Privacy Policy, Visant Labs

Last updated: January 27, 2025

Visant Labs is committed to protecting your privacy. This Policy explains how we collect, use, and protect your information when using Visant Labs, our AI-powered design platform.

1. INFORMATION WE COLLECT

1.1 Account Information

  • Name
  • Email address
  • User ID
  • Profile picture (when provided)
  • Authentication data via providers (Google/Apple/Email)

1.2 Payment Information

  • Subscription data (active plan, renewals, history)
  • Billing identifiers via third-party providers (Pagar.me, PagSeguro, Stripe, or others)
  • We never store complete card data.

1.3 Usage Data

  • Number of images generated
  • Prompts submitted by users
  • Platform usage time
  • Error logs for maintenance

1.4 Technical Data

  • IP address
  • Device type
  • Browser
  • Language preferences

1.5 Google Authentication Data

When you choose to sign in with Google, we request the following permissions (OAuth 2.0 scopes):

  • email, Access to your Google account email address
  • profile, Access to your basic profile information

The specific data we collect from your Google account includes:

  • Email address, Used as your primary account identifier
  • Full name, Used to personalize your profile
  • Profile picture, Used as your account avatar (optional)
  • Google User ID (sub), Used for authentication and account linking

Important: We do not access your Google contacts, calendar, drive files, or any other Google services beyond the basic profile information listed above.

1.6 API Keys

If you choose to use your own Gemini API key with our service, we collect and store:

  • Your encrypted Gemini API key, Stored securely using AES-256-GCM encryption
  • API key metadata, Associated with your account for usage tracking

Important: Providing your own API key is completely optional. If you choose to provide one, it will be encrypted immediately upon saving and never stored in plaintext.

2. HOW WE USE YOUR DATA

We use your data to:

  • Operate and improve Visant Labs
  • Process subscriptions and payments
  • Monitor plan usage limits
  • Personalize your experience
  • Prevent abusive or fraudulent use
  • Comply with legal obligations

2.1 Use of Google Authentication Data

We use the data collected from your Google account exclusively for:

  • Creating and managing your Visant Labs account
  • Authenticating your identity when you sign in
  • Linking your Google account to your existing account (if applicable)
  • Pre-filling your profile information (name and profile picture)
  • Preventing duplicate accounts and fraudulent activity

We do not use your Google data for advertising, marketing, or any purpose other than account management and authentication. Your Google credentials are never stored by us; we only store the profile information provided by Google's OAuth service.

2.2 Use for AI Training

Prompts and generated images are not used to train Visant Labs' internal models, unless you provide explicit consent.

2.3 Use of API Keys

If you provide your own Gemini API key, we use it exclusively for:

  • Processing your AI image generation requests
  • Using your Google Cloud quota and credits instead of our system's default key
  • Prioritizing your key over the default key for your account's requests

Important: We never use your API key for any purpose other than processing your requests. All API calls made with your key are billed to your Google Cloud account, not ours. We never share your API keys with third parties or use them for any other purpose.

3. DATA SHARING

We may share information with:

3.1 Service Providers

  • Third-party AI image generation APIs
  • Payment providers
  • Hosting and storage services
  • Authentication services (MongoDBAuth)
  • Analytics services (Google Analytics), for website usage statistics only

We share only the minimum necessary for service operation. Analytics data shared with Google Analytics is anonymized and does not include personally identifiable information.

3.2 Google Data Sharing

We do not share your Google account data with any third parties. The data we collect from Google (email, name, profile picture, and Google User ID) is:

  • Stored securely in our own database
  • Used exclusively for authentication and account management
  • Not sold, rented, or shared with advertisers or marketing partners
  • Not used for any purpose beyond what is necessary to operate the Visant Labs service

The only exception is when required by law enforcement or court order (see section 3.3).

3.3 Legal Obligations

We may disclose information (including Google authentication data) if required by law or court order.

3.4 API Key Sharing

We do not share your API keys with any third parties. Your API keys are:

  • Stored securely in our encrypted database
  • Used exclusively for processing your requests
  • Never sold, rented, or shared with advertisers, marketing partners, or service providers
  • Never exposed in API responses, logs, or any other output
  • Only decrypted in memory when needed for API calls, then immediately discarded

The only exception is when required by law enforcement or court order (see section 3.3).

