Legal
Privacy policy
Last updated: 9 August 2026 · Pursuant to GDPR (EU) 2016/679
1. Who is responsible
Florin-Elis Buju, Bauernstraße 6, 2514 Traiskirchen, Austria, is the controller for everything described here — for this website and for the Interious app. For access, rectification, erasure, or any other request under the GDPR, write to office@interious.at. There is no form to fill in. An informal email is enough, and a person answers it.
2. This website
The page you are reading informs you about Interious and processes very little itself. Our host keeps short-lived server logs (IP address, timestamp, requested page) to keep the site up and to stop abuse; the legal basis is Art. 6(1)(f) GDPR, and they are deleted after 14 days at the latest. One strictly necessary cookie stores your language choice (German/English); it needs no consent (§ 165(3) TKG 2021). Fonts are self-hosted.
Google Analytics. To measure how this website is used, we use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA). Google Analytics sets cookies and processes your truncated IP address, the pages you visit, how long you stay and technical device data, so we can see how the site is used. Data may be transferred to Google LLC servers in the United States; Google LLC is certified under the EU-US Data Privacy Framework. Google Analytics runs only if you consent via the cookie banner (Art. 6(1)(a) GDPR, § 165(3) TKG 2021); without consent it is not loaded at all. You can withdraw your consent at any time in the cookie settings, with effect for the future. Analytics data is deleted after 14 months at the latest.
3. The app: what we process, and why
Your room photo, room size and budget. Uploaded without an account, and with your agreement to the US transfer (section 4): the upload form asks for it, and without it no room is created and no photo is kept. The photo is re-encoded the moment it arrives, which removes the metadata your camera attached to it, meaning location, device and timestamp. It is stored in a private bucket in Frankfurt that is not reachable from the public internet. Legal basis: Art. 6(1)(b) GDPR, because it is the service you asked for. The agreement to send it onward is recorded against the room, with the exact wording you agreed to and the date.
Your account. When you render for the first time you sign in with a code we email you. From then we keep your email address, the moment you verified it, a copy of the transfer agreement your room carries (section 4) with any withdrawal of it, and a render ledger: one dated row per successful render, so your 3 free renders, and any credits you bought after them, can be counted down. The ledger records that you rendered, never what. There is no name, no profile, no advertising identifier, and no record of what you looked at.
The beta waitlist. If you ask to hear when custom design, the door that measures your room from a video, opens, we store your email address and the moment you asked, and nothing else. That moment is the record of your agreement. Legal basis: Art. 6(1)(a) GDPR, your consent, given by typing the address into a field whose one stated purpose sits beside it; § 174 TKG 2021 covers sending the message. We will write to you exactly once, when the beta opens. There is no newsletter, nothing else is sent, and the address is not joined to anything else we hold. A waitlist entry is not an account, and signing up does not create one.
Server logs. Our host keeps short-lived request logs (IP address, time, requested path) to keep the service up and to stop abuse. Legal basis: Art. 6(1)(f), our legitimate interest in operating a working, un-abused service.
Crash reports. When something fails, on our server or in your browser, we record the error, the technical trace of where it happened, the page you were on, and, if you are signed in, your internal account number. Not your email address, not your photo, and no link to it. A crash in your browser also carries a masked replay of the moments before it (section 7). Legal basis: Art. 6(1)(f), our legitimate interest in a service that works, and in hearing about it when it doesn't rather than waiting to be told.
4. Your room photo goes to the United States
Two things are done with your room photo by an AI model operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA: the visualization of a concept in your own room is produced from it, and the room is read (its colours, its materials, how bright it is, and which pieces of furniture it already has) to match products to it, so what we suggest suits the room you actually have.
The reading is done from the photo alone. The picture needs more, so with your re-encoded room photo we send a floor plan of the room, which we draw from the room size you gave us and which shows where each product is to stand, the product images, and one line of text per product. The room size is written into the instructions as well, so the picture keeps the proportions of the room you measured. Your budget is not sent: it decides which pieces of our own catalogue you are offered, and that happens here. We do not send your email address, your account identifier, or anything else that names you.
