Fiava legal
Fiava Creator Program Privacy Notice
Effective and last updated September 10, 2026
Effective September 10, 2026.
1. Who this notice covers
Fiava, Inc. ("Fiava," "we," "us") is responsible for the personal information described here. Our address is 1209 Mountain Road Place NE, Suite R, Albuquerque, NM 87110, USA. Our privacy contact is Imran, at legal@fiava.ai. You may also write to that postal address.
This notice covers people applying to or participating in the Fiava Creator Program, including the creator portal at creators.fiava.ai. It explains how we recruit and admit creators, manage collaborations, review performance, arrange compensation and respond to requests. If you also use Fiava's consumer product, the Fiava Privacy Policy covers that separate use. Tell us whether a request concerns your creator relationship, consumer account, particular content, or all of them.
The Creator Program is for people aged 18 or older. We ask for confirmation of eligibility. Stripe may separately require identity or business verification before enabling payouts. Program availability and payment eligibility depend on the countries and services currently supported; this notice does not promise worldwide payout coverage.
2. Information we collect and where it comes from
| Category | Examples and source |
|---|---|
| Application and contact | Your name, social profile links, WhatsApp number and contact permission, age-eligibility confirmation, application date and communications. You provide these, or an authorized Fiava administrator records information you supplied. We may review relevant information you intentionally publish on the social profiles and posts considered for the collaboration. |
| Sign-in and admission | Email, verified-email status, display name and account identifier returned by WorkOS; invitation, acceptance, partner status and access records created by Fiava. WorkOS handles sign-in credentials; Fiava does not receive your password. |
| Collaboration | Briefs, agreed terms, agreement versions, approved social accounts, content selections, deadlines, submitted publication links, corrections and communications. These come from you and Fiava's administrators. |
| Performance and review | Native analytics you submit, relevant geographic view totals, reporting periods, screenshots/files, review notes, verified counts and approval/dispute history. Public post information may help verify your submission. Please remove unrelated audience identities or sensitive information before submitting evidence. |
| Compensation and payout status | Approved amounts, currency, payment dates, payment references, corrections and disputes; Stripe connected-account identifiers, account country, readiness/restriction status, transfer identifiers and bank-payout status. We receive limited status and transaction information from Stripe. |
| Creator tools and media | Reference images you choose to upload, generation settings and derived prompts, selected or generated CTA media, technical file information, job status and the allowance used for a collaboration. These records arise when you use an available creator tool. |
| Support and security | Your messages and relevant attachments, request/response history, proportionate identity-verification facts, access events and safe diagnostic information. Our infrastructure also processes network/browser information needed to deliver and secure the service. |
Stripe collects bank, identity and any required verification information on its own hosted pages. The creator portal does not provide fields or ordinary upload slots for bank numbers or identity documents. Do not send those documents in analytics uploads, ordinary email or support chat. Fiava's payout records do not contain copies of Stripe's identity documents or full bank credentials.
Information necessary to authenticate you, establish an agreement, verify performance or arrange payment is needed for the corresponding feature. If it is missing, we may be unable to provide that part of the program. You can ask us to correct information or discuss another suitable contact method.
The portal uses essential sign-in and security cookies. A creator sign-in has a 30-day session limit and can end earlier through sign-out or revocation; that cookie limit does not delete your partnership or payment records. A saved language preference supports localized public pages. WorkOS and Stripe explain cookies on their own hosted pages under their respective notices.
3. Why we use the information
Where a legal basis is required, we use the following bases for the stated purposes. The basis depends on the actual activity; accepting a privacy notice is not blanket consent to every use.
