Privacy Policy

Last updated: September 2026

This Privacy Policy outlines how 9523-9778 Quebec Inc., doing business as Emero ("Emero," "we," "us," and "our") collects, uses, processes, and protects your personal data when you use our platform and services. It also details your rights regarding your data and how we comply with applicable privacy laws, including GDPR, CCPA/CPRA, PIPEDA, Quebec Law 25, and other state privacy laws.

Policy Updates: We may update this Privacy Policy from time to time. Your continued use of our services after changes constitutes acceptance of the updated policy. We will notify you of material changes via email and through the platform.

1. Your Relationship With Emero

Emero is an AI creative studio. When you sign up, you have a direct relationship with us for all data requests and concerns, full access to your data subject rights under applicable privacy laws, and control over your privacy settings. The personal data we collect and how we use it is described below.

2.1. Types of Personal Data Collected

We collect the following personal data to provide the service:

  • Account information — your name and email address when you register, and any correspondence with our support team.
  • Billing information — processed by our payment provider; we do not store full card numbers.
  • Prompts, reference material, and uploads — the text prompts, reference images, and other files you provide to generate content.
  • Generated content — the images, video, music, and speech you create with the Platform.
  • Usage and device data — device type, operating system, browser type, IP address, and how you use the Platform (pages visited, features used, time spent).

How your prompts and content are used

To fulfill a generation, we route your prompts and reference material to the third-party AI model providers you choose. We store your prompts and the content you generate so that you can access, search, and reuse them in your library. We do not use your content, prompts, or generations to train any AI model, and we never use one user's data to benefit another.

Connecting a third-party AI assistant

If you connect a third-party AI assistant (such as Claude or ChatGPT) through our connector, that assistant accesses your account and creations to act on your behalf. You can disconnect it at any time from your account settings, which revokes its access. You are responsible for the assistant and its provider's own terms and privacy practices.

2.2. Data Minimization

We collect only the personal data we need to run the service, and we keep identifiable data separate from analytics wherever practical. Product analytics use aggregated or de-identified data where we can. We retain full IP addresses only for security purposes — detecting unauthorized access, preventing fraud, and protecting your account — and these security logs are automatically deleted after 30 days unless required for an active investigation.

2.3. Purposes of Data Collection and Processing

Personal data is collected and processed by Emero for specific, legitimate purposes:

To Provide and Improve Services:

The primary purpose is to let you generate images, video, music, and speech with the third-party AI models offered on the Platform, store and retrieve your creations, and manage your account. We also use data to personalize and improve the Emero platform and user experience.

Communication:

Data is used to respond to user inquiries, provide customer support, send service-related notifications, and communicate updates regarding terms and policies. With appropriate consent, it may also be used for delivering newsletters or other marketing communications.

Security and Compliance:

Data processing is necessary for verifying accounts and activity, combating harmful conduct, maintaining the integrity of Emero's services, and investigating suspicious activities or breaches of the Terms of Use. It also ensures compliance with legal obligations and regulatory requirements.

Analytics and Research:

Emero conducts internal analytics to understand and improve its services. This often involves the use of aggregated, de-identified, or anonymized insights where possible.

No Model Training on Your Data:

We do not use your prompts, uploads, or generated content to train any AI model, and we never use one user's data to benefit another. Your creations belong to you.

2.4. Legal Bases for Processing Personal Data (GDPR Article 6)

For each processing activity involving personal data, Emero identifies and relies upon a valid legal basis under GDPR. These bases include:

  • Performance of a Contract: Processing is necessary for the performance of a contract with the data subject or to take steps at the request of the data subject prior to entering into a contract. This applies to data processing directly required to deliver Emero's core services, such as generating and storing the content you create.
  • Consent: Where processing is not strictly necessary for contract performance or other legal bases, explicit consent is obtained. This is particularly relevant for marketing communications, the use of non-essential cookies, or certain types of analytics. Consent must be freely given, specific, informed, and unambiguous, and it must be as easy for the data subject to withdraw as it was to give.
  • Legitimate Interests: Processing may be based on Emero's legitimate interests (e.g., fraud prevention, service improvement, network security), provided these interests do not override the fundamental rights and freedoms of the data subject.
  • Legal Obligation: Processing may be necessary for compliance with a legal obligation to which Emero is subject (e.g., data retention for tax purposes, responding to lawful government requests).

