We may update this notice as Poiema or the law changes. The date above identifies the current version. Material changes will be communicated in the service or by email where appropriate.