Privacy Policy
Last updated: 1 May 2026
This policy covers all services operated by Alexiuz AS, including alexiuz.com, Botlor, Generor, Darobodo, Muuic, Dupliself, NewsCompute, Ahudio, Vaibie, Caistom, and Discussier (collectively "Alexiuz Services").
1. Data Controller
Alexiuz AS (Org.nr: 918851933), Gamlegrensa 8A, 3747 Skien, Norway is the data controller for all personal data processed across Alexiuz Services.
2. What We Collect
Account Data (all services)
- Email address, username, hashed password, account status
- Hashed IP address, session tokens (not stored long-term)
- Login timestamps, hashed IP, originating service
- Consent records (terms, marketing, product updates)
Service-Specific Data
- Botlor — conversations, preferences, AI interaction history
- Generor — generated content (text, images, audio, video), generation settings
- Darobodo — coaching sessions, wisdom tradition preferences
- Muuic — generated music, MIDI exports, style preferences
- Dupliself — training data, digital twin configurations, voice models
- NewsCompute — news topics, AI-generated stories, preferred AI model, content language, subscription tier, push notification device tokens, generated audio files, inbound emails to [email protected]
- Ahudio — no account data and no audio uploads in v1. The editor runs in your browser; imported, recorded, edited, saved (.ahud) and exported audio is processed locally and never uploaded. Standard webserver access logs (IP, user-agent, request URL, timestamp) apply but are not linked to any account. Optional MP3/OGG/M4A/FLAC/AAC export lazily loads encoder modules from third-party CDNs (esm.sh / Cloudflare); WAV export is fully local.
- Caistom — account link (Alexiuz user ID), cloud-saved designs, uploaded and AI-generated images, print-ready order files, order history and shipping details (shared with production partner Gelato for fulfillment), promotion claims and coupons, and credit usage for AI features.
- Vaibie — game/experience prompts, AI-generated source code, project metadata, gallery entries you choose to publish, render history, and credit usage. Prompts are sent to third-party AI model providers to generate code; do not include secrets or sensitive data in prompts.
- Discussier — forums, threads, posts and replies you create, reactions, follows, profile fields (display name, bio, avatar URL), and a non-monetary energy/reputation score, all linked to your Alexiuz account ID. No wallet or on-chain data is collected.
Credits & Payment Data
- Credit balance (paid, free, earned), transaction history
- Purchase records (processed by Stripe — we do not store card details)
Advertising Data
- Listing submissions, company information provided by advertisers
- Campaign details, bid amounts, click logs (hashed IP, user agent hash, timestamp)
- PPC credit balances and transaction history
3. Legal Basis (GDPR Art. 6)
- Contract (Art. 6.1.b): Account creation, authentication, and service delivery
- Legitimate interest (Art. 6.1.f): Security logging, fraud prevention, service improvement
- Consent (Art. 6.1.a): Newsletter subscriptions, marketing communications
4. Cross-Service Data Sharing
When you use your Alexiuz account on a connected service, that service receives your Alexiuz user ID and email address. Each service stores its own application data linked to this ID. Your credit balance is centralized on alexiuz.com and accessible from any connected service.
5. Shadow Accounts
When a service stores data on your behalf, a shadow account may be created using only your email address. No additional data is collected. You can claim, view, or delete shadow accounts at any time.
7. Data Retention
- Account data: retained while account is active
- Session tokens: cleared on logout or new login
- Auth tokens: single-use, expired entries purged automatically
- Login audit logs: retained for 12 months
- Newsletter subscribers: retained while active; 30 days after unsubscribe
- IP addresses: hashed for sessions; raw IPs for rate limiting retained 90 days
- Generated content: minimum 365 days if you have ever purchased credits, otherwise minimum 14 days; normally retained while the account is active; deleted on account deletion (see AI-Generated Content)
- Uploaded reference material: same minimums as generated content; retained until you delete it or your account is deleted (see AI-Generated Content)
- Advertising data: campaigns, bids, transactions retained while account is active
- Click logs: retained for 24 months for fraud detection
- Payment records: retained as required by Norwegian bookkeeping law (5 years)
8. Your Rights (GDPR Art. 15-22)
You have the right to:
- Access your data via your account page or by contacting us
- Rectify incorrect information
- Delete your account (cascades to all services)
- Port your data in a machine-readable format on request
- Object to processing based on legitimate interest
- Withdraw consent for newsletters or marketing at any time
- Unsubscribe from any newsletter via the link in each email
9. Cookies
- Session cookies: Used on alexiuz.com and authenticated service pages for login sessions
- Functional cookies: Some services (e.g., directories) use cookies for user preferences
- Advertising cookies: Some of our sites are funded by advertising and show ads supplied by Google AdSense. On those sites, third-party vendors including Google use cookies to serve ads based on your prior visits to that site and to other websites. Where consent is required by law (EEA, UK, Switzerland) it is collected through Google's certified consent management platform supporting IAB TCF v2.2, and you can change your answer at any time from the cookies page on the site you are visiting. Sites that carry no advertising set no advertising cookies.
You can also turn off personalised advertising for your Google account at Google Ads Settings, and opt out of many other vendors at aboutads.info/choices. Turning personalisation off does not remove ads; it makes them less relevant.
10. Security
Passwords are hashed with bcrypt. IP addresses are stored as SHA-256 hashes where possible. Sessions use cryptographically random 256-bit tokens. All connections require HTTPS. Payment processing is handled entirely by Stripe.
11. Third-Party Processors
- ElasticEmail: Transactional and newsletter email delivery
- Stripe: Payment processing (credit purchases, advertising, listing packages)
- AI model providers: OpenAI, Anthropic, Google, and others for content generation (prompts may be sent to these providers to generate responses)
- Google AdSense: Advertising delivery, measurement and consent collection on the sites that carry advertising. See how Google uses information from sites that use its services.
12. International Transfers
Our servers are located in Europe. Third-party processors may process data outside the EEA under appropriate safeguards (Standard Contractual Clauses or equivalent mechanisms).
13. Children
Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children.
14. Changes
We may update this policy. Material changes will be communicated via email or in-service notice. The "Last updated" date reflects the most recent revision.
15. Discussier — Forum Data
Discussier (discussier.com) stores the forums you create, your threads, posts and replies, reactions, follows, and profile fields (display name, bio, avatar URL), along with a non-monetary energy/reputation score, all linked to your Discussier user ID, which maps to your Alexiuz account ID. Content you post to public forums is visible to others and may be indexed by search engines. Deleting your Alexiuz account cascades a deletion request to Discussier; published posts may be retained in anonymised form where necessary for thread integrity. Discussier authenticates only via Alexiuz SSO and does not collect wallet addresses or on-chain data.
16. Contact
Alexiuz AS · Org.nr: 918851933 · Gamlegrensa 8A, 3747 Skien, Norway · [email protected]