Privacy & Security Policy
Last Updated: 25/09/2025
At AI Avatar BD App, we value your privacy and are committed to protecting your personal data in compliance with Bangladesh's Digital Security Act 2018 and applicable data protection standards.
1. Information We Collect
1.1 Account Information
- Personal Data: Name, email address, phone number, date of birth
- Account Data: Username, password (encrypted), account preferences
- Verification Data: Email and phone verification status
- Profile Data: Avatar preferences, usage history, settings
1.2 Usage Information
- App Usage: Features used, time spent, interaction patterns
- Content Data: Text inputs, images uploaded, AI-generated content
- Device Data: Device type, operating system, app version, IP address
- Performance Data: Error logs, crash reports, loading times
1.3 Payment Information
- Transaction Data: Purchase history, coin balance, payment methods
- Billing Data: Payment processor information (we do not store full payment details)
- Purchase Behavior: Spending patterns, feature usage after purchases
1.4 Communication Data
- Support Interactions: Customer service conversations, feedback, complaints
- Marketing Communications: Email preferences, promotional responses
- User Feedback: Ratings, reviews, suggestions, bug reports
1.5 Device Permissions and Media Access
- Camera Access: Video capture during video calls and avatar creation features
- Microphone Access: Audio recording during video calls and audio calls
- Media Processing: Real-time processing of audio and video data for call functionality
- Call Data: Audio and video content during active calls (not stored permanently)
- Media Quality: Technical parameters for optimizing call quality and performance
2. How We Use Your Information
2.1 Service Provision
- Creating and managing your account
- Processing in-app purchases and coin transactions
- Providing AI avatar and content generation services
- Facilitating video calls using camera access for real-time video communication
- Enabling audio calls using microphone access for voice communication
- Processing audio and video data in real-time for call quality optimization
- Personalizing your app experience
- Customer support and technical assistance
2.2 Service Improvement
- Analyzing usage patterns to improve features
- Training and improving AI models and algorithms
- Developing new features and services
- Optimizing app performance and user experience
- Conducting research and analytics
2.3 Communication
- Sending service-related notifications
- Providing customer support responses
- Sharing updates about new features or changes
- Marketing communications (with your consent)
- Security alerts and important notices
2.4 Legal and Safety
- Complying with legal obligations
- Protecting against fraud and abuse
- Enforcing our Terms and Conditions
- Ensuring content policy compliance
- Responding to legal requests
3. Information Sharing and Disclosure
3.1 Service Providers
We share your information with trusted third-party service providers who assist us in operating our app and providing services to you. By using our app, you explicitly consent to the sharing of your data with these providers:
- Payment Processors: For handling in-app purchases securely
- Cloud Services: For data storage and app infrastructure
- Analytics Providers: For app performance and usage analysis
- Customer Support Tools: For providing efficient customer service
- Security Services: For fraud prevention and security monitoring
- AI Service Providers: Third-party AI APIs including but not limited to OpenAI, Google AI, Anthropic, Microsoft Azure AI, Amazon AWS AI, and other AI service providers for content generation, image processing, text analysis, and AI avatar creation
- API Partners: External services that power various app features
Important Notice Regarding Third-Party AI Services:
- User content including text inputs, images, questions, and generated content may be transmitted to and processed by third-party AI service providers
- These third-party AI services may use your content to improve their models and services unless specifically prohibited by their terms
- We cannot guarantee the privacy practices of third-party AI providers beyond our contractual agreements with them
- By using our AI features, you acknowledge and consent to this data sharing with third-party AI services
- Third-party AI providers may have their own data retention and usage policies
- We implement reasonable safeguards but cannot control third-party processing practices
- No refunds will be provided for concerns related to third-party AI data processing
3.2 Legal Requirements
- Government Authorities: When required by Bangladesh law
- Law Enforcement: For legitimate legal investigations
- Court Orders: In response to valid legal proceedings
- Regulatory Compliance: As required by applicable regulations
3.3 Business Transfers
- In case of merger, acquisition, or sale of assets
- Data will be transferred with appropriate protections
- Users will be notified of any ownership changes
- Privacy commitments will be maintained by successors
3.4 What We Don't Share
- We do not sell personal data to third parties
- We do not share data for third-party marketing without consent
- We do not provide data to unauthorized parties
- We maintain strict controls on data access
4. Data Security and Protection
4.1 Technical Safeguards
- Encryption: Data encrypted in transit and at rest using industry standards
- Access Controls: Role-based access with multi-factor authentication
