likna← Back to home

Legal / Privacy Policy

Privacy Policy

Last updated: 16 August 2026

Likna is an AI avatar, image and video generation service operated by Bjole AB, a company registered in Sweden. This policy explains what personal data we process, why, the legal basis under the EU General Data Protection Regulation (GDPR), and the rights you have.

1. Who is responsible (controller)

The data controller is Bjole AB (org.nr 559526-2824), Kårstahöjden 109, 186 60 Vallentuna, Sweden. For any privacy matter, contact likna@bjole.dev. We have not appointed a Data Protection Officer because the GDPR Art. 37 thresholds are not met — we do not carry out large-scale processing of special-category data or systematic large-scale monitoring of individuals. Our lead supervisory authority is the Swedish Authority for Privacy Protection (IMY); if you are in another EU/EEA country you may also contact your local data protection authority.

2. What we collect

Account data

  • Email address — used to sign you in (a one-time code) and to send service messages. This is the only account identifier we require.
  • Your Stripe customer reference and subscription/plan status. We never see or store your card details — Stripe handles those directly.

Content you provide

  • Photos you upload to train an avatar (a private AI model of a likeness).
  • The consent confirmation you make before training an avatar from real photos (§5 of our Terms) — which of “this is me” / “I have permission” / “fictional subject” you selected, recorded together with a timestamp and your IP address at the time, and kept even if the avatar or account is later deleted, because its evidentiary value matters most exactly then.
  • Prompts you submit, and the images and videos generated from them.

Safety & abuse-prevention records

  • An automated safety-classification result for images you submit and images we generate, kept as a screening record.
  • A count of policy violations (“strikes”) against your account where content you submitted or generated was blocked, used to decide whether your account should be flagged or suspended.
  • If you or someone else contacts us to report abuse or a policy violation, we receive whatever you send us (a description, and, if provided, an example asset) and your contact details if you give them. We do not currently operate an automated intake form for this — reports reach us by email.

Technical data

  • Minimal server logs (IP address, timestamps) for security and abuse prevention.
  • An authentication session cookie (see §10 — this is the only cookie tied to you personally).
  • Anonymous, aggregate visit statistics via our self-hosted, cookieless analytics (Umami) — see §10.
  • Technical error reports sent to our error-monitoring tool (Sentry) when something breaks. We deliberately exclude prompts, image URLs, email addresses, filenames, and access tokens from what's sent, with an automated filter as a backstop.

We do not sell your personal data, and we do not use it for advertising or behavioural profiling.

3. Legal basis

  • Contract (Art. 6(1)(b)) — to create your account, train your avatar, and generate the content you request.
  • Legitimate interest(Art. 6(1)(f)) — to secure the service, prevent abuse and the misuse of someone else's likeness, and investigate reports.
  • Legal obligation (Art. 6(1)(c)) — to retain billing records where Swedish law requires it, and to report illegal content (in particular child sexual abuse material) to the relevant authorities.

4. AI processing

Generating an image or video means your prompt — and, for avatar training or an image-to-image edit, the relevant photo — is processed by an AI model to produce the output. Depending on the feature and how busy our own capacity is, that processing happens either on our own infrastructure or via a third-party AI provider; see §5 for who those providers are.

Some of our video rendering — MiniMax H3 as the standard tier's automatic fallback — runs on open-weight models we operate ourselves, on our own infrastructure in Sweden; no data leaves our systems for that specific rendering step. Other video and image rendering, including MiniMax H3 for our Boosted (premium) video tier, is submitted to fal.ai (United States) or RunPod (United States), third-party providers that receive the prompt and source image needed to render your request.

Before or after generation, images you submit or that we produce may also be sent to our LLM gateway (a service we operate ourselves, which in turn calls out to third-party model providers, currently including Google, via OpenRouter) for an automated check for prohibited content. We do not send your email address or account identifiers as part of that check.

5. Sub-processors

We use a small set of vetted processors to run Likna:

  • Supabase — database, authentication, and file storage. Data is stored within the EU.
  • fal.ai — third-party AI image and video generation, used for some renders (United States).
  • RunPod — third-party GPU rental, used to render standard-tier video (United States).
  • Stripe — payment processing and subscription management. Stripe receives your email address and payment details directly; we never see or store your card details.
  • Resend — delivery of sign-in codes and service emails. Receives your email address.
  • Sentry — error monitoring, so we can find and fix bugs. Receives technical crash data; prompts, image URLs, email addresses, filenames, and tokens are excluded before anything is sent.
  • OpenRouter and the model providers it routes to (currently including Google) — automated content-safety classification of prompts and images, via our own LLM gateway.

