Privacy Policy

Version: 2.1 Effective date: August 31, 2026 Last updated: August 31, 2026

This Privacy Notice for OMAC (FZE) ("we," "us," or "our"), registered under Trade Licence No. 11651 issued by SRTI Free Zone Authority, with its registered office at Block B - Office B58-111, Sharjah Research Technology and Innovation Park, University City, Sharjah, United Arab Emirates, P.O. Box 66636, describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services").

Athina AD's initial primary market is the United States, but the Services may be accessed by eligible users in other countries. This Privacy Notice applies to users worldwide. Additional rights and obligations may apply depending on where you live and where we operate, including when you:

  • Visit our website at https://athinaad.com, or any website of ours that links to this Privacy Notice.
  • Use Athina AD. Athina AD is an accessibility SaaS platform. It produces audio description, written scene descriptions, transcripts, and narration audio for video that the customer supplies, so that the video can be understood by blind, low-vision, and other users who need it. Every output is derived from the customer's own source video; the Services do not create standalone media from a text prompt.
  • Engage with us in other related ways, including any marketing or events.

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have questions or concerns, please contact us at info@athinaad.com.

Summary Of Key Points

This summary provides key points from our Privacy Notice, but you can find more details in the full sections below.

What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.

Do we process any sensitive personal information? Some information may be considered "special" or "sensitive" in certain jurisdictions. We may process sensitive personal information when necessary with your consent or as otherwise permitted by applicable law.

Do we collect any information from third parties? We do not generally collect personal information from third parties. If you submit a YouTube link, we use YouTube API Services to retrieve public video metadata needed to validate and process the link. The YouTube-specific data and practices are described below.

How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.

In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties.

How do we keep your information safe? We have organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure.

What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.

Where is information processed? We are established in the United Arab Emirates, and our Services use infrastructure and providers in the United States and potentially other locations disclosed by our service providers. International transfers are described below.

How do you exercise your rights? The easiest way to exercise your rights is by visiting https://athinaad.com/#contact, emailing info@athinaad.com, or otherwise contacting us.

Table Of Contents

  1. What Information Do We Collect?
  2. How Do We Process Your Information?
  3. When And With Whom Do We Share Your Personal Information?
  4. Do We Use Cookies And Other Tracking Technologies?
  5. Do We Offer Artificial Intelligence-Based Products?
  6. How Long Do We Keep Your Information?
  7. How Do We Keep Your Information Safe?
  8. Do We Collect Information From Minors?
  9. What Are Your Privacy Rights?
  10. International Transfers And Regional Disclosures
  11. Controls For Do-Not-Track Features
  12. Do United States Residents Have Specific Privacy Rights?
  13. Do We Make Updates To This Notice?
  14. How Can You Contact Us About This Notice?
  15. How Can You Review, Update, Or Delete The Data We Collect From You?

1. What Information Do We Collect?

Personal Information You Disclose To Us

In short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, participate in activities on the Services, or otherwise contact us.

Account and registration information. When you create an account, we collect your first and last name, email address, age range, and referral source. The signup interface also requires you to make age, legal, privacy, acceptable-use, and upload-responsibility confirmations before it will submit a registration. The current Services do not collect a separate document-version and timestamp record for each confirmation. Firebase Authentication receives and handles your password and authentication credentials. We do not receive or store your password in plain text. We receive authentication tokens, user identifiers, verification status, session information, and authentication-event information needed to operate and secure your account.

User Materials and processing choices. When you use the Services, we process the uploaded video, audio, public video link, filename, metadata, prompts, feedback, and related information you submit (collectively, "User Materials"). We also process choices and instructions such as selected categories, a custom category, focus instructions or other free text, requested output type, timestamps, narration voice, and feature or model selections. We create and store outputs and related records such as transcripts, visual descriptions, narration text and audio, timing data, processing warnings, and, where available, merged or infused video files.

Job, feedback, and interaction information. We associate jobs with your account and may collect ratings, written feedback, support notes, filename or YouTube details, job identifiers, play or download events, output choices, and processing outcomes. This lets us deliver account history, investigate a specific result, respond to feedback, and understand whether features function correctly.

Contact form information. If you use a public or in-app contact form, we collect your email address, optional name and phone number, selected contact purpose, message, page from which the form was submitted, IP address, user agent, submission time, delivery status, and the internal recipients of the message. The message and related details are stored by us and may be delivered through Brevo to authorized Athina AD personnel.

Creator Plan waitlist information. If you ask to be notified about the Creator Plan, we collect your email address, optional name, IP address, user agent, and submission time so we can record your request and send the requested launch notification.

Required and optional information. The account-creation fields, email verification, age confirmation, and legal/acceptable-use confirmations presented as required are necessary to create and use an account. Contact forms require an email address, purpose, and usually a message; name and phone number are optional. The Creator Plan waitlist requires an email address; name is optional. If you do not provide a required field, we cannot complete the relevant registration, request, or service.

