Skip to content

YOUR AI STAND-IN FOR SOCIAL

Privacy policy.

What we collect, who processes it and what you can ask us to do about it.

Understudy is operated by [COMPANY LEGAL NAME], [REGISTERED ADDRESS] ("Understudy", "we"). You can reach us about anything on this page at contact@understudy.my.

This policy covers the Understudy app at understudy.my. It is written to describe what the service actually does today. Where a policy, a marketing claim and our records disagree, ask us and we will correct the record.

What we collect

  • Account details. Your email address, which we use to send a sign-in code. We do not ask for or store a password.
  • Brand details you save. Business name, website, description and chosen colours.
  • Reference images you upload. Photos you add to your library, such as a logo, product photo or owner portrait, including any faces in them.
  • Content you give us. The brief you type for each creation, any customer review text you paste, and the generation settings you choose.
  • Content we create for you. The generated Reels and images, and the prompt we expanded from your brief.
  • Billing records. Your plan, credit balance, Stripe customer and subscription identifiers, invoices and payment status. Card numbers are handled by Stripe and never reach us.
  • Service records. Sign-in sessions, error diagnostics and provider request identifiers needed to investigate failures or duplicate charges. Routine logs deliberately exclude prompts, uploads and media links.

We do not use your content to train models, and we do not sell personal data.

Why we use it

  • To sign you in and keep you signed in.
  • To create the content you ask for, including passing your prompt and attached references to the generation provider.
  • To take payment, award credits and keep your balance correct, including refunding credits when a creation fails.
  • To store your results privately and give you time-limited links to view and download them.
  • To answer support requests and investigate faults, abuse and duplicate charges.
  • To meet accounting, tax and legal obligations.

We rely on performing our contract with you for the first four purposes, on our legitimate interest in keeping the service working and safe for support and diagnostics, and on legal obligation for accounting records.

Who processes your data

We use the providers below. Each receives only what it needs for its part of the service.

Supabase

Account authentication, database records and private file storage.

Location: Ireland or the region configured for our project

Stripe

Payments, subscriptions, invoices and receipts. Card details are entered with Stripe; we never receive them.

Location: Global

Higgsfield

AI generation. Receives your prompt, the reference images you attach to a creation and the output settings.

Location: Global

DeepSeek, or OpenAI if configured

Rewrites your brief into a detailed generation prompt. Receives the brief, your saved brand details and any review text you paste.

Location: Global

Resend

Sign-in codes and other account email.

Location: United States

Netlify

Website hosting and server logs.

Location: Global

Some of these providers process data outside your country. Where that happens we rely on the safeguards those providers offer, such as standard contractual clauses. Ask us if you need the current detail.

How long we keep it

  • Sign-in codes are short-lived and expire on their own.
  • Reference images and brand details are kept until you remove them or delete your account.
  • Generated content is kept in private storage so you can return to it. Removing content from your library currently hides it from your account but does not delete the stored file. Tell us if you need a file erased and we will do it.
  • Provider retention. The generation provider makes output available for at least seven days, after which it may remove it. We copy your result into our own storage so your download survives that.
  • Billing records are kept for as long as tax and accounting rules require, even after you close your account.
  • Analytics is not enabled today. See the cookie policy for what will change when it is.

Security

Your files sit in private storage that is not publicly readable. The app hands you time-limited links, and access is restricted to your own account so that one customer cannot reach another's uploads, generations or billing details. Our own administration uses server-side credentials that are never exposed to the browser.

No service can promise perfect security. If you believe your account has been accessed by someone else, tell us straight away at contact@understudy.my.

Your choices and requests

Email contact@understudy.my from your account address to:

  • ask what we hold about you, or ask for a copy;
  • correct anything that is wrong;
  • delete specific uploads or generated files;
  • delete your account and its data.

For account deletion, cancel any active subscription first. We delete your account, brand details, uploads and generated files, and keep only the billing records we are required to retain, plus anything needed to prevent fraud or abuse. We will confirm when it is done.

Depending on where you live you may have further rights, including objecting to processing or complaining to a data protection authority. We will help where we can, and we will not treat a privacy request as a reason to withdraw the service.

Children

Understudy is a business tool and is not intended for children. We do not knowingly collect data from anyone under 18. If you believe a child has used the service, contact us and we will remove the account.

Changes to this policy

When we change this policy we will update the date at the top. If the change is significant, such as adding analytics or a new provider, we will tell account holders by email before it takes effect.

Related pages

Terms of service, Cookies and Refunds.