Legal

Privacy Policy

Last updated: July 24, 2026 · Effective: July 24, 2026

The short version, in plain English. Most of your work never leaves your own computer — projects and media are stored in your browser by default, not on our servers. We collect the minimum needed to run an account: your email, your plan, and your credit balance. We do not sell your data, we do not use your work to train AI models, and we do not show you third-party advertising. When you generate something, your prompt and any images you supplied are sent to the AI provider that produces it — that is the one unavoidable sharing, and it is described in Section 5. This summary is for readability; the sections below are the actual policy.

1.Who we are

IceBerree is operated by HypeFuze LLC (“we”, “us”, “our”), a limited liability company based in Santa Monica, California, United States of America. For the purposes of the UK and EU General Data Protection Regulation, we are the data controller for the personal data described in this policy.

This policy explains what we collect when you use the IceBerree website and application (the “Service”), why, and what control you have. It should be read alongside our Terms of Service.

2.Where your work is stored

Local-first by design. IceBerree deliberately keeps your projects, uploads and generated media in your own browser's storage rather than uploading them to our servers. We made this choice for privacy and cost: content we never hold is content that cannot be exposed in a breach of our systems.

Practically, this means your product photographs, canvases, generated images and finished videos normally live on your device. We cannot see them, browse them, or retrieve them for you.

The trade-off you need to know. Browser storage is tied to one browser on one device and to one website address. Clearing your browsing data, switching browser or computer, or a change of our domain can make locally stored work unreachable — and we cannot recover it, because we never had it. Download anything you want to keep. The Service includes export and “download all my files” tools for exactly this reason.

Some features are opt-in and do involve our servers — for example account-based cloud storage, if you enable it. Where that happens, files are stored with our infrastructure providers described in Section 5, under a key that is derived from your verified account so that no other account can read them.

3.What we collect

Information you give us

  • Account information — your email address and authentication credentials, handled by our authentication provider. If you sign in with a third-party identity provider, we receive your email address and basic profile identifier from them, not your password.
  • Billing information — your plan, billing status and transaction history. We never see or store your full card number. Card details are collected and processed directly by our payment processor.
  • Content you submit for processing — the prompts you write and any images or files you supply for a generation, at the moment you request that generation. See Section 6.
  • Communications — anything you send us by email or a support form.

Information collected automatically

  • Usage and credit records — which type of operation you ran, when, and how many credits it consumed. We keep this to run your balance, prevent abuse, and understand cost. It is a record that a generation happened; it is not a copy of what you generated.
  • Technical data — IP address, browser type and version, device and operating system, language, referring page, and timestamps. IP address is used for security, rate limiting and abuse prevention.
  • Diagnostic data — error messages and performance information when something fails.

What we do not collect

  • We do not collect your contacts, location beyond coarse IP-derived country, browsing history outside our Service, or data from other apps.
  • We do not run third-party advertising trackers or advertising pixels on the application.
  • We do not knowingly collect sensitive categories of personal data. Please do not upload them.

4.How we use it

PurposeData usedLegal basis (UK/EU)
Create and run your accountAccount informationPerformance of a contract
Produce the generations you requestPrompts, supplied imagesPerformance of a contract
Meter credits and take paymentUsage records, billing dataPerformance of a contract
Keep the Service secure; prevent abuse and fraudTechnical data, usage recordsLegitimate interests
Fix bugs and improve reliabilityDiagnostic data, usage recordsLegitimate interests
Reply to your support messagesCommunicationsLegitimate interests
Send service notices (billing, security, changes)Account informationPerformance of a contract / legal obligation
Send marketing email, if you opt inAccount informationConsent — withdrawable at any time
Meet legal, tax and accounting obligationsBilling recordsLegal obligation

We do not use your personal data for automated decision-making that produces legal or similarly significant effects about you.

5.Who we share it with

We share data only with service providers who help us run IceBerree, and only to the extent they need it. They act on our instructions under contract and may not use your data for their own purposes.

Category of providerWhat they receiveWhy
Authentication & database hostingEmail, account identifier, plan and credit balanceTo sign you in and hold your account record
Edge compute & object storageRequests routed through our servers; files only if you enable cloud storageTo run the application and store opt-in files
AI model providersThe prompt and any images you supplied for that generationTo actually produce the image, video, audio or text
Payment processorBilling details, entered directly with themTo take payment and manage subscriptions
Email deliveryEmail address and message contentTo send account and service email

We may also disclose information where required by law, valid legal process or a governmental request; to enforce our Terms or protect the rights, safety and property of IceBerree, our users or the public; or in connection with a merger, acquisition, financing or sale of assets — in which case we will give notice before your data becomes subject to a different privacy policy.

We do not sell your personal information and we do not share it for cross-context behavioural advertising, as those terms are defined under California and other US state privacy laws. We have never done so.

6.AI providers and your content

To generate an image, a video, speech or written copy, the content required for that specific request must be transmitted to the AI provider that runs the model. Depending on the feature, that is:

  • the text of your prompt, including any product facts or dialogue you wrote;
  • the images you attached to that request — for example a product photograph used as a visual reference; and
  • technical parameters such as duration, aspect ratio and quality.

