AI360 Privacy and Personal Data Processing Policy

Version dated 28 August 2026

Russian original. This English text is a translation for convenience. If the texts differ, the Russian original prevails to the extent permitted by mandatory law.

This Policy covers AI360 mobile clients, the ai360.tnick.cc backend, web interfaces and the shared Billing system as used for an AI360 account. It is not consent by itself. Where consent is required, the User gives it through a separate affirmative action after access to the applicable text; AI360 records the text version, date, method and technical evidence.

1. Controller

The controller/operator is Nikita Andreevich Andrianov, taxpayer ID 773001849734, a Russian Professional Income Tax payer.

Privacy requests and legally significant electronic communications: thismailnotbad@gmail.com. Official page: tnick.cc.

2. Scope and roles

2.1. This Policy covers account registration, authentication, panorama processing, support, security, Billing and voluntary account linking with Filexa.

2.2. Apple, Google, Telegram, payment services and AI/API providers may independently process data under their own policies for operations they control. AI360 is responsible for its own processing and for processor instructions where applicable.

3. Data processed

3.1. Account and authentication: email and normalized email, password hash, registration and consent timestamps/version, account status, external Apple/Google identifier if that login is used, session and device-security records.

3.2. Photos and panoramas: uploaded source photos, capture/layout parameters, temporary intermediate materials and the generated panorama. Images may include other people or location details.

3.3. Technical data: IP address, user agent, installation ID, device/app/OS version, request and job IDs, model and mode, timestamps, safe error codes, security events and rate-limit data. Operation fingerprints may include keyed User/job/file IDs, SHA-256 and perceptual hashes, MIME type, byte size, image dimensions and preparation/delivery flags; the result bytes are not stored in that record. Ordinary logs exclude secrets and image bodies.

3.4. Billing and support: product/account ID, plan, balance and operation history, purchase channel, amount, currency, payment/transaction status and identifier, receipt reference, support message and evidence supplied by the User. AI360 does not receive a full card number, CVC/CVV or payment password.

3.5. Camera and photo-library permissions are controlled by the operating system. Local panorama history remains on the User’s device unless the User transmits it to the Service.

3.6. Notifications, complaints and deletion controls: APNs/FCM token, installation ID, locale, notification preferences and delivery state; complaint text and materials, review candidates, decision and a de-identified case record; keyed HMAC derivatives preventing repeat welcome bonuses; and a technical deletion outbox. Shared Billing may retain financial history and a minimal anti-abuse marker after product-profile deletion.

4. Purposes and legal bases

| Purpose | Main data | Basis |

| --- | --- | --- |

| create and secure an account | account, session and device-security data | perform the contract; consent where required; legitimate security interest |

| create and deliver a panorama | photos, parameters, job data | perform the contract; consent where required |

| manage plan, allowance, payment and refund | account and Billing records | perform the contract; legal and tax duties |

| prevent abuse and investigate incidents | technical and security data | legal duties; legitimate interest in service security |

| answer requests and establish legal claims | contact, request and relevant operation data | legal duties; contract; legitimate interest in protecting rights |

AI360 does not sell personal data, use it for cross-context behavioural advertising, or create an advertising profile from photo content.

5. AI processing and providers

5.1. The minimum photos and parameters required for a selected operation may be sent to CometAPI (Terms, Privacy), ProxyAPI (Terms, Privacy), and models supplied directly or downstream by OpenAI (Terms, Privacy) or Google Gemini (Generative AI Terms, Privacy information). The route depends on the function and availability; a named provider is not used in every operation.

5.2. No password, full payment credentials or complete account history is sent for a generation. Automatic masking may replace text-like personal details, but it cannot guarantee removal of every detail and is not a substitute for User minimisation.

5.3. Images are processed as graphical data for panorama generation, not to establish identity. AI360 does not perform biometric identification.

6. Other recipients

Each recipient receives only data reasonably needed for its function.

