Iconnih

Privacy Policy

Effective date: 18 August 2026
Document version: 1.2

This Privacy Policy explains how Iconnih (the “Platform”) collects, uses, stores, shares, and protects information when you use the Platform. We aim to process data fairly, transparently, securely, and in line with applicable personal data protection law, including Indonesia’s Personal Data Protection Act.

Language: this English text is provided for your convenience. If its meaning differs from the Indonesian version, the Indonesian version prevails. You can read it at iconnih.com/privacy.

1. What we collect

  • Account data: your email and credentials, handled securely through Supabase Auth (your name is also recorded if you sign up with Google).
  • Transaction data: the package purchased, credit amount, price, payment status, and order identifier. All transactions are currently processed in Indonesian Rupiah through Midtrans. Card and payment instrument details are never stored by the Platform — they are handled by the payment processor.
  • Input and Output: your text prompts, images uploaded for the conversion feature, your style and motion preset choices, and the static icons and animated videos produced.
  • Technical data: IP address, device type, browser, operating system, logs, access times, and performance data.
  • Usage data: which features you use, how many icons you generate, convert, or animate, credit usage, errors, and your interactions with the Platform.
  • Usage-limit records: the time of each generate, convert, or animate request, kept to enforce fair use limits and prevent automated abuse. These records contain neither your prompts nor your images, and are deleted automatically after 2 days.
  • Animation job records: the processing status of each animation request (running, finished, failed), used to stop a single account from running several jobs at once.
  • System alert records: events that need operator review — for example a payment whose status looks irregular. These may contain an order number, but never payment details or the contents of your Input.
  • Communication data: the contents of messages when you contact support or report abuse.

2. Personal data inside images

The image-to-icon feature lets you upload images that may contain personal data, including faces or information that identifies someone — and the result can later be animated. You are responsible for ensuring there is a lawful basis for uploading and processing those images.

We recommend not uploading identity documents, health data, financial data, or other sensitive information that the service does not need.

3. Why we process data

  • to provide and run the icon generation, conversion, and animation features;
  • to process payments, credits, and account administration through the payment providers we use;
  • to enforce fair use limits and prevent automated abuse;
  • to store your Output so it stays available in your history;
  • to maintain security and prevent fraud, spam, abuse, and unlawful use;
  • to diagnose errors and improve service stability;
  • to provide customer support;
  • to run product analytics and develop features;
  • to meet legal obligations and respond to lawful requests from authorities.

4. Legal basis

Depending on the context and the law that applies, processing may rest on performance of a contract or provision of the service, your consent, legitimate interests, compliance with a legal obligation, or another basis recognised by law.

5. Processing by AI and other third-party providers

To deliver the service, your Input (prompts and images) is sent to and processed by:

  • Kie.ai, the AI infrastructure provider that forwards the Platform’s requests to the Nanobanana model (generating and converting static icons) and Kling (animating icons). The text prompts and images you send are processed through this provider;
  • Supabase, for database hosting, authentication, and storage of static icons;
  • Vercel, for application hosting;
  • Cloudflare, for storing animation results;
  • Midtrans, for processing payments from customers in Indonesia.

We list these so you know where your data goes and can exercise your rights over it. Providers may change over time; material changes will be reflected on this page.

Payment for international customers is not yet available. When it is enabled, the provider will be listed here before that service opens.

Whether Kie.ai and the underlying AI models use data for model training is governed by each provider’s own policy and is outside the Platform’s direct control.

6. Is your data used to train AI models?

As far as the Platform knows and can control, your Input and Output are NOT used to train any AI model of our own — the Platform neither owns nor trains AI models. Whether Input/Output is used for training by the third-party model providers (Nanobanana/Kling via Kie.ai) depends on each of those providers’ data policies.

7. Storage and retention

We keep data for as long as needed to provide the service, fulfil the purposes above, resolve disputes, enforce agreements, meet legal obligations, and maintain security. Account data is kept while the account is active; transaction data is kept for the period the law requires.

Output (the icons you generate) is stored on the Platform’s own storage infrastructure, not merely linked from the AI provider. Output is kept while your account is active so it stays available in your history. We do not delete Output on a schedule; it is removed when you delete your account.

Images you upload for the conversion feature are treated the same way and are accessible only to the account that uploaded them.

Usage-limit records are deleted automatically after 2 days. Orders that are never completed are marked expired after 24 hours.

8. Deleting your data

You can delete your account yourself at any time from the Account page inside the Platform — no need to contact us, and no approval to wait for.

Deleting your account removes, in a single step:

  • your account and credentials;
  • your entire generation, conversion, and animation history;
  • every stored file — both the images you uploaded and the Output produced;
  • your transaction history and credit balance;
  • your usage-limit records and animation job records.

Please note: deletion is permanent and cannot be undone, and any remaining credits are forfeited with no refund.

You may also request deletion or access to your data by writing to iconnihsupport@gmail.com. Deletion may have exceptions where data must be retained for legal obligations, security, fraud prevention, dispute resolution, or another lawful interest — for example transaction records that must be kept for tax purposes.

9. Who we may disclose data to

We may disclose data to the following categories where necessary and lawful:

  • Kie.ai and the underlying AI models (Nanobanana, Kling);
  • Supabase, Vercel, and Cloudflare for hosting, database, and storage;
  • the payment provider that processes your transaction;
  • analytics, monitoring, email, and customer support providers;
  • professional advisers, auditors, or other parties in a corporate transaction;
  • government authorities or law enforcement where required or permitted by law.

10. Cross-border data transfers

Because Kie.ai, Supabase, Vercel, and Cloudflare may process data on servers located outside Indonesia, your data may be processed across borders. The Platform will apply the mechanisms required by applicable law for such transfers. Payment processing currently takes place in Indonesia through Midtrans.

11. Security

The Platform applies reasonable technical and organisational measures, which may include encryption in transit, access control, authentication, logging, backups, monitoring, rate limiting, secret management, and restrictions on internal access.

No system can be guaranteed completely secure. If a security incident occurs that meets the notification criteria under applicable law, the Platform will act and notify as required.

12. Cookies and similar technologies

The Platform may use cookies, local storage, or similar technologies for authentication, security, preferences, and analytics. You can configure your browser to refuse some cookies, but parts of the Platform may then not work properly.

13. Your rights

Subject to applicable law, you may have the right to request access, correction, updating, deletion, restriction of processing, withdrawal of consent, or other rights over your personal data. Requests can be sent to iconnihsupport@gmail.com. The Platform may verify your identity before acting on a request.

14. Minors

The Platform is not intended for users below the minimum age of 18 set out in the Terms of Service. If we learn that a minor’s data has been collected improperly, we will take reasonable steps to delete or otherwise handle it as the law requires.

15. Data about other people

If you upload images containing other people for the conversion or animation features, you are responsible for ensuring the legal basis, notice, and/or consent needed for that processing.

16. Changes to this Privacy Policy

This Privacy Policy may be updated to reflect changes to the service, technology, providers, or the law. Material changes will be announced on the Platform or by another reasonable method.

17. Document language

The Indonesian version of this Privacy Policy is the binding one. This English text is provided to help you read it; if the two differ in meaning, the Indonesian version prevails.

18. Data protection contact

Email: iconnihsupport@gmail.com
Target response time: 14 business days, while still meeting any deadlines the law imposes.