Aristotto

Privacy Policy

Last updated: September 18, 2026

This Privacy Policy explains how Aristotto, Inc. (“Aristotto”, “we”, “us”) collects, uses, and shares information when you use aristotto.ai and related services (the “Service”).

Contact

Aristotto, Inc.
1401 21st ST, #14283
Sacramento, CA 95811
United States
Support: support@aristotto.ai
Privacy: info@aristotto.com

Information We Collect

  • Account information: email address, username (if set), and profile details you provide.
  • Content and metadata: prompts, settings/parameters, uploads, generated outputs, and any visibility choices (public/private/team) associated with your content.
  • Usage data: interactions with the Service (features used, pages viewed), diagnostic logs, and approximate device/network information (such as IP address and user agent). If your account receives a moderation action for violating our Terms (including a warning, suspension, or ban), we may retain associated IP addresses in our moderation records; where the account is suspended or banned, we may also use them to decline new account sign-ups that attempt to evade that action.
  • Cookies and similar technologies: used to keep you signed in, remember preferences, and understand usage patterns. If you arrive through an affiliate referral link, first-party referral cookies (_fprom_tid, _fprom_ref) are set for up to 30 days so the referring affiliate can be credited; they do not track your browsing on other websites and are not used to build advertising profiles.
  • Payments: payments are processed by Stripe. We receive limited information (such as subscription status and payment identifiers) but do not store your full card number.
  • Support and safety information: correspondence, reports, relevant content and account activity, moderation decisions, and appeals used to address requests, investigate abuse, and protect the Service.
  • Connected services and collaboration: account and connection identifiers, permissions and tokens, organization membership and roles, and files or content you choose to share, import, or export through enabled features.

We receive information directly from you, through your use of the Service, and from sources such as payment and sign-in providers, connected services you authorize, collaborators, and reports. Content submitted by you or another user may include images, voices, or personal or sensitive information about other people. Submit such information only when you have the necessary permission or other lawful authority.

How We Use Information

  • Provide, operate, and maintain the Service (including generating outputs you request).
  • Process transactions, manage subscriptions, and provide customer support.
  • Improve and develop the Service, including reliability, performance, and safety.
  • Prevent abuse, enforce our Terms, and comply with legal obligations.
  • Communicate with you about the Service (including important updates).
  • Operate our affiliate program: attributing account signups and purchases to the referring affiliate, calculating commissions, and preventing referral fraud.

Subscription Payments and Recovery

We use payment status and transaction identifiers received from our payment processor to manage subscriptions, payment recovery, and subscription credits.

For individual subscriptions, if a renewal payment fails, your subscription becomes past due. We may retry payment for a limited recovery period and restrict paid features while payment remains outstanding. New credits for the unpaid renewal period are issued only after payment succeeds. If payment remains unsuccessful after the recovery attempts, the subscription is canceled.

You may cancel an individual subscription during payment recovery. Cancellation while your renewal is overdue takes effect immediately and stops further automatic collection for that subscription. If your current billing period has already been paid, cancellation takes effect at the end of that paid period and access continues until then.

Model Training Preferences

Aristotto does not currently use customer prompts, uploads, or generated content to train models. This includes public content, private content, and team workspace content.

Processing your content to generate an output or perform a safety check is different from using it to train a model.

The training preferences in Settings → Privacy relate to a possible future program. When you change these settings, we store a preference version and timestamp. An existing default or timestamp does not by itself establish that you affirmatively agreed to join a training program.

Before introducing customer-content training, we will explain its purposes, eligible content, recipients, retention, and withdrawal controls, and ask for a new, specific opt-in before including your content. Publishing content or leaving a preference enabled does not by itself enroll you. Team workspace content remains excluded unless separately agreed with the organization.

You may withdraw an optional training consent for future use. Any future program will explain how withdrawal applies to data already processed and any applicable limitations, subject to your legal rights.

This describes Aristotto’s own training practices. Third-party AI providers process information to fulfill generation and safety requests; our training preferences do not determine those providers’ independent retention or data-use practices. See the Privacy Policy’s sharing information and contact us for details about the provider used for a feature.

How We Share Information

  • Service providers: vendors that help us operate the Service (hosting, storage, analytics, customer support, and email).
  • Payment processor: Stripe, to process payments and manage subscriptions.
  • Affiliate program: FirstPromoter, which administers our affiliate program. If you arrive through an affiliate referral link and create an account, we share your email address, account identifier, and the referral tracking identifiers so the referring affiliate can be credited on signups and purchases. FirstPromoter processes this data on our behalf and may not use it for its own purposes.
  • AI processing providers: we may send prompts and content to third-party AI providers (for example, Replicate and FAL) to generate outputs, and to providers that perform safety checks. The information needed depends on the feature and provider.
  • Legal and safety: if required by law, or to protect the rights, safety, and security of Aristotto, our users, or the public.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Policy.

Content Visibility and Safety Review

Content you publish may be viewed, copied, downloaded, or indexed by others. Making it private or removing it does not retrieve independent copies already received elsewhere. Private and team content is subject to the permissions of the relevant account, workspace, and sharing features.

Authorized personnel and providers may process relevant content, including private content, to deliver requested features, provide support, investigate reports, and meet legal obligations. Automated safety checks may block a request, withhold an output, or refer activity for review. If you believe an action is mistaken, use the appeal channel described in our Terms. Applicable rights concerning automated decisions remain available.

