Skip to content
Stunora
Log inCreate account

Privacy Policy

Effective from 3 October 2026

This Policy explains which personal data europio s. r. o. processes when you visit stunora.com or use Stunora, why we process it, who receives it and what rights you have.

Contents
  1. Who is responsible for your data
  2. What we process today, why, and on what legal basis
  3. What will be added when image generation and paid plans open
  4. What we do not collect
  5. Who receives your data
  6. Where your data is processed
  7. How long we keep your data
  8. Your rights
  9. Whether you have to provide data
  10. Automated decisions
  11. Security
  12. Children
  13. Changes to this Policy
  14. Contact

Contents

  1. Who is responsible for your data
  2. What we process today, why, and on what legal basis
  3. What will be added when image generation and paid plans open
  4. What we do not collect
  5. Who receives your data
  6. Where your data is processed
  7. How long we keep your data
  8. Your rights
  9. Whether you have to provide data
  10. Automated decisions
  11. Security
  12. Children
  13. Changes to this Policy
  14. Contact

Key points

  • We collect very little: your email address, a password that we store only in protected form, and the technical records needed to keep you signed in and the site secure.
  • The website has no analytics, no advertising and no third-party scripts.
  • We do not sell personal data.
  • Your account data is stored in the European Union.
  • You can ask for a copy of your data, or for its deletion, at any time: contact@takury.com.

This summary is here to help you. It is not part of the document and does not replace it.

1. Who is responsible for your data

The controller of your personal data is europio s. r. o., with its registered office at K lesu 2218/39A, 040 18 Košice, Slovak Republic, company identification number (IČO) 57 442 452, registered in the Commercial Register of the Municipal Court Košice, Section Sro, Insert No. 64897/V.

For anything that concerns your personal data, write to contact@takury.com or call +421 907 178 695. The law does not require us to appoint a data protection officer, and we have not appointed one.

2. What we process today, why, and on what legal basis

The table shows the processing that takes place today. We receive this data from you and from your browser. GDPR means Regulation (EU) 2016/679.

Personal data we process today
PurposePersonal dataLegal basisKept for
Creating and running your accountEmail address. Password, stored only as a salted hash. Date the account was created. Your confirmation that you are at least 18. The version of the Terms of Service you accepted and the time you accepted it.Performance of the contract with you, Article 6(1)⁠(b) GDPR. For the record of your age confirmation and of your acceptance: our legitimate interest in being able to prove them, Article 6(1)⁠(f) GDPR.As long as the account exists. Deleted within 30 days after the account is closed.
Keeping you signed inA random session token, kept in a cookie in your browser. We store only a hash of it, with the time it was created and the time it expires.Performance of the contract, Article 6(1)⁠(b) GDPR.Up to 30 days, or until you log out.
Protecting sign-up and log-in against abuseA hash of your IP address and a hash of the email address used in a sign-in attempt, each with a counter of attempts.Our legitimate interest in keeping accounts secure, Article 6(1)⁠(f) GDPR.The counter runs for up to one hour. The record is deleted within 24 hours.
Delivering the website and defending it against attacksIP address, date and time of the request, the address requested, browser and device information, and the approximate location derived from the IP address.Our legitimate interest in running a secure and reliable website, Article 6(1)⁠(f) GDPR.Processed when the page is delivered. Our infrastructure provider keeps security and traffic records only for a short period under its own retention rules. We keep no access logs of our own.
Answering your messagesYour email address or telephone number and the content of your message.Performance of the contract where the message concerns it, Article 6(1)⁠(b) GDPR. Otherwise our legitimate interest in answering you, Article 6(1)⁠(f) GDPR.Until the matter is closed, and then for up to three years.
Establishing, exercising and defending legal claims, and complying with legal obligationsThe data above, to the extent needed in the individual case.Our legitimate interest in protecting our rights, Article 6(1)⁠(f) GDPR, or a legal obligation, Article 6(1)⁠(c) GDPR.For the limitation period that applies to the claim, or for the period the law prescribes.

3. What will be added when image generation and paid plans open

The following processing does not take place yet. We describe it so that you know what to expect, and we will update this Policy before any of it begins.

  • Your content. The reference images, prompts and settings you provide, the models trained from them and the images generated for you. We will process them to provide the service you ask for, to review each persona before training and to screen content for breaches of the Acceptable Use Policy. Reference images must not show real people, and we do not use any image to identify a person.
  • Payments. A payment provider will process your payment and billing details. We will not receive or store full card numbers.
  • New service providers. A provider of image-generation infrastructure and a payment provider will be added to the list of recipients in Section 5 before they receive any of your data.

