Privacy Policy
Last updated: 7. July 2026
Privacy Policy
This privacy policy describes how Claibe ApS collects, uses, and processes your personal information when you use our AI-powered image processing platform.
Who are we?
Data Controller: Claibe ApS
CVR: 45872289
Address: Kastanievej 15, 1876 Frederiksberg C, Denmark
Email: contact@claibe.com
We comply with applicable Danish and EU data protection legislation (GDPR).
What information do we collect?
Account Information
- First name, last name, and email address
- Company name
- Industry and team size
- Organization name
- Password (stored only as an encrypted hash)
- Phone number, if you enable two-factor authentication via SMS
- Subscription status and credits
Usage Data
- Uploaded images and files
- AI-generated results
- Platform activity and settings
- IP address and browser information
- Technical signals for abuse prevention, including device fingerprinting (see the security and abuse prevention section)
- Support requests and communication
Payment Information
- Billing address
- Payment method (we do not store card numbers)
- Transaction history
How do we use your information?
Providing the Service
- Processing and enhancing your images with AI
- Managing your account and subscription
- Providing customer support
- Sending important service notifications
Improving the Platform
- Analyzing user behavior to improve the platform and user experience
- Developing new features
- Optimizing platform performance
We do not train AI models on your data.
Security and Abuse Prevention
- Preventing and detecting abuse of free trials and the platform in general
- For this purpose we use device fingerprinting (FingerprintJS) and captcha (Cloudflare Turnstile), based on our legitimate interest in protecting the service
Legal Compliance
- Fulfilling accounting and auditing obligations
- Complying with Danish law
- Handling disputes and legal claims
Legal Basis for Processing
We process your personal information based on:
- Contract: For providing our services (GDPR art. 6.1.b)
- Legitimate interest: For service improvement, security, and abuse prevention (GDPR art. 6.1.f)
- Consent: For marketing and analytics cookies, where you have given consent (GDPR art. 6.1.a)
- Legal obligation: For compliance with legal requirements (GDPR art. 6.1.c)
Data Storage and Security
Where is your data stored?
- Images and generated content are stored on servers in the EU (AWS in Frankfurt and Hetzner in Germany)
- Some of our sub-processors - e.g. database, hosting, error monitoring, and certain AI services - process data in the USA
- All transfers to the USA are based on the EU-U.S. Data Privacy Framework (DPF) and/or the European Commission's Standard Contractual Clauses (SCCs), see the section on international transfers
Security Measures
- All communication is encrypted in transit (TLS/HTTPS), and data is encrypted at rest with our cloud providers
- Passwords are stored only as bcrypt hashes
- Two-factor authentication available
- Internal security audits and ongoing vulnerability monitoring
- Access control and logging of security-relevant events
Retention Periods
- Account information: As long as your account is active
- Images and content: Deleted no later than 30 days after account deletion
- Payment information: 5 years (Danish Bookkeeping Act)
- Support requests: 2 years
- Abuse signals: Up to 90 days
- Anonymized usage data: Up to 3 years for product improvement
Sharing with Third Parties
We only share your information with data processors necessary to provide the service:
Infrastructure and Operations
- AWS (EU, Frankfurt) and Hetzner (Germany) - image storage
- Neon (USA) - database
- Vercel (USA) - platform hosting
- Upstash (USA) - temporary cache and rate limiting
- Sentry (USA) - error monitoring and logging
AI Processing
When you use an AI feature, the specific image and/or your text instruction is sent to the relevant AI provider - without your name, email, or organization details. Note that AI-generated images contain embedded traceability metadata (XMP/C2PA) including an internal user ID; if you re-process a generated image, this metadata may accompany the image:
- Google (Gemini), Black Forest Labs / FLUX (Germany), Freepik/Magnific (Spain), Photoroom (France), Reve AI (USA), OpenAI (USA), fal.ai (USA), OpenRouter (USA), Recraft, and Vectorizer.ai
None of these providers may use your data to train AI models.