Sensitive information. A selected screen reader, accessibility request, or other accessibility-related information may reveal or suggest disability information and may be considered sensitive or special-category information in some jurisdictions. Uploaded media, public video links, prompts, support messages, or feedback may also contain health, disability, biometric, racial or ethnic, religious, sexual-orientation, political, or other sensitive information about you or another person. We process such information only as needed for the request you make, with explicit consent where required, or under another condition permitted by applicable law. We do not use sensitive information to infer characteristics for advertising or profiling.

Where explicit consent is required for an optional accessibility or disability-related field, we will request it at the point of collection and provide a way to withdraw it. Please do not submit sensitive information that is unnecessary for the requested service, and do not submit another person's sensitive information unless you have the legal authority and any required consent.

Payment and purchase data. Paid purchases are sold by OMAC (FZE) and processed on our behalf by our payment provider, which is identified at checkout. The provider collects payment-method details, billing country, tax information, transaction information, and information needed to process payments, subscriptions, cancellations, refunds, fraud checks, and receipts. Athina AD receives and retains the purchase and subscription records needed to provide paid access, including customer and transaction identifiers, purchased plan or minutes, payment and subscription status, billing period, cancellation and refund status, currency, amount, and relevant timestamps. We do not receive or store complete payment-card numbers. The provider processes information under its own privacy notice.

All personal information that you provide to us must be true, complete, and accurate, and you must notify us of material changes.

Information Automatically Collected

In short: Some information, such as your Internet Protocol (IP) address and browser and device characteristics, is collected automatically when you visit our Services.

We automatically collect certain information when you visit, use, or navigate the Services. This information may include your IP address; approximate country derived from IP address; selected or detected time zone; browser, operating system, device type and full user agent; language and referring URL; account or user identifier; authentication and session events; dates and times; feature, page, play and download interactions; rate-limit and abuse-prevention events; and processing status, failure reasons, warnings, and other technical information. This information is primarily needed to operate and secure the Services, deliver account history and support, prevent abuse, and produce internal operational reporting.

Like many businesses, we also collect information through cookies and similar technologies. The information we collect includes:

  • Job, log, and diagnostic data. For a processing job, we may record the account identifier and email; IP-derived country; browser, operating system, device and user agent; original filename; file size, duration, format, codec or other media properties; upload source; user selections and focus text; timestamps; processing stages and timings; model used; token and estimated cost information; output storage keys; transcript or dialogue character counts; status, errors, warnings, safety results, retries, and diagnostic journey information. Some records are copied into per-user history, feedback, system-event, authentication-event, or administrative records.

Athina AD uses YouTube API Services when you choose to submit a YouTube video link. By using this feature, you acknowledge that Athina AD uses YouTube API Services and that Google's handling of information is governed by the Google Privacy Policy.

For a submitted link, we may retrieve and process public YouTube API Data such as the video ID, title, channel name, publication date, duration, privacy and upload status, embedding availability, region restrictions, made-for-kids status, public-statistics availability, license or licensed-content status, and content-rating information. We also store the YouTube URL you submit and technical results or errors returned while validating it.

We use this information to verify that the link is supported and publicly available, enforce restrictions such as rejecting private, unlisted, made-for-kids, embedding-disabled, or region-blocked videos, process the video through our AI workflow, display relevant job information to you, troubleshoot failures, prevent abuse, and comply with law and platform requirements. We may share the submitted link and information derived from the processing request with Google services, including YouTube API Services and our disclosed Google AI and cloud providers, only as needed for these purposes. Authorized personnel may access this information for the limited support, security, legal, and diagnostic purposes described in this Notice.

Athina AD currently uses public, non-authorized YouTube data and does not ask for your YouTube login credentials, request access to your private YouTube account, or use OAuth authorization to act on your YouTube channel. Athina AD does not use this feature to upload, edit, delete, like, comment on, or otherwise modify content or data on YouTube.

Public availability on YouTube does not establish that you own or have permission to process a video. You remain responsible for having all rights and permissions required by our Terms of Use, YouTube's terms, and applicable law.

Our use of information received from Google APIs will comply with the applicable Google and YouTube API terms and policies. You can review the YouTube Terms of Service, YouTube API Services Terms of Service, and YouTube Developer Policies.