2.5. Data Sharing and Disclosure

Emero engages in data sharing and disclosure under specific circumstances:

  • With AI Model Providers: To fulfill a generation, we send your prompts and any reference material to the third-party AI model provider you select. These providers process that input to return the content you requested and are bound by their own terms and privacy practices.
  • With Third-Party Service Providers: Personal data may be shared with trusted third-party service providers who perform functions on Emero's behalf. These include, but are not limited to, cloud hosting providers, payment processors, analytics providers, and customer support tools. These providers are contractually bound to protect data and use it solely for the specified purposes, often under Data Processing Agreements.
  • For Legal Reasons: Data may be disclosed if required by law, court order, governmental request, or when necessary to enforce Emero's policies, or to protect the rights, property, or safety of Emero, its users, or the public.
  • In Business Transfers: In the event of a merger, acquisition, or asset sale, user data may be transferred as part of the transaction.
  • Aggregated/De-identified Data: Emero reserves the right to share aggregated or de-identified information that cannot reasonably be used to identify an individual, for purposes such as industry analysis or marketing.

2.6. User Rights and Choices Regarding Their Data

Emero is committed to upholding the data rights of its users as mandated by applicable laws. The Privacy Policy serves to inform users clearly and transparently about these rights and how to exercise them.

GDPR Data Subject Rights:

  • Right to be Informed: Individuals have the right to receive clear and transparent information about the collection and processing of their personal data.
  • Right of Access: Users can request confirmation of whether their personal data is being processed and obtain a copy of that data.
  • Right to Rectification: Users have the right to request the correction or updating of inaccurate personal data.
  • Right to Erasure ("Right to be Forgotten"): Under certain circumstances, users can request the deletion of their data.
  • Right to Restrict Processing: Users can limit how their data is processed under specific conditions.
  • Right to Data Portability: Users can request to receive their data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Right to Object: Users have the right to object to the processing of their personal data, particularly for direct marketing purposes. This right must be easy to exercise.
  • Rights related to Automated Decision-Making and Profiling: Users have the right to be informed if automated decisions are made about them and to challenge such decisions. Emero will disclose if its AI-driven features involve profiling that significantly impacts users.

CCPA/CPRA Specifics (for California Residents):

Important Notice: Emero does NOT sell personal information. We have never sold personal information and have no plans to ever sell personal information. This is a core principle of our business.

Your California Rights: You have the right to know what personal information we collect, delete your personal information, correct inaccurate information, and limit the use of sensitive personal information. You also have the right to non-discrimination for exercising your privacy rights.

PIPEDA Rights (for Canadian Residents):

Individuals have rights to access their personal information, challenge its accuracy, and challenge the organization's compliance with PIPEDA. They also have the right to withdraw consent.

Quebec Law 25 Rights (for Quebec Residents):

Individuals have rights to access, review, and correct their personal information, and to withdraw consent. The law also introduces rights to de-indexation and re-indexation.

2.7. Managing Your Privacy Settings

You control your data directly from your account settings:

  • Connected AI assistants: Disconnect any third-party AI assistant (such as Claude or ChatGPT) at any time, which revokes its access to your account and creations.
  • Your creations: View, download, and delete the content you generate at any time.
  • Marketing communications: Opt out of newsletters and marketing emails at any time.
  • Account deletion: Delete your account and associated data — see Section 2.13.

To modify any of these settings, log into your Emero account and navigate to Settings. Changes take effect immediately.

2.8. Data Retention Periods

Emero adheres to the principle of storage limitation, retaining personal data only for as long as necessary to fulfill the purposes for which it was collected, including for legal, accounting, or reporting requirements. Specific retention periods are determined based on the type of data and its purpose. Once data is no longer needed, it is securely destroyed, erased, or anonymized to prevent unauthorized access or use.

Specific Retention Periods:

Data CategoryRetention PeriodRetention Basis
Account InformationActive period + 90 daysAccount recovery & transition period
Billing & Payment Records7 yearsTax & accounting requirements
Prompts & Generated ContentUntil you delete itRetrieval & reuse in your library
Support Communications12 monthsIssue resolution & service quality
Marketing PreferencesUntil withdrawn + 3 yearsCompliance proof for opt-outs
Security Logs (IPs, access attempts)30 daysFraud detection & security investigations

* Retention periods may be extended if required by law, legal proceedings, or with your consent.

