Privacy Policy
Version 2026-09-06
This policy explains what Staiple Technologies Inc. ("Staiple", "we") does with personal information in Bluffy — the desktop application, the bluffy.ai website and the services behind them. Staiple is incorporated in British Columbia, Canada, and this policy is written against Canadian privacy law: the Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA).
Questions, access requests and complaints: hello@bluffy.ai. The person accountable for privacy at Staiple is named in section 12.
1. The short version
- We do not train models on your work, and our providers' terms do not permit them to train on it either.
- We do not sell personal information, and we do not use it for advertising.
- Your project files live on your own computer. The cloud holds what is needed to do the work you asked for and clears it out on a schedule.
- Faces and voices are sensitive. We treat them that way, and there are things we refuse to do with them.
- The work is done by providers outside Canada. Section 4 names them.
2. What we collect
Account. Your email address, and a display name if you give one. Your password is held by our authentication provider in hashed form; we never see it. If you link Discord, we store your Discord ID and username.
Billing. A Stripe customer reference, your credit balance, and a ledger of purchases and charges. We never receive or store your card details — you enter them on Stripe's page.
Your creative content. Prompts you write, media you upload, and the outputs generated for you. This is the material the service exists to process, and it may contain personal information — including faces and voices — if you put it there.
Your Library. Characters, locations, looks, voice samples and other assets you choose to save to your cloud Library so they can be reused across projects.
Operational records. Render jobs and their parameters, costs and errors; records of when a safety check refused something and why; and product usage events (which feature was used, in which project, on which app version — event names and identifiers, never the content of your work).
Diagnostics. Crash and error reports sent to Sentry from the app and the service. Both are configured not to send personal data by default, and the app scrubs creative content before a report leaves it.
Support. If you send us a problem report from the app, it goes out through your own email program, and the diagnostics it attaches — app version, platform, account email, the project you had open, recent errors — are shown to you before you send. Nothing is sent automatically.
3. Faces, voices and other sensitive information
If you upload a photograph of a person or a recording of a voice, you are giving us sensitive personal information, and you are confirming you have that person's consent (see the Terms and the Acceptable Use Policy).
Assets saved at a provider. Two features save your material as a durable asset at a provider, under our account, rather than passing it through:
- Registered characters. A character saved as a Virtual Character is registered with BytePlus ModelArk, which stores its identity images (face, body, design sheets) as a provider asset so the model can keep the character consistent across renders. Before that happens we run automated checks on the image, on the prompts that produced it where they exist, and — for a photoreal human — an automated celebrity-face comparison through AWS Rekognition. A record of what those checks decided is kept as evidence they ran.
- Cloned voices. A voice cloned from a sample in your Library is stored as a voice asset by the provider (Kling, through FAL) so it can be used in later renders.
These assets stay at the provider until the character or voice is retired, replaced or deleted (section 6). We do not use uploaded faces or voices for anything except the work you asked for.
4. Who we send it to, and where
To do the work, Bluffy sends content to the processors below. This is the complete list of external services the software contacts today; adding a provider means adding a row here.
| Processor | Where | What it receives | Why |
|---|---|---|---|
| Supabase | United States (Oregon) | account, billing ledger, job records, usage events, uploaded and generated media in transit, your Library, installers | database, authentication, file storage |
| Vercel | United States (Washington, DC) | every request to our API; page views on bluffy.ai | hosting the service and the website; page-view counts on the website |
| Vercel AI Gateway | United States | prompts, scripts, story material, and images or clips you ask the assistant to analyse | routes to the language or vision model you selected — today models from Anthropic, Google, OpenAI, xAI, Alibaba, Moonshot AI and DeepSeek; image and clip analysis is pinned to Google |
| FAL (fal.ai) | United States | prompts, reference images, source video, audio for transcription, voice samples for cloning | image and video generation, editing, upscaling, matting, segmentation, lip-sync, speech-to-text, voice cloning. FAL runs models from ByteDance (Seedream, Seedance, Dreamina), Google, OpenAI, xAI, Black Forest Labs, Alibaba, MiniMax, Ideogram, Microsoft, Moonshot AI, Bria, Veed, Pixelcut, Kuaishou (Kling), Topaz Labs, ElevenLabs, Meta (SAM) and others you may add through the model registry |
| BytePlus ModelArk | Singapore | prompts, reference images, and the identity images of registered characters | video generation, and the Virtual Character registry |
| AWS Rekognition | outside Canada | the face image of a photoreal human character, at registration only | the celebrity-likeness check |
| Stripe | United States | your email and payment details, entered on Stripe's page; our account and credit references | payments |
| Sentry | United States | crash and error reports, without personal data by default | diagnostics |
| Discord | United States | your Discord identity, if you choose to link it | joining you to the Bluffy Discord server and granting the member role |
| Cloudflare Turnstile | worldwide | browser and network signals on the bluffy.ai early-access form | telling people from bots on that one form |
Authentication emails (invitations, password resets) are sent by Supabase's mail service on our behalf.
