Last updated 7 September 2026
Privacy Policy
What we collect, why we're allowed to, how long we keep it, and how to make us delete it.
Growthnix is the controller of the personal data described here. This policy covers the FireplaceUGC platform and this website. It is written to be read, not to be survived — if a section is unclear, that is a defect and we would like to hear about it.
1. What we collect, and why
| Data | Why we have it | Lawful basis |
|---|---|---|
| Name, work email, company | Creating and running your account | Performance of the contract |
| Billing details | Taking payment. Card numbers go directly to our payment processor — we never receive or store them | Performance of the contract |
| Uploads (product images, logos, scripts, brand assets) | Generating your creative | Performance of the contract |
| Generated creative and its metadata | Delivering output and letting you revisit it | Performance of the contract |
| Product usage — features used, generations run, errors | Keeping the service working and deciding what to build | Legitimate interests |
| Support correspondence | Answering you, and improving common answers | Legitimate interests |
| IP address, device and browser | Security, abuse prevention, fraud detection | Legitimate interests |
| Non-essential analytics | Understanding how the product is used | Consent — refuse it and everything still works |
We do not buy personal data from brokers, we do not build advertising profiles, and we do not sell or share personal data as those terms are defined under US state privacy laws.
2. We do not train on your data
Your uploads, your scripts, and your generated creative are not used to train generative models — ours or anyone else’s. Where a vendor’s standard terms would permit training on data passed to them, we contract out of it before routing anything to them. Every vendor that processes your data is named on the Sub-processors page.
We do use aggregate, non-identifying counts — how often a feature is used, how often a generation fails — to run and improve the service. Those cannot be traced back to you or your creative.
2a. Custom actors and cloning data
If you create a custom actor from a photo, a face scan, or footage and voice of a person, those recordings and the likeness data derived from them are used solely to build and operate that actor for your workspace. We never use a cloned likeness to create content for anyone else. Source recordings and derived likeness data are deleted within 60 days of the actor being deleted, the account being closed, or a verified request from the person depicted — whichever comes first. The consent rules for uploading a real person are on the Actor Likeness & Consent page.
3. How long we keep it
- Account data — while your account is open, then for a short period after closure for legal, billing and security purposes (currently no more than 90 days), then deleted.
- Uploads and generated creative — while your account is open, and for 30 days after cancellation so you can export them. You can delete any item sooner, and deletion removes it from live systems immediately.
- Backups — deleted material persists in encrypted backups until the backup cycle ages it out. We do not restore deleted items from backup to circumvent a deletion request.
- Billing records — kept as long as tax law requires, typically six to seven years, regardless of account closure.
- Security, abuse and diagnostic logs — rolling windows, no longer than 12 months.
4. Your rights
Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable format. Where we rely on consent, you can withdraw it at any time without affecting what we did before you withdrew.
Ask by writing to hello@fireplaceugc.com. We reply within 30 days. We will not charge you, and we will not treat you differently for asking — no degraded service, no price change.
If you are in the UK or EEA and think we have got this wrong, you can complain to your national data protection authority. We would prefer you told us first so we can fix it.
5. International transfers
Our vendors are largely US-based, so personal data is transferred out of the UK and EEA. Those transfers rely on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, with a transfer risk assessment on file. Each vendor’s location is listed on the Sub-processors page. If your organisation needs a signed Data Processing Agreement with us, ask at hello@fireplaceugc.com and we will provide one.
6. Security
Data is encrypted in transit and at rest. Access to production data is limited to staff who need it, requires multi-factor authentication, and is logged. We review access periodically and revoke it when someone changes role.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant regulator within 72 hours of becoming aware and tell affected users without undue delay — including what happened, what data was involved, and what we are doing about it.
7. Children
The service is for business users aged 18 and over. We do not knowingly collect data from children. If you believe a child has given us personal data, tell us and we will delete it.
8. Cookies
Covered in full, cookie by cookie, on the Cookie Policy page.
9. Changes
If we change this policy materially — new purposes, new categories of data, a new basis for processing — we will email account holders before the change takes effect rather than quietly restamping the date.
Questions about this document? Write to hello@fireplaceugc.com. If something here contradicts another page in this set, tell us — a conflict between our own policies is our problem to fix, not yours to interpret.