2. How Do We Process Your Information?

In short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

  • Create, authenticate, and secure accounts. This includes registration, required signup confirmations, email verification, signed-in sessions, password-reset support, access control, account history, and authentication/security events. At signup, we record the versions of the Terms of Use, Privacy Policy, and Refund and Cancellation Policy presented with the acceptance checkbox, together with the acceptance time, account identifier and email, acceptance surface, IP address, and user agent, to document the agreement and protect legal rights.
  • Process media and deliver requested outputs. This includes validating uploads and links; performing safety checks; sending required inputs to AI and cloud providers; generating transcripts, descriptions, narration, timing information, and video outputs; storing requested history; and issuing time-limited access links.
  • Operate, troubleshoot, and improve the Services. This includes monitoring processing stages, reproducing failures, reviewing limited diagnostic material, evaluating output quality, improving prompts and workflows, measuring reliability and performance, and maintaining operational dashboards. As described above, this does not include training or fine-tuning a model with customer content.
  • Protect users, providers, and the Services. This includes rate limiting, content and safety screening, fraud and abuse prevention, investigating suspicious activity, enforcing our Terms, and protecting accounts, infrastructure, rights, and property.
  • Provide support and respond to communications. This includes handling contact forms, complaints, suggestions, feedback, copyright requests, privacy requests, and other inquiries, and sending replies through our staff and email provider.
  • Administer requested programs and notifications. This includes Creator Plan launch notifications. We do not currently use these lists for unrelated third-party advertising.
  • Send administrative communications. This includes verification and password-reset messages, service and security notices, material policy changes, account information, and communications you specifically request. Where a message is optional marketing, we will provide any consent and unsubscribe mechanism required by law.
  • Comply with law and handle claims. This includes responding to lawful requests, maintaining legally required records, handling copyright or privacy claims, and establishing, exercising, or defending legal rights.

3. When And With Whom Do We Share Your Personal Information?

In short: We may share information in specific situations described in this section and/or with the following third parties.

Vendors, consultants, and other third-party service providers. We may disclose information to vendors, contractors, or agents that perform services for us and need the information for that work. Their processing is governed by the applicable service terms, data-processing commitments, confidentiality obligations, and other contractual protections available for the relevant service. We assess and document the appropriate contractual role and safeguards before relying on a provider for material personal-information processing; we do not mean to imply that every provider uses an identical contract or acts in the same legal role.

The third parties we may share personal information with include:

  • Google Cloud Run: hosts and executes backend application services and receives requests, account/session context, submitted inputs, and operational data needed to run the Services.
  • Google Cloud Storage: stores original source-video uploads for up to ninety (90) days, temporary provider-processing copies, generated outputs, history markers, job and system logs, feedback, and contact records. Original source-video uploads are not displayed in the customer dashboard or account history and are not made available to customers for viewing or download after submission.
  • Google Firestore: stores rate-limit and operational records, Creator Plan waitlist submissions, legal-document records, purchase and entitlement records, and certain account-related or service records.
  • Firebase Authentication: handles account creation, password and authentication operations, email-verification links, tokens, session security, and user-account functionality.
  • Google Gemini API and related Google AI services: receive submitted videos or public video links, prompts and processing instructions, and generate descriptions, transcripts, narration audio, timing information, and related outputs. The paid-service data treatment is described in Section 5.
  • Google Cloud Video Intelligence and Cloud Vision: receive source video or extracted frames and technical context needed to perform automated content and safety checks before or during processing.
  • Google Cloud Text-to-Speech: where enabled for a feature, receives narration text and voice or language selections to generate audio.
  • YouTube API Services: when you submit a YouTube link, we retrieve the public metadata described in YouTube API Services And Public Video Links to validate the link, enforce YouTube and product restrictions, and process your request. YouTube and Google may receive the link, API request information, IP address, and ordinary device or network information when their services are contacted. Google's processing is described in the Google Privacy Policy.
  • Our payment provider (identified at checkout): processes checkout, payment methods, billing location, tax calculation, fraud checks, subscriptions, cancellations, refunds, and receipts on behalf of OMAC (FZE), which remains the seller and merchant of record. Athina AD receives the transaction and entitlement information needed to provide and administer paid access.
  • Brevo / Sendinblue: receives recipient names and email addresses and the content needed to send verification, password-reset, support, contact-form, Creator Plan, and other requested or transactional messages. Public contact-form submissions may be sent through Brevo to designated Athina AD staff inboxes and may include the submitted contact details, message, purpose, time, and IP address.
  • Authorized Athina AD personnel: may receive or access account, support, feedback, job, diagnostic, safety, copyright, security, and privacy-request information on a need-to-know basis for the purposes described in this Notice.

We also may need to share your personal information in the following situations:

  • Legal process, safety, security, and enforcement. We may disclose information when we reasonably believe disclosure is necessary to comply with applicable law, a court order, subpoena, or other valid legal process; respond to a regulator or lawful request from a public authority; investigate or prevent fraud, abuse, infringement, or security incidents; protect the rights, property, or safety of users, providers, OMAC FZE, or another person; enforce our Terms; or establish, exercise, or defend legal claims. We limit disclosure to information we reasonably believe is necessary for the relevant purpose.
  • Business transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

4. Do We Use Cookies And Other Tracking Technologies?

In short: We use essential cookies and local storage to operate the Services. We do not currently use advertising pixels or targeted advertising technologies.

We currently use the following first-party cookies and browser storage:

TechnologyPurposeTypical duration
Signed, HttpOnly session cookieKeeps a verified user signed in and supports authenticated requests.Up to seven (7) days unless cleared, expired, or revoked earlier.
Staff-only admin-promotion cookieProvides short-lived elevated access to authorized internal administrative features.Up to one (1) hour.
Browser local storageSaves interface preferences such as theme and text size on the device.Until the user clears browser storage or the application removes the preference.

