Skip to legal document
Legal←Back to website

Documents

  1. Legal Center
  2. Terms of Use
  3. Privacy & Cookies Policy
Legal/Privacy & Cookies Policy
Browse legal documents

Documents

  1. Legal Center
  2. Terms of Use
  3. Privacy & Cookies Policy

On this page

ScopeCollected dataPromptsUseSharingProvidersCookiesRetentionRightsTransfersContact

Legal document

Privacy& Cookies

Last updated: August 19, 202611 sections

Visu.Haus is an AI-assisted creative software service for generating, editing, storing, exporting, and sharing interactive visual files. The service can also be used through APIs and a Model Context Protocol server that lets compatible AI clients interact with Visu.Haus on a connected user account. This Privacy & Cookies Policy explains what information we collect, why we collect it, and how it is used.

We collect information to operate the product, process requests, protect the service, support users, process payments, improve reliability, and understand how Visu.Haus is used. For privacy requests, contact contact@visu.haus.

Scope and Controller

This Policy applies to Visu.Haus websites, accounts, editor surfaces, generator routes, gallery pages, billing flows, emails, support, exports, public links, APIs, MCP server access, connected-client features, and related services. Third-party services that you choose to use with Visu.Haus may have their own terms and privacy policies.

For purposes of privacy laws, Visu.Haus is generally the controller of account, billing, product, support, analytics, and saved library information. AI providers, authentication providers, payment processors, hosting providers, email providers, analytics providers, and storage providers may process information as service providers or independent controllers depending on their role and terms.

Information We Collect

Account information
Name, email address, authentication identifiers, profile details, account status, plan, role, locale, settings, and sign-in state.
Creation information
Prompts, instructions, generation settings, generated visus, saved .visu files, uploaded reference assets, uploaded media, covers, previews, exports, edit history, gallery submissions, share links, titles, tags, creator attribution, MCP tool requests, API requests, connected-client actions, and generated or uploaded files saved through integrations.
Billing information
Plan, credit balances, subscription status, invoices, Stripe customer identifiers, purchase history, cancellation state, refunds, payment events, and billing support records. Stripe processes payment card details; Visu.Haus does not store full card numbers.
Usage and device information
IP address, browser, device, operating system, approximate location inferred from network data, pages viewed, features used, timing, clicks, errors, logs, performance data, analytics events, security signals, API metadata, MCP session metadata, client identifiers, authorization status, and feature-gate decisions.
Messages and support
Emails, feedback, bug reports, legal notices, copyright reports, billing disputes, security reports, commercial inquiries, and other information you send directly.

Do not upload secrets, passwords, private credentials, highly sensitive personal information, confidential client files, or material you do not have the right to use.

Prompts, Outputs, and Internal Improvement

We may log prompts, uploaded context, generation settings, outputs, errors, MCP tool calls, API requests, saved-file actions, and related metadata to operate, debug, secure, monitor abuse, support, and improve Visu.Haus internally.

We do not sell your private prompts or private uploaded files. We do not publish private prompts, private uploads, or private saved files without your permission, except where required to comply with law, enforce rights, investigate abuse, protect safety, or operate the service through trusted providers.

Private prompts and private uploaded files may be processed by AI providers, hosting providers, storage providers, analytics providers, connected clients you authorize, and operational vendors as needed to provide and improve the service. We do not use private prompts or private uploaded files to train public third-party AI models unless you explicitly opt in.

Public gallery items, public share links, public titles, public creator attribution, public previews, and public .visu files are public by design and may be indexed, viewed, copied, opened, or remixed by others depending on product features and settings.

How We Use Information

  • Provide, secure, maintain, personalize, and improve Visu.Haus accounts, editor tools, gallery pages, saved files, exports, billing, and support.
  • Generate, update, render, store, duplicate, publish, share, download, and export visus at your request.
  • Authenticate MCP and API access, expose account status and product instructions to compatible clients, save generated visus to your library, and return links or files requested through connected workflows.
  • Track credits, plan limits, feature gates, subscriptions, purchases, billing status, refunds, and account state.
  • Detect abuse, prevent fraud, enforce limits, troubleshoot errors, protect the service, prevent misuse, and protect other users.
  • Measure usage, reliability, conversion, product quality, performance, and feature adoption.
  • Send transactional emails, account notices, receipts, plan updates, support replies, legal notices, and, where allowed, product updates.
  • Comply with legal obligations, accounting rules, tax requirements, payment records, security requirements, and valid legal requests.

How We Share Information

We do not sell personal information in the ordinary sense of that phrase. We share information only when needed to operate Visu.Haus, when you choose to publish or share something, when a provider is needed to process a request, or when legal, safety, security, or business reasons require it.

