Back to home

Legal

Privacy Policy

Last updated: May 31, 2026

We do not train on your data.

NIUA does not use customer inputs (uploaded images, prompts, reference media) or outputs (generated meshes, animations, textures, audio, images) to train, fine-tune, or evaluate any AI model — proprietary or third-party. This applies to every account and every generation, including free usage — NIUA has no plan tiers. There are no exceptions, no opt-outs to enable, no enterprise upgrade required.

Some platforms in this space include language in their terms permitting training on non-Enterprise customer data. We do not operate that way, for anyone.

We make no claim on derivative works of our outputs. Use them however you want, including to train your own models. That is your right as the IP owner of the asset you generated. (One upstream model license restricts training on voice audio specifically — see the Terms §5 carve-out and the Model Licenses page.)

1. Introduction

NIUA ("we", "our", "us") is operated by ohao.tech. This Privacy Policy explains how we collect, use, and protect your information when you use NIUA at niua.ohao.tech.

2. GDPR Compliance & Data Minimization

NIUA is operated in compliance with the European Union's General Data Protection Regulation (GDPR). The protections, rights, and disclosures described in this policy apply to all users globally — we do not run a two-tier privacy regime where EU users get different treatment than the rest of the world.

We practice data minimization. We collect only the data strictly necessary to operate the service. We do not gather information about you for marketing, profiling, behavioural advertising, third-party data brokers, or any other purpose disconnected from delivering the service you signed up for.

Specifically: basic account information (name, email, profile picture from your OAuth provider), payment data (handled by Stripe; we never see your card number), and the content you choose to upload for generation jobs (which we store privately in your account so the service can function). The only other data we collect is first-party, cookieless product analytics (see §3).

3. Information We Collect

Account information: When you sign in via Google or GitHub, we receive your name, email address, and profile picture from the OAuth provider. We do not receive or store your password.

Payment information: When you top up your wallet, payment is handled by Stripe. We store the resulting wallet balance and a Stripe customer ID; we do not see, store, or process your card number, CVV, or full payment details directly.

Uploaded content: Images, prompts, video clips, and reference media you submit to generate assets. Stored privately in your account so the service can produce outputs from them.

Operational metadata: Job status, processing duration, model used, error logs. Used to operate the service, not to profile you.

Product analytics (first-party, cookieless): We record first-party usage events — page views and a few key actions (signing up, requesting early access, starting a generation, primary button clicks) — to understand how the product is used and make it better. This uses no cookies and no third-party trackers: we store a first-party anonymous id in your browser's local storage (never a cookie, never shared) and post events only to our own servers. The data is never sold, never used for advertising, and never used to build a cross-site profile of you. We also derive a coarse country from your IP address for aggregate geographic insight; the country is stored and the raw IP address is immediately discarded.

IP geolocation by DB-IP, licensed under CC BY 4.0.

4. How We Use Your Information

  • To run the generation jobs you submit and return the resulting assets
  • To authenticate your account and manage your sessions
  • To bill your wallet for the generations you run
  • To communicate service updates or respond to support requests
  • To monitor uptime, error rates, and system performance

We do not use your inputs or outputs to train, fine-tune, or evaluate AI models. See the headline clause above.

5. Data Storage & Retention

Your data is stored using industry-standard cloud services (Railway PostgreSQL for account and job data, Cloudflare R2 for file storage). All data is transmitted over HTTPS.

Uploaded inputs and generated outputs are retained in your account indefinitely, until you delete them. There is no automatic expiry. When you delete an asset, all associated files and job records are permanently removed.

6. Third-Party Services

We use the following third-party services to operate NIUA. Each is contractually limited to its operational role; none receive your generated content for training or marketing purposes.

  • Resend — transactional email delivery (e.g. magic-link sign-in)
  • Cloudflare — hosting and file storage (R2)
  • Modal — GPU compute for image, mesh, motion, rigging, music, and text-to-motion generation
  • Stripe — payment processing and wallet top-ups (PCI-DSS compliant; we do not handle card data directly)
  • Google / GitHub — OAuth sign-in providers

7. Data Sharing

We do not sell, trade, or otherwise transfer your personal information to third parties. Your inputs and generated outputs are private to your account and are not shared with other users, used in marketing materials, or fed into model training pipelines — ours or anyone else's.

8. Your Rights

Under GDPR, and applied to all users regardless of jurisdiction, you have the right to:

  • Access — download all data we hold on you, including generated assets and operational metadata
  • Rectification — correct inaccurate account information
  • Erasure ("right to be forgotten") — delete your account and all associated data permanently
  • Portability — export your data in a standard, machine-readable format
  • Objection — opt out of any non-essential processing (we don't run any, but the right is yours)
  • Commercial use — use your generated outputs commercially, including to train your own models, with no attribution required

To exercise any of these rights, contact privacy@ohao.tech. We respond within 30 days as required by GDPR.

9. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated revision date.

10. Contact

For questions about this privacy policy, contact us at privacy@ohao.tech.