We also use server-side rate-limit, session, and security records that are not browser cookies but may be associated with an IP address, account, or authentication event.

We do not currently use advertising pixels, targeted advertising technologies, shopping cart reminder tracking, Google Analytics, or Sentry on the live Services. We currently rely on internal logs, operational dashboards, and service records to understand usage, failures, performance, and abuse prevention. If optional analytics or diagnostics providers are added later, we will update this Privacy Notice and provide consent controls where required by law.

Because we do not currently use targeted advertising technologies, we do not currently use cookies or tracking technologies for a "sale" or "sharing" of personal information as those terms are defined under applicable US state privacy laws.

If we publish a separate Cookie Notice or enable optional analytics or diagnostics providers later, that notice will explain how we use those technologies and how you can refuse or control them where required.

5. Do We Offer Artificial Intelligence-Based Products?

In short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.

As part of our Services, we offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies (collectively, "AI Products"). These tools are designed to enhance your experience and provide you with innovative solutions. The terms in this Privacy Notice govern your use of the AI Products within our Services.

Use Of AI Technologies

We provide the AI Products through third-party service providers ("AI Service Providers"), including Google AI services such as Gemini and related Google Cloud AI services. As outlined in this Privacy Notice, your input, output, and personal information will be shared with and processed by these AI Service Providers to enable your use of our AI Products for purposes outlined in When And With Whom Do We Share Your Personal Information?. You must not use the AI Products in any way that violates the terms or policies of any AI Service Provider.

Our AI Products

Our AI Products are designed for the following functions:

  • Video analysis.
  • Transcript and accessibility description generation.
  • Narration audio generation.
  • Accessible video rendering or merging, where available, by combining a user-provided video with generated narration.

How We Process Your Data Using AI

All personal information processed using our AI Products is handled in line with our Privacy Notice and our agreement with third parties. This helps safeguard your personal information throughout the process.

No Model Training And Limited Service Improvement

Athina AD does not currently operate its own foundation model and does not use User Materials, uploaded videos, submitted public links, prompts, or generated outputs to train or fine-tune an Athina AD machine-learning model or any other model.

We may use the minimum information reasonably necessary, including prompts, generated outputs, diagnostic copies, metadata, and error or performance logs, to provide support, investigate failed or inaccurate results, reproduce and correct errors, evaluate output quality, improve prompts and processing workflows, prevent abuse, and improve the reliability, accessibility, and safety of the Services. This is operational service improvement and prompt evaluation, not model training or fine-tuning.

Access to identifiable User Materials for these purposes is limited to authorized personnel who need access for the relevant task. Where reasonably practical, we use redacted, de-identified, synthetic, or dedicated test data instead of identifiable customer content. The retention periods and diagnostic exceptions described in this Notice continue to apply.

If we later intend to use customer content to train or fine-tune an Athina AD or third-party model for our benefit, we will update this Privacy Notice before beginning that processing and obtain consent or another valid legal basis where required. Previously collected customer content will not automatically be repurposed for model training merely because this Notice changes.

Athina AD uses the Gemini API through a Google Cloud project with active Cloud Billing. Under Google's terms for paid Gemini API services, Google states that it does not use prompts, associated files, or responses to improve Google's products and processes them under Google's applicable data-processing terms.

Google may log prompts and responses for a limited period for detecting and preventing violations, maintaining safety and security, and making required legal or regulatory disclosures. Google may also process account, billing, usage, operational, safety-filter, error, authentication, quality, performance, device, cookie or token, and IP-address information under its applicable controller terms and privacy policy. Provider-side processing and retention remain governed by Google's then-current contracts, terms, and documented service settings.

We do not claim that the Gemini API provides zero data retention unless the relevant Google service, feature, account, and configuration have been verified as eligible for zero data retention. If the project loses active billing or we materially change the Google service or data-sharing configuration, we will reassess and update this Notice before continuing to submit customer content under materially different data-use terms.

Human Review And Diagnostics

Athina AD uses automated systems to process videos, public video links, and generated outputs. In limited cases, authorized team members may review uploaded content, public video links, generated outputs, metadata, logs, and diagnostic copies when needed to provide support, investigate failed processing, replay or debug jobs, review safety or abuse issues, respond to DMCA or copyright claims, comply with legal obligations, protect the security of the Services, or enforce our legal terms.

Access is limited to authorized personnel who need it for those purposes.

Choices About AI Processing

AI processing is intrinsic to Athina AD's media-analysis and generation features. We do not currently offer a non-AI generation mode for those features. If you do not want User Materials processed by our disclosed AI providers, do not upload a video, submit a public video link, or start an AI generation request.

Contacting us does not convert an AI feature into a non-AI service or reverse processing that has already occurred. You may contact us to ask questions, withdraw an optional consent for future processing where consent applies, or request deletion subject to Section 15 and applicable retention exceptions.

6. How Long Do We Keep Your Information?

In short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law.

We apply the following periods or criteria. A longer period may apply where reasonably necessary to comply with law, preserve evidence, resolve a dispute, investigate abuse or a security incident, enforce our Terms, or protect legal rights. When an exception applies, we limit the retained information to what is reasonably necessary for that purpose.

