1.Who we are
IceBerree is operated by HypeFuze LLC (“we”, “us”, “our”), a limited liability company based in Santa Monica, California, United States of America. For the purposes of the UK and EU General Data Protection Regulation, we are the data controller for the personal data described in this policy.
This policy explains what we collect when you use the IceBerree website and application (the “Service”), why, and what control you have. It should be read alongside our Terms of Service.
2.Where your work is stored
Practically, this means your product photographs, canvases, generated images and finished videos normally live on your device. We cannot see them, browse them, or retrieve them for you.
Some features are opt-in and do involve our servers — for example account-based cloud storage, if you enable it. Where that happens, files are stored with our infrastructure providers described in Section 5, under a key that is derived from your verified account so that no other account can read them.
3.What we collect
Information you give us
- Account information — your email address and authentication credentials, handled by our authentication provider. If you sign in with a third-party identity provider, we receive your email address and basic profile identifier from them, not your password.
- Billing information — your plan, billing status and transaction history. We never see or store your full card number. Card details are collected and processed directly by our payment processor.
- Content you submit for processing — the prompts you write and any images or files you supply for a generation, at the moment you request that generation. See Section 6.
- Communications — anything you send us by email or a support form.
Information collected automatically
- Usage and credit records — which type of operation you ran, when, and how many credits it consumed. We keep this to run your balance, prevent abuse, and understand cost. It is a record that a generation happened; it is not a copy of what you generated.
- Technical data — IP address, browser type and version, device and operating system, language, referring page, and timestamps. IP address is used for security, rate limiting and abuse prevention.
- Diagnostic data — error messages and performance information when something fails.
What we do not collect
- We do not collect your contacts, location beyond coarse IP-derived country, browsing history outside our Service, or data from other apps.
- We do not run third-party advertising trackers or advertising pixels on the application.
- We do not knowingly collect sensitive categories of personal data. Please do not upload them.
4.How we use it
| Purpose | Data used | Legal basis (UK/EU) |
|---|---|---|
| Create and run your account | Account information | Performance of a contract |
| Produce the generations you request | Prompts, supplied images | Performance of a contract |
| Meter credits and take payment | Usage records, billing data | Performance of a contract |
| Keep the Service secure; prevent abuse and fraud | Technical data, usage records | Legitimate interests |
| Fix bugs and improve reliability | Diagnostic data, usage records | Legitimate interests |
| Reply to your support messages | Communications | Legitimate interests |
| Send service notices (billing, security, changes) | Account information | Performance of a contract / legal obligation |
| Send marketing email, if you opt in | Account information | Consent — withdrawable at any time |
| Meet legal, tax and accounting obligations | Billing records | Legal obligation |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects about you.
5.Who we share it with
We share data only with service providers who help us run IceBerree, and only to the extent they need it. They act on our instructions under contract and may not use your data for their own purposes.
| Category of provider | What they receive | Why |
|---|---|---|
| Authentication & database hosting | Email, account identifier, plan and credit balance | To sign you in and hold your account record |
| Edge compute & object storage | Requests routed through our servers; files only if you enable cloud storage | To run the application and store opt-in files |
| AI model providers | The prompt and any images you supplied for that generation | To actually produce the image, video, audio or text |
| Payment processor | Billing details, entered directly with them | To take payment and manage subscriptions |
| Email delivery | Email address and message content | To send account and service email |
We may also disclose information where required by law, valid legal process or a governmental request; to enforce our Terms or protect the rights, safety and property of IceBerree, our users or the public; or in connection with a merger, acquisition, financing or sale of assets — in which case we will give notice before your data becomes subject to a different privacy policy.
6.AI providers and your content
To generate an image, a video, speech or written copy, the content required for that specific request must be transmitted to the AI provider that runs the model. Depending on the feature, that is:
- the text of your prompt, including any product facts or dialogue you wrote;
- the images you attached to that request — for example a product photograph used as a visual reference; and
- technical parameters such as duration, aspect ratio and quality.
This transmission is the mechanism by which the feature works; it is not optional, and it happens only when you actively request a generation. Content sitting in your browser that you never submit is never transmitted.
Our AI providers process this content to return a result to us, which we pass back to you. Their retention practices are governed by their own agreements with us and their own policies. We select providers that offer business or API terms and we do not enrol your content in any model-improvement programme where an opt-out is available to us.
We can name our current providers on request, and we will update this policy if the categories change materially.
