# Jizzfield Personal Privacy Notice Last updated: 28 September 2026 ## 1. Who is responsible Jizzfield is operated by **Frames Media B.V.**, registered with the Netherlands Chamber of Commerce under number **42089589**, at **Rio Grandestraat 42, 1448 XK Purmerend, the Netherlands**. Contact us about your personal data at **support@jizzfield.com**. You do not need an account or an active subscription to make a privacy request. Frames Media is the controller for this personal service, its public information, account administration, support, security and business records, and the former early-access waitlist. ## 2. Scope This document applies to Jizzfield personal accounts. Personal accounts do not include organisation workspaces, seats or subscriptions. You may create fully fictional people from text prompts. Image-to-video may use only an eligible image generated on Jizzfield from text prompts, with verified platform provenance. Files from your device, external URLs, imported images or videos, and material depicting or identifying a real person are not permitted as generation input. This also excludes re-uploading an exported image. Permission from a real person does not create an exception. This notice describes the personal service, the public website, correspondence and available internal tests. Merely visiting the website or creating an account does not send a generation request. Do not send identity documents, verification selfies or intimate photographs to support. Start with a description and the relevant request or file reference. If further evidence is necessary, we explain what is needed and how to provide it. ## 3. Data, purposes and legal bases We receive information directly from you, from your use of the website and available services, and from providers involved in those functions. Where the GDPR applies, the following bases apply to our own processing: | Activity | Personal data and purpose | Legal basis | |---|---|---| | Website delivery and protection | IP address, request and device/browser information, timestamps and necessary technical records, to deliver the website, investigate errors and prevent abuse. | Our legitimate interests in providing a functioning, secure website and protecting visitors and the service. | | Optional public-site analytics | Cookie identifiers, device/browser information, public-page visits, including visits to the sign-up page, to understand use of the public website and improve it. | Your consent through the analytics choice. You can refuse or withdraw it through cookie settings. | | Former early-access waitlist | Email address, registration and invitation status and related dates of people who joined before the waitlist closed on 23 September 2026, to send the invitation or update that was requested. | Your consent when you joined. You can withdraw it by contacting us. It is not a newsletter list. | | Personal account and requested features | Email address, account identifier, display name, optional profile image, access status and the information needed to provide the features you request. | Performance of our agreement with you, or steps you request before entering it. | | Welcome credits | The account reference, the grant record, any exclusion record, whether your sign-in email address was confirmed when we checked, and a hashed form of your email address, to give free welcome credits only once per person and to prevent abuse. | Performance of our agreement with you for the welcome credits themselves; our legitimate interest in offering a free start fairly and preventing abuse for the hashed email address, the exclusion record and the confirmation check. | | Support and business enquiries | Your contact details, message, necessary attachments and handling records. | Performance of our agreement where the request concerns your service; otherwise our legitimate interest in responding to enquiries and resolving problems. | | Complaints, privacy requests and concrete safety cases | Relevant contact details, account/file references, evidence, decisions and responses. | Compliance with applicable legal duties, including responding to GDPR requests; our legitimate interests in investigating complaints, protecting affected people and establishing or defending concrete legal claims where applicable. | | Terms and business administration | The relevant party/account reference, accepted document version, language, date and necessary notification or dispute records. Where a purchase occurs, order/payment references, amount, currency, status, token movements and adjustments; the payment method with a masked card or account number; the invoice details you give us, such as your name and address; the email address of your account at the moment of purchase; the country of your connection and the country of the card or bank account that the payment provider reports, as evidence of where you are for VAT; the VAT treatment we record for the purchase; and the invoices, receipts and credit documents we issue. | Performance and evidence of applicable agreements, our legitimate interest in resolving concrete disputes, and applicable accounting or tax obligations. | For legitimate-interest processing, we limit the data to the stated purpose and consider its effect on you. You may object for reasons relating to your particular situation. We will assess the objection and explain our response. You can browse public information without creating an account. An email address is needed to provide an email-based account. Information required for a particular account, purchase or age-assurance step is identified in that step. Optional analytics is separate from these requirements. Acceptance of our Terms and Conditions is not consent to every use of personal data. ## 4. Prompts, source images and generated results A generation processes your text prompt, any requested rewritten prompt, selected settings, results and associated job and account references. We use them to carry out the request, present history, record usage and investigate failures. Our internal tests and demonstrations reported to date use fictional people. Fictional subject matter does not make linked account or usage data anonymous. For image-to-video, the source is an eligible image previously generated from text on Jizzfield, selected through the platform. We process the necessary image, provenance and job references to make that video and verify the permitted origin. No external image, video, face or other real-person reference may be imported or supplied for generation. The prompt-check and optional rewriting service processes text, relevant settings and, where needed, the prior prompt of the eligible source image. It