Privacy Policy
Last updated: 14 September 2026
1. About this Policy and the data controller
This Privacy Policy describes how Stratum S.R.L. (“Stratum”, “we”, “us” or “our”) collects, uses and shares personal data when you use Raw Edit AI (the “Service”). Stratum is the data controller in respect of your personal data processed in connection with the Service.
Stratum S.R.L. is a limited liability company organised under the laws of the Republic of Moldova, registered under fiscal code 1026023045265, with its registered office at str. Alexandr Pușkin 49, ap.(of.) 67, MD-2005, Chișinău, Republic of Moldova. You can reach us at support@rawedit.ai or +373 69 766 011.
2. Legal framework
We process personal data in accordance with Law No. 133 of 8 July 2011 of the Republic of Moldova on the protection of personal data, and, where applicable, with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”). The competent supervisory authority in the Republic of Moldova is the National Center for Personal Data Protection (Centrul Național pentru Protecția Datelor cu Caracter Personal — CNPDCP), based in Chișinău. You may contact CNPDCP at any time to lodge a complaint about how we handle your personal data.
3. Personal data we collect
We collect the following categories of personal data:
- Account data — managed for us by Clerk. Includes your email address, your Clerk user identifier and authentication artefacts (such as session tokens). Password handling, multi-factor verification and sign-in flows are operated by Clerk on our behalf. We do not store your password.
- Generation data — the text prompts you submit, the input images you upload, the generated outputs returned to you, the selected aspect ratio, quality level and model version, the resulting job identifier, and the associated timestamps.
- Billing data — records of credit purchases, the credit pack purchased, your credit balance and transaction identifiers. Card, bank-account and UPI details are handled exclusively by our payment providers — Paynet (paynet.md) or, for purchases made from India, Dodo Payments (dodopayments.com) — and are never collected, seen or stored by us.
- Technical data — IP address, user-agent string, device type, browser type and settings, language, and basic analytics events such as the signup source (for example UTM parameters or click identifiers available in your browser at signup).
- Communications — the content of messages you send us when you contact support, together with the channel used (email or phone).
We do not seek to collect special-category personal data (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic, biometric or health data, or data concerning a natural person’s sex life or sexual orientation). Please do not include such data in your prompts or inputs. We cannot control the content of what you submit.
4. Purposes and legal bases for processing
We process your personal data for the following purposes and on the following legal bases under Article 6(1) GDPR and the corresponding provisions of Law No. 133/2011:
- To provide, maintain and operate the Service, including running generations, displaying your history and delivering the output to you — necessary for the performance of our contract with you (Article 6(1)(b)).
- To process payments and manage credit balances — necessary for the performance of our contract with you (Article 6(1)(b)).
- To prevent abuse, fraud, jailbreaking, scraping, and other misuse, to ensure security and integrity of the Service, and to investigate violations of our Terms — necessary for our legitimate interests in protecting the Service, its users and third parties (Article 6(1)(f)).
- To comply with our legal obligations, including responding to lawful requests from authorities, tax and accounting record-keeping, and law-enforcement cooperation (Article 6(1)(c)).
- To send service-related communications, such as security alerts, billing receipts, policy updates and outage notifications — necessary for the performance of our contract or to comply with a legal obligation (Article 6(1)(b) and (c)).
- To send marketing communications about new features or model updates — only with your prior, freely given consent (Article 6(1)(a)), which you may withdraw at any time.
5. Third-party processors and recipients
To run the Service we rely on the following third-party providers, who act as our processors or independent controllers within the meaning of the GDPR. Your data may be transmitted to and processed by these providers, in some cases outside the Republic of Moldova and the European Economic Area.
- Clerk — authentication and account management. Account data is governed by Clerk’s own privacy policy and terms (clerk.com/legal).
- AtlasCloud AI — inference provider. Your prompts and input images are forwarded to AtlasCloud to fulfil each generation request. You are also bound by the following AtlasCloud documents: Privacy, Acceptable Use, Data Deletion Policy and Data Retention. AtlasCloud may retain prompts and content for longer than the one-hour window applied within our own systems; that retention is governed by AtlasCloud’s policies and is outside our control.
- Paynet — payment processor (paynet.md). Paynet handles all sensitive payment data on its own infrastructure under its own privacy policy and applicable payment-industry standards.
- Dodo Payments — payment provider and merchant of record for purchases made from India (dodopayments.com). For those purchases, Dodo receives your name, email address and billing country to process the payment, and handles all sensitive payment data — including card and UPI details — on its own infrastructure under its own privacy policy and applicable payment-industry standards. We receive back transaction identifiers and payment status, never your payment details.
- Cloudflare — hosting, object storage, database, image transformation and content delivery. Data may be processed at Cloudflare edge locations worldwide.
- PostHog — product analytics. PostHog Inc. operates PostHog Cloud US in the United States and, where enabled, processes usage events, device and browser data, approximate location derived from your IP address, and account identifiers so we can understand how the Service is used. Analytics requests route through our own first-party subdomain (r.rawedit.ai) but are processed by PostHog in the United States; these transfers are protected by appropriate safeguards (standard contractual clauses). See PostHog’s privacy policy. For visitors in the EU/EEA, the United Kingdom, Switzerland and Moldova, behavioural analytics and analytics storage are disabled entirely; for those visitors we process only minimal service telemetry (for example, generation-completion events tied to your account identifier) on the basis of our legitimate interests (Article 6(1)(f)), and no analytics identifiers are stored on your device.
