Privacy Policy

Last updated: 9 September 2026 · Filtroo OÜ, operating as “Aitoma Studio”

1. Who we are

The data controller is Filtroo OÜ, a private limited company under Estonian law, registry code 16246756, VAT EE102381229, registered address Tööstuse tn 48, 10416, Põhja-Tallinna linnaosa, Tallinn, Estonia, operating under the brand “Aitoma Studio”.

This policy covers our marketing sites (including aitoma.studio) and the Aitoma Studio application at studio.aitoma.ai. For all privacy matters, contact hello@aitoma.ai.

2. Data we collect

Account

Email address, name, and password when you create an account. Authentication is managed by our provider Supabase; passwords are stored hashed and are never visible to us.

Onboarding answers

If you complete the onboarding questionnaire: your role, team size, main challenge, content type, expected monthly volume, and preferred language. We use these to configure your workspace.

Payment

Payments are processed entirely by Stripe. We never see or store your card number. We store your Stripe customer and subscription identifiers, your plan, invoice status, and your credit ledger.

Content you upload

Product photos, brand assets, reference images, scripts and briefs, voice samples, and face or likeness images for AI clones (see Section 3), plus any support or feedback messages including screenshots.

Generated content and usage

The videos, images, and copy the service produces for you, your generation history, and the linkage to social accounts you connect (see Section 5).

Technical

IP address, browser and device information, approximate (country-level) location, and the cookie identifiers described in Section 6.

3. Face and voice data (AI clones)

To create an AI clone, you upload face images and voice samples. We treat these as sensitive data and process them only with your explicit consent, which you give when you start clone creation, and only to build and render your clone.

4. How we use your data and lawful bases

We do not sell personal data. We do not use your uploads or your generated content to train our own AI models.

5. Connected social and advertising accounts, and public-content analytics

Auto-posting runs through our publishing partner Ayrshare. When you connect Instagram, TikTok, YouTube, or Facebook, your platform login tokens are held by Ayrshare, not by us. We store only your Ayrshare profile reference and post metadata (captions, schedule, publish results).

Meta advertising accounts. If you connect a Meta advertising account, you authorise Aitoma Studio to work with it through Meta’s Marketing API. We access only what the feature needs: the ad accounts and Facebook Pages in your Meta business portfolio, so you can choose which to use; the Facebook Page and Instagram account an ad runs under; your campaigns, ad sets, ads and their creative; and their performance figures, meaning spend, impressions, clicks and conversions. We use this for two purposes only: to create the advertising objects you asked Studio to build, and to report performance back to you inside Studio. Every campaign, ad set and ad we create is created paused and cannot spend money until you activate it, and you set a daily budget cap we enforce on our side. Your access token is encrypted at rest and is never shared with another customer. What Studio learns from your results is used for your account only and is never pooled across customers, and we do not use your ads data to train AI models. Disconnecting in the app revokes our access and stops all further collection immediately; you can also remove Aitoma Studio at any time from your Meta business settings. Deletion of the data we already hold is covered in our Data Deletion Policy.

The service can also retrieve publicly available social posts and profile statistics, including for third-party accounts you choose to track, through our data partner Bright Data. Our lawful basis is our and our customers' legitimate interest in analysing publicly published content. We do not access private accounts or non-public data. If you appear in public content processed this way and want it removed from a customer's workspace, contact hello@aitoma.ai.

6. Cookies and tracking

Essential storage. We use first-party cookies and browser storage for things the service needs to work: your session, language, interface preferences, and your consent choice. These require no consent.

Advertising measurement. Our production sites use the Meta Pixel and Meta Conversions API to measure whether our ads work. In the EU/EEA, the United Kingdom, and Switzerland, these load only after you accept the consent banner; elsewhere they load by default. What Meta receives when active: a hashed version of your email and user ID, the _fbp/_fbc cookie identifiers, your IP address, your browser user agent, and purchase value for conversion events.

You can decline or withdraw at any time via the banner or by clearing this site's data. The service works fully without advertising cookies.

7. Who we share data with

We share data only with vetted providers under data-processing agreements, and only what each needs to do its job:

We may also disclose data where required by law, or as part of a corporate transaction (in which case we will give you notice). We update this list as providers change; material changes are reflected in the “Last updated” date.

8. International transfers

We are based in the EU. Several of our providers process data in the United States. Where they do, transfers rely on the EU–US Data Privacy Framework for certified providers, and otherwise on the European Commission's Standard Contractual Clauses together with supplementary measures. A copy of the relevant safeguards is available on request via hello@aitoma.ai.

9. How long we keep data

Step-by-step deletion instructions, including for data from connected platforms, are at aitoma.studio/data-deletion.

10. Your rights

Under the GDPR you can ask us for access to your data, rectification, erasure, restriction of processing, portability, and you can object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time without affecting processing that already happened.

To exercise any right, email hello@aitoma.ai from your account email address. We respond within one month.

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or with your local supervisory authority.

11. Security

Data is encrypted in transit (TLS) and at rest with our infrastructure providers. We apply access controls and least-privilege principles internally, and card data never touches our systems (it is handled on Stripe-hosted pages). No system is perfectly secure; if a breach affects you, we will notify you and the supervisory authority as the GDPR requires.

12. Children

Aitoma Studio is built for business and professional use and is not directed at anyone under 16. We do not knowingly collect children's data, and we will delete it if we discover it.

13. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top changes with every revision, and we announce material changes by email or in the app before they take effect.

14. Contact

Filtroo OÜ · Tööstuse tn 48, 10416, Põhja-Tallinna linnaosa, Tallinn, Estonia · hello@aitoma.ai

See also our Terms & Conditions.