Privacy Policy
Effective as of January 28, 2026
Introduction
At Bricksfusion, your privacy is a top priority. We are committed to protecting your personal information and ensuring transparency in how we collect, use, and safeguard your data. This Privacy Policy outlines the measures we take to respect your privacy and handle your personal information responsibly.
This policy applies to all Bricksfusion products and services, including BricksFusion Animations, BricksFusion AI plugin, and BricksFusion Studio.
Data Controller
The data controller responsible for your personal data is:
Bricksfusion
Email: support@bricksfusion.com
Location: Spain
We process personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and Spanish data protection legislation (LOPDGDD).
Information We Collect
We collect various types of personal data when you interact with our website or use our services:
- Account Information: Name, email address, and contact information provided during registration or purchase through SureCart.
- License Information: License keys, activation status, and domains where Bricksfusion is activated.
- Usage Data: Information about how you interact with our website and services, including IP address, browser type, pages visited, and actions taken.
- Technical Data: Device information, operating system, and browser version used to access our services.
- Cookies and Tracking Technologies: Small text files stored on your device to improve your experience and provide relevant content.
BricksFusion Studio Data Collection
When you use BricksFusion Studio, we collect and process additional data specific to the AI-powered service:
Data We Store
- User Account: Email address (from SureCart purchase), license type, and account status.
- Preferences: Your selected AI provider, framework preference (Vanilla, ACSS, Core Framework), language, and other Studio settings.
- API Keys: Your third-party API keys, stored encrypted (see "API Keys Storage" section).
Data We Process but Do Not Store
- Prompts: The text descriptions you write to generate sections. These are transmitted to your selected AI provider but are not stored by Bricksfusion.
- Reference Images: Images you upload for AI analysis. These are transmitted to your AI provider and processed in memory only—they are not stored on our servers.
- Generated Output: The JSON code and layouts generated by AI. These are returned to you directly and not retained by Bricksfusion.
Legal Basis for Processing
We process Studio data based on:
- Contract Performance: Processing necessary to provide you the Studio service you purchased.
- Legitimate Interest: Processing necessary for service improvement and security.
API Keys Storage and Security
BricksFusion Studio allows you to store your third-party AI provider API keys for convenience. Here is how we handle them:
- Encryption: All API keys are encrypted using AES-256-GCM encryption before being stored in our database. The encryption key is stored separately and securely.
- Access: Your API keys are only decrypted when you actively use Studio to make AI requests. They are never exposed in plain text in our database or logs.
- Optional Storage: Storing API keys is optional. You may choose not to save them, in which case you would need to enter them each session.
- Deletion: You may delete your stored API keys at any time through the Studio interface. Deletion is immediate and permanent.
- Your Responsibility: While we implement security measures, you acknowledge that storing API keys with any third-party service carries inherent risks. We recommend using API keys with appropriate usage limits set in your provider's dashboard.
Third-Party AI Services Data Processing
When you use Studio, your data is transmitted to the AI provider you select. Each provider has their own privacy policy governing how they process your data:
Prompts, reference images, and context are sent to Anthropic's API.
Privacy Policy →Prompts and images are sent to OpenAI's API.
Privacy Policy →Prompts and images are sent to xAI's API.
Privacy Policy →Prompts and images are sent to Google's API.
Privacy Policy →Bricksfusion does not control how these third-party providers process, store, or use your data. We encourage you to review each provider's privacy policy before using their services through Studio.
How We Use Your Information
We use the information collected to:
- Provide and Maintain Services: Process transactions, deliver services, verify licenses, and maintain your account.
- Personalize Your Experience: Remember your preferences and settings across sessions.
- Communicate with You: Respond to inquiries, provide customer support, and send important updates regarding our services.
- Improve and Optimize: Analyze usage patterns to identify areas for improvement and enhance the overall user experience.
- Security: Detect and prevent fraud, abuse, and security threats.
- Legal Compliance: Comply with applicable laws and regulations.
Data Sharing and Third-Party Disclosure
We only share your personal data in the following cases:
- Service Providers: We use trusted third-party services to operate our business:
- SureCart — Payment processing and license management
- Supabase — Database and authentication services
- Vercel — Hosting and deployment
- AI Providers: When you use Studio, your prompts and images are sent to your selected AI provider (Anthropic, OpenAI, xAI, or Google).
- Legal Compliance: We may disclose your data to comply with legal obligations, enforce our policies, or protect our rights, property, or safety, as well as those of our users or others.
We do not sell, rent, or lease your personal information to any third parties.
Data Security
We take data security seriously and implement appropriate technical and organizational measures to protect your personal information:
- Encryption of sensitive data (API keys use AES-256-GCM)
- Secure HTTPS connections for all data transmission
- Access controls and authentication requirements
- Regular security reviews and updates
However, please note that no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security.
Data Retention
We retain your personal data only for as long as necessary:
- Account Data: Retained while your account is active and for a reasonable period after to comply with legal obligations.
- License Data: Retained for the duration of your license and as required for transaction records.
- API Keys: Retained until you delete them or request account deletion.
- Usage Logs: Retained for a limited period for security and analytics purposes.
Once data is no longer needed, we will securely delete or anonymize it.
International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including:
- United States — where some of our service providers (Vercel, Supabase, AI providers) are located.
When we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your data in accordance with GDPR requirements.
Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data ("right to be forgotten").
- Right to Restrict Processing: Request limitation of how we process your data.
- Right to Data Portability: Receive your data in a structured, commonly used format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, please contact us at support@bricksfusion.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local supervisory authority.
Children's Privacy
Bricksfusion's services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that such data has been inadvertently collected, we will take immediate steps to delete it.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or relevant laws. When we make significant updates, we will:
- Post the revised policy on our website with an updated effective date
- Notify you via email for material changes
Continued use of Bricksfusion after these changes constitutes acceptance of the new terms.
Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Email: support@bricksfusion.com
We aim to respond to all inquiries within 30 days.
By using Bricksfusion, you acknowledge that you have read, understood, and agree to this Privacy Policy.