The model we use is a preview model, and preview models do not come with the usual EU safeguards. There are no standard contractual clauses under Art. 46 GDPR covering this transfer and no processor guarantees of the kind that cover our other providers. US authorities can, under US law, demand access to data held there, and enforcing your rights against a US company is harder than against an Austrian one. Google may handle preview traffic differently from its generally available services.
Because of that, the transfer runs on your explicit consent under Art. 49(1)(a) GDPR. We ask for it on the upload form, before your photo is sent anywhere at all, on a box you have to tick yourself, covering both of the things above. It is asked once per room, because it is the room's photo that gets sent, and we record the exact wording you agreed to alongside it. If the wording ever changes, we ask again rather than treating an old agreement as covering something new.
If you do not agree, we cannot take your room any further. Nothing is sent, nothing is stored, and no room is created. There is also no concept, no plan and no shopping list, because all of them start from the photo. We would rather say that plainly here than let you find it out at the end.
You can withdraw at any time, from your account page in one tap, or by emailing office@interious.at. After that we send nothing further about the rooms you already have. Withdrawal does not undo renders already made (Art. 7(3)); deleting your account does, and takes the photos with it. A new room asks the question again, and a fresh agreement stands on its own.
Every render is labelled as an AI visualization in the app, and the images carry Google's invisible SynthID watermark.
5. Who else touches your data
These companies touch your data in the running of the service. All of them except the payment provider process it on our behalf under Art. 28 GDPR, on our instructions only, and never for their own purposes. The payment provider is different, and it is named here as what it is: it sells the credit packs in its own name as merchant of record, so for the sale it decides for itself, under its own privacy notice, rather than acting on ours.
- Supabase, Inc. (USA): Database, private file storage and the sign-in service. The project runs in the EU region eu-central-1 (Frankfurt, Germany); room photos and renders are stored there and nowhere else. Standard data protection agreement including EU standard contractual clauses.
- Vercel, Inc. (USA): Hosting for the app, and the page-view analytics that comes with it: first-party, cookieless, and counting visits rather than visitors. Server functions are pinned to the fra1 region (Frankfurt, Germany). Vercel keeps short-lived request logs for operational security. Standard data protection agreement including EU standard contractual clauses.
- Resend, Inc. (USA): Delivers the emails this service sends: the sign-in emails that carry your 6-digit code, and the single message to the beta waitlist when custom design opens. Receives your email address and nothing else.
- Functional Software, Inc. d/b/a Sentry (USA): Error tracking. When something in the app fails, Sentry receives the error, its stack trace, the page it happened on and, if you were signed in, your internal account number, which is a random identifier and not your email address. Reports are stored in Sentry's EU region (Frankfurt, Germany). Standard data protection agreement including EU standard contractual clauses.
- Paddle.com Market Ltd (United Kingdom): Sells the render credit packs. Paddle is the merchant of record: it is the seller, it takes the payment, it issues the invoice, and it handles the VAT, which is why your card statement shows PADDLE.NET. Its checkout is loaded only where packs are on sale, and only then does Paddle see your IP address; if you buy, it receives the email address you buy under, your country and your payment details. We never see your card. Because Paddle sells in its own name it decides these things as a controller in its own right, under its own privacy notice, rather than on our instructions. What comes back to us is the address you bought under, Paddle's own customer and transaction identifiers, and how many renders the pack granted.
- Google: receives your room photo for reading and rendering only with your explicit consent (section 4), and runs the audience measurement on this website (section 2, Google Analytics, consent only).
We do not sell data, and we pass nothing to advertisers. A link to a retailer may carry an affiliate identifier that tells them the visit came from Interious. It identifies us, not you, and nothing about you travels with it. What you then do on the retailer's site is covered by their privacy policy, not this one.
6. How long we keep things
Room photos and renders: 12 months of inactivity. They are kept while you are using the service, and deleted after 12 months in which you have neither uploaded a room nor made a render. Because we keep no record of your visits, simply signing in or reopening an old render does not count. If you want to keep a photo, make something with it. A photo uploaded without ever signing in is deleted 12 months after upload. This runs automatically, every night.