2.9. Security Measures

Emero implements industry-standard security measures to protect your data:

  • Data encryption: Industry-standard encryption for data in transit and at rest
  • Access controls: Multi-factor authentication and principle of least privilege
  • Security monitoring: Continuous monitoring for threats and vulnerabilities
  • Employee policies: Strict data access policies with comprehensive audit logging
  • Infrastructure protection: Enterprise-grade hosting with redundancy and protection measures

Our Security Commitment & Transparency: We believe in being honest: no system is 100% secure. Even the largest tech companies with unlimited resources experience breaches. What matters is how seriously we take security and how we respond when issues arise.

What we do:

  • Implement security best practices and stay current with emerging threats
  • Regularly review and update our security measures
  • Minimize the data we collect
  • Maintain incident response procedures

Our promise if a breach occurs:

  • Notify affected users within 72 hours of discovery
  • Provide clear information about what data was affected
  • Take immediate steps to contain and remediate the issue
  • Cooperate fully with regulatory authorities
  • Learn from the incident and strengthen our defenses

By using Emero, you acknowledge that while we implement robust security measures, you should never store extremely sensitive information (like social security numbers or health records) in any creative platform, including ours.

2.10. International Data Transfers and Safeguards

Emero may transfer and store personal data in countries outside of the user's country of residence, including to servers in jurisdictions such as the United States. The inherently global nature of Emero's service necessitates a proactive and continuously evolving approach to international data transfer compliance.

For transfers of personal data from the EU/EEA, UK, or Quebec to countries not deemed to provide an adequate level of data protection, Emero implements appropriate safeguards, such as:

  • Standard Contractual Clauses (SCCs): These are standardized legal provisions approved by the European Commission, providing a framework for transferring personal data and imposing data protection obligations on both the transferring and receiving parties.
  • Transfer Impact Assessments (TIAs) / Privacy Impact Assessments (PIAs): Emero conducts assessments to identify and evaluate the risks involved in transferring personal data outside a specific jurisdiction. These assessments consider the specific circumstances of the transfer, including the categories and format of the data, the type of recipient, and the relevant local laws and practices in the destination country. This is a mandatory requirement for transfers under Quebec Law 25.
  • Binding Corporate Rules (BCRs): If applicable for internal group transfers, BCRs provide a framework for data transfers within a corporate group, subject to approval by relevant data protection authorities.
  • Explicit Consent: In specific situations where other transfer mechanisms are not feasible or applicable, explicit consent may be obtained from individuals for data transfers.

Emero also ensures that data is encrypted during transmission for all cross-border transfers. The dynamic nature of international data transfer regulations, exemplified by developments like the EU-US Data Privacy Framework, requires Emero to commit to ongoing monitoring and regular updates of its transfer mechanisms and assessments to ensure continuous compliance.

2.11. Age Restrictions - 18+ Only Platform

Emero is strictly an 18+ platform. Users must be at least 18 years old to create an account or use our services. This is a non-negotiable requirement due to:

  • The platform's paid subscription and the financial obligations it involves
  • Legal requirements for entering into binding contracts

We implement age verification measures during account creation and do not knowingly collect, use, or disclose information from anyone under 18. For users in Quebec, we specifically comply with Quebec Law 25 regarding minors. If we discover that someone under 18 has created an account or provided us with personal information:

  • The account will be immediately terminated
  • All associated data will be permanently deleted
  • No refunds will be provided for any fees paid

If you become aware that someone under 18 has created an account on Emero, please contact us immediately at hello@emero.studio.

2.12. Cookie Policy

We use cookies and similar tracking technologies to track activity on our platform and hold certain information. Cookies are files with small amounts of data which may include an anonymous unique identifier. For detailed information about our use of cookies, how to manage cookie preferences, and our response to Do Not Track signals, please refer to our separate Cookie Policy.

Do Not Track:Some browsers incorporate a "Do Not Track" (DNT) feature that signals to websites that you do not want to be tracked. Currently, our platform does not respond to DNT signals.

2.13. Data Deletion and Account Control

Complete Data Control & Deletion Rights

We believe in complete transparency and user control over personal data. You can request immediate deletion of your data through multiple convenient methods:

1. Instant Self-Service Deletion: Delete your account and all associated data instantly from your account settings. This action is immediate. Access Data Deletion Portal

2. Privacy Team Support: Our dedicated privacy team responds to all deletion requests within 24 hours. Email: hello@emero.studio

Data Deletion Timeline & Process

Data CategoryDeletion TimelineProcess
Account ProfileImmediateAutomated deletion upon request
Prompts & Generated ContentImmediateComplete removal from all systems
Backup DataWithin 90 daysAutomated purge from all backups

Legal Retention Exceptions: Certain records may be retained longer if required by law (e.g., financial records for tax compliance) or if necessary for legal proceedings. These records are securely isolated and used only for required legal purposes.

