Privacy Policy

Effective Date: 1 June 2025

1 Who We Are

Second Enlightenment Limited (“SEL,” “we,” “us” or “our”) is a company registered in England and Wales (Company Number 16274940). We operate the AI-generation platform available at sunra.ai (the “Service”). SEL is the controller of the personal data described in this Privacy Policy, unless stated otherwise.

For any privacy-related questions, contact [email protected].

2 Scope of This Policy

This Policy explains how we collect, use, store, share and secure personal data when you:

It does not cover websites, apps or services that we do not own or control. We encourage you to review the privacy policies of any third-party services you use.

3 Personal Data We Collect

CategoryWhat We CollectSourceMandatory?
Account InformationEmail address, password hash, authentication tokens, preferences.YouYes – required to create an account.
Billing & PaymentPayment card details (handled by our payment processor), billing address (if provided), transaction history, credit balance.You / payment processorYes – required to purchase credits or subscriptions.
Service Usage DataGeneration requests (metadata such as prompt length, model selected, parameters, timestamps), API keys, IP address, browser/device type, log files, error reports.Your device / automatically collectedCollected automatically for service delivery.
CommunicationsMessages or emails you send us, feedback, support tickets.YouVoluntary.
Input DataText prompts, images, audio, video and other content you upload.YouNecessary to perform the requested generation.
Output DataAI-generated results delivered to you.Generated by our systemN/A

We designed the Service to minimise personal-data collection. We do not ask for your name, phone number or special-category data to operate your account.

4 How and Why We Use Personal Data

PurposeLegal Basis (UK GDPR)
Provide and maintain the Service (account creation, authentication, generation requests, credit administration).Performance of a contract (Art. 6 (1)(b)).
Process payments (charging your payment method, issuing invoices).Performance of a contract; legitimate interests (Art. 6 (1)(b) & (f)).
Operate, secure and improve the Service (monitor usage, prevent fraud, debug, optimise performance, develop new features).Legitimate interests (Art. 6 (1)(f)).
Communicate with you (respond to enquiries, send service emails, billing notices, changes to Terms).Performance of a contract; legitimate interests (Art. 6 (1)(b) & (f)).
Limited marketing (if you opt-in, inform you about new features or offers).Consent (Art. 6 (1)(a)); withdraw anytime.
Legal compliance (tax, accounting, lawful requests).Legal obligation (Art. 6 (1)(c)).

5 Do We Use Input Data for Training?

By default, no. We do not use the raw Input Data you upload (or the Output Data we deliver) to fine-tune or retrain our core models. Files are processed transiently and stored only as long as necessary to complete your request and allow you to download the result.

We may collect aggregate statistics (e.g., model latency, prompt-length distribution) to improve reliability and user experience. These statistics do not identify you or reveal prompt content.

If we ever introduce an opt-in programme for model improvement, we will request explicit consent and provide a way to withdraw consent at any time.

6 Cookies & Similar Technologies

We use:

You can control cookies in your browser, but disabling essential cookies may impair functionality.

7 How We Share Personal Data

We do not sell or rent your personal data. We share only as necessary:

RecipientPurposeSafeguards
Cloud hosting partnersHost servers, store logs, run compute for generation.Confidentiality and security obligations.
Payment processorsProcess card payments and detect fraud.PCI-DSS compliant; we never store full card numbers.
Analytics providersAggregate, anonymised usage metrics.Data minimised and pseudonymised.
Professional advisersLegal, accounting or auditing services.Bound by confidentiality duties.
AuthoritiesWhen required by law or to protect rights, property or safety.Disclosure limited to lawful, proportionate requests.
Corporate transactionsIn connection with a merger, acquisition or asset sale.Data handled consistent with this Policy.

8 International Data Transfers

Primary servers are in the United Kingdom and the European Economic Area. When personal data is transferred outside these regions, we rely on:

9 Data Retention

Data TypeRetention Period
Account dataFor as long as the account is active, then up to 12 months after deletion for security logs and audit.
Payment records7 years (statutory requirement).
Input & Output dataTypically deleted automatically within 30 days; you may delete sooner via your dashboard.
Service logsUp to 90 days for diagnostics, then anonymised or deleted.
Marketing consentsUntil you withdraw consent or unsubscribe.

Longer retention may occur if required to establish, exercise or defend legal claims.

10 Security

We implement technical and organisational measures to protect personal data, including:

No internet service is completely secure, but we work diligently to safeguard your data.

11 Your Rights

Under the UK GDPR (and, where applicable, the EU GDPR) you have the right to:

To exercise these rights, email [email protected]. We may verify your identity before responding. You can also complain to the UK Information Commissioner’s Office or another supervisory authority.

12 Children

The Service is intended for users 18 years and older. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us so we can delete it.

13 Changes to This Policy

We may update this Privacy Policy occasionally. If we make material changes, we will notify you (e.g., by email or on the site) before they take effect. The “Effective Date” shows when the current version became active.

14 Contact Us

For questions, concerns or requests about privacy or your personal data, email [email protected].

We aim to respond promptly and within legal timeframes.