InformationRetention period or criteria
Account, profile, authentication, age-range, and referral recordsRetained while the account is active. After a verified termination or deletion request is completed, active account data is deleted or deactivated, except for limited fraud-prevention, security, legal, and dispute records retained as necessary for those purposes.
Legal-acceptance recordsThe document versions, acceptance timestamp, account identifier and email, acceptance surface, IP address, and user agent recorded at signup are retained while the account is active and may be retained after account deletion for as long as reasonably necessary to establish the agreement, comply with law, resolve disputes, and protect legal rights. Access is restricted to those purposes.
Original source-video uploadsRetained by Athina AD for up to ninety (90) days after upload for processing, troubleshooting, service reliability, quality evaluation, safety, abuse prevention, and support, and then automatically deleted. Original uploads are not displayed in the customer dashboard or account history and are not available to customers for viewing or download after submission. If the account is deleted earlier, the active original upload is deleted as part of account deletion, subject to limited legal, security, fraud, dispute, and provider backup or soft-deletion exceptions.
Temporary provider-processing copiesTemporary copies submitted to a processing provider may expire earlier under that provider's rules. For example, a copy submitted through the Gemini Files API may be retained by that service for up to forty-eight (48) hours. Provider backup or soft-deleted copies may remain temporarily after deletion before permanent erasure through the provider's documented deletion cycle.
Generated transcripts, descriptions, narration audio, video outputs, assistant interactions, job records, and per-user historyRetained while the account remains active. When the user deletes the account, these customer-facing records are deleted, subject to limited records retained separately where necessary for security, fraud prevention, payment and tax obligations, disputes, copyright matters, legal compliance, or proof that a request was honored. Users should download outputs they need before requesting account deletion.
Public, non-authorized YouTube API DataRetained only as long as needed for the request and for no longer than thirty (30) calendar days unless refreshed from YouTube or longer retention is required by law. After that period, the submitted URL, copied metadata, and YouTube API fields are removed from retained logs, history, and related records. Relevant YouTube API Data is deleted as soon as possible and within seven (7) calendar days after a valid user deletion request.
Job, authentication, system, rate-limit, security, and diagnostic logsRetained for up to ninety (90) days for operations, security, abuse prevention, support, and debugging, unless a specific incident, legal claim, or investigation requires a limited record for longer.
Feedback and product-quality recordsRetained while reasonably needed to investigate the relevant job, respond to the user, improve prompts or workflows, and document the resulting action. Identifiable content is then deleted or de-identified unless needed for an active legal, safety, or dispute purpose.
Contact and support submissionsRetained until the request or complaint is resolved and for a reasonable follow-up period based on the nature of the communication, then deleted or archived with access restricted where needed for legal, security, complaint-history, or dispute purposes.
Creator Plan waitlistRetained until the requested launch notification is sent, the user withdraws the request, or the waitlist is discontinued, plus a limited period needed to document delivery or withdrawal.
Provider-side copiesRetained under the applicable provider contract, service configuration, and documented deletion cycle. Paid Gemini API logging is described in Section 5.

Deleting information stored by Athina AD does not delete or otherwise affect information or content stored by YouTube. To delete content or information from YouTube itself, you must use YouTube or another authorized service that supports that action.

Where immediate deletion from a provider backup or technically isolated system is not possible, we restrict further use and delete the information through the applicable deletion cycle. We periodically review whether retained identifiable information remains necessary under the criteria above.

7. How Do We Keep Your Information Safe?

In short: We aim to protect your personal information through a system of organizational and technical security measures.

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. Transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.

If we become aware of a personal-information incident, we will investigate and document it, take reasonable containment and remediation steps, assess the risk to affected individuals, and notify affected individuals, service providers, regulators, or other authorities when and within the time required by applicable law. You can report a suspected privacy or security incident to info@athinaad.com.

8. Do We Collect Information From Minors?

In short: We do not knowingly collect data from or market to children under 18 years of age.

We do not knowingly collect, solicit data from, or market to children under 18 years of age, nor do we knowingly sell such personal information. The Services are intended only for users who are at least 18 years old. If we learn that personal information from a user under 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data. If you become aware of any data we may have collected from a child under age 18, please contact us at info@athinaad.com.

The adult-only account rule is separate from whether a submitted video depicts or contains information about a minor. A user must not submit content involving a minor unless the user has all rights, notices, consents, permissions, and other legal authority required for Athina AD and its providers to process that content. We reject YouTube videos identified as made for kids. We may also reject or remove other child-related content where processing would violate law, safety requirements, provider policies, or our Terms.

9. What Are Your Privacy Rights?

In short: You may review, change, or terminate your account at any time, depending on your country, province, or state of residence.

If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time by contacting us using the contact details provided in How Can You Contact Us About This Notice?.

Withdrawing consent will not affect the lawfulness of processing before its withdrawal, nor will it affect processing conducted in reliance on lawful processing grounds other than consent where applicable law allows.

