Privacy Policy
Last updated: August 26, 2026
1. Data Controller and Contact
Vistella is independently operated by Liu Yusong, an individual proprietor. The controller’s tax residence and registered address are provided in the applicable merchant review materials, checkout disclosures, and as required by law; these details must be completed before production sales in any jurisdiction that requires them. The privacy, data-rights, security-report, and account-support contact is support@vistella.xyz.
2. Information We Collect
We collect the following types of information: - Account information: username and email address provided during registration - Payment information: Waffo processes checkout as Merchant of Record; we do not directly store full credit card numbers. - Usage data: API call logs, model usage, and request logs - Technical information: IP address, browser type, and device information
3. How We Use Your Information
We use the information we collect for the following purposes: - Providing and maintaining the Service - Processing payments and billing - Sending service-related notifications - Improving and optimizing platform performance - Preventing fraud and abuse - Complying with legal obligations
4. Information Sharing
We do not sell your personal information. We share the minimum data needed to operate the Service in the following circumstances: - With our payment processor when you purchase credits or a subscription, sharing necessary payment and order details - With automated safety services when moderation is enabled, sharing the prompt, relevant request metadata, or temporary image data only for safety classification - With hosting, storage, email, and security providers acting on our instructions - When required by law or in response to law enforcement requests - With your consent
5. Cookies and Tracking
We use essential cookies to maintain user sessions and authentication state. We do not use third-party advertising or tracking cookies.
6. Data Security and Breach Notices
We implement reasonable technical and organizational measures to protect your information, including TLS/HTTPS, password hashing, secure storage, least-privilege access controls, and audit logs. However, no method of internet transmission or storage is 100% secure. If a personal-data incident is likely to affect your rights, we will notify you and the relevant authority within 72 hours after discovery and initial assessment, or within any shorter period required by law; if that timing cannot be met, we will explain the reason and provide updates.
7. Data Retention and Deletion
We retain account information while your account is active. API call logs and moderation audit metadata are retained for 90 days by default; transaction and tax records are retained as required by law and the payment provider. Images sent for automated safety review are transmitted temporarily and are not intentionally retained by Vistella after the review request; generated files remain subject to the retention period shown in the Service. You can use the account deletion flow or contact support@vistella.xyz to request deletion. We normally delete or anonymize deletable personal data within 30 days; data retained for legal, dispute, or safety-audit purposes is deleted when the applicable period ends.
8. Your Rights and Response Times
Depending on applicable data protection laws, you may have the following rights: - Access and obtain a copy of your personal data; - Correct inaccurate or incomplete data; - Request deletion or restriction of processing; - Data portability; - Object to processing based on legitimate interests; - Withdraw consent where processing is based on consent; - Complain to your local data-protection authority. To exercise a right, contact support@vistella.xyz with your account email, request type, and the data concerned. We normally respond within 30 days; where applicable law permits an extension for complex or numerous requests, we will explain the reason within the initial period. We may request reasonable identity verification to protect the account.
9. Children's Privacy
The Service is not intended for users under the age of 16. We do not knowingly collect personal information from children under 16.
10. International Data Transfers
Vistella and our payment, hosting, storage, email, and safety-service providers may process data outside your country or region. Where a cross-border transfer occurs, we use safeguards recognized by applicable law, such as an adequacy decision, standard contractual clauses (SCCs), or equivalent provider commitments, and transfer only the minimum data needed to provide the Service.
11. Service Notices and Marketing Choices
We send necessary account, billing, security, service-status, and policy-update notices; these cannot be disabled through marketing unsubscribe controls. We send product updates or marketing email only where the consent required by applicable law has been obtained. Marketing messages include an unsubscribe link, and you may also contact support@vistella.xyz to stop marketing.
12. Third-Party Links
The website may link to model providers, payment processors, documentation, social networks, or other third-party sites. Those sites have their own privacy policies and security practices. Vistella does not control their content or processing, so review the relevant policy before leaving our website.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated via email or website notice. Continued use of the Service constitutes acceptance of the updated policy.
14. Contact
For questions about this Privacy Policy, please contact support@vistella.xyz.