does not receive that image through the text-check route. A refused request may already have been processed by the text-check service. The selected generation service receives the relevant text and settings and, for the permitted image-to-video step, the eligible platform-generated source image. We do not send each request to all generation services. Returned files and job information are stored in Jizzfield’s infrastructure. We update relevant processing information before introducing a different service or purpose. Some prompts, outputs or linked account information can reveal sensitive information, including about sex life or sexual orientation. The fictional-only restriction does not by itself establish a legal basis for every use of that information. Do not include identifying information about a real person in a prompt. Only authorised staff may access prompts and results when necessary for support, complaints, concrete safety concerns or faults. Not every automatically refused prompt is manually reviewed; a refusal alone does not establish wrongdoing. You may ask support to review a disputed outcome. ## 5. Age assurance and use of customer material Where stronger age assurance is required for access, the verification step must identify the service involved and explain its data, checks, returned result, retention and rights before processing begins. This notice does not request consent to an unspecified identity or biometric check. Where the required process is unavailable, restricted access remains unavailable. Our policy is to retain the necessary age-assurance result and evidence, rather than copies of identity documents or selfies created solely for that check. The verifier’s processing must be explained before it is used. Frames Media does not use customer prompts or outputs for general AI training or advertising without separate consent for that purpose. This describes our purposes, not a promise that every provider offers zero retention. Creating a requested result is separate from training a general model. Where processing relies on privacy consent, you may withdraw it. Withdrawal does not make earlier lawful processing unlawful. We assess any further storage against its purpose and legal basis. ## 6. Providers and other recipients | Category of recipient | Function and relevant information | |---|---| | **Cloud hosting, security and storage providers** | Website/application delivery, security, database and file infrastructure. This involves technical request data and the data stored or processed in the relevant hosted function. | | **Account and authentication providers** | Account creation, invitations and authentication. They process the supplied email address, registration/account status and necessary account, session, device and security information. Some account information may be processed under a provider's own responsibilities as well as on our behalf. | | **Support email providers** | Our support mailbox and company correspondence, including messages and attachments that you send us. | | **Transactional email provider** | Amazon Web Services, through Amazon Simple Email Service in the AWS Europe (Frankfurt) region: the recipient address, the mail of an invoice, receipt or credit document with its PDF attachment, the mail telling you that we added free welcome credits, and the delivery results (sent, delivered, delayed, bounced, complaint). Prompts and generated files are never included. | | **Website analytics providers** | Optional measurement of public-site visits after analytics consent, as explained in section 8. | | **Payment providers** | Taking payment for a token purchase and paying back a refund. We send the amount, currency, a description of the purchase and our references; you enter your payment details on the provider's own page. From its report we keep the payment result, the payment method, a masked card or account number and the country of the card or bank account. Payment details may be processed under the provider's own responsibilities as well as on our behalf. | | **Bookkeeping providers** | Necessary contact, invoice and transaction information forming part of Frames Media's administration. Prompts and generated files are not routinely included. | | **AI text-processing and generation providers** | The prompt, settings and eligible platform-generated source image needed for the permitted video step described in section 4. Not every request goes to every provider. | External identity/age verification is being prepared. The relevant verification information, including who receives the data and for what purpose, must be provided in that route before it is used. We use Amazon SES for invoice mail, for the mail telling you that we added free welcome credits and, when those functions are available, for other necessary service notices. It processes the recipient address, necessary message content and sending results. We will not include generation prompts, generated images or identity-verification documents in these service emails. Our support email service remains the support channel. We may disclose limited information to professional advisers or competent authorities where necessary and supported by an applicable legal basis, for example a specific legal duty or concrete claim. A request or allegation does not give unrestricted access to your complete account, content or verification records. You can request information about the recipients of your personal data at **support@jizzfield.com**. We provide their identities where required by applicable data-protection law. The categories above do not limit that right. ## 7. International processing Jizzfield uses international providers. Processing may take place outside the European Economic Area, including in the United States, Singapore, Malaysia and Indonesia. AI service documentation identifies processing in Malaysia, Indonesia and/or the EU/EEA; this does not mean every request is processed in all those places. A European storage location does not, by itself, place all support, authentication or other processing inside Europe. International transfer arrangements depend on the recipient and processing involved. They may include an applicable adequacy decision, including the EU–US Data Privacy Framework for a covered recipient, or standard contractual clauses for restricted transfers. Before a new route processes personal data, we must establish the applicable recipient, location and lawful transfer arrangement. This is not a statement that every planned integration or use of sensitive data has already been approved. You can request the safeguards applicable to your information and a copy of the relevant transfer