Account Information

The Services do not currently provide a comprehensive self-service account-erasure or data-export control. To review or correct account information, request an export, terminate an account, or request deletion, contact us through https://athinaad.com/#contact or email info@athinaad.com from the address associated with the account. We may need to verify your identity and clarify the scope of the request.

Once a verified termination or deletion request is approved, we will carry out the applicable manual deletion process across active account, output, history, log, feedback, and program records in accordance with Section 6 and applicable law. Some limited information may be retained for fraud prevention, security, active investigations, enforcement, disputes, copyright matters, or legal obligations. Deactivating Firebase Authentication alone does not constitute deletion of every Athina AD record.

Cookies And Similar Technologies

Most web browsers are set to accept cookies by default. You can usually choose to set your browser to remove cookies and reject cookies. If you choose to remove or reject cookies, this could affect certain features or services of our Services.

If you have questions or comments about your privacy rights, you may email us at info@athinaad.com.

10. International Transfers And Regional Disclosures

In short: Athina AD is established in the United Arab Emirates, initially focuses its marketing on the United States, and may be used by eligible users elsewhere. Your information may therefore be processed outside the country where you live.

International Transfers

We and our service providers may process personal information in the United Arab Emirates, the United States, and other countries in which our providers maintain facilities or personnel. These countries may have privacy laws that differ from those in your country.

Where applicable law requires a transfer mechanism or safeguard, we will use an appropriate legal mechanism, such as contractual data-protection commitments, standard contractual clauses, an adequacy mechanism, consent where legally valid, or another mechanism permitted by applicable law. You may contact us to request more information about the safeguards relevant to your information.

The location of a cloud server or service provider does not change the rights you may have under applicable law. We do not rely solely on your continued use of the Services as the legal basis for every international transfer.

United Arab Emirates

OMAC FZE is established in the United Arab Emirates and acts as the controller of the personal information described in this Privacy Notice, except where we process information solely on documented instructions from an organizational customer under a separate agreement.

Where the UAE Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data applies, you may have rights to obtain information about processing, access or transfer your information, correct or erase it, restrict or stop certain processing, object to certain automated processing, and submit a complaint to the competent authority. These rights are subject to the conditions and exceptions in applicable law.

Depending on the processing activity and applicable UAE law, we process information with consent where required; as necessary to perform or prepare to perform a contract or user request; to protect rights and interests, maintain information security, prevent abuse, and handle claims as permitted by law; and to comply with legal obligations and lawful requests. Accessibility or disability-related information is processed only under an applicable sensitive-data condition.

Our providers may process information outside the UAE. Where UAE law applies, we will use a cross-border transfer basis and safeguards permitted by that law. Nothing in this section limits a right or obligation imposed by a mandatory UAE or applicable free-zone privacy rule.

European Economic Area And United Kingdom

Athina AD does not currently direct its primary marketing to the European Economic Area ("EEA") or United Kingdom ("UK"), but eligible individuals there may be able to access the Services. If the EU GDPR or UK GDPR applies to a particular processing activity, we rely on one or more of the following legal bases:

  • Contract or steps requested before a contract: to create and administer your account, process the media or link you submit, generate and deliver outputs, maintain requested account history, and provide requested support.
  • Legitimate interests: to secure and operate the Services; maintain necessary job, authentication and system logs; troubleshoot failures; evaluate output quality; improve prompts and workflows; prevent abuse and fraud; respond to ordinary inquiries; understand service performance; and establish, exercise, or defend legal claims. We assess the purpose, necessity, and effect on your rights and do not rely on this basis where your interests or rights override ours.
  • Consent: for the Creator Plan notification, optional marketing where required, optional sensitive or accessibility information where explicit consent is required, and other processing for which we specifically request permission. You may withdraw consent for future processing. We do not make an optional sensitive field mandatory where we rely on freely given consent for that field.
  • Legal obligation: to comply with applicable law, lawful requests, tax or recordkeeping duties, and valid copyright or legal claims.

If we process accessibility or disability-related information that qualifies as special-category data under applicable law, we will rely on explicit consent or another condition permitted by law and will not use it for unrelated advertising or to infer characteristics. Please do not include unnecessary sensitive information in uploads, feedback, prompts, or support messages.

Subject to applicable law, EEA and UK individuals may have rights of access, correction, erasure, restriction, portability, objection, and withdrawal of consent, and may lodge a complaint with the data-protection authority where they live or work. Rights are not absolute and depend on the purpose and legal basis for processing.

Where required, transfers from the EEA or UK will use an adequacy decision, approved standard contractual clauses, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard. If applicable law requires us to appoint an EEA or UK representative or data protection officer, we will publish the relevant contact details before the requirement applies.

Other Countries

If you live outside the United States, UAE, EEA, or UK, you may have additional rights under the law where you live. You may submit a request using the contact details below. We will assess and respond to the request as required by applicable law.

