Last updated: May 29, 2026
Privacy Policy
How audioguia.ai collects, uses, and protects your data.
In plain language
- ✓We only collect data strictly necessary to operate the service: name, email, venue details, and usage analytics.
- ✓Visitors to your audio guides are completely anonymous — we store no IPs, no device identifiers, nothing personal.
- ✓We never sell or rent your data to third parties.
- ✓Payments are processed by Stripe; audioguia.ai never sees or stores card data.
- ✓You can request access, correction, or deletion of your data at any time.
- ✓Data is hosted on U.S.-based infrastructure under certified providers.
1. Who We Are
audioguia.ai is an AI-powered audio guide platform for museums, churches, galleries, and cultural venues. The data controller is the operator of audioguia.ai. For privacy matters, contact us at privacidad@audioguia.ai.
This Policy applies to curators — registered users who create and manage audio guides. End visitors to audio guides are fully anonymous; see Section 5.
2. Data We Collect
2.1 Data you provide
- Account: full name, email address, password (stored encrypted).
- Venue: venue name, type, city, country.
- Content: narration scripts, stop titles, and tour names you enter.
2.2 Data generated automatically
- Usage analytics: pages visited within the curator portal, features used — processed by PostHog.
- System logs: technical errors and security events for diagnostics.
- Audit log: consent record (terms version accepted + timestamp).
2.3 Payment data
Payments are processed entirely by Stripe. audioguia.ai only receives payment confirmations and subscription IDs. We never access or store card numbers, CVV codes, or full banking details.
3. How We Use Your Data
- Service delivery: creating your account, processing payments, hosting your audio guides.
- Transactional communications: registration confirmation, subscription alerts, quota notifications — you cannot opt out of these.
- Product improvement: aggregated usage analytics.
- Marketing: newsletters and product updates — only with your explicit consent. Unsubscribe anytime.
- Legal compliance: retaining records required by law.
4. Legal Basis (GDPR)
For users in the European Union (Spain and others):
- Contract performance (Art. 6.1.b): data necessary to provide the contracted service.
- Legitimate interest (Art. 6.1.f): usage analytics to improve the platform; security and fraud prevention.
- Consent (Art. 6.1.a): marketing communications.
- Legal obligation (Art. 6.1.c): retention of billing records.
5. Visitor Data
End visitors who scan your QR codes are completely anonymous. We only store:
- Stop and tour identifier (not visitor identifier).
- Selected language code.
- Event type (play, pause, completion).
- UTC timestamp.
We do not storeIP addresses, device identifiers, browser fingerprints, or any personal visitor data. Language preferences are stored only in the visitor's browser localStorage and never sent to our servers.
Visitor player analytics are processed by Plausible Analytics, a cookie-free, GDPR-compliant tool by design.
6. Third-Party Processors
- Supabase, Inc. (USA) — database and authentication.
- Stripe, Inc. (USA) — payment processing.
- ElevenLabs, Inc. (USA) — AI voice synthesis (narration texts are sent to generate audio).
- Anthropic, PBC (USA) — AI script assistant.
- Cloudflare, Inc. (USA) — audio file storage (R2).
- PostHog, Inc. — curator portal analytics.
- Plausible Analytics — visitor player analytics (cookie-free).
- Loops, Inc. — transactional and marketing emails.
All processors have their own privacy policies and, where applicable, Standard Contractual Clauses for international data transfers from the EU.
7. Data Retention
- Active subscription: data retained while subscription is active.
- Trial (no conversion): deleted at day 75 from trial start.
- Cancelled subscription: deleted at day 60 from cancellation.
- Curator-deleted content: CDN cleared within 24 h; database within 7 days.
- Analytics events: retained 24 months, then aggregated and raw data deleted.
- Audit log: retained 36 months for legal compliance.
8. Your Rights
Under GDPR (EU users) and applicable privacy laws, you have the right to:
- Access: request a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data.
- Portability: receive your data in a structured format.
- Objection: object to processing based on legitimate interest.
- Restriction: request restriction of processing in certain circumstances.
To exercise any of these rights, email privacidad@audioguia.ai. We will respond within 30 days.
9. Security
We implement technical and organizational measures including TLS 1.3 encryption in transit, encryption at rest, least-privilege access controls, and access auditing. Passwords are stored as bcrypt hashes managed by Supabase Auth.
10. Changes
We may update this Policy periodically. Material changes will be notified by email at least 15 days in advance. The "last updated" date always reflects the current version.
11. Contact
Privacy inquiries: privacidad@audioguia.ai
For Mexican LFPDPPP rights, see our Aviso de Privacidad.