  • Service providers: hosting, storage, database, authentication, analytics, advertising and conversion measurement, payments, email, security, AI generation, logging, customer support, and operational tooling. Each provider is named individually in the Service Providers and Subprocessors section below.
  • AI providers: prompts, uploaded context, settings, and related data may be sent to AI providers to generate or update output.
  • Connected clients: if you connect Visu.Haus to an MCP client, AI assistant, automation, or third-party tool, information needed to complete your requested action may be returned to or processed by that client. Visu.Haus does not control the privacy practices, retention, security, or costs of those external clients.
  • Public sharing: published gallery items, public links, titles, creator names, previews, source files, metadata, and files needed to display or open the shared visu.
  • Legal and safety: information may be disclosed to comply with law, enforce terms, protect rights, investigate abuse, prevent harm, or respond to valid requests.
  • Business changes: information may transfer as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.

Service Providers and Subprocessors

The companies below process personal information on behalf of Visu.Haus so that the service can operate. Each one is bound by its own agreement with Visu.Haus and may use the information only to provide its service. This list reflects the providers in use as of the date shown at the top of this page.

Clerk
Account authentication, sign-in, sign-up, sessions, and identity management. Receives name, email address, authentication identifiers, profile details, sign-in metadata, and IP address.
Neon
Managed PostgreSQL database. Stores account records, profiles, plans, subscriptions, credit ledgers, library metadata, generation job records, activity events, and email delivery events.
Vercel
Application hosting, edge network, and serverless execution for the website, editor, and APIs; Vercel Blob file storage for uploaded and generated files; and Vercel Web Analytics for page-level traffic measurement. Receives request metadata, IP address, and any content processed or stored through those surfaces.
Cloudflare
R2 object storage and delivery for saved .visu files, covers, previews, gallery media, and exports served from the Visu.Haus asset domain. Receives the stored files and the request metadata of anyone who loads them.
Stripe
Payment processing, subscription billing, checkout, invoices, the billing portal, and tax identifiers where they are required. Receives name, email address, billing address, payment method details, and purchase records. Visu.Haus does not store full card numbers.
OpenRouter
Routing of managed AI generation to the underlying model providers. Receives prompts, uploaded context, reference images, audio submitted for transcription, generation settings, and related request metadata.
Fal.ai
Image-to-3D and image-to-splat generation jobs. Receives the reference images, settings, and job metadata submitted for those generations, and returns the generated asset.
Resend
Transactional email delivery for account, credit, plan, and support messages. Receives recipient email address, message content, and delivery events.

These providers are established primarily in the United States and may process information there and in other countries where they or their own infrastructure providers operate. See the international transfer section below.

Separately from the providers above, the third parties below receive your IP address, browser user agent, and the address of the page being loaded whenever your browser requests resources directly from them. They are not acting on behalf of Visu.Haus for those requests, and their own policies apply.

Google — advertising and conversion measurement
A Google Ads tag loads on pages of the website for conversion and advertising measurement. It can set and read advertising identifiers in your browser and receives the page address, IP address, and user agent.
Adobe Typekit and Google Fonts
Typeface files used by the website and by the prompt engine surface are requested from Adobe and Google font hosts when a page loads.
jsDelivr and esm.sh
Public content delivery networks used to load browser libraries for the editor and for page instrumentation.
Google — MediaPipe models
When you enable camera tracking in the editor, the face, hand, and gesture recognition models are downloaded from Google model hosting. The tracking itself runs in your browser.

If you connect Visu.Haus to an MCP client, AI assistant, automation, or other external tool, that client is chosen and controlled by you. Information needed to complete your requested action is returned to it, and Visu.Haus does not control its privacy practices, retention, security, or costs.

Providers change as the product changes. When a provider that processes personal information is added or replaced, this section is updated and the date at the top of this page changes with it. To ask which providers handled a specific request, contact contact@visu.haus.

Cookies, Local Storage, and Analytics

Visu.Haus may use cookies, local storage, session storage, IndexedDB, and similar technologies to keep you signed in, protect sessions, remember preferences, route traffic, support editor state, store temporary launch intents, measure performance, understand product usage, and improve reliability.

Essential technologies
Authentication, security, routing, billing, fraud prevention, editor state, saved preferences, and product functions that are needed for the service to work.
Analytics technologies
Measurement tools that help us understand traffic, page views, feature usage, performance, errors, and product quality. These run only if you allow the analytics category.
Advertising technologies
A Google Ads tag that measures whether an advertisement led to a signup. It sets an advertising identifier in your browser and shares it with Google. It runs only if you allow the advertising category, and it is not loaded at all until you do.
Browser controls
You can block or delete cookies and storage through your browser. Blocking some technologies may affect sign-in, billing, saved preferences, editor behavior, exports, uploads, or security features.

