Privacy Policy
Last updated 8 October 2026 · Version 2026-10-08
We built InstaStudio to keep your creative work private by default. This policy explains what personal data we process when you use InstaStudio, why, who we share it with, and the choices and rights you have under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and, where it applies to you, the EU/UK General Data Protection Regulation (“GDPR”).
1. Who we are
InstaStudio is operated by InstaDataHelp Analytics Services, India. For the purposes of the DPDP Act we are the Data Fiduciary (and, under the GDPR, the controller) for account, billing and usage data. For the content you upload and generate, we process data on your instructions to provide the Service. Contact us at support@instadatahelp.com.
2. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password hash, workspace names, role, terms acceptance record | You |
| Billing data | Plan, purchases, amounts, invoice details, GSTIN (if provided), payment status and transaction IDs. We do not receive full card numbers, UPI PINs or bank credentials. | You, PayU, Stripe |
| Content | Prompts, uploaded images/video/audio, voice samples, avatar photos, generated outputs, editor projects, chat messages with the studio assistant | You |
| Usage data | Jobs run, models used, credits spent, feature usage, error logs | Automatically |
| Device & log data | IP address, browser user-agent, timestamps, approximate location derived from IP, session identifiers | Automatically |
| Communications | Support emails, feedback, grievance correspondence | You |
Uploads may contain personal data of other people (for example a face or voice). You must only upload such data where you have the person’s consent or another lawful basis — see our Acceptable Use Policy.
3. How we use personal data
- Provide the Service — create and secure your account, run your generations, store and display your assets, operate team workspaces and sharing.
- Billing — process payments, issue GST invoices, manage credits and refunds, prevent payment fraud, meet tax and accounting obligations.
- Safety and abuse prevention — automated and human review of prompts and outputs to enforce our policies, detect fraud and multiple-account abuse, rate-limit misuse, and respond to legal requests.
- Support and communications — answer requests, send service and transactional emails (receipts, password resets, security notices, plan expiry reminders). Marketing emails are sent only with your consent and you can unsubscribe at any time.
- Improve reliability — aggregate analytics on usage, latency, failures and costs to improve routing, pricing and features. We do not use your content to train AI models.
4. Legal bases
Under the DPDP Act we process personal data on the basis of your consent (given when you sign up and accept our Terms and this policy) and for legitimate uses permitted by Section 7, such as compliance with law, responding to legal orders and processing data you voluntarily provide for a specified purpose. Under the GDPR, our bases are performance of a contract (providing the Service), legitimate interests (security, fraud prevention, product improvement), legal obligation (tax, accounting, law-enforcement requests) and consent (marketing, optional cookies). You may withdraw consent at any time; this does not affect processing already carried out, and withdrawing consent needed to run the Service means we will have to close your account.
5. How AI processing works
- When you run a generation, your prompt and the relevant inputs are sent to the model provider that runs that job (see Section 6), and the output is downloaded and stored on our servers. Provider-hosted copies are temporary.
- For features such as prompt rewriting, Auto-mode intent detection, scripts and storyboards, prompts are processed by large-language-model providers via our routing gateway.
- We do not use your prompts, uploads or outputs to train AI models, and we select providers whose API terms do not permit them to train on customer inputs submitted through their APIs.
- Prompts and outputs may be screened by automated safety classifiers. Content flagged for potential serious violations (for example CSAM) may be reviewed by trained staff and, where required, reported to authorities.
6. Sharing and processors
We do not sell personal data. We share it only with:
- AI model and infrastructure providers that run generations on our behalf, such as fal.ai and the underlying model developers (e.g. Google, ElevenLabs, Kuaishou, ByteDance, Black Forest Labs, OpenAI, Alibaba, MiniMax, Luma AI), and LLM providers reached through the InstaRoute gateway — only the prompt and inputs needed for the job.
- Payment processors — PayU Payments Private Limited (India) and Stripe, Inc. (international), which process your payment under their own privacy policies.
- Hosting, email and operations vendors — cloud hosting in India, transactional email delivery and error monitoring, under contracts that restrict their use of your data.
- Other users — only what you choose to share: assets you make public or share by link, items featured in Explore with your permission, and content visible to members of a team workspace you belong to.
- Authorities — where required by law, a court order or a lawful request from a government agency, or to protect the rights, safety and property of our users, the public or us.
- Business transfers — a successor in a merger, acquisition or asset sale, subject to this policy.
7. International transfers
Our primary servers and media storage are located in India. Some model providers and processors operate outside India (for example in the United States or the European Union), so job inputs and limited account data may be transferred abroad. We only transfer data to countries not restricted by the Central Government under Section 16 of the DPDP Act, and for GDPR-covered users we rely on appropriate safeguards such as Standard Contractual Clauses.
8. Data retention
| Data | Retention |
|---|---|
| Account data | While your account is open, then deleted within 30 days of closure (except as below) |
| Assets and prompts | Until you delete them or close your account. Deleted assets are removed from active storage immediately and purged from backups within 30 days |
| Billing and tax records | 8 years from the end of the relevant financial year, as required by Indian tax and company law |
| Security and access logs | Up to 180 days, or longer where required by CERT-In directions or an ongoing investigation |
| Content removed for policy violations | Retained securely for as long as needed for legal reporting and to defend claims |
9. Your rights
Subject to applicable law, you have the right to:
- Access a summary of the personal data we hold about you and the processing activities, and the identities of those we have shared it with;
- Correction, completion and updating of inaccurate or incomplete data;
- Erasure of data that is no longer needed or for which you withdraw consent (you can delete assets and your account yourself, or ask us);
- Withdraw consent at any time, as easily as you gave it;
- Nominate another person to exercise your rights in the event of your death or incapacity (DPDP Act Section 14);
- Grievance redressal through our Grievance Officer, and to complain to the Data Protection Board of India once you have exhausted our process;
- for GDPR-covered users, additionally: data portability, objection to processing based on legitimate interests, restriction of processing, and to lodge a complaint with your local supervisory authority.
To exercise a right, email support@instadatahelp.com from your account email. We may need to verify your identity. We respond within 30 days (or sooner where the law requires).
10. Cookies and similar technologies
We use a small number of cookies and local-storage entries:
- Strictly necessary — the
ss_sessioncookie keeps you signed in (httpOnly, secure, expires after inactivity); security and load-balancing cookies; payment-processor cookies during checkout. - Preferences — remembering choices such as your currency, theme or last-used model (stored in your browser).
- Analytics — if we enable privacy-friendly analytics, it is aggregated and does not track you across other sites. We do not use advertising or cross-site tracking cookies.
You can block or delete cookies in your browser settings, but the Service will not work without strictly necessary cookies.
11. Security
We protect data with TLS encryption in transit, hashed passwords (bcrypt), random unguessable file names for media, least-privilege access for staff, isolated infrastructure and regular backups. No system is perfectly secure; if a personal data breach occurs we will notify affected users and the Data Protection Board of India (and CERT-In, where applicable) as required by law.
12. Children
InstaStudio is not intended for anyone under 18 and we do not knowingly collect personal data from children. If you believe a child has created an account, contact support@instadatahelp.com and we will delete it.
13. Changes to this policy
We will post updates here and update the date at the top. For material changes we will notify you by email or in the Service before they take effect.
14. Contact and Grievance Officer
Questions, requests and complaints: Grievance Officer, InstaDataHelp Analytics Services — support@instadatahelp.com (subject “Privacy”). We acknowledge within 48 hours and aim to resolve within 15 days.