Bespoke AI home

    Privacy Policy

    Last updated: June 14, 2026 · Controller: Haiku Labs, Paris, France

    1. Who we are

    Bespoke AI is operated by Haiku Labs. Contact: privacy@bespokeai.build.

    2. Data we collect

    • Account: email, hashed password, display name.
    • Billing: name, billing address, VAT number, tokenised payment method (held by Stripe — we never see card numbers).
    • Project content: sketches, images, prompts, generated renders, 3D meshes, CAD exports.
    • Technical: IP address, browser type, timestamps for security and abuse prevention.

    3. Lawful basis (GDPR Art. 6)

    • Contract: account, billing, project storage.
    • Legitimate interest: security logging, fraud prevention, service improvement.
    • Consent: non-essential cookies and analytics.
    • Legal obligation: invoice retention.

    4. Retention

    • Account data — for the life of the account.
    • Project files in the temporary processing bucket — purged after 30 days.
    • Security logs — 12 months.
    • Invoices — 10 years (French tax law).
    • Encrypted backups — 30 days rolling.

    5. Sub-processors

    The full list is maintained at /sub-processors.

    6. International transfers

    Some sub-processors host in the United States. Transfers rely on the EU Standard Contractual Clauses (2021/914).

    7. Your rights

    You can access, rectify, export, restrict, or delete your data at any time. The fastest path is the "Delete Account" button in your subscription settings. For other requests, email privacy@bespokeai.build. You also have the right to lodge a complaint with your local supervisory authority.

    8. AI processing

    Image and prompt inputs are sent to the AI sub-processors listed at /sub-processors strictly for the purpose of generating the output you requested. We do not use your content to train foundation models. We contractually require sub-processors to do the same where the option exists.

    9. Security

    TLS 1.2+ in transit, AES-256 at rest, RLS-isolated multi-tenant data, JWT auth, MFA available, audit logging, and the controls described in our Data Processing Agreement.

    10. Changes

    We will notify subscribers by email of material changes at least 30 days before they take effect.