4. STORAGE AND SECURITY

All data, including Google authentication data, is protected using industry-standard security measures:

  • Your data is stored on secure servers with encryption at rest and in transit.
  • We use MongoDB, DigitalOcean, and Vercel as our primary infrastructure.
  • We apply reinforced authentication, RLS, and security best practices.
  • OAuth tokens are handled securely and never stored in plain text.
  • All database connections use encrypted channels (TLS/SSL).

4.1 Google Authentication Security

  • We use OAuth 2.0, the industry-standard authentication protocol.
  • Google access tokens are never stored in our database.
  • We only store the Google User ID (sub) and profile information provided by Google after successful authentication.
  • Your Google password is never accessible to us and remains secure with Google.
  • You can revoke our access to your Google account at any time through your Google account settings.

4.2 API Key Security

We implement military-grade security measures to protect your API keys:

  • Encryption: We use AES-256-GCM encryption, a military-grade encryption standard, to encrypt your API keys before storage
  • Master Key: Encryption keys are stored securely in environment variables, never in code or version control
  • No Plaintext Storage: Your API key is never stored in plaintext in our database, logs, or anywhere else
  • In-Memory Decryption: API keys are only decrypted in memory when needed for API calls, then immediately discarded
  • User Isolation: Each user can only access their own encrypted API key
  • Authentication Required: Only authenticated users can save or access their own API keys
  • No Exposure: We never return decrypted API keys in API responses, we only confirm successful operations
  • Audit Trail: API key operations (save/delete) are logged for security auditing

Your Responsibilities: Keep your API key secure, never share it with others, and consider rotating it periodically. Monitor your Google Cloud Console for unexpected usage or charges. Configure API key restrictions in Google AI Studio to limit where it can be used.

5. YOUR RIGHTS

You can:

  • Access your data
  • Correct information
  • Request account deletion
  • Export your data
  • Revoke consents

To exercise your rights, contact Visant Labs support.

6. COOKIES AND TRACKING TECHNOLOGIES

We use cookies for:

  • Authentication
  • Interface preferences
  • Internal metrics

6.1 Google Analytics

We use Google Analytics to understand how visitors interact with our website. Google Analytics collects:

  • Page views and navigation patterns
  • Scroll depth and user interactions
  • Outbound clicks
  • Device and browser information
  • General geographic location (country/city level)

Google Analytics uses cookies and similar technologies. The data collected is processed by Google according to their Privacy Policy. You can:

  • Opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on Browser Add-on
  • Manage cookie preferences through your browser settings
  • Use browser extensions that block tracking

We do not send personally identifiable information (PII) to Google Analytics. We have configured Google Analytics to respect user privacy and comply with data protection regulations.

We do not use advertising cookies or tracking pixels for marketing purposes.

7. DATA RETENTION AND DELETION

7.1 General Data Retention

  • Account data is retained while your subscription is active.
  • Logs and metrics may be retained for up to 12 months.
  • Data may be anonymized for internal analysis.

7.2 Google Authentication Data Retention

Google authentication data (email, name, profile picture, Google User ID) is retained:

  • While your Visant Labs account is active
  • For up to 90 days after account deletion (for security and fraud prevention purposes)
  • As required by law or legal obligations

7.3 API Key Data Retention

Your encrypted API keys are retained:

  • While your Visant Labs account is active and you choose to use your own API key
  • Until you explicitly delete your API key from our system
  • Permanently removed immediately upon deletion, no retention period

7.4 Requesting Data Deletion

You have the right to request deletion of your data, including Google authentication data and API keys:

  • You can delete your API key directly through the Visant Labs settings at any time
  • You can delete your account directly through the Visant Labs settings
  • Contact us at contato@visant.co to request immediate deletion
  • Upon API key deletion, your encrypted key is permanently removed from our systems immediately
  • Upon account deletion, your Google User ID and associated profile data will be permanently removed from our systems
  • To revoke Google OAuth access, visit your Google Account settings at myaccount.google.com/permissions

Note: Some data may be retained for up to 90 days after deletion for security, fraud prevention, or legal compliance purposes, but will not be used for any other purpose during this period. API keys are an exception and are deleted immediately with no retention period.

8. CHANGES TO THIS POLICY

We may update this policy periodically. Substantial changes will be communicated via email or within the application.

9. CONTACT

Visant Labs ®

Support email: contato@visant.co

By using Visant Labs, you agree to this Privacy Policy.