2.14. Third-Party Service Providers

Emero works with trusted third-party service providers (such as cloud hosting, payment processors, and analytics services) to deliver our services. These providers are contractually bound to protect your data and use it only for the specific purposes we authorize.

We do not retain personal information from any third-party services to develop, improve, or train generalized AI or machine learning models. All third-party integrations are subject to strict data protection agreements and regular security audits.

2.15. User Data Rights and Exercise Mechanisms

RightDescriptionHow to ExerciseResponse Time
Right to AccessRequest a copy of your personal dataEmail hello@emero.studioWithin 30 days
Right to RectificationRequest correction of inaccurate dataEmail hello@emero.studioWithin 30 days
Right to ErasureRequest deletion of personal dataEmail hello@emero.studioWithout undue delay
Right to Data PortabilityExport your personal dataEmail hello@emero.studioWithin 30 days
Right to Withdraw ConsentWithdraw consent for processingEmail hello@emero.studioImmediately

3. State-Specific Privacy Rights

3.1. California Privacy Rights (CCPA/CPRA)

In addition to the rights mentioned above, California residents have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: You can request information about the personal information we collect, use, and disclose
  • Right to Delete: You can request deletion of your personal information, subject to certain exceptions
  • Right to Correct: You can request correction of inaccurate personal information
  • Right to Limit Use: You can limit use and disclosure of sensitive personal information
  • Right to Non-Discrimination: You will not be discriminated against for exercising your privacy rights
  • No Sale of Data: We do not sell personal information, so there is no need to opt-out

Authorized Agents:You may designate an authorized agent to make requests on your behalf. We may require verification of the agent's authority and your identity.

Shine the Light: California residents may request information about disclosure of personal information to third parties for direct marketing purposes.

3.2. Colorado Privacy Rights (CPA)

Colorado residents have the right to opt-out of targeted advertising, sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. You also have rights to access, correct, and delete your personal information, and the right to appeal if we decline to take action on your request.

3.3. Connecticut Privacy Rights (CTDPA)

Connecticut residents have similar rights to access, correct, delete, and obtain a copy of personal data, as well as to opt-out of targeted advertising, sale, and certain profiling activities. You have the right to appeal our decision if we decline your request.

3.4. Utah Privacy Rights (UCPA)

Utah residents have the right to access, delete, and obtain a copy of personal data, and to opt-out of targeted advertising and the sale of personal data.

3.5. Virginia Privacy Rights (VCDPA)

Virginia residents have rights to access, correct, delete, and obtain a copy of personal data, to opt-out of targeted advertising, sale, and profiling, and to appeal decisions regarding their requests.

To exercise any of these state-specific rights, please contact us using the information in the Contact Us section below. We will respond to your request within the timeframe required by applicable law.

4. International Data Transfers and Compliance

Emero is headquartered in Montreal, Quebec, Canada. When you use our services, your personal information may be transferred to and processed in countries other than your country of residence, including to our service providers and cloud infrastructure.

Canadian Privacy Compliance

As a Canadian company, Emero is primarily regulated by the Privacy Commissioner of Canada under PIPEDA (Personal Information Protection and Electronic Documents Act) and by the Commission d'accès à l'information du Québec under Quebec Law 25.

For international data transfers, we implement appropriate safeguards including:

  • Contractual clauses with service providers ensuring equivalent protection
  • Encryption of all data in transit and at rest
  • Regular privacy impact assessments for cross-border transfers
  • Compliance with sector-specific requirements for each jurisdiction

Global Privacy Standards

While headquartered in Canada, Emero voluntarily adheres to international privacy standards including:

  • GDPR Standards: For European users, we follow GDPR requirements even though not directly subject to EU jurisdiction
  • US State Laws: We comply with CCPA, CPRA, and other US state privacy laws for American users
  • APEC Privacy Framework: Following cross-border privacy rules for Asia-Pacific region users

For privacy complaints or inquiries, Canadian users may also contact the Privacy Commissioner of Canada at www.priv.gc.ca.


Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at hello@emero.studio. For general contact information, mailing addresses, and other departments, please visit our Contact Page. We aim to respond to all privacy-related requests within 30 days, or sooner if required by applicable law.

Impact-Site-Verification: f22b389a-665a-4f41-b42a-320558fb4238