arrangements at **support@jizzfield.com**. We protect unrelated confidential information without limiting your statutory access rights. One of our AI generation services states that it does not use customer data for its own model training without prior customer authorisation. We do not participate in that service's optional data-sharing rewards programme. Its safety processing retains inputs and outputs flagged by its content filter for **180 days in Malaysia**. This specific provider retention is separate from Jizzfield's library-deletion periods; it is not a retention period for every generation request or every provider. ## 8. Cookies and browser storage Functional cookies and browser storage support account access, security, your choices and account use. Our authentication service uses session and client cookies to maintain account access. A short-lived authentication token is refreshed during a valid session; its token lifetime is not the retention period for your account. Where the site records an analytics choice, the first-party `jizzfield_consent` cookie remembers allowance or refusal for **180 days** from that choice. You can change it earlier through cookie settings. This period is for your choice, not for any information held by an analytics provider. We use **optional analytics on public pages after you allow analytics**. It measures public-page visits, including visits to the sign-up page, using technical browser/device information and cookie identifiers. It does not report what a visitor enters or submits. Our measurement code limits reported page addresses to the public page category and removes query strings and fragments. The analytics tag is excluded from the signed-in workspace. The site does not load the analytics tag before permission or after refusal. Cross-service advertising signals are disabled, and advertising personalisation is excluded in both our measurement code and analytics settings. Optional sharing for the analytics provider’s additional purposes is switched off; the provider still processes data to provide, maintain and protect the analytics service. Our policy excludes prompts, source images, generated results and age-assurance information from Analytics, and excludes advertising tracking and remarketing. Analytics is not a condition of account access. We have disabled additional automatic measurement of additional interactions such as scrolling, outbound links, site searches, form interactions, video engagement and file downloads. Our own measurement is limited to public-page visits. Standard technical session events may accompany these measurements. Our analytics service uses first-party cookies to distinguish browsers and sessions. The configured default cookie lifetime is **two years**, refreshed on subsequent visits when analytics is permitted. Your browser can apply a shorter limit. This is separate from Jizzfield's 180-day record of your analytics choice and from the retention of analytics records. Our analytics service is set to retain **event data for two months** and **user data for fourteen months**. New activity resets the fourteen-month user-data period; it does not restart the retention period of every older event. The analytics provider removes expired records through its monthly deletion process. These settings do not set an expiry for standard aggregated reports. You can withdraw permission through cookie settings or clear cookies in your browser; that does not by itself delete records already sent to the analytics provider. You can contact us about access to or deletion of analytics information relating to you. If you use your account, browser storage can preserve preferences, an unfinished generation draft or references to running jobs. Session storage is associated with the browser session; local storage can remain until cleared by the application or your browser. You can remove site data through your browser settings, although doing so can sign you out or remove an unfinished draft. Removing a server file does not necessarily clear all copies or references already held on your device. ## 9. Retention and deletion The following are our retention rules. Contact **support@jizzfield.com** to request removal or ask about particular data. We handle requests through our team where a self-service option is unavailable; your privacy rights do not depend on an automated control being available. | Category | Retention rule | |---|---| | Separate waitlist registration (closed on 23 September 2026) | Until successful sign-up, withdrawal from the waitlist or the definitive end of the invitation process; then remove the separate registration. It is not kept as a newsletter list. An account already created follows its own account policy. | | Account profile | While needed for current access and management. After permanent closure , remove fields and permissions that are no longer needed; keep only the limited records necessary for outstanding settlement, a legal obligation or a concrete claim. | | Personal images and videos | During active use, then six calendar months without active account use. The policy requires notice 30 and 7 days before the deletion deadline. Timely resumed activity stops the existing inactivity schedule. The file rule does not itself close the account or remove purchased credit. | | Prompts for requests with results | Remove original and rewritten prompt copies when all results of that request have been permanently deleted. Limited payment records or evidence for a concrete case are separate. | | Definitively failed requests with no result | Keep the prompt and necessary reuse settings under the personal library rules, so the request can be reread or retried. This does not authorise an archive of all technical provider responses or a free retry. | | Remaining lawful credit and payment adjustments | Keep the limited link between the rights holder, purchase, value and adjustments until the balance and outstanding adjustments are settled. This is not a reason to retain unrelated content or an entire profile. | | Welcome credit record | While we offer welcome credits; when we stop, we erase the hashed email addresses within three months. Until then also after account closure: the grant record, any exclusion record and a hashed form of your email address (still personal data), without the address itself. | | Terms acceptance and changes | Keep the relevant version, party reference, date and necessary notification/objection evidence while agreements and associated rights or duties remain relevant. Review when agreements are replaced or finally settled; retain later evidence only for a specific obligation or concrete claim. | | Tax administration | Retain records subject to the Dutch basic tax-record obligation for seven years, calculated from the applicable statutory start point. A different period applies only to records actually covered by another applicable tax rule. These duties do not automatically cover prompts, media or complete identity files. | | Invoices, receipts and credit documents, the billing details frozen for each purchase and the VAT treatment recorded for it, with the evidence of the country it was based on | Ten years from the end of the year of the purchase, also after your account is closed. The Dutch tax-record obligation is seven years; the EU VAT One Stop Shop scheme requires ten for the sales it covers (Art. 369k(2) of Directive 2006/112/EC), and we apply ten years to every purchase. These records are not edited after they are made. | | Invoice details saved for your next purchase | Until your next purchase replaces them, or until your personal account is permanently closed, when they are deleted. | | Invoice mail records | The recipient's domain and a one-way code of the address (never the address itself), the provider's message reference and the delivery results, kept as long as the document they belong to. | | Delivery event receipts | Seven days, to recognise a delivery event that the provider sends twice. | | Ordinary support correspondence and attachments | Twelve months after handling is completed, then deletion. Necessary accounting records, privacy requests and concrete complaint or safety files follow their own rules. | | Ordinary refused-prompt records | Up to thirty days from each event: necessary account reference, date, the kind of run, which check refused it, rule category and outcome, and the refused text (your prompt, any negative prompt and, where one was made, our rewrite and the text that would have been sent). Only authorised staff can open the text, and each opening is recorded. Later activity does not extend an older record. Staff also see how many prompts an account had refused in the last 48 hours, to decide whether the account needs a review; this count uses the same records and the same thirty days, and is never shown to anyone outside the team. | | Account review status | Repeated refusals of your own prompts in the minors category place your account under review. We keep the review record (dates, the number of refusals that started it, an acknowledgement where one was given, and staff decisions, no prompt text) while your account exists, and after the account is closed as a record of the safety decisions taken about it, tied only to the closed account without your name or email address. The refusals that count are kept for thirty days from each refusal, without their text; a copy in our database backups can remain until that copy expires, no more than thirty days later. | | Concrete complaints, privacy requests and safety cases | During necessary handling. Afterwards, reduce to necessary evidence of receipt, references, decision, action and response. Keep extensive content, including available prompt evidence, only for a documented concrete need with a deletion or review point. An automatic refusal alone does not establish that need. | | Our own database backups | No more than thirty days from creation of each copy, for recovery. | | Ordinary application error logs | No more than seven days, without an additional archive for those logs. This is not the rule for payment records or a specific evidence file. | A statutory duty, valid deletion request or necessary safety measure can require different handling of particular data. We limit any exception to the data and duration actually needed. An eligible generated source image may be used for a permitted video request only while retained and accessible. Retention of one result does not permit indefinite retention of unrelated data. After active-system deletion, an existing backup may still contain data until that copy expires. Earlier deletions and restrictions must be respected if a backup is restored. A provider's own recovery or legal-retention process is separate from our database-backup period; we do not describe all provider copies as instantly erased. Permanent account closure and a privacy request are different actions. Explicitly confirmed permanent closure ends access and starts deletion of personal files without a six-month restoration period. Necessary settlement and evidence follow their own rules. Invoices, receipts, credit documents, the billing details frozen for a purchase and its recorded VAT treatment are kept for the ten-year tax retention period, also after closure. A privacy request is not automatically an instruction to close the commercial account or surrender lawful credit. For a planned permanent service closure without customer fault, the agreed download period is at least thirty calendar days for retained, permitted files, including for inactive accounts. Ordinary cleanup must not cut that period short. Earlier valid deletion obligations and necessary access restrictions still apply. ## 10. Your choices and rights You can contact **support@jizzfield.com** to request access, correction, deletion, restriction or portability, to object to processing or to withdraw consent. The conditions for each right depend on the processing and applicable law. Include enough information to identify the relevant account or request, without sending unnecessary sensitive evidence. If additional identification is necessary, we ask for proportionate information. Under the GDPR we normally respond within one month. If a permitted extension is needed, we explain the reason and extension within that first month. A support acknowledgement is separate from our substantive response. Automated prompt or access checks can prevent a particular action. You may ask for an explanation and review. A failed technical check is not proof of misconduct. Where a decision falls under the GDPR's rules on solely automated decisions with legal or similarly significant effects, the applicable safeguards and rights continue to apply. You may complain directly to the [Dutch Data Protection Authority](https://autoriteitpersoonsgegevens.nl/een-tip-of-klacht-indienen-bij-de-ap) or another competent supervisory authority. You do not have to complete our internal complaint process first. Applicable local privacy rights remain available. ## 11. Changes We update this notice when the service or relevant processing changes and show the revision date. We provide additional information before a new purpose or route requires it and notify you where required. Publishing a revised notice does not provide consent for a purpose that needs separate consent. Version 2026-09-28 · English