This Privacy Policy explains how ImmoStory collects, uses, stores, shares, and protects personal data when you visit the website, create an account, connect property sources, generate marketing assets, purchase credits, or contact our team.
Who we are and what this policy covers
ImmoStory AI acts as the controller for account, website, support, and billing data processed to provide the platform. Depending on how you use the service, we may also act as a processor on your behalf when handling listing materials, contact information, and publication assets that you instruct us to transform or generate.
This policy covers website visitors, trial users, paid customers, agency collaborators, and support contacts. It also covers data received from third-party listing pages, uploads, connected services, and operational security logs.
Categories of data we process
We may process account identifiers, names, emails, passwords or authentication metadata, team membership data, invoices, payment metadata, billing addresses, support messages, notification preferences, and feature usage records. Where you provide or connect listing data, we may process property descriptions, images, floor plans, logos, branding settings, text prompts, generated scripts, subtitles, rendered videos, export metadata, and publication-related settings.
We also process technical and security data such as IP-derived region information, browser or device characteristics, audit logs, API usage, anti-abuse signals, and troubleshooting information needed to keep the service reliable.
Purposes and lawful bases
We process personal data to provide the service you request, authenticate users, ingest and transform listing materials, render generated assets, manage subscriptions or credits, issue invoices, secure the platform, prevent abuse, analyse reliability, respond to support requests, and meet legal obligations. Our lawful bases include contract performance (GDPR Art. 6(1)(b)), legitimate interests (Art. 6(1)(f)), consent where required (Art. 6(1)(a)), and compliance with legal obligations (Art. 6(1)(c)).
Where we rely on legitimate interests, those interests typically include fraud prevention, service stability, product quality, secure access control, support responsiveness, and internal reporting that does not override your rights and freedoms.
Automated decision-making and AI
We use third-party AI providers (large language models, text-to-speech, image and video generation) to transform the listing material you submit into marketing assets. These operations are content-generation tools and do not produce legal effects or similarly significant decisions about you within the meaning of GDPR Art. 22. You can always discard, edit, or regenerate any AI output before publishing it. We do not use your personal data to train external AI providers; provider-side training opt-outs are configured where available.
Subprocessors and international transfers
To run the platform we rely on a limited number of vetted subprocessors. We do not sell personal data. A current list of subprocessors and their processing role is published at /security and is updated when material changes occur. Typical categories include:
- Cloud infrastructure and storage — EU/EEA hosting partners and object-storage providers.
- Payment processing — Stripe Payments Europe (Ireland) for card payments, invoicing and tax handling.
- AI providers — OpenAI, Anthropic, ElevenLabs, Higgsfield, Replicate or comparable suppliers for text, voice, image and video generation.
- Email and notifications — transactional email and push-notification providers.
- Monitoring and analytics — error tracking and aggregated product analytics, only after the corresponding consent where required.
Where data is transferred outside the EEA, we rely on the European Commission’s Standard Contractual Clauses, adequacy decisions, or equivalent safeguards offered by the receiving provider.
Connected social accounts and Google/YouTube data
When you connect a social account (such as YouTube, via Google OAuth) to ImmoStory AI, you authorise us to publish content to that account on your behalf. For YouTube we request the youtube.upload and youtube.readonly permissions. We use these solely to (a) upload the videos you generate in ImmoStory AI to your own channel at your request, and (b) read your channel's name and ID to show you which account is connected. We store the OAuth access and refresh tokens only to perform these actions, and the channel name and ID for display. We do not read, modify, or delete your existing videos, and we never sell this data or use it for advertising.
ImmoStory AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect a connected account at any time from your ImmoStory AI account settings, or revoke access from your Google Account security settings (myaccount.google.com/permissions).
Retention periods
We retain personal data only as long as needed for the purposes set out in this policy. Typical retention windows are:
- Active account data — for the lifetime of the account plus up to 30 days after deletion to allow account recovery.
- Finished videos, scripts and uploaded listings — for the duration of the account plus 90 days, or until you delete them earlier.
- Working files (AI-generated clips, voice-over audio, subtitle files) — kept for as long as the account exists on accounts that have purchased credits. On accounts that have never purchased, they are deleted 60 days after the video is finished, and we email the account owner 7 days beforehand. Deleting them never affects the finished video; it only means that video can no longer be re-edited or re-rendered.
- Invoices and payment records — 7 years to comply with Belgian and EU accounting and tax obligations.
- Support correspondence — up to 3 years after the last interaction.
- Security and audit logs — up to 12 months, longer if needed for a specific incident investigation.
- Backups — encrypted backups rotate on a 30-day cycle; deleted data is purged from backups within that window.
Where applicable law imposes a longer mandatory retention, that period applies.
Your rights and how to exercise them
Depending on your location, you may have the right to: (a) access your personal data, (b) correct inaccurate data, (c) request deletion, (d) restrict processing, (e) object to processing based on legitimate interests, (f) request data portability, and (g) withdraw consent where processing is based on consent.
Many settings are available directly in your account (data export, account deletion, consent toggles). You can also email [email protected] to exercise any right. We aim to respond within 30 days, in line with GDPR Art. 12. We may need to verify your identity to protect your data.
Supervisory authority
If you believe our processing infringes data-protection law, you have the right to lodge a complaint with a supervisory authority — preferably in the EU member state where you live, work, or where the alleged infringement took place. For Belgium, the competent authority is the Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels, www.dataprotectionauthority.be. We invite you to contact us first at [email protected] so that we can try to resolve your concern directly.
Data breach notification
If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required by GDPR Art. 33. Where the breach is likely to result in a high risk, we will also inform affected individuals without undue delay in accordance with Art. 34, using the contact details we hold for them. Security incidents can be reported to [email protected].
Children’s privacy
ImmoStory is a professional B2B service and is not directed to children. We do not knowingly collect personal data from individuals under 16. If you believe a child has provided personal data, please contact us and we will delete it.
Security and updates
We use organisational and technical measures designed to protect personal data, including access controls, role-based permissions, environment separation, encrypted transport (TLS), credential rotation, audit logging, dependency scanning, and operational security monitoring. No internet service can be guaranteed 100 percent secure, so you should also protect your credentials and connected integrations.
We may update this Privacy Policy when the service, legal requirements, processors, or risk profile changes. The latest published version applies from its publication date.
Contact
Privacy questions, rights requests, or complaints can be sent to [email protected]. General support is reachable at [email protected]. Security disclosures and incident reports go to [email protected].