| Purpose | Basis where applicable |
|---|---|
| Respond to your application, arrange an agreement, authenticate you, deliver creator tools and manage the collaboration | Steps you request before entering a contract, and performance of that contract. |
| Verify eligible performance, calculate and approve compensation, reconcile transfers and resolve payment questions | Performance of the collaboration agreement; applicable accounting/tax duties for the records those duties require. |
| Consider relevant public creator information and maintain a limited record of recruitment decisions | Legitimate interests in selecting suitable collaborators and answering questions about selection, subject to necessity, proportionality and your rights. |
| Send WhatsApp recruitment messages where you have agreed to that contact | Your consent where required. You may withdraw it at any time by replying or contacting us; withdrawal does not affect earlier lawful processing. Necessary agreement/payment communications can continue through an appropriate channel on a separate basis. |
| Protect accounts, prevent duplicate/fraudulent payments, investigate misuse and maintain a reliable service | Legitimate interests in security and accountable operations, and applicable legal duties. |
| Handle privacy requests, legal claims and official demands | Applicable legal obligations and legitimate interests in resolving claims and documenting our response. |
Fiava administrators review admission, performance evidence and earnings approvals. Software applies the agreed calculation and checks; Stripe performs its own payment-eligibility and verification processes. You may ask Fiava for a human review or explanation of a collaboration or compensation decision. A transfer into your Stripe balance and a payout to your bank are separate events.
We do not sell creator personal information or share it for cross-context behavioral advertising. We do not use creator analytics or private uploaded media to target advertising to you. Compensation is for the agreed creative work and performance, not a payment for selling your personal information.
4. Who receives information
Authorized Fiava staff see the information needed for their role. We use service providers for the following functions:
| Provider or recipient | Purpose and information |
|---|---|
| WorkOS | Hosted authentication and account recovery; identity and security/session information. |
| Cloudflare | Website/API delivery, network security and private media storage; requests, limited diagnostics and the files stored for your collaboration. |
| Neon | Database and backups; account, collaboration, review, generation and payment records. |
| Stripe | Connected-account onboarding, identity/bank verification and payment processing; information you enter with Stripe and the account/payment information needed to arrange and reconcile creator compensation. Stripe also processes some information for its own regulatory and security purposes under its Privacy Policy. |
| Postmark | Application/account email delivery where Fiava sends those messages; the recipient address, message content and delivery information needed for that message. |
| Google Cloud and Kie | When personalized CTA generation is available and you use it, Google prepares images and Kie's Grok service generates video using the applicable prompt, settings and reference/opening image. Other enabled video routes may use Google Vertex/Veo. Kie's attribution of a model to xAI does not mean Fiava sends a request directly to xAI. |
| Anthropic | Where the enabled creative-intake or safety step is used, the submitted creative text and processing instructions. |
| Social and communication platforms you use | TikTok/Instagram host the posts and analytics you provide. WhatsApp handles messages sent through that channel. These platforms operate their own services under their own terms. |
We may disclose a limited record to professional advisers, payment partners or authorities when needed for a transaction, legitimate claim or legal duty. If the business changes ownership, relevant records may transfer subject to the applicable privacy protections and required notice.
Using a provider does not make your creator dashboard public. Information you publish on a social platform is governed by your publication choices and that platform's rules. We do not promise that closing a Fiava account removes a post you published elsewhere.
5. AI processing, location and provider limits
Private reference media and generated CTAs are used to provide the requested creator tool. Fiava does not add your session credentials or payout details to creative requests, and does not use your private creator material to train its own models. Prompts and pictures may nevertheless identify you or someone else if you include that information.
Provider protections vary by product and agreement. We do not promise that all AI providers offer zero retention, no training under every setting, or immediate request-level deletion. Kie's public guidance describes generated-media retention of 14 days and text/metadata logs of two months; it does not establish the retention of every submitted or downstream copy. A temporary image link expiring does not erase a copy a provider already retrieved.
Fiava is based in the United States and its providers operate internationally. Your information may be processed outside your country. Google's global image endpoint is not a fixed-country guarantee; a separate regional video endpoint does not change that. Where a transfer requires safeguards, the applicable recipient and transfer arrangement must meet those requirements, which can include recognized adequacy decisions or contractual safeguards. Contact legal@fiava.ai for information about the arrangements relevant to your data.