4. What we do not collect

The website runs no analytics, no advertising and no third-party scripts, and it does not track you across other sites. We do not build profiles of you. We do not obtain personal data about you from anyone else, and we do not ask for special categories of personal data.

5. Who receives your data

Recipients of personal data
RecipientRoleWhat it does
Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USAProcessor acting on our instructionsHosts and delivers the website, protects it against attacks and stores the account database.
Providers of our email serviceRecipients acting on our behalfDeliver and store the messages you exchange with us.
Lawyers, accountants and other professional advisersIndependent recipients bound by confidentialityReceive data only where a specific matter requires it.
Courts and public authoritiesIndependent recipientsReceive data only where the law requires us to provide it, or where we report unlawful content.

If the service is transferred to a successor, your data may pass to that successor. We would tell you beforehand. We do not sell personal data and do not share it for advertising.

6. Where your data is processed

The account database is stored in the European Union.

Cloudflare is established in the United States and operates a worldwide network. When it delivers the website or protects it against attacks, it can process the technical data described above outside the European Economic Area, including in the United States. Such transfers rely on the safeguards provided for in Chapter V of the GDPR: the standard contractual clauses adopted by the European Commission, which form part of our agreement with Cloudflare, and, for as long as it remains in force, the adequacy decision for the EU–US Data Privacy Framework, under which Cloudflare is certified. You can ask us for a copy of these safeguards.

7. How long we keep your data

The periods are set out in the table in Section 2. When you close your account, we delete your account data from our live systems within 30 days. Backup copies are overwritten within a further 30 days.

We keep data longer only where we need it to establish, exercise or defend legal claims, or where the law obliges us to keep it. In that case we keep only what is necessary, and only for the period concerned.

8. Your rights

Under the GDPR you have the right to:

  • obtain confirmation of whether we process your data, and receive a copy of it (access);
  • have inaccurate data corrected (rectification);
  • have your data deleted (erasure);
  • have the processing of your data restricted;
  • receive the data you gave us in a commonly used, machine-readable format, or have it sent to another controller (portability); and
  • withdraw consent at any time where processing is based on consent. Today none of our processing is based on consent.

Right to object. Where we process your data on the basis of our legitimate interests, you can object at any time, on grounds relating to your particular situation. We will then stop, unless we have compelling legitimate grounds that override your interests, or we need the data to establish, exercise or defend legal claims.

To use your rights, write to contact@takury.com from the email address of your account. We reply within one month. If a request is complex, the law allows us to extend this by up to two further months, and we will tell you if we need to. Using your rights is free of charge.

You also have the right to lodge a complaint with a supervisory authority. Ours is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), dataprotection.gov.sk. You can also turn to the authority of the EU country where you live or work, or where you believe the infringement took place.

9. Whether you have to provide data

An email address, a password and the confirmation that you are at least 18 are needed to conclude the contract. Without them we cannot create an account for you. You are not obliged to give us any other data.

10. Automated decisions

We do not make decisions that produce legal effects for you, or similarly significant effects, by automated means alone, and we do not carry out profiling. Our security system can automatically slow down or temporarily block repeated sign-in attempts. The block lifts by itself, at the latest after one hour.

11. Security

All traffic between your browser and the website is encrypted. Passwords are stored only as salted hashes. Session tokens and the identifiers used for abuse protection are stored only as hashes. The website loads no third-party code and applies a strict browser security policy. Access to personal data is limited to the people who need it.

If a personal data breach is likely to result in a high risk to your rights and freedoms, we will inform you without undue delay, as the GDPR requires.

12. Children

Stunora is for adults only. We do not knowingly process the personal data of anyone under 18. If you believe that a minor has created an account, tell us and we will delete it.

13. Changes to this Policy

We update this Policy whenever our processing changes, and always before a new kind of processing begins. The date at the top shows when the current version took effect. If you have an account, we tell you about material changes by email before they take effect.

14. Contact

europio s. r. o., K lesu 2218/39A, 040 18 Košice, Slovak Republic. Email contact@takury.com, telephone +421 907 178 695.

All legal documents

  • Terms of Service
  • Acceptable Use Policy
  • Privacy Policy
  • Cookie Policy
  • Legal Notice

Stunora

Operated by europio s. r. o., K lesu 2218/39A, 040 18 Košice, Slovak Republic. Company ID (IČO) 57 442 452.

Registered in the Commercial Register of the Municipal Court Košice, Section Sro, Insert No. 64897/V.

Terms of ServiceAcceptable Use PolicyPrivacy PolicyCookie PolicyLegal Noticecontact@takury.com