This transmission is the mechanism by which the feature works; it is not optional, and it happens only when you actively request a generation. Content sitting in your browser that you never submit is never transmitted.

Our AI providers process this content to return a result to us, which we pass back to you. Their retention practices are governed by their own agreements with us and their own policies. We select providers that offer business or API terms and we do not enrol your content in any model-improvement programme where an opt-out is available to us.

We can name our current providers on request, and we will update this policy if the categories change materially.

7.We do not train on your work

A commitment, not a hedge. We do not use your uploads, your generated images or video, your prompts, your brand assets or your projects to train, fine-tune, evaluate or improve any artificial-intelligence model — ours or anyone else's. We do not build datasets from customer work. We do not license customer work to model developers.

When we improve the Service, we do so using aggregated, non-identifying operational signals — for example how often a feature errors, or how long a generation takes — not the substance of what you created.

8.Cookies and local storage

We use a deliberately small set of browser storage technologies:

  • Strictly necessary — a session or token store that keeps you signed in, and security tokens that protect against request forgery. The Service cannot work without these.
  • Preferences — small values remembering your settings, such as theme and interface choices.
  • Application storage (IndexedDB) — the substantial local database holding your projects, uploads and generated media, as described in Section 2. This never leaves your device unless you explicitly export or enable cloud storage.

We do not use advertising cookies, cross-site trackers, social-media pixels or data brokers. You can clear this storage at any time through your browser — but note that doing so will also delete locally stored work, permanently.

9.How long we keep things

DataRetention
Account recordWhile your account is open, then deleted within 30 days of closure
Locally stored projects and mediaUntil you delete them, or your browser storage is cleared — controlled entirely by you
Items you delete in-appHeld in Recently Deleted for 60 days, then purged automatically
Opt-in cloud filesWhile your account is open, or until you delete them
Usage and credit recordsUp to 24 months, for billing accuracy and abuse prevention
Billing and tax recordsAs required by law, typically 7 years
Support correspondenceUp to 24 months after the matter closes
Security and error logsTypically 90 days

Backups are cycled on a rolling basis; data deleted from live systems may persist briefly in backups before being overwritten.

10.Deleting your data

You are in unusually direct control here:

  • Individual files and projects — delete them in the app. They go to Recently Deleted for 60 days, where you can restore them, and are then purged.
  • Everything stored locally — clearing site data in your browser removes all of it immediately and irreversibly.
  • Your whole account — contact us at contact@hypefuze.com and we will delete your account record and any cloud-stored files. We will confirm when it is done.

We may retain the minimum necessary for legal, tax, accounting or fraud-prevention purposes, and anonymised records that can no longer identify you.

11.Security

We take reasonable and appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS/TLS), encryption at rest with our infrastructure providers, verified-token authorisation on requests that touch account data, isolation of stored files by account so one account cannot read another's, rate limiting, and least-privilege access to production systems.

Keeping most content local rather than on our servers is itself a security decision: content we do not hold cannot be taken from us.

No system is perfectly secure, and we cannot guarantee absolute security. You are responsible for the security of your own device, browser and account credentials. If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required by law.

12.International transfers

We and our providers operate globally, so your information may be processed in countries other than your own, including the United States. Where we transfer personal data out of the UK or European Economic Area, we rely on an appropriate safeguard — typically the European Commission's Standard Contractual Clauses (and the UK Addendum), or a finding of adequacy. You may request a copy of the relevant safeguard using the contact details below.

13.Your rights (UK / EU)

If you are in the UK or the European Economic Area, you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data (“right to be forgotten”), subject to legal retention;
  • restrict or object to processing carried out on the basis of legitimate interests;
  • data portability — receive data you gave us in a structured, machine-readable format;
  • withdraw consent at any time where we rely on consent, without affecting prior processing; and
  • complain to your supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).

To exercise any of these, email contact@hypefuze.com. We will respond within one month and will not charge you or penalise you for asking.

14.Your rights (California and other US states)

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect and how we use and disclose it; to request deletion; to request correction; and to be free from discrimination for exercising these rights. Residents of other US states with comprehensive privacy laws have broadly equivalent rights.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of — but the right to opt out would be honoured if that ever changed, and we would tell you before it did.

Requests can be made to contact@hypefuze.com. We will verify your identity through your account email before acting. You may use an authorised agent, with proof of authorisation.

15.Children

IceBerree is not directed to children. You must be at least 16, or the age of digital consent where you live if higher, to use it. We do not knowingly collect personal data from children below that age. If you believe a child has provided us personal data, contact us and we will delete it promptly.

16.Do Not Track

We do not track users across third-party websites, so we do not respond differently to Do Not Track signals. We simply do not do the thing those signals ask us not to do.

17.Changes to this policy

We may update this policy as the Service changes. The “Last updated” date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will give you notice by email or in the application before it takes effect. Material changes will never be applied retroactively to data already collected without a lawful basis.

18.Contact

For any privacy question, request or complaint, email contact@hypefuze.com.

We read every message and aim to reply within a few business days, and always within the period the law requires.