6. Retention
The following periods describe our creator retention schedule. A verified rights request can require earlier deletion. A specific accounting duty or active claim can require a different period for the limited records it actually covers; we do not keep all creator data merely because one financial record must remain.
| Records | Retention policy |
|---|---|
| Applications that do not become partnerships | Up to six months after the final decision or withdrawal. For an inactive undecided application, the clock starts with the last substantive applicant interaction. A new unsolicited Fiava message does not restart it. |
| Active partner profile and operational contact | While needed for the partnership. After the relationship and necessary close-out communications end, remove unnecessary contact within 30 days. A required financial identity record is kept separately under the financial rule. |
| Nonfinancial submission/review detail | Up to 12 months after the relevant collaboration closes. Keep only the smaller subset needed to substantiate a continuing contractual or financial record for that record's period. |
| Accepted agreements and minimum compensation, tax, correction and dispute evidence | Seven years after the collaboration's final financial resolution, subject to a different specifically applicable duty or claim. This is Fiava's business retention period, not a statement that every country requires seven years. |
| Private insight, reference and CTA media | While the associated work remains available and the asset is undeleted. Approved deletion removes availability first; physical cleanup follows the existing 30-day grace. Private agreement copies follow the applicable agreement rule. |
| Detailed provider prompt | Only while submission, retry or authoritative recovery needs it; after the generation is terminal and its allowance is settled, the cleanup target is within 24 hours. Other creative-history fields remain with the associated work until approved deletion. |
| Temporary uploads | Promoted temporary copies: within 24 hours. Abandoned intents: expire after 24 hours, with object cleanup within the next 24 hours. Invalid/quarantined objects: at most 72 hours after the terminal decision. Minimized validation and terminal-intent records: 30 days. |
| Media-access and transactional email delivery records | 180 rolling days under their respective event/request clocks. |
| Support, legal and privacy-request cases | Normally three years after resolution, with a narrower or longer period where a specifically applicable duty or active claim requires it. |
| Prepared privacy export | Available for no more than seven days, with individual download links expiring sooner. A fresh verified request can produce a new export. |
Routine diagnostic logs follow the limits stated in the main Fiava Privacy Policy and the verified infrastructure configuration. Operational replay caches, financial replay-prevention records and accounting history are different data categories and are not all deleted on the same clock.
Stripe and other providers may retain information under their own applicable terms or legal duties after account closure. Fiava's deletion of local records does not itself delete those provider records. Encrypted backups may retain deleted information until ordinary rotation. A restored backup remains subject to the original deletion request before normal processing resumes. We explain known remaining retention when responding to your request.
7. Your requests and choices
Contact legal@fiava.ai to request access, correction, deletion, a portable copy, restriction, objection, withdrawal of consent or review of a denied request. You can write to our postal address as well. You do not need to create a new account or pay for the ordinary request process.
We offer the core request process to creators wherever they live, subject to applicable rights and lawful exceptions. Where applicable, you may object to uses based on legitimate interests and have the rights provided by the GDPR, UK GDPR or relevant U.S. state privacy law. You may complain to the privacy authority with jurisdiction over your case, including the authority where you live or work in the EEA or the UK Information Commissioner's Office.
We verify identity proportionately before disclosing or changing private data; an authorized representative may submit a request with suitable authority. We aim to respond within 30 calendar days and, where applicable, no later than one calendar month. A shorter applicable deadline controls. If an extension is permitted and needed, we explain it before the original deadline.
Requests are handled by a person; there is no self-service account-deletion button. A deletion request can close creator access without necessarily closing a separate consumer account. We identify the requested scope with you, remove or minimize the applicable local information, arrange controllable media/provider steps, and explain any part retained or refused. We do not erase settled payment history to disguise a debt, payment or correction, or recreate a closed payout relationship just because the same email signs in again.
Exercising a privacy right does not reduce compensation already earned. If a request removes information necessary for a future collaboration or verification, we explain the practical effect rather than treating the request as misconduct. You can stop WhatsApp recruitment contact without withdrawing an existing right to payment. Contacting Stripe directly through its Privacy Center may be appropriate for information Stripe holds in its own capacity; Fiava still handles the information for which it is responsible.
8. Security and changes
Fiava uses access controls, encrypted connections and private storage to protect creator information. Staff access is limited to authorized purposes. No system can guarantee absolute security; report a suspected issue to support@fiava.ai. Never share a sign-in link, Stripe onboarding link or dashboard session.
Material changes receive an updated version/effective date and the notice or choice required for the new processing. We do not change a previous agreement or approval record to pretend that you received a different notice.