Account data (email, verification date, your copy of the transfer agreement and any withdrawal of it, and the render ledger) is kept while your account exists. Each room's own consent record is part of that room, so it is deleted whenever the room is, either by the purge above or by deleting your account.
What a credit pack leaves behind (that a pack was bought under your address, Paddle.com Market Ltd's own customer and transaction identifiers, how many renders it granted and when) is kept while your account exists too. It is not on the twelve-month clock above: it is what your balance is counted from, so deleting it would delete the credits with it. A pack bought under an address that never signs in has no account to delete, so that record simply stays until someone asks us to erase it. Email office@interious.at and we will. Paddle keeps its own seller records of the sale under its own duties; what is described here is our copy.
The beta waitlist: until we write to you, and no longer. Your address is kept until we send the one email it exists for, and deleted once that email has gone. You do not have to do anything to be forgotten, and the message itself will say so, naming the day you signed up and telling you the address has already been removed. If you would rather it went sooner, write to office@interious.at and it goes the same day.
You can delete your account at any time from your account page. That erases your photos, your renders, your ledger, the record of any credit pack bought under your address and our copy of that address at Paddle.com Market Ltd, and the address itself, including at the sign-in provider, immediately and without asking why. Any unspent credits are lost with it and are not refunded, which is why the page that asks you to confirm says how many they are; if you want a refund instead, ask Paddle before you delete. If you would rather we did the deletion, email office@interious.at.
This website: server logs are deleted after 14 days at the latest, Google Analytics data after 14 months at the latest (section 2).
7. Cookies
On this website, one strictly necessary cookie stores your language choice. Google Analytics sets cookies of its own — but only after you consent via the cookie banner (section 2). If you decline, nothing is loaded and nothing is set.
The app sets exactly one cookie, __Host-interious_session, and only after you sign in. It holds a signed reference to your account so the server knows the renders are yours. It lasts 30 days, cannot be read by scripts, and is not sent when another site links to us. A strictly necessary cookie needs no consent under § 165(3) TKG 2021, which is why the app shows no banner. There is no advertising in the app, no ad network and no tracking pixel, and nothing there follows you to another site.
Two things run alongside the app itself, on every page. One is the error tracker in section 5, which waits for something to break. The other is a page-view count served from our own domain: it records that a page was opened and which step of the flow it was: a photo uploaded, concepts seen, a sign-in begun, a sign-in finished, the section 4 transfer agreed to or refused, the render balance run out, and a link followed to a shop, with the kind of furniture it was and the shop it led to. That is the whole list, and none of it says who did any of it. Before anything is counted, the web address is stripped of the identifiers the app puts in it, so the count knows a room page was opened and never which room. Neither of the two sets a cookie, and neither tries to recognize you from one visit to the next.
A third thing appears only where render credits are on sale. There, the page loads the checkout of Paddle.com Market Ltd, the seller of the packs named in section 5, so that it can show a price already correct for your country and take the payment. That much means Paddle sees your IP address; if you go on to buy, you give Paddle your email address and your payment details in its own overlay, and we never see the card. The overlay is Paddle's page inside ours, so whatever it stores in your browser, including any cookie of its own, is covered by Paddle's privacy notice rather than by this one. It is not loaded on the other pages, and none of it is advertising.
If it does break, the crash report carries a replay of the moments before it. Nothing is stored for a visit that works: the recording is held in your browser and thrown away unless an error actually fires. All text is masked and all images and video are blocked, so your room photo and your render are black rectangles. What we get is where you clicked and how the page was laid out, never what your home looks like. While the app is open, the error tracker keeps one short-lived entry in your browser's session storage to tie a replay together; your browser discards it when you close the tab.
8. Your rights
You have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict or object to processing (Art. 18, 21), to receive it in a portable form (Art. 20), and to withdraw any consent you gave (Art. 7(3)) without affecting what was lawful before — the analytics consent in this website's cookie settings, the transfer agreement as described in section 4. Write to office@interious.at, and we answer within a month.
You can also complain to the Austrian data protection authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
9. Changes
Interious is early, and the way it works still moves. If the processing changes we update this page and its date; if the change affects the US transfer we ask for your consent again rather than reusing the old one.