We do not use MiniMax (the company behind MiniMax H3) as a sub-processor. Depending on which tier renders your request, MiniMax H3 runs either on our own infrastructure (the standard tier's automatic fallback) or on fal.ai's infrastructure (our Boosted video tier, see the fal.ai row above) — either way, no user data is sent directly to MiniMax.

6. International transfers

Your account data, avatar training photos, and generated content are stored on Supabase infrastructure within the EU. Some processing happens outside the EU/EEA — in particular fal.ai, RunPod, Stripe, Resend, Sentry, and the model providers reached through OpenRouter are based in or process data in the United States. Where personal data is transferred outside the EU/EEA, we rely on the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, as applicable to each processor.

7. How long we keep it

  • Account data (your email, plan/subscription status): for as long as your account is active.
  • Avatar training photos, prompts, and generated content: while your account is active, or until you delete them.
  • Consent/likeness attestation records (§2, §5 of our Terms): kept permanently, independent of account or avatar deletion — see §2 above for why.
  • Screening records and strike counts: kept for as long as needed to enforce our Acceptable Use Policy and to demonstrate compliance if a decision is challenged.
  • Security logs: typically deleted within 90 days.
  • Billing records: retained as required by the Swedish Bookkeeping Act (Bokföringslagen), up to 7 years.

8. Security

  • All traffic is encrypted in transit via HTTPS/TLS.
  • Access to your data is governed by Row-Level Security (RLS) in our database — no other user can see your account's data.
  • Access to any reported or flagged content is restricted to what's needed to investigate it.
  • We do not knowingly collect special-category data (Art. 9) beyond what's inherent in processing a photograph of a person, which is handled under the consent and security measures described in this policy and our Terms.

9. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction, data portability, and to object to processing, as well as to withdraw consent where processing is based on it. To exercise any of these, email likna@bjole.dev. We respond within one month.

Deleting your account. You can delete your account at any time from Settings. Deletion removes your account data, avatar models, generated content, and uploaded photos, with two narrow exceptions required by law or by the nature of an evidentiary record: billing records are kept for the statutory retention period (§7), and a likeness-consent attestation (§2) survives account deletion by design, stripped of its link to your account, because its purpose is to remain provable even after the account it was about is gone.

Reports and enforcement records. If your account was the subject of an abuse report or a safety strike, we may retain the relevant records after account deletion where needed to investigate an ongoing matter or comply with a legal request.

10. Cookies

Summary: Likna sets no advertising or cross-site tracking cookies, and our analytics is cookieless. The only cookie tied to you is the one that keeps you signed in.

Authentication (strictly necessary)

When you sign in, our authentication provider (Supabase) sets a session cookie (named sb-<project-ref>-auth-token) that keeps you signed in between page loads. It's required for the service to work at all and can't be switched off without losing the ability to stay signed in. We never share it with a third party.

Analytics (cookieless)

We use Umami, a self-hosted analytics tool, to see aggregate traffic to our public pages. Umami sets no cookies, does not collect your IP address or any other personal identifier, and cannot be used to identify you.

No advertising or cross-site tracking

We don't run advertising pixels, and we don't set any cookie for cross-site tracking or ad targeting.

Because we only use a strictly-necessary authentication cookie and cookieless analytics, no cookie-consent banner is required under the ePrivacy rules. You can still block or delete cookies via your browser's settings, but blocking the authentication cookie will prevent you from signing in.

11. Data breaches

If we become aware of a personal-data breach that risks your rights and freedoms, we will notify IMY within 72 hours (Art. 33) and affected users without undue delay where the risk is high (Art. 34). Suspect an incident? Email likna@bjole.dev.

12. Changes & contact

We may update this policy; material changes are reflected by the “last updated” date above. Questions go to likna@bjole.dev. You also have the right to lodge a complaint with IMY (imy.se) or your local EU/EEA supervisory authority.

liknaYour avatar, unlimited.
likna.me
LegalTerms of Service
Privacy Policy
Bjole AB