Privacy Policy
Last updated: August 23, 2026
This Privacy Policy explains how Kydnos Labs LLC ("Kydnos Labs", "we", "us", or "our") handles personal data when you visit this website or use our mobile applications. We build products around a simple idea: collect as little data as possible, and never sell it.
1. Data we collect on this website
This website is informational. We do not require accounts, and we do not use advertising trackers.
- Server logs. Our hosting provider records basic technical data such as IP address, browser type, and the pages you request. We use this data to keep the website secure and functioning, and we retain it only as long as needed for that purpose.
- Email. If you write to us, we receive your email address and the contents of your message. We use them only to respond to you.
2. Data in our applications
Each of our applications has its own privacy notice, shown on its App Store listing and inside the app. If an application's notice differs from this policy, that notice controls for data processed by the application. Across all of our applications we follow the same principles:
- we collect only the data an app needs to do its job;
- we keep data on your device whenever that is practical;
- we do not sell personal data, and we do not share it with data brokers;
- we ask for permissions (such as camera or health data) only when a feature requires them, and the app keeps working if you decline.
Some of our applications will offer optional AI features. Where such a feature processes sensitive data, such as photos you choose to upload, the application will explain what is processed, where, by which provider, and for how long, and will ask for your explicit consent before any processing begins. These features are always optional, and declining them never blocks the rest of the app.
3. Face photos and AI avatars (Motionly)
When you create an avatar in Motionly, or use a filter or creation that works from your own photo, you can upload photos of your face. Face photos are sensitive data, and we treat them that way.
What we collect. The face photos you choose to upload, and the personal avatar model created from them. Nothing is uploaded without your explicit consent, which we ask for in the app before your first upload.
What they are used for. Your photos are used for one purpose: producing the stylized images and videos you request. That covers training a personal avatar model from several photos, and using a single photo for a one-off filter or creation without training a model at all. Your photos and your model are never used to train shared or general AI systems, never used for advertising or marketing, and never sold.
Who processes them. Your photos are stored on our cloud infrastructure provider, and avatar training and generation run on our AI provider, fal.ai. Both are located in the United States and process your photos only on our behalf, under contractual data protection safeguards that include a commitment not to use your content to train their own models. Your photos are encrypted in transit and are transferred to the United States under the safeguards described in the international transfers section of this policy.
Retention and deletion schedule. Your uploaded photos are permanently deleted from our systems and our provider's systems within 7 days of upload, and you can delete them sooner from the app. We keep them for that short window rather than erasing them the moment a result is ready, so that you can regenerate a result without uploading your photo again. Your avatar model is kept so you can keep generating avatars. Because the model can reproduce your likeness, we treat it as your personal data: you can delete it at any time in the app's settings, and deleting your account deletes it automatically. In all cases, we destroy face photos and avatar models no later than three years after your last interaction with Motionly, or earlier where the law of your state requires it.
Your choices. Avatars are optional, and Motionly works without them. You can withdraw your consent at any time in the app's settings, which also deletes your photos and your model. The avatar feature is not available to users under 16.
4. Room photos and AI designs (Roomhaus)
Roomhaus redesigns a photo of a room, garden, or building exterior. The photo you choose is the only thing it uploads.
What we collect. The photo you pick for a design, the choices you make about it — the type of space, the style, an optional palette, and how far the redesign should go — and the image the AI returns. Nothing is uploaded without your explicit consent, which the app asks for before your first design and which you can decline without losing the rest of the app.
What it is used for. One purpose: producing the design you asked for. Your photos are never used to train any model, ours or anyone else's, and they are never shown to other users.
Who processes it. The redesign itself runs at fal.ai, our AI processing provider. It receives the photo and the instruction for the duration of the job and processes them on our behalf under contract, and may not use them for its own purposes.
Create with AI. Premium Create with AI sends the chat messages you submit and any photo you choose to OpenAI, which processes them on our behalf to provide design advice. These requests are not used to train OpenAI's models. We disable response storage; however, OpenAI may retain prompts, responses, and related safety data for up to 30 days for abuse monitoring.
How long we keep it. The photo you upload is deleted from our servers within 7 days. Deleting a design in the app deletes the photo and the result immediately. Designs you keep stay in your history until you delete them.
