Privacy Policy
Effective Date: July 24, 2026
1. Who We Are
Futuristica d.o.o. ("we," "us," "our"), Ul. Frana Žižka 20, 2000 Maribor, Slovenia, operates the Renamer.ai website, applications, and AI file renaming service (the "Service").
For your account, billing, and website usage data, we act as the data controller. For the contents of files you submit for processing, we act as a data processor on your behalf. Questions about this policy: hi@renamer.ai.
2. Information We Collect
- Account data: email address, first and last name, and login credentials (passwords are stored hashed, never in plain text).
- Billing data: payments are handled by our payment provider Stripe; we retain invoicing records as required by law. We do not store full card numbers.
- Files you submit: the files you upload or process, including their names and contents, solely to provide the renaming service (see Section 3).
- Service metadata: your renaming history — which operations ran, their status, and credits used.
- Usage data: IP address, browser type and version, pages visited, timestamps, and diagnostic data.
- Cookies and similar technologies: see Section 11.
3. Your Files and How We Process Them
This is the heart of our Service, so we want to be precise:
- Web platform uploads are stored on our servers in the EU (AWS, Frankfurt) for a maximum of 24 hours, solely to provide you with the download link for your renamed files — nothing else — and are then automatically deleted.
- Files processed via the desktop application are not stored on our infrastructure; their contents are processed transiently.
- To generate file names, file contents are transmitted to a small number of specialised AI subprocessors engaged under commercial API terms.
- Your files and their contents are never used to train AI models — not by us, and not by our AI subprocessors, who are contractually bound not to use API inputs or outputs for training. AI subprocessors may retain inputs for up to 30 days solely for abuse monitoring, after which they are deleted.
- We do not sell, share, or use your file contents for any purpose other than providing the Service.
4. Purposes and Legal Bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the Service (processing files, managing your account and credits) | Performance of a contract |
| Billing and invoicing | Performance of a contract; legal obligation |
| Service communications (e.g. changes to the Service) | Performance of a contract |
| Security, fraud and abuse prevention; establishing or defending legal claims | Legitimate interests |
| Analytics and advertising | Legitimate interests |
| Improving and monitoring the Service | Legitimate interests |
5. Where Your Data Is Stored
Customer data is stored and processed on Amazon Web Services infrastructure in the eu-central-1 region (Frankfurt, Germany). Futuristica d.o.o. is established in Slovenia, in the European Union.
6. International Data Transfers
Some processing involves transfers outside the European Economic Area:
- AI processing: file contents submitted for renaming may be processed by our AI subprocessors in the United States. These transfers are safeguarded by Standard Contractual Clauses incorporated into each provider's data processing agreement; these providers additionally participate in the EU-U.S. Data Privacy Framework.
- Cloudflare: our security and content delivery provider operates a global network and may process connection data at locations worldwide, safeguarded by Standard Contractual Clauses.
Copies of the relevant safeguards are available on request.
7. Data Retention
| Data | Retained for |
|---|---|
| Files uploaded via the web platform | 24 hours |
| Files processed via the desktop application | Not stored |
| Service metadata (renaming history, credit usage) | Duration of your account |
| Application and access logs | 90 days |
| Account data | Duration of your account |
| Invoicing records | Statutory retention periods under applicable accounting law |
When you delete your account (or request erasure), your data is deleted within 30 days, with two exceptions: invoicing records retained as required by law, and a minimal record consisting of your email address and renaming/credit-usage entries (excluding all file names and file contents), retained for up to 5 years solely for fraud and abuse prevention and to establish, exercise, or defend legal claims. This record is stored separately and is never used for marketing or any other purpose.
8. Your Rights
Under the GDPR you have the right to access, rectify, and erase your personal data; to restrict or object to its processing; to data portability; and to withdraw consent at any time (without affecting prior processing). To exercise any of these rights, email hi@renamer.ai — we respond within one month.
You also have the right to lodge a complaint with a supervisory authority, in particular the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec, www.ip-rs.si) or the authority in your country of residence.
9. Subprocessors and Service Providers
We engage a limited number of subprocessors to provide the Service, in the following categories: cloud hosting (in the EU), security and content delivery, AI processing, payments, and analytics/advertising. Each subprocessor is bound by a data processing agreement imposing data protection obligations equivalent to ours.
The current subprocessor list is available upon request at hi@renamer.ai. Customers with a Data Processing Agreement are notified in advance of subprocessor changes.
10. Security of Data
We protect your data with, among other measures: encryption in transit (TLS 1.2+), encryption at rest (AES-256), access controls on a least-privilege basis with multi-factor authentication, and hosting on infrastructure certified to ISO 27001 and SOC 2. No method of transmission or storage is 100% secure, but we work to protect your personal data in line with industry practice.
11. Cookies, Analytics and Advertising
We use cookies and similar technologies:
- Essential cookies (session, preferences, security) — required for the Service to function.
- Analytics — Google Analytics and PostHog (EU-hosted) help us understand how the Service is used. Learn more about Google's practices: https://policies.google.com/technologies/partner-sites
- Advertising — Google Ads conversion tracking and remarketing, and the Meta (Facebook) pixel, help us measure and improve our marketing. Opt out of Google's ad cookies at https://adssettings.google.com
You can instruct your browser to refuse cookies, though parts of the Service may not function without essential cookies.
12. Disclosure for Legal Reasons
We may disclose personal data in the good-faith belief that it is necessary to comply with a legal obligation, protect our rights or property, prevent or investigate wrongdoing in connection with the Service, protect the safety of users or the public, or protect against legal liability.
13. Links to Other Sites
Our Service may contain links to sites we do not operate. We advise you to review the privacy policy of every site you visit; we have no control over, and assume no responsibility for, their content or practices.
14. Children's Privacy
Our Service is not directed at anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by email and/or a prominent notice on the Service before they take effect, and update the effective date above.
16. Contact
Futuristica d.o.o., Ul. Frana Žižka 20, 2000 Maribor, Slovenia · hi@renamer.ai