The specific cookies and stored values in use are listed below. Durations are the maximum lifetime set at the time of writing; a technology may be removed before then.

visu_haus_consent — Visu.Haus, 180 days, essential
Records the cookie choices you made and when you made them, so that we do not ask again and can show that a choice was offered. Cleared when you change your choices.
__session and related Clerk cookies — Clerk, session, essential
Keep you signed in and protect the session against forgery. Set by our authentication provider.
visu_haus_site_gate — Visu.Haus, 7 days, essential
Records access while the site is closed for development. Removed when the site opens publicly.
visu_control_panel — Visu.Haus, session, essential
Signed administrative session for the internal control panel. Only set for operators.
_gcl_au and related Google Ads identifiers — Google, up to 90 days, advertising
Measures whether an advertisement led to a signup. Set only after you allow the advertising category.
Vercel Web Analytics — Vercel, page-level measurement, analytics
Counts page views and performance. Loaded only after you allow the analytics category.
Editor and preference values in local storage — Visu.Haus, until cleared, essential
Editor state, onboarding progress, saved preferences and temporary launch intents, held in your browser so the product behaves consistently between visits. Not transmitted for measurement or advertising.

Non-essential technologies are denied by default. When you first visit, nothing in the analytics or advertising categories is loaded, and advertising signals are set to denied until you choose otherwise. You can change your choices at any time through the cookie preferences control, or contact contact@visu.haus to request privacy choices or restrictions tied to your account.

Web fonts are handled differently and are not part of the choices above. Our typefaces are delivered by Adobe and, on one surface, Google. Requesting a font file discloses your IP address and browser to those providers but sets no cookie and stores no identifier. We rely on our legitimate interest in presenting the service in its intended design (GDPR art. 6(1)(f) / LGPD art. 7 IX); our licence for the Visu.Haus typeface does not allow us to serve those files from our own servers. You may object to this processing at any time by contacting contact@visu.haus, and you can ask us for the balancing assessment behind it.

Retention and Security

We keep information for as long as reasonably needed to provide Visu.Haus, maintain records, resolve disputes, enforce agreements, protect against abuse, support users, improve the product, and meet legal, tax, accounting, and security obligations.

  • Account, profile, plan, and library information are generally kept while the account is active.
  • Saved files, public gallery items, share links, covers, previews, and exports may remain until removed, unpublished, deleted, or restricted according to product controls and platform rules.
  • MCP and API logs, tool-call metadata, authorization metadata, generated links, upload records, and troubleshooting data may be retained for operational, security, abuse-prevention, support, billing, and legal reasons.
  • Billing, subscription, invoice, credit ledger, tax, dispute, and accounting records may be retained for legally required or commercially reasonable periods.
  • Logs, analytics, security events, delivery events, and troubleshooting data are kept for limited operational periods unless needed for abuse prevention, legal claims, safety, or security.
  • Backups, caches, provider logs, and archived records may retain copies for a limited time after deletion from live product surfaces.

We use reasonable administrative, technical, and organizational safeguards, including access controls, provider security controls, and encryption for sensitive stored information where appropriate. No internet service can guarantee perfect security.

Privacy Choices and Rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for certain processing of your personal information. You may also have rights to opt out of certain sharing, targeted advertising, profiling, or marketing and to avoid discrimination for exercising privacy rights.

To make a request, contact contact@visu.haus. We may need to verify your identity and account before responding. Some information may be retained when needed for security, billing, accounting, legal, fraud prevention, abuse prevention, or legitimate operational reasons.

If you are located in a jurisdiction with a privacy regulator, you may have the right to complain to that regulator. We ask that you contact us first so we can try to address the issue.

Children, International Transfers, and Updates

Visu.Haus is not directed to children under 16. Paid accounts should be used only by adults or by users with permission from a parent, guardian, or authorized organization.

Visu.Haus and its providers may process information in the United States and other countries where we or our service providers operate. Those countries may have privacy laws different from the laws where you live.

We may update this Policy as the product, providers, laws, or business changes. If changes are material, we will take reasonable steps to notify users through the site, product, account area, or email.

Contact

For privacy requests, cookie questions, security concerns, provider questions, MCP access questions, or requests about prompts and saved content, contact Visu.Haus at contact@visu.haus.

Questions about this policy?

Contact Visu.Haus
← PreviousLegalTerms of Use

On this page

ScopeCollected dataPromptsUseSharingProvidersCookiesRetentionRightsTransfersContact

Create

Download for macOSDownload on the App StoreLoad .visu

About

PricingArticlesDocs

Connect

@visu_hausCreated by@luzcasluzContact

Legal

Legal CenterTerms of UsePrivacy & Cookies