7.We do not train on your work
When we improve the Service, we do so using aggregated, non-identifying operational signals — for example how often a feature errors, or how long a generation takes — not the substance of what you created.
8.Cookies and local storage
We use a deliberately small set of browser storage technologies:
- Strictly necessary — a session or token store that keeps you signed in, and security tokens that protect against request forgery. The Service cannot work without these.
- Preferences — small values remembering your settings, such as theme and interface choices.
- Application storage (IndexedDB) — the substantial local database holding your projects, uploads and generated media, as described in Section 2. This never leaves your device unless you explicitly export or enable cloud storage.
We do not use advertising cookies, cross-site trackers, social-media pixels or data brokers. You can clear this storage at any time through your browser — but note that doing so will also delete locally stored work, permanently.
9.How long we keep things
| Data | Retention |
|---|---|
| Account record | While your account is open, then deleted within 30 days of closure |
| Locally stored projects and media | Until you delete them, or your browser storage is cleared — controlled entirely by you |
| Items you delete in-app | Held in Recently Deleted for 60 days, then purged automatically |
| Opt-in cloud files | While your account is open, or until you delete them |
| Usage and credit records | Up to 24 months, for billing accuracy and abuse prevention |
| Billing and tax records | As required by law, typically 7 years |
| Support correspondence | Up to 24 months after the matter closes |
| Security and error logs | Typically 90 days |
Backups are cycled on a rolling basis; data deleted from live systems may persist briefly in backups before being overwritten.
10.Deleting your data
You are in unusually direct control here:
- Individual files and projects — delete them in the app. They go to Recently Deleted for 60 days, where you can restore them, and are then purged.
- Everything stored locally — clearing site data in your browser removes all of it immediately and irreversibly.
- Your whole account — contact us at contact@hypefuze.com and we will delete your account record and any cloud-stored files. We will confirm when it is done.
We may retain the minimum necessary for legal, tax, accounting or fraud-prevention purposes, and anonymised records that can no longer identify you.
11.Security
We take reasonable and appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS/TLS), encryption at rest with our infrastructure providers, verified-token authorisation on requests that touch account data, isolation of stored files by account so one account cannot read another's, rate limiting, and least-privilege access to production systems.
Keeping most content local rather than on our servers is itself a security decision: content we do not hold cannot be taken from us.
No system is perfectly secure, and we cannot guarantee absolute security. You are responsible for the security of your own device, browser and account credentials. If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required by law.
12.International transfers
We and our providers operate globally, so your information may be processed in countries other than your own, including the United States. Where we transfer personal data out of the UK or European Economic Area, we rely on an appropriate safeguard — typically the European Commission's Standard Contractual Clauses (and the UK Addendum), or a finding of adequacy. You may request a copy of the relevant safeguard using the contact details below.
13.Your rights (UK / EU)
If you are in the UK or the European Economic Area, you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”), subject to legal retention;
- restrict or object to processing carried out on the basis of legitimate interests;
- data portability — receive data you gave us in a structured, machine-readable format;
- withdraw consent at any time where we rely on consent, without affecting prior processing; and
- complain to your supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).
To exercise any of these, email contact@hypefuze.com. We will respond within one month and will not charge you or penalise you for asking.
14.Your rights (California and other US states)
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect and how we use and disclose it; to request deletion; to request correction; and to be free from discrimination for exercising these rights. Residents of other US states with comprehensive privacy laws have broadly equivalent rights.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of — but the right to opt out would be honoured if that ever changed, and we would tell you before it did.
Requests can be made to contact@hypefuze.com. We will verify your identity through your account email before acting. You may use an authorised agent, with proof of authorisation.
15.Children
IceBerree is not directed to children. You must be at least 16, or the age of digital consent where you live if higher, to use it. We do not knowingly collect personal data from children below that age. If you believe a child has provided us personal data, contact us and we will delete it promptly.
16.Do Not Track
We do not track users across third-party websites, so we do not respond differently to Do Not Track signals. We simply do not do the thing those signals ask us not to do.
17.Changes to this policy
We may update this policy as the Service changes. The “Last updated” date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will give you notice by email or in the application before it takes effect. Material changes will never be applied retroactively to data already collected without a lawful basis.
18.Contact
For any privacy question, request or complaint, email contact@hypefuze.com.
We read every message and aim to reply within a few business days, and always within the period the law requires.