Communication and Payment
- Resend (USA) - transactional emails (receipts, account notifications)
- Klaviyo (USA) - newsletters and marketing emails (only with consent)
- Twilio (USA) - SMS codes for two-factor authentication
- Stripe (EU, Ireland) - payment processing
- Dinero/Visma (Denmark) - bookkeeping
Analytics and Security
- Hotjar (Malta) - user experience analytics (pseudonymized, with consent)
- Google Tag Manager / Google Analytics and Vercel Analytics - traffic analytics (with consent)
- FingerprintJS and Cloudflare Turnstile - abuse prevention
Legal Requirements
- Danish authorities upon legally mandated requests
- Auditors and lawyers when needed
- Payment card companies in case of suspected fraud
We never sell your personal information to third parties.
International Transfers
Several of our sub-processors are established in the USA, and use of the platform therefore involves transferring personal data to the USA. All transfers are based on:
- The EU-U.S. Data Privacy Framework (DPF), where the provider is certified, and/or
- The European Commission's Standard Contractual Clauses (SCCs)
A complete and up-to-date list of sub-processors including transfer mechanisms is available in our Data Processing Agreement, which business customers can request via contact@claibe.com.
Your Rights Under GDPR
You have the following rights:
Right of Access (art. 15)
- Receive a copy of all your personal information
- Know how we use your data
Right to Rectification (art. 16)
- Have incorrect information corrected
- Have incomplete information completed
Right to Erasure (art. 17)
- Have your data deleted when no longer necessary
- Withdraw consent
Right to Restriction (art. 18)
- Restrict the processing of your data
- Temporarily "freeze" your information
Right to Data Portability (art. 20)
- Receive your data in a structured, machine-readable format
- Transfer data to another service provider
Right to Object (art. 21)
- Object to processing based on legitimate interest
- Unsubscribe from marketing
To exercise your rights, contact us at contact@claibe.com. We respond within 30 days.
Cookies and Tracking
Necessary Cookies
- Session ID and authentication
- Language settings
- Security functions (including Cloudflare Turnstile)
Analytics and Tracking (with consent)
- Google Tag Manager / Google Analytics
- Hotjar for user experience
- Vercel Analytics and performance monitoring
You can always change your cookie settings in your browser or on our platform. See also our cookie policy.
AI and Machine Learning
Use of Your Images
- Your uploaded images are only used to deliver the requested AI processing
- Neither we nor our AI providers train AI models on your images
- Both input and output images are stored in your account for later use
- No manual review of your images
Third-Party Models
- We use AI APIs from the providers listed under "Sharing with Third Parties"
- These services have their own privacy policies
- We do not send your name, email, or organization details to these services - only the image and instruction to be processed (but see the note about embedded metadata above). Please note that images you upload may themselves contain personal data (e.g. depicted individuals); you are responsible for having a legal basis for processing such images
Children's Data
Our platform is not intended for persons under 18 years of age. We do not knowingly collect personal information from minors.
Changes to This Policy
We may update this privacy policy to reflect:
- Changes in legislation
- New features or providers on the platform
- Improved security measures
Notification of Changes
- Material changes are announced 30 days in advance via email
- Minor changes are updated on the website
- You can always see the latest version at claibe.com/en/privacy
Complaints and Supervision
Complaints to Us
Contact us first at contact@claibe.com if you have concerns about our processing of your data.
Complaints to the Danish Data Protection Agency
You have the right to complain to Datatilsynet:
- Website: datatilsynet.dk
- Email: dt@datatilsynet.dk
- Phone: +45 33 19 32 00
- Address: Borgergade 28, 5., 1300 Copenhagen K, Denmark
Data Breaches
In case of data breaches affecting your rights:
- We notify the Danish Data Protection Agency within 72 hours
- We inform you directly if there is a high risk
- We publish information on our website if necessary
Contact Regarding Data Protection
Email: contact@claibe.com
We treat all inquiries confidentially and respond within 5 business days.
This privacy policy was last updated: July 7, 2026 Next scheduled review: January 7, 2027