- Network Security: Firewalls, intrusion detection, and monitoring systems
- Regular Updates: Security patches and system updates applied promptly
- Secure Development: Security-focused coding practices and code reviews
4.2 Administrative Safeguards
- Staff Training: Regular security and privacy training for all employees
- Background Checks: Screening for personnel with data access
- Access Policies: Strict policies governing data access and handling
- Incident Response: Comprehensive procedures for security incidents
- Regular Audits: Internal and external security assessments
4.3 Physical Safeguards
- Secure Facilities: Data centers with physical security controls
- Environmental Controls: Climate and power management systems
- Access Restrictions: Limited physical access to server infrastructure
- Equipment Security: Secure disposal and destruction of hardware
- Backup Systems: Redundant systems for data protection and recovery
5. Your Privacy Rights and Choices
5.1 Access and Control
- Data Access: Request copies of your personal data
- Data Correction: Update or correct inaccurate information
- Account Settings: Control privacy and communication preferences
- Download Data: Export your account data and created content
5.2 Consent Management
- Marketing Opt-out: Unsubscribe from promotional communications
- Data Processing: Withdraw consent for optional data processing
- Cookie Controls: Manage cookie and tracking preferences
- Feature Controls: Disable optional data collection features
- Device Permissions: Control camera and microphone access through device settings
- Call Privacy: Video and audio calls require explicit permission for each session
5.3 Account Management
- Account Deletion: Request permanent deletion of your account
- Data Retention: Understand how long we keep your data
- Service Termination: Stop using services while retaining account
- Data Portability: Transfer your data to other services where possible
6. Data Retention and Deletion
6.1 Retention Periods
- Account Data: Retained while account is active plus 1 year
- Transaction Records: 7 years for tax and legal compliance
- Content Data: Retained while account is active or as needed for services
- Support Records: 3 years for customer service quality and training
- Security Logs: 2 years for security monitoring and incident response
6.2 Deletion Procedures
- Account Deletion: Permanent removal of account and associated data
- Content Removal: Deletion of user-generated content upon request
- Automated Deletion: Scheduled removal of expired data
- Secure Deletion: Cryptographic erasure and secure data destruction
- Verification: Confirmation of successful data deletion
7. Children's Privacy
7.1 Age Requirements
- Users must be at least 13 years old
- Users aged 13-17 require parental consent for account creation
- Enhanced privacy protections for users under 18
- Limited data collection for younger users
7.2 Parental Controls
- Parents can review their child's account information
- Parental consent required for data processing of minors
- Parents can request deletion of their child's data
- Special procedures for handling minor's personal information
8. International Data Transfers
8.1 Data Location
- Primary data storage within Bangladesh when possible
- Some services may require international data processing
- Appropriate safeguards for cross-border data transfers
- Compliance with Bangladesh data localization requirements
8.2 Transfer Protections
- Standard contractual clauses for international transfers
- Adequacy assessments of destination countries
- Additional security measures for sensitive data
- Regular monitoring of international data handling
9. Cookies and Tracking Technologies
9.1 Types of Cookies
- Essential Cookies: Required for app functionality
- Analytics Cookies: For understanding app usage and performance
- Preference Cookies: To remember your settings and preferences
- Marketing Cookies: For personalized content and advertisements (with consent)
9.2 Cookie Management
- Users can control cookie preferences through app settings
- Essential cookies cannot be disabled without affecting functionality
- Third-party cookies are subject to their respective privacy policies
- Regular review and cleanup of unnecessary cookies
10. Updates to This Privacy Policy
10.1 Change Notifications
- Material changes will be communicated through the app
- Email notifications for significant privacy policy updates
- 30-day notice period for changes affecting user rights
- Continued use constitutes acceptance of updated policy
10.2 Version Control
- Previous versions of the privacy policy are archived
- Change logs document specific modifications
- Users can review historical versions upon request
- Clear identification of current policy version
11. Contact Information for Privacy Matters
AI Avatar Bangladesh Ltd.
- Trade Licence: TRAD/DNCC/047970/2023
- Address: House No-6 (5th Floor), Road No - 2/B, Baridhara J Block, Dhaka 1212
- Phone: +880 1909-147875
- Email: info@aiavatar.com.bd
Privacy Officer:
- Email: info@aiavatar.com.bd
- Phone: +880 1909-147875
- Address: House No-6 (5th Floor), Road No - 2/B, Baridhara J Block, Dhaka 1212
Data Protection Inquiries:
- Email: info@aiavatar.com.bd
- Response Time: Within 7 business days
General Support:
- Email: info@aiavatar.com.bd
- Phone: +880 1909-147875
- In-App Support: Available through help section
This Privacy & Security Policy is effective as of the date last updated and supersedes all previous versions. Your continued use of the App constitutes acceptance of this policy.