Transfers outside Canada. All of these providers store and process information outside Canada — in the United States, in Singapore, and in the case of worldwide networks wherever their nearest point of presence is. Information held in another country is subject to that country's laws, including lawful access by its authorities. By using Bluffy you consent to this. If that is not acceptable for a piece of work, do not bring that work into Bluffy.
5. Training
We do not train on your content. Our providers' API terms state that material submitted through their APIs is not used to train their models; we rely on those terms and review them, and where a provider offers a setting or agreement that prevents training, we use it. We do not hold a separately negotiated guarantee from every provider, and we will list any exception here.
Where you ask Bluffy to build something from your own material — a registered character, a cloned voice — that is work done for you on your material, for your project, and is covered by section 3.
6. How long we keep things
Your project files are stored on your computer and are yours to keep or delete. The cloud is a courier, and it is emptied on a schedule. A cleanup runs daily at 03:40 UTC:
| What | Kept for |
|---|---|
| Uploaded inputs to a render, once the render has finished | 1 hour |
| Generated outputs and anything else in transit storage | 30 days |
| The prompt text recorded against a render job | 30 days, then erased from the record; the billing entry survives without it |
| Chat and assistant logs, and records of a legal-floor refusal | 30 days |
| Records of a likeness refusal at character registration | kept — they are the evidence the check ran |
| Your Library | until you delete an item, or close your account |
| Assets saved at a provider (registered characters, cloned voices) | until the character or voice is retired, replaced or deleted; a provider may also expire an asset on its own |
| Product usage events | while your account is open |
| Crash reports at Sentry | Sentry's standard retention (90 days) |
| Billing ledger | as long as tax and accounting law requires |
| Account record | until you close your account |
7. Security
Every request to the service is authenticated and checked against the account that made it. Provider API keys are held only on the server; the desktop application never holds one. Stored files are reachable only through short-lived signed links scoped to their owner, and your Library is in a private bucket. Provider assets are tied to the account that registered them, and a render cannot use another user's registered character or cloned voice.
No system is perfectly secure. If a breach creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as the law requires.
8. Your rights
Under PIPEDA and BC PIPA you may ask us to:
- show you the personal information we hold about you;
- correct it where it is wrong;
- delete your account and the information attached to it, including assets saved at providers for you;
- withdraw consent, understanding that most of Bluffy cannot work without it;
- explain what we hold and why, and to whom it has been disclosed.
Write to hello@bluffy.ai. We will respond within 30 days. If you are not satisfied, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca).
9. Children
Bluffy is not for anyone under the age of majority where they live, and we do not knowingly collect information from children. If you believe a child has given us information, write to hello@bluffy.ai and we will delete it.
10. Cookies and tracking
The bluffy.ai website keeps you signed in using your browser's local storage, counts page views with Vercel's analytics, and uses Cloudflare Turnstile on the early-access form. There are no advertising trackers and no third-party analytics profiles. The desktop application does not use cookies.
11. Changes
We will post any change here with a new version date, and tell you before a material change takes effect.
12. Contact and accountability
Staiple Technologies Inc. PO Box 91881, 1427 Bellevue Ave West Vancouver, BC V7T 1C0, Canada hello@bluffy.ai
Privacy Officer: Brett Keyes — the individual accountable under PIPEDA for Staiple's compliance with this policy. Write to hello@bluffy.ai, attention Privacy Officer.