Legal
Privacy & Consent
Last updated: June 2026
Draft for attorney review. This policy and the biometric consent flow must be reviewed and finalized by a licensed attorney (BIPA / CUBI / Washington-grade) before launch. It is not legal advice. See also the Terms of Service and Acceptable Use Policy.
Who we are
Amaze AI Models (amazeaimodel.com) is operated by Amaze LLC, a Louisiana limited liability company, which is the data controller for the information described here. Privacy requests: support@amazeaimodel.com(subject: “Privacy”).
Information we collect
- Account: name, email, password, role (talent/brand), and profile details you provide.
- Photos & biometric data: the facial images you upload and a live verification selfie, and the facial geometry/embeddings derived to create and match your twin.
- Generated content: the twin images/videos and looks you create.
- Transactions: licenses, subscriptions, tokens, and payout records. Card details are handled by Stripe — we do not store full card numbers.
- Usage & device: log data, IP address, and basic device/browser information used for security and rate-limiting.
- Support: messages you send us or other users on-platform.
How we use it
To create, host, moderate, and improve your twin and the service; to operate the marketplace (licensing, payments, payouts); to verify identity and prevent impersonation, fraud, and abuse; to provide support; to send service and transactional messages; and to comply with law. We do not sell your personal information, and we never sell biometric data.
Biometric data & consent (BIPA-grade)
The facial images you upload and the facial-geometry embeddings derived from them are biometric identifiers / biometric information. We handle them per the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14) standard:
- Purpose & written release (§15(b)). Before we collect anything, we tell you in this policy the specific purpose — to create, host, match, and operate your AI twin (including optionally training a personal model (Pro Twin) on your own photosto improve your twin), and to fulfill licenses you approve — and the term we keep it, and we obtain your written release(an electronic signature counts, per the 2024 BIPA amendment), recorded with a version and timestamp. Any personal model we train is yours, kept private, and used only to generate your twin — we don’t use your data to train general or third-party models, and we require our AI provider not to either.
- Retention & destruction schedule (§15(a)). We permanently destroy your biometric data when its purpose is satisfied — when you delete your twin or revoke consent — and in any case within 3 years of your last interaction with Amaze, whichever comes first.
- No sale or profit (§15(c)). We never sell, lease, trade, or otherwise profit from your biometric data. Your embedding is used onlyto render and operate your twin and is never the thing being sold. Amaze’s fees are for the technology/platform service; your earnings come from licensing your own likeness.
- No disclosure (§15(d)). We never hand your biometric identifier to brands or third parties. Brands only ever receive the generated images under a license you approve. Our processors (e.g. the face-match and generation providers) act on our behalf and do not retain or profit from it.
- Security (§15(e)). Biometric data is stored in private, access-controlled storage with row-level security, signed time-limited URLs, and encryption in transit — protected at least as well as our other confidential data.
Identity verification
We verify your identity (a live selfie matched to your uploaded photos, and, for payouts, Stripe’s KYC) to confirm a twin belongs to the person creating it and that payouts go to the right person. Verification data is used only to confirm identity and prevent impersonation.
How we share information
We share information with service providerswho process it on our behalf, including: Supabase (database/storage/auth), fal.ai (AI generation), AWS Rekognition (face-match verification), Hive (content moderation), Stripe (payments & payouts), and our email/SMS providers. These act on our behalf only and may not retain or profit from your data. For the AI generation provider in particular, we instruct it to auto-expire the generated media on its servers and not to retain the request inputs/outputs, and we copy every asset to our own private storage immediately — so your biometric inputs aren’t left sitting on a third-party CDN. We share with a brand only the licensed asset and what a license requires. We may disclose information to comply with law, enforce our terms, protect safety, or report CSAM to NCMEC. If Amaze is involved in a merger or acquisition, information may transfer subject to this policy.
Data retention & deletion
We keep personal information for as long as your account is active or as needed to provide the service, then delete or de-identify it within our published retention schedule, except where we must keep records longer for legal, tax, safety, or dispute-resolution reasons (and CSAM preservation as required by law). You can delete your twin and source photos anytime from your dashboard.
Your rights & choices
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to revoke biometric consent, and to opt out of certain processing. Exercise any of these from your dashboard or by emailing support@amazeaimodel.com. We will not discriminate against you for exercising your rights.
Security
We protect data with encryption in transit, row-level security on every table, scoped access keys, private storage for source photos and biometric selfies, and signed, time-limited URLs. No system is perfectly secure, but biometric breach is treated as our highest-priority risk.
Cookies
We use only essential cookies needed to sign you in and keep the service secure. We do not use third-party advertising trackers.
Children
Amaze is strictly for adults 18+. We do not knowingly collect data from, or create twins of, minors. If we learn a minor has used the service, we delete the account and data.
Content credentials & provenance
Every generated image carries C2PA content credentials marking it as AI-generated and tied to your verified likeness, plus an independent trusted timestamp recorded in our provenance ledger.
Third-party misuse
Anything visible on the internet can be copied by bad actors. Amaze is not responsible for theft or deepfake misuse of content by third parties (see the Terms). What we provide is proof and recourse — verification, consent records, content credentials, and a cease-and-desist tool.
U.S. processing
Amaze is operated from the United States and information is processed in the U.S. We do not currently target or offer the service to individuals in the EU/EEA/UK; EU-specific rights and transfer mechanisms will be added before any such launch.
Changes to this policy
We may update this policy; material changes will be posted here with a new “last updated” date and, where appropriate, additional notice.
Contact
Amaze LLC — support@amazeaimodel.com.