Spaces, not people. Roomhaus is for spaces. The app asks you to keep people and pets out of the frame, and we do not run face recognition of any kind on the photos you send.
5. How we use data
We use the data described above to operate and secure the website, respond to messages, provide and improve our applications, and meet our legal obligations. We do not use your personal data for third-party advertising.
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases: our legitimate interests in operating, securing, and improving the website and our applications; the performance of a contract when we provide an application or service you have requested; your consent where we ask for it, which you can withdraw at any time; and compliance with our legal obligations.
6. Sharing and service providers
We do not sell your personal data. We share it only in the ways described here.
Service providers. We work with a small set of providers that process data on our behalf, under contracts that limit how they may use it, to run our website and applications. For our mobile applications these fall into the following categories:
- cloud infrastructure and storage providers, which host the app backend, accounts, database, stored media, and push notifications;
- AI processing providers, which train and run the avatar models, and which redesign the photos of spaces you send to Roomhaus;
- subscription and payment providers, which manage in-app purchases and subscriptions;
- analytics and attribution providers, which help us understand how the app is used and how people discover it;
- crash and error reporting providers, which help us diagnose problems.
We do not send your photos, media, name, or other directly identifying information to our analytics, attribution, or crash reporting providers. Those providers receive only app events, numeric parameters, and anonymous identifiers.
Legal and safety. We disclose personal data to authorities when the law requires it, or to protect our rights, users, and services.
Corporate transactions. We may transfer personal data as part of a merger, acquisition, or sale of assets, in which case this policy will continue to apply until it is updated.
7. Data retention
We keep personal data only as long as necessary for the purposes described in this policy, and then delete or anonymize it. Correspondence is kept while we handle your request and for a reasonable period afterwards.
8. Deleting your account
You can delete your account and all of its data at any time, from Settings inside the app. No email or support request is needed.
When you do, we permanently delete the face photos you uploaded, your avatar models, the photos and videos you generated, and your account record and sign-in, together with the corresponding data held by our AI provider. We also ask our analytics provider and our subscription provider to delete the data they hold about you, and we do not report your deletion as complete until those requests have been accepted.
In Roomhaus, this removes the photos you uploaded, every design you generated from them, your remaining credits, and your anonymous sign-in. Your credit movements are kept with the owner stripped out, for the accounting reason below.
Some records necessarily remain:
- Purchases. Apple is the seller of every in-app purchase in our apps and keeps its own record of your transactions. We cannot delete those on your behalf; contact Apple about your purchase history.
- Anonymized financial and safety records. We keep a small record of coin and credit transactions and of any content reports, with your identifiers removed, because we are required to account for payments and to keep our safety systems honest. These records can no longer be linked back to you.
- A deletion marker. We keep a non-identifying marker so that a delayed payment event cannot recreate an account you deleted.
Deleting your data does not cancel a paid subscription. Subscriptions are managed by Apple and continue until you cancel them in your Apple account settings.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. This includes rights under the EU and UK General Data Protection Regulation and under state privacy laws in the United States such as the California Consumer Privacy Act. To exercise any of these rights, email us at privacy@kydnoslabs.com. We will not discriminate against you for exercising any of these rights. We use sensitive personal information, such as face photos uploaded for avatar features, only to provide the services you request, and we do not use or disclose it for purposes that would require a right to limit under California law. You also have the right to lodge a complaint with your local data protection authority.
10. Children
Our website and applications are not directed to children under 13, or under the higher minimum age required for consent to data processing in their country (up to 16 in some countries), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Security
We use technical and organizational measures appropriate to the risk, such as encryption in transit and access controls, to protect personal data. No system is perfectly secure, but minimizing what we collect is our first line of defense.
12. International transfers
Our service providers may process data in countries other than your own. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission's standard contractual clauses and, for transfers from the United Kingdom, the UK Addendum to those clauses.
13. Changes to this policy
We may update this policy from time to time. The date at the top of this page shows the latest revision, and material changes will be highlighted on this page.
14. Contact
For privacy questions or requests, write to privacy@kydnoslabs.com or to Kydnos Labs LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States.