- Meta Platforms — advertising measurement and attribution for our advertising campaigns. Where enabled (see below), we share a limited set of data with Meta Platforms, Inc. and Meta Platforms Ireland Limited to measure and attribute conversions from our ads: a hashed (irreversible) version of your email address, your IP address, browser information, advertising click identifiers (such as the Meta click identifier carried in your browser), and the value and currency of a purchase. Data is transferred to the United States under the EU–US Data Privacy Framework and/or standard contractual clauses; see Meta’s privacy policy. Meta tracking is not used for visitors from the EU/EEA, the United Kingdom, Switzerland, Moldova and similar jurisdictions — determined by geolocation — and no Meta cookies or identifiers are set for those visitors.
We do not sell your personal data. Other than the advertising measurement described for Meta above (see also Section 9), we do not share your personal data with third parties for their own marketing purposes.
6. Data retention
- Input images are deleted from our systems within one hour of the generation being processed. A one-day lifecycle policy acts as a back-stop in case automated cleanup fails.
- Generated images are deleted from our systems within one hour of generation, with the same lifecycle back-stop.
- Prompts, job metadata and timestamps are retained for an indefinite period for the purposes of abuse prevention, dispute resolution, security, legal-hold compliance and statutory record-keeping under Moldovan law.
- Account and billing records are kept while your account is active and, after closure, for the periods required by Moldovan tax and accounting legislation (typically up to six years), or longer if a legal hold applies.
- AtlasCloud’s own retention of prompts and content is independent and governed by AtlasCloud’s policies.
7. International data transfers
Some of our providers are based outside the Republic of Moldova and the European Economic Area, including in the United States. When personal data is transferred to such countries, we rely on appropriate safeguards under applicable law, such as Standard Contractual Clauses, adequacy decisions, or — where strictly necessary — your explicit consent or another derogation permitted by Article 49 GDPR and the corresponding provisions of Moldovan law.
8. Your rights
Subject to applicable law, you have the right to: access your personal data (Article 15 GDPR); request rectification of inaccurate or incomplete data (Article 16); request erasure of your data (Article 17); restrict our processing of your data (Article 18); receive your data in a portable format (Article 20); object to processing based on our legitimate interests (Article 21); withdraw any consent you have given (Article 7(3)); and lodge a complaint with CNPDCP in Chișinău or with another competent supervisory authority.
To exercise any of these rights, please write to support@rawedit.ai from the email address associated with your account. We may need to verify your identity before acting on your request. We will respond within the statutory deadlines. Please note that some rights are limited where law requires us to retain certain data, or where granting the request would adversely affect the rights of others.
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
9. US State Privacy Rights
If you are a resident of California or another US state with a comprehensive privacy law, additional rights may apply to you. Our sharing of online identifiers with Meta for advertising measurement and attribution may constitute “sharing” for cross-context behavioural advertising under those laws. We enable Meta’s Limited Data Use processing for US users. You may opt out of this sharing, or exercise your other state-law rights, by writing to support@rawedit.ai.
10. Children
The Service is not directed to, and may not be used by, persons under 18 years of age, or under the local age of majority if higher. We do not knowingly collect personal data from minors. Accounts identified as belonging to minors will be terminated and the associated personal data will be deleted, subject to any applicable legal-hold obligations. If you believe a minor has provided us with personal data, please contact us at support@rawedit.ai.
11. Security
We use industry-standard technical and organisational measures to protect your personal data, including transport-layer encryption (HTTPS), encryption at rest on Cloudflare R2 and D1, least-privilege access controls and audit logging. No method of transmission or storage is completely secure; you are responsible for safeguarding your account credentials and for using a strong, unique password.
12. Cookies and local browser storage
For all visitors, the Service uses strictly necessary cookies and local browser storage required to keep you signed in, maintain your session, and remember basic UI preferences. Additionally, for visitors located outside the EU/EEA, the United Kingdom, Switzerland and Moldova, we store first-party analytics identifiers in your browser’s local storage for product analytics (PostHog). For those same visitors outside the EU/EEA, the United Kingdom, Switzerland and Moldova, we and Meta also set advertising-attribution cookies — Meta’s _fbp and _fbc, together with a first-party _fbc fallback cookie we write ourselves to preserve an ad-click identifier when Meta’s own script is blocked — each with a lifetime of up to 90 days, used solely to measure and attribute our advertising campaigns. For visitors inside those countries, client-side analytics and Meta advertising tracking are disabled and no analytics or advertising identifiers are stored on your device. You can configure your browser to refuse cookies or to delete local storage; some parts of the Service may not function correctly if you do so.
13. Disclosures to authorities
We may preserve and disclose your personal data in response to lawful requests from competent authorities in the Republic of Moldova, or from foreign authorities acting through lawful channels (for example mutual legal assistance treaties or Interpol), as well as where we believe in good faith that disclosure is necessary to prevent imminent harm. Further details are set out in Section 6 of our Terms of Service.
14. Changes to this Policy
We may update this Privacy Policy from time to time. We will notify you of material changes at least thirty (30) days in advance by email or through an in-product notice. Non-material changes take effect when published on this page. Your continued use of the Service after the effective date constitutes your acceptance of the updated Policy.
15. Contact and complaints
For any question about this Policy, or to exercise any of your rights, write to support@rawedit.ai or call +373 69 766 011. Postal address: Stratum S.R.L., str. Alexandr Pușkin 49, ap.(of.) 67, MD-2005, Chișinău, Republic of Moldova. Additional contact details are available on the Support page. You may also lodge a complaint with our lead supervisory authority, the National Center for Personal Data Protection (CNPDCP) in Chișinău, Republic of Moldova (datepersonale.md). If you are located in the EU/EEA or the United Kingdom, you may instead lodge a complaint with the data protection supervisory authority in your country of residence, place of work or the place of the alleged infringement.