LegalPrivacy Policy

Privacy Policy.

A UK-focused privacy notice for an AI creative workspace: accounts, uploads, outputs, workflows, cookies, transfers, retention, and rights.

Updated
Apr 29, 2026
Framework
UK GDPR + PECR
Applies to
Site + app
Contact
Privacy
01

Controller and UK company details

Linocut AI is operated by SNAPCRAFT DIGITAL SOLUTIONS LTD, a company registered in England and Wales, for the Linocut AI website, app, workspace, and related services. For UK GDPR purposes, SNAPCRAFT DIGITAL SOLUTIONS LTD is the controller of personal data processed for account administration, billing, security, analytics, product operation, and customer support.

Where a business customer uses Linocut AI to process personal data inside its own workspace, that customer may be the controller and Linocut AI may act as processor under the applicable workspace agreement or data processing addendum.

Field
Details
Legal entity
SNAPCRAFT DIGITAL SOLUTIONS LTD
Jurisdiction
England and Wales
Registered office / service address
128, City Road, London, EC1V 2NX, United Kingdom
Support contact
Data protection contact
Legal contact
02

Scope of this policy

This policy applies when you visit Linocut AI, create an account, join a workspace, upload media, enter prompts, generate or edit outputs, save workflows, use beta features, contact support, subscribe to emails, or purchase a plan.

This policy does not cover third-party websites, model providers, social platforms, payment providers, or integrations that publish their own privacy notices, except where they process personal data on our behalf.

03

Personal data we collect

The exact data we collect depends on how you use the product. Linocut AI is a creative workspace, so some uploads or outputs may include personal data if they contain identifiable people, voices, names, addresses, handles, or other personal information.

Category
Examples
Account data
Name, email address, sign-in method, workspace name, team role, language, plan status, account preferences.
Creative inputs
Images, video, audio, text prompts, masks, captions, files, project notes, style references, inpainting selections, and workflow settings.
AI outputs
Generated images, edits, video clips, audio outputs, transcripts, text drafts, previews, exports, and workflow run history.
Usage data
Pages viewed, tools used, timestamps, clicks, feature events, approximate region, device type, browser, session diagnostics, and performance data.
Support data
Messages, attachments, feedback, bug reports, survey responses, troubleshooting information, and customer success notes.
Billing data
Plan, renewal state, invoices, taxes, payment status, transaction identifiers, billing contact details, and fraud-prevention signals.
Security data
IP address, authentication events, device identifiers, abuse signals, rate-limit events, and audit logs.
04

Sources of data

We collect data directly from you, from workspace administrators or collaborators, from your device and browser, from service providers, and from third-party integrations you choose to connect.

If another user uploads personal data about you into a workspace, we process that data to provide the requested creative workflow and to operate the service, subject to the controls in this policy and the applicable workspace terms.

05

Purposes and lawful bases

Under UK GDPR, we need a lawful basis to process personal data. The table below summarises the main purposes and lawful bases we expect to rely on.

Purpose
Data used
Lawful basis
Provide the workspace
Account data, creative inputs, AI outputs, run history, settings
Contract, or legitimate interests for free/beta users
Generate and edit content
Uploads, prompts, masks, model settings, outputs
Contract, legitimate interests, and user instruction
Team collaboration
Workspace membership, shared projects, comments, activity logs
Contract and legitimate interests
Billing and tax
Billing contact, plan, invoices, transaction IDs
Contract and legal obligation
Security and abuse prevention
IP address, logs, abuse signals, authentication events
Legitimate interests and legal obligation
Product analytics
Usage events, performance metrics, approximate region
Legitimate interests, or consent where cookies or similar technologies require it
Marketing emails
Email address, preferences, engagement data
Consent or soft opt-in where permitted by PECR
Legal compliance
Account records, logs, correspondence, transaction records
Legal obligation and legitimate interests
06

Creative uploads and AI outputs

Private workspace content is used to provide, maintain, secure, and improve the features you ask us to run. We do not publish your private uploads or private outputs as public marketing material without permission.

We do not use private workspace content to train public foundation models unless you opt in, the relevant workspace agreement allows it, or the content has been made public by you. Aggregated and de-identified product signals may be used to improve reliability, interface design, routing, and abuse prevention.

Some workflows involve people, faces, voices, likenesses, or other identifiers. You are responsible for having the rights and permissions needed to upload, edit, generate, publish, or share that content.

07

Sensitive data and biometric-like content

Linocut AI is not designed for medical, legal, financial, employment, immigration, or other high-impact decision-making. Do not upload sensitive personal data unless it is necessary for the workflow and you have a lawful basis to do so.

