Privacy Policy
1. Introduction
Powius Ltd (“we”, “our”, or “us”) operates CARIUSB, an AI-powered car visualization platform. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over your data.
By using CARIUSB, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use of the Service.
Powius Ltd is registered in England and Wales and acts as the data controller for personal information processed through the Service.
All users of the Service, including those on the free tier, are required to register with a valid email address. Unregistered or anonymous use of the Service is not available.
2. Information We Collect
2.1 Account Information
- Email address (required for registration and authentication)
- Display name or community username
- Profile avatar (optional, user-uploaded)
- Account creation date and authentication identifiers
2.2 Content You Provide
- Source photos and images you upload for AI processing
- Text prompts and instructions you enter for generating outputs
- AI-generated images and video outputs produced by the Service
- Community posts you choose to publish (image, tags, captions)
2.3 Usage and Technical Data
- Generation job status, error logs, and performance metrics
- IP address, browser type, device type, and operating system
- Pages visited, features used, and session duration
- Timestamps of actions (uploads, generations, community posts)
2.4 Billing and Payment Data
- Subscription plan and status (e.g., active, cancelled)
- Stripe customer ID and transaction identifiers
- Boost Credit balances, purchase history, and expiry dates
- Full payment card details are processed and stored exclusively by Stripe; Powius Ltd does not store card numbers, CVVs, or bank details.
2.5 Cookies and Tracking
We use essential cookies and similar technologies to maintain your session and authentication state. If you opt in, we may also use optional analytics and marketing technologies to measure performance and improve the product. Please see our Cookie Policy for details and how to manage preferences.
3. How We Use Your Information
We process your personal information for the following purposes:
- Service delivery: to authenticate you, deliver outputs, and manage your subscription and credits.
- AI inference: your uploaded images and text prompts are transmitted to third-party AI inference providers (currently fal.ai) solely for the purpose of generating your requested outputs. Your content is not used to train, fine-tune, or improve any AI model by Powius Ltd or its AI processing partners. We require our AI inference providers to process your content solely for output generation and not for their own model training purposes. Please review fal.ai's terms of service and privacy policy for their independent data handling practices at fal.ai.
- Community features: to display your public posts and enable community interaction.
- Safety and moderation: to detect and prevent abuse, fraud, policy violations, and illegal content.
- Service improvement: to diagnose technical issues, monitor performance, and improve the platform.
- Communications: to send essential service messages including billing receipts, security alerts, and policy updates. We do not send marketing emails without your explicit consent.
- Legal compliance: to meet our obligations under applicable law, respond to lawful requests, and protect our legal rights.
- Marketing (opt-in only): we may use your generated outputs in promotional materials only with your explicit consent.
4. Legal Basis for Processing (UK/EU Users)
For users in the UK and European Economic Area, we rely on the following lawful bases under UK GDPR / GDPR:
- Contract performance: processing necessary to provide the Service you have signed up for, including generating AI outputs and managing your account.
- Legitimate interests: fraud prevention, security monitoring, service improvement, and platform integrity.
- Legal obligation: compliance with applicable laws and regulatory requirements.
- Consent: marketing communications and any optional data uses, where you have given clear consent that you can withdraw at any time.
5. Sharing Your Information
- Public Community: content you share to the Community feed is publicly visible to all visitors, including non-registered users.
- Service providers: we share data with trusted third-party providers necessary to operate the Service, including Supabase (database, authentication, and file storage), Stripe (payment processing), and cloud infrastructure providers. These providers are contractually required to protect your data and may not use it for their own purposes.
- Legal disclosures: we may disclose your information where required by law, court order, regulatory authority, or to protect the rights, safety, or property of Powius Ltd, our users, or the public.
- Business transfers: in the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or use of your personal information.
6. Data Retention
- Account data: retained for as long as your account is active. Upon account deletion, your personal data will be removed within 30 days, subject to the exceptions below.
- Credits and operations: all remaining monthly operations and Boost Credits are permanently deleted upon account deletion. They cannot be recovered after this point.
- Uploaded content and outputs: retained while your account is active. You may delete your uploads and community posts at any time through the platform.
- Billing and transaction records: retained for up to 7 years to comply with financial and tax regulations.
- Security and fraud logs: retained for up to 12 months to support fraud prevention and investigation.
- Legal holds: certain data may be retained longer if required by law or for the resolution of legal disputes.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure (“right to be forgotten”): request deletion of your personal data, subject to legal retention obligations.
- Restriction: request that we limit the processing of your data in certain circumstances.
- Portability: receive your personal data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at contact@cariusb.com. We will respond within 30 days. UK/EU residents may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your rights have been violated.
8. International Data Transfers
Powius Ltd is based in the United Kingdom. Your data may be processed in the UK, the European Economic Area, and other countries where our service providers (including Supabase and Stripe) operate. Where data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or equivalent mechanisms, as required by UK GDPR.
9. Security
We implement industry-standard technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These include encrypted data transmission (HTTPS/TLS), access controls, and regular security reviews.
However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk.
10. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at contact@cariusb.com and we will promptly delete it.
11. Cookies
We use cookies and similar technologies to operate the Service. For details on the cookies we use and how to manage them, please see our Cookie Policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date at the top of this page and by sending you an email notification. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our data protection contact at:
Email: contact@cariusb.com
Company: Powius Ltd
Jurisdiction: England and Wales, United Kingdom