7. Shared Billing and linking

7.1. After voluntary two-sided confirmation, shared Billing processes technical AI360/Filexa identity IDs, product code, plan, wallets and operations. It automatically selects one active financial profile; linking does not transfer or add funds.

7.2. Accounts are not linked merely because names, emails or usernames match. Linking alone does not expose an AI360 password, photos or panoramas to Filexa.

7.3. Unlinking stops future access through the removed link but does not erase legally retained financial history or the minimal de-identified anti-abuse marker.

8. Retention and deletion

8.1. Account data is kept until deletion. After the purpose ends or consent is withdrawn, data lacking another legal basis is deleted within the period required by Article 21 of Russian Federal Law 152-FZ, normally no later than 30 days.

8.2. Source images, intermediate files and results are not intended for permanent database storage. They are processed transiently and deleted after technical completion or expiry of an incomplete transfer. An explicitly enabled diagnostic archive is isolated, time-limited and treated as sensitive.

8.3. Diagnostic aggregates are kept up to 30 days; completed operational records and ordinary technical logs up to 90 days; account-security audit up to 365 days; complaints, decisions and consent evidence up to 3 years after closure, relationship end or withdrawal; payment, tax and primary accounting records for at least 5 years and afterwards only while a separate lawful purpose remains, subject to annual necessity review; destruction acts and system-journal extracts for 3 years. A record isolated for an incident, claim or court matter remains restricted until that process and the applicable rights-protection period end. A minimal anti-abuse marker is reviewed at least every 3 years and deleted when no longer needed.

8.4. Backups rotate automatically within 30 days. Deleted data may remain isolated in a backup until scheduled replacement and is not used in ordinary operation. If a backup is restored for disaster recovery, deletion actions are reapplied.

9. Russian localisation and international transfers

9.1. When personal data of Russian citizens is collected, initial recording, systematisation, accumulation, storage, updating and retrieval take place in databases in the Russian Federation. AI360 uses Russian FirstVDS locations identified in the provider’s server-location certificate.

9.2. A later AI/API or platform transfer after initial Russian recording may be international. It does not replace localisation and remains separately subject to cross-border-transfer procedure, recipient assessment and data minimisation under Article 12 of Russian Federal Law 152-FZ as applicable on the transfer date. A transfer-dependent feature may be unavailable until this is done.

9.3. Where EEA/UK transfer rules apply, AI360 will rely on an applicable lawful transfer mechanism and supplementary safeguards where required. This clause does not claim that every provider route is approved for every country.

10. Security and incidents

AI360 uses proportionate access controls, HTTPS, password hashing, short-lived verification material, separated service keys, rate limiting, ownership checks, log minimisation and encrypted rotating backups. No security method is absolute.

An incident is recorded, contained and investigated. Authorities and affected individuals are notified where, when and within the periods required by applicable law.

11. Rights

The User may request information and access, correction, deletion, restriction or cessation of processing, object where applicable, withdraw consent without affecting earlier lawful processing, and complain to a competent authority or court. A request may be limited where retention is required by law or necessary to protect rights.

If the EU GDPR or UK GDPR applies, applicable rights may also include data portability, objection to legitimate-interest processing and a complaint to the competent EEA supervisory authority or the UK Information Commissioner. AI360 does not make solely automated decisions producing legal or similarly significant effects about the User.

If California privacy law applies, the User may request the categories and specific pieces collected, correction or deletion and may exercise applicable non-discrimination rights. AI360 does not sell or share personal information for cross-context behavioural advertising as those concepts are ordinarily used in California privacy law.

Requests are sent to thismailnotbad@gmail.com. AI360 may verify control of the account and will not ask for a password or full card details.

12. Account deletion

The User can request deletion through the Profile flow or email. Product data is deleted or anonymised except for narrowly retained financial, tax, security, anti-abuse and dispute records. Deleting AI360 does not delete a linked Filexa profile or cancel an external subscription.

13. Changes

The current Policy is available from the Service. Material changes are communicated through an available channel. A new affirmative action is requested if the changed processing requires a new consent.