Images, video, voice, and face-related workflows can reveal sensitive traits or biometric-like information. We process such content only as needed to provide the requested creative tool, maintain security, comply with law, or enforce our terms.

08

AI model and infrastructure providers

To run image, video, audio, and text workflows, we may send relevant inputs and settings to infrastructure providers, model providers, storage providers, and other processors. We limit what is shared to what is necessary for the workflow.

Providers may process data in the UK, EEA, United States, or other locations. We use contractual, technical, and organisational controls to protect transfers and processing by those providers.

09

Cookies, local storage, and analytics

We use strictly necessary cookies and local storage to keep the service secure, remember session state, load the workspace, prevent fraud, and maintain user preferences.

Where we use non-essential analytics, performance, marketing, or similar technologies that store or access information on your device, we will request consent where required by PECR and provide controls to reject or change those choices.

Type
Purpose
Consent
Strictly necessary
Authentication, security, routing, load balancing, workspace preferences
Not required where essential to provide the requested service
Analytics and performance
Understand usage, errors, load times, feature adoption
Consent where required by PECR
Marketing
Measure campaigns, prevent repeated ads, understand referrals
Consent where required
Local storage
Remember product state, drafts, UI preferences
Depends on purpose and whether storage is essential
10

Sharing and disclosure

We share personal data only where needed to operate Linocut AI, comply with law, protect the service, complete a transaction, support a workspace, or follow your instructions.

  • Cloud hosting, storage, database, security, monitoring, and content delivery providers.
  • AI model, media processing, transcription, upscaling, moderation, and workflow execution providers.
  • Payment, invoicing, tax, fraud prevention, and accounting providers.
  • Customer support, email delivery, analytics, product operations, and CRM providers.
  • Workspace administrators and collaborators, according to workspace permissions.
  • Professional advisers, regulators, law enforcement, courts, or public authorities where legally required or necessary to protect rights and safety.
  • Successors or counterparties in a merger, acquisition, restructuring, financing, or asset transfer, subject to appropriate confidentiality and continuity protections.
11

International transfers

Some providers, team members, or infrastructure may be located outside the UK. Where UK GDPR transfer rules apply, we rely on UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful transfer mechanism.

Where appropriate, we assess transfer risks and apply additional safeguards such as access controls, encryption in transit, provider due diligence, contractual security obligations, and limited retention.

12

Retention

We keep personal data only for as long as needed for the purposes described in this policy, unless a longer period is required for legal, accounting, security, dispute, or enforcement reasons.

Data
Typical retention
Account and workspace records
For the life of the account, then deleted or anonymised after closure unless needed for legal or security reasons.
Creative uploads and outputs
Until deleted by the user, workspace administrator, or account closure process; backup deletion may take additional time.
Temporary processing files
Usually short-lived and deleted after workflow completion, debugging, or cache expiry.
Security and audit logs
Typically 12 to 24 months, longer if needed to investigate abuse, fraud, or legal claims.
Billing and tax records
Usually 6 years plus the current financial year where required for UK tax and accounting obligations.
Support records
Usually up to 3 years after the last interaction, unless needed for an active issue or claim.
Marketing preferences
Until you unsubscribe or withdraw consent; suppression records may be kept to respect opt-outs.
13

Security

We use technical and organisational measures designed for a media-heavy AI workspace, including access controls, encrypted transport, logging, operational monitoring, least-privilege permissions, provider due diligence, and internal controls for production systems.

No online service can guarantee perfect security. You are responsible for protecting your account credentials, managing workspace access, and using secure export and sharing practices.

14

Your UK GDPR rights

Depending on the context, you may have the right to request access, correction, deletion, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent where processing is based on consent.

To exercise rights, contact [email protected]. We may need to verify your identity, understand the relevant workspace, and account for rights of other people whose data appears in shared projects or generated media.

If you are unhappy with how we handle personal data, you can complain to the UK Information Commissioner's Office at ico.org.uk, or contact the ICO at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom.

15

Automated decisions

Linocut AI uses automated systems to generate, transform, classify, moderate, route, and improve creative workflows. These systems are intended to assist creative production, not to make decisions with legal or similarly significant effects about individuals.

If we introduce features that make automated decisions with legal or similarly significant effects, we will provide additional notice and controls required by law.

16

Children

Linocut AI is not intended for children under 16 unless a parent, guardian, school, or authorised organisation has approved the use and the relevant plan allows it.

We do not knowingly collect personal data from children in a way that is inconsistent with applicable law. If you believe a child has provided personal data without appropriate permission, contact [email protected].

17

Changes to this policy

We may update this policy as Linocut AI develops, as we add new tools or workflows, or as legal requirements change. Material changes will be posted on this page with an updated date and, where appropriate, communicated in-product or by email.