Our current primary market does not prevent mandatory privacy or consumer protections from applying where the Services are legally offered or used. Before actively marketing, pricing, establishing operations, or entering significant customer contracts in a new country, we intend to review that country's applicable privacy, consumer, tax, and data-transfer requirements.

11. Controls For Do-Not-Track Features

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to ordinary DNT browser signals. This statement does not limit any obligation to recognize a legally required opt-out preference signal. Athina AD does not currently sell personal information or use it for cross-context behavioral advertising.

California law requires us to let you know how we respond to web browser DNT signals. Because there currently is not an industry or legal standard for recognizing or honoring DNT signals, we do not respond to them at this time.

12. Do United States Residents Have Specific Privacy Rights?

In short: Where a US state privacy law applies to OMAC FZE and to your information, you may have rights to request access to and details about the information we maintain, correct inaccuracies, obtain a copy, delete information, withdraw consent, appeal a decision, or exercise other rights provided by that law. Applicability may depend on your state and statutory business, revenue, processing-volume, or other thresholds.

Categories Of Personal Information We Collect

The table below shows the categories of personal information we have collected in the past twelve (12) months. The table includes illustrative examples of each category and does not reflect every piece of personal information we collect from you.

CategoryExamplesCollected
A. IdentifiersName, email address, Firebase or Athina AD user identifier, account identifier, online identifier, IP address, and optional phone number. We do not currently request a postal address through the account, contact, or waitlist forms.YES
B. Personal information as defined in the California Customer Records statuteName, email address, and optional phone number submitted through contact forms.YES
C. Protected classification characteristics under state or federal lawAge-range or age confirmation, and accessibility or disability-related information users choose to provide, such as screen reader preference or accessibility needsYES
D. Commercial informationPayment-provider transaction and customer identifiers, purchased plan or minutes, amount, currency, payment and subscription status, billing period, cancellation and refund status, tax-related information, purchase history, and relevant timestamps. Athina AD does not receive or store complete payment-card numbers.YES
E. Biometric informationWe do not use uploaded faces or voices to uniquely identify or authenticate a person and do not create faceprints or voiceprints.NO
F. Internet or other similar network activityIP address, browser, operating system, device and user-agent information, referring URLs, service interactions, authentication and session events, upload attempts, job stages, play/download events, status, errors, warnings, and diagnostic information.YES
G. Geolocation dataApproximate country derived from IP address and a selected or detected time zone. We do not currently collect precise GPS location.YES — approximate only
H. Audio, electronic, visual, thermal, olfactory, or similar informationUploaded videos and audio; extracted frames; generated narration; transcripts; descriptions; timing data; and related media, output, feedback, or diagnostic records.YES
I. Professional or employment-related informationBusiness contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with usNO
J. Education informationWe do not request student records or education information as a structured account field. Education information may nevertheless appear in a video, audio track, public link, prompt, feedback, support message, or other User Material submitted by a user.NOT REQUESTED AS A STRUCTURED FIELD; MAY BE PRESENT IN USER MATERIALS
K. Inferences drawn from collected personal informationInferences drawn from any of the collected personal information listed above to create a profile or summary about an individual's preferences and characteristicsNO
L. Sensitive personal informationAuthentication information handled by Firebase and optional accessibility information; and sensitive information users include in media, links, prompts, support messages, feedback, contact forms, or Open Lab submissions.YES

We only collect sensitive personal information, as defined by applicable privacy laws, for the purposes allowed by law or with your consent. Sensitive personal information may be used or disclosed to a service provider or contractor for additional specified purposes. You may have the right to limit the use or disclosure of your sensitive personal information. We do not collect or process sensitive personal information for the purpose of inferring characteristics about you.

We may also collect other personal information outside of these examples when you interact with us in person, online, or by phone or mail in the context of:

  • Receiving help through our customer support channels.
  • Providing ratings, feedback, suggestions, complaints.
  • Facilitation in the delivery of our Services and to respond to your inquiries.

We use these categories only for the purposes described in Sections 2 and 5. The category-specific periods and criteria are provided in How Long Do We Keep Your Information?, including the 90-day original-source-video rule and diagnostic and log limits, 30-day YouTube API Data limit, account-life output/history criteria, and form or program-specific criteria.

Sources Of Personal Information

We collect personal information from:

  • You: through account registration, uploads, public video links, choices, prompts, contact and support forms, feedback, waitlist requests, and privacy or legal requests.
  • Your browser or device: through requests, cookies, local storage, IP and user-agent headers, technical events, and interactions with the Services.
  • Our processing systems: through generated outputs, job and safety results, model and token information, errors, logs, history records, and administrative actions.
  • Service providers: such as Firebase authentication and verification results, Google/YouTube API responses, cloud processing results, and Brevo delivery status.
  • Public sources: limited public YouTube metadata when you submit a YouTube link.

How We Use And Share Personal Information

Learn more about how we use your personal information in How Do We Process Your Information?.

We disclose personal information to service providers under the applicable service terms, data-processing commitments, confidentiality obligations, and contractual protections described in When And With Whom Do We Share Your Personal Information?.

