Erza Studioerza AI

LEGAL

Privacy Policy

Last updated: 12 August 2026

This policy explains what personal data Erza AI collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. We have tried to write it in plain language rather than boilerplate.

1. Scope of this policy

This policy covers personal data we process when you visit our website, create an account, or use Erza AI (the “Service”). It applies alongside our Terms of Service.

It does not cover the practices of third-party sites or services you reach through links from ours, which have their own policies.

2. Who we are and how to reach us

Erza AI is the data controller for the personal data described here. We operate from Yudistiro St., Palgading, Sinduharjo, Ngaglik District, Sleman Regency, Special Region of Yogyakarta 55581, Indonesia.

For any privacy question, request, or complaint, write to hello@erza.ai with “Privacy” in the subject line, or call +62 851-1132-9511.

3. Data we collect

We collect only what we need to run the Service, and we group it as follows.

  • Account data: your name, email address, password hash, optional phone number, profile picture, language and appearance preferences, and two-factor authentication settings.
  • Content data: the prompts, documents, drafts, uploads, imported URLs, and generated output you create in the Service, plus the collections and templates you organise them into.
  • Usage data: features used, credits consumed, generation history, timestamps, and interaction logs we use to operate quotas and improve the product.
  • Technical data: IP address, browser and device type, operating system, referring page, session identifiers, and error diagnostics.
  • Billing data: your plan, transaction history, and invoice details. Card numbers are handled by our payment processor and never reach or get stored on our servers.
  • Communication data: messages you send to support, and your preferences for product and marketing email.
  • Authentication data from third-party sign-in: if you sign in with a provider such as Google, we receive the basic profile and email address that provider releases to us.

4. How we use your data

We use personal data for these purposes and no others.

  • Providing the Service: creating your account, generating and storing content, and syncing your workspace across devices.
  • Billing: processing subscriptions and credits, issuing invoices, and preventing payment fraud.
  • Security: authenticating you, detecting abuse or unauthorised access, and keeping audit and session records.
  • Support: answering your questions and diagnosing faults you report.
  • Improving the Service: understanding aggregate usage patterns, measuring performance, and prioritising what to build next.
  • Communication: sending service notices you cannot opt out of, such as security alerts and billing receipts, and product or marketing email you can opt out of at any time.
  • Legal compliance: meeting tax, accounting, and regulatory obligations, and responding to lawful requests.

6. How your content is processed by AI

When you use a generative feature, your prompt and the surrounding context are transmitted to the AI model provider serving that feature, processed to produce a response, and returned to you. The result is stored in your workspace.

We do not sell your content, and we do not use your content to train our own models. We select providers that contractually commit not to train their models on data submitted through their business APIs, but we cannot guarantee the internal practices of every provider — so please avoid submitting credentials, government identity numbers, health records, or other sensitive data you would not want leaving your organisation.

7. Who we share data with

We do not sell personal data. We share it only with the categories of processor below, each bound by a contract limiting them to our instructions.

  • AI model providers, to generate the output you request.
  • Cloud hosting and storage providers, to run the application and hold your data.
  • Payment processors, to take payments and manage subscriptions.
  • Email and notification providers, to deliver transactional and product email.
  • Analytics and error-monitoring providers, to measure performance and diagnose faults.
  • Professional advisers and authorities, where disclosure is legally required or needed to establish or defend a legal claim.
  • An acquirer, in the event of a merger, acquisition, or asset sale — in which case we will notify you before your data becomes subject to a different policy.

8. Cookies and similar technologies

We use strictly necessary cookies to keep you signed in, remember your language and theme, and protect against cross-site request forgery. These cannot be turned off without breaking the Service.

We also use analytics and preference cookies, which are optional and which we set only with your consent. You can change your choice at any time in your browser settings or through our cookie controls; blocking non-essential cookies does not affect your access to any feature.

9. How long we keep data

We keep personal data only as long as we need it for the purpose we collected it, then delete or anonymise it.

  • Account and content data: for as long as your account is open, and for 30 days after you delete it so that an accidental deletion can be reversed.
  • Backups: encrypted backups age out on a rolling 90-day cycle, after which deleted data is gone from them too.
  • Billing records: retained for 10 years, as Indonesian tax and accounting rules require.
  • Security and access logs: retained for 12 months.
  • Support conversations: retained for 24 months after the case is closed.

10. How we protect your data

We apply technical and organisational measures proportionate to the risk: encryption in transit with TLS and at rest, hashed passwords, optional two-factor authentication, role-based access control, session management with revocation, isolated environments, and regular dependency and infrastructure patching.

No system is perfectly secure. If a breach occurs that is likely to create a risk to your rights, we will notify you and the relevant authority within 72 hours of becoming aware of it, as UU PDP requires.

11. Your rights

You have the following rights over your personal data. Write to hello@erza.ai to exercise any of them; we will respond within 30 days and will not charge you unless a request is manifestly excessive.

  • Access: get a copy of the personal data we hold about you.
  • Rectification: correct data that is inaccurate or incomplete.
  • Erasure: have your data deleted, subject to records we must keep by law.
  • Restriction and objection: limit or object to processing based on legitimate interests.
  • Portability: receive your data in a structured, machine-readable format, or have it sent to another provider.
  • Withdraw consent: at any time, for anything based on consent.
  • Complain: to us first, and to Indonesia's personal data protection authority — or your local supervisory authority — if you remain unsatisfied.

12. International transfers

Our providers operate data centres outside Indonesia, so your data may be processed abroad. Where that happens we rely on the safeguards UU PDP and the GDPR recognise: an adequacy finding for the destination country, or contractual clauses that hold the recipient to an equivalent standard of protection.

You can ask us for details of the safeguards that apply to a specific transfer.

13. Children

Erza AI is not directed at children under 17, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact hello@erza.ai and we will delete the account and its data promptly.

15. Changes to this policy

We will update this policy when our practices or the law change. The date at the top of this page always shows the current version, and we keep it accurate rather than backdated.

Where a change materially affects how we handle your data, we will give at least 30 days notice by email or an in-product notice before it takes effect, and where the law requires it we will ask for your consent again.

16. Contact and complaints

We would rather hear from you than have you wonder.

Email: hello@erza.ai — Phone: +62 851-1132-9511 — Address: Yudistiro St., Palgading, Sinduharjo, Ngaglik District, Sleman Regency, Special Region of Yogyakarta 55581, Indonesia.