Legal Bases and International Processing

Where EU/EEA or UK data-protection law applies, the basis for processing depends on the purpose: contractual necessity for requested account, generation, and purchase functions; applicable legal obligations for required records and disclosures; legitimate interests, subject to the required balancing and safeguards, for reliability, safety, and support; and consent where required for optional uses. Special-category or other specially protected information requires an additional applicable legal condition. Information necessary for a requested feature is needed for that feature to work; optional consent is separate from accepting our Terms.

Aristotto is based in the United States. Providers and authorized personnel may process information in the United States and other countries, whose laws may differ from those where you live. Contact info@aristotto.com for information about relevant recipients, processing countries, and applicable transfer safeguards, or to request a copy of a safeguard where available. International processing remains subject to applicable data-protection requirements; using the Service is not a blanket waiver of those protections.

Connected Apps and AI Assistants

You can connect your account to an AI assistant or another app that supports the Model Context Protocol. A connection starts on our consent screen, which names the app and lists what it can do: see the model catalog and prices, generate images and videos with your credits, generate audio with your credits when that permission is shown, and view, list, and cancel your generations. The app receives access to your account only after you allow the connection.

  • What the app receives: the results of requests it makes on your behalf, including the catalog and prices, quotes and started jobs with their credit cost, and your generation jobs (their status, model and task, and links to their outputs), together with an account identifier that is not your email address. It never receives your password.
  • What we receive: requests the app sends on your behalf, including prompts and settings, and the app’s registration details (its name, logo, and redirect address). Generations started through an app run on your account, use your credits, and are covered by this Policy, including the current training information above, like generations you start directly on the Service.
  • The app operator: what the app does with results it receives, including what it stores or shows in its own product, is governed by its operator’s privacy policy.
  • Your controls: Settings → Connected apps lists every active connection and lets you disconnect it. Disconnecting ends the app’s access immediately. It does not delete information or outputs the app already received; contact its operator about those copies.

Data Retention

We retain information for as long as necessary to provide the Service and for legitimate business and legal purposes. If you delete content or close your account, we will take steps to delete or de-identify data as appropriate, subject to technical and legal constraints (including backups).

Retention depends on the type of information and its purpose: account and content records support your use of the Service; payment and credit records support accounting and disputes; support records support case handling; and relevant safety and security records support investigation, appeals, and proportionate prevention of repeat abuse. Hiding content or suspending an account is different from deleting the underlying information.

Deletion and access requests are subject to applicable exceptions, including valid preservation obligations. For material covered by the report-related preservation requirements of 18 U.S.C. §2258A, the statutory preservation period is one year after a qualifying CyberTipline submission, with the required protection of preserved material. Additional lawful preservation obligations may apply. This is not a general one-year retention rule for all customer content.

For connected apps: an access token is valid for one hour, and a refresh token for 30 days, renewed each time the app uses it. A daily cleanup deletes sign-in codes and price quotes once a day has passed since they expired, so within two days of expiry, and deletes a self-registered app that never completed a connection once 30 days have passed since it registered. A replaced refresh token is kept for about 30 days so that any reuse of it can be detected.

The record of a connection, including when you disconnected it, is kept while your account exists.

Your Choices

  • Update your profile and privacy settings in your account settings.
  • Review the current training information and preferences in Settings → Privacy.
  • Review and disconnect connected apps in Settings → Connected apps.
  • Opt out of marketing emails using the unsubscribe link (where available). Necessary account, billing, and safety messages may continue.
  • Use available cookie preferences and browser controls to manage cookies. The applicable choices depend on the technology, its purpose, and the law that applies.

You can contact info@aristotto.com about personal information, including if your account is suspended or closed or you do not have an account. We may request proportionate information to verify your identity or a representative’s authority. Please do not send passwords, full payment-card numbers, or unnecessary identity documents. An account restriction does not remove applicable privacy rights.

California and Other US Privacy Rights

If you are a California resident, you may have rights to request access to, deletion of, or correction of certain personal information, subject to exceptions. To exercise these rights, contact us at info@aristotto.com.

Depending on your state and whether its law applies, you may also have rights to a portable copy, to opt out of specified uses such as sale, sharing, targeted advertising or certain profiling, to limit certain uses of sensitive information, or to appeal a denied request. We do not unlawfully discriminate against people for exercising applicable privacy rights. These rights and their conditions vary by jurisdiction.

EU/EEA and UK Privacy Rights

Where applicable data-protection law covers our processing, you may request access, correction, erasure, restriction, or portability, subject to the relevant conditions and exceptions. You may object to processing based on legitimate interests and to direct marketing, and withdraw consent without affecting the lawfulness of earlier consent-based processing. You may complain to your competent data-protection authority. Requests are handled within applicable legal time limits, with any permitted extension explained.

To raise a UK data-protection complaint, contact info@aristotto.com and describe your concern. Where the UK complaint requirements apply, we acknowledge receipt within 30 days, investigate appropriately without undue delay, keep you informed, and communicate the outcome. You may also contact the Information Commissioner’s Office. This complaint process is separate from data-rights requests, which have their own legal deadlines.

Australian Privacy Rights

Where the Australian Privacy Act applies, you may request access to or correction of your personal information and complain about its handling. Contact info@aristotto.com with enough information to identify the concern. We will review the complaint and communicate the outcome and applicable escalation options, including the Office of the Australian Information Commissioner.

Children

The Service is not intended for anyone under 18.

If you believe a minor is using an account or that we have mishandled a child’s information, contact info@aristotto.com. We will review the concern and take the steps required by applicable law. To report prohibited content involving minors, identify its location; do not send suspected child sexual abuse material as an attachment.

Changes

We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last updated” date. We will provide additional notice or obtain consent when required. A policy update does not itself authorize an incompatible new use of previously collected information.