We may use the minimum information reasonably necessary for the operational improvement purposes described in Section 5, such as troubleshooting, output-quality evaluation, prompt and workflow improvement, reliability, accessibility, safety, and abuse prevention. We do not use User Materials or generated outputs to train or fine-tune a model and do not treat this limited operational use as a sale of personal information.

We have not sold personal information or shared personal information for cross-context behavioral advertising in the preceding twelve (12) months. We have disclosed the following categories of personal information to service providers for business or operational purposes in the preceding twelve (12) months:

  • Category A. Identifiers.
  • Category B. California customer-record information.
  • Category C. Protected classification or accessibility information that a user chooses to provide.
  • Category F. Internet or other electronic network activity information.
  • Category G. Approximate geolocation information.
  • Category H. Audio, electronic, visual, and similar information.
  • Category L. Sensitive personal information.

The categories of third parties to whom we disclosed personal information for a business or commercial purpose can be found under When And With Whom Do We Share Your Personal Information?.

Your Rights

You have rights under certain US state data protection laws. These rights are not absolute, and in certain cases we may decline your request as permitted by law. These rights include:

  • Right to know whether or not we are processing your personal data.
  • Right to access your personal data.
  • Right to correct inaccuracies in your personal data.
  • Right to request deletion of your personal data.
  • Right to obtain a copy of the personal data you previously shared with us.
  • Right to non-discrimination for exercising your rights.
  • Right to opt out of processing of your personal data if it is used for targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.

Depending upon the state where you live, you may also have the following rights:

  • Right to access the categories of personal data being processed.
  • Right to obtain a list of the categories of third parties to which we have disclosed personal data.
  • Right to obtain a list of specific third parties to which we have disclosed personal data.
  • Right to obtain a list of third parties to which we have sold personal data.
  • Right to review, understand, question, and depending on where you live, correct how personal data has been profiled.
  • Right to limit use and disclosure of sensitive personal data.
  • Right to opt out of the collection of sensitive data and personal data collected through the operation of a voice or facial recognition feature.

How To Exercise Your Rights

To exercise these rights, you can contact us by visiting https://athinaad.com/#contact, emailing info@athinaad.com, or referring to the contact details at the bottom of this document.

Under certain US state data protection laws, you can designate an authorized agent to make a request on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with applicable laws.

Request Verification

Upon receiving your request, we will need to verify your identity to determine that you are the same person about whom we have information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request.

If you submit the request through an authorized agent, we may need to collect additional information to verify your identity before processing your request, and the agent will need to provide written and signed permission from you to submit such request on your behalf.

Appeals

Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by emailing us at info@athinaad.com. We will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decision. If your appeal is denied, you may submit a complaint to your state attorney general.

California "Shine The Light" Law

California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits California residents to request and obtain from us, once a year and free of charge, information about categories of personal information, if any, we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing using the contact details provided below.

13. Do We Make Updates To This Notice?

In short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last updated" date at the top of this Privacy Notice. If we make a material change, we will provide notice appropriate to the change, such as a prominent in-service notice, an email to account holders, or a request to review and accept the revised notice before continuing to use an affected feature. If we begin accessing, collecting, or using YouTube API Data or other information for a materially new purpose not covered by the notice previously accepted, we will request re-acceptance or consent where required before that new use begins.

14. How Can You Contact Us About This Notice?

If you have questions or comments about this notice, you may email us at info@athinaad.com or contact us by post at:

OMAC (FZE) Sharjah Research Technology and Innovation Park University City, Sharjah, UAE P.O. Box 66636 Block B - Office B58-111 Trade Licence No. 11651 Licensed by SRTI Free Zone Authority Telephone: +971 50 596 7665 United Arab Emirates

15. How Can You Review, Update, Or Delete The Data We Collect From You?

Based on applicable law, you may have the right to request access to personal information, information about processing, correction, export or portability, restriction, objection, deletion, withdrawal of consent, or an appeal. These rights are not absolute and may depend on your location, the legal basis, verification, and lawful exceptions.

The Services do not currently provide a comprehensive self-service export or erasure control. To submit a request, including a request involving a submitted YouTube link, visit https://athinaad.com/#contact or email info@athinaad.com from the address associated with your account. Identify the relevant account and, where possible, the job, filename, submission, or YouTube URL. We may request additional information reasonably necessary to verify identity, authority, and scope.

We will acknowledge and respond within the period required by applicable law. A verified YouTube API Data deletion request is handled as soon as possible and within seven (7) calendar days, subject to a legal exception. Other verified requests are completed within the applicable statutory period or, where no specific period applies, within a reasonable time based on scope and technical complexity.

Our manual deletion procedure must search the active systems reasonably associated with the request, which may include Firebase Authentication and claims, Firestore collections, Cloud Storage uploads and diagnostic copies, generated results and history markers, job/authentication/system logs, feedback, contact records, waitlists. We may retain a limited record where necessary for security, fraud prevention, active investigations, disputes, copyright matters, legal obligations, or proof that a request was honored. Deleting data held by Athina AD does not delete content or information held by YouTube.