Privacy Policy
This Privacy Policy explains how On Air Kit (“we,” “us,” or “our”) collects, uses, and protects your information — including the photos and descriptions you use to generate custom emotes, emoji, sub badges, and PNGtuber avatars.
Last updated: July 27, 2026
Who We Are
On Air Kit is operated by RMT Services OÜ, a private limited company registered in Estonia (registration code 16803586), with its registered address at Hobujaama 4, 10151 Tallinn, Estonia. We are the data controller for the personal data described in this Policy.
What We Collect
- Account data. When you sign in, we receive your handle, profile picture/avatar colour, and — for Twitch specifically — your broadcaster status (none, affiliate, or partner), synced from the identity provider you connect.
- Content you provide.The text descriptions (“briefs”) you write and any reference photos you choose to upload. See Section 3.
- Generated content. The images the Service produces for you, stored so you can access, re-download, and reuse them later.
- Payment information. When credit purchases are available, transaction details (amount, credit pack, timestamp) are recorded against your account. Your full payment card details are collected and processed directly by Stripe — we never see or store them.
- Usage and technical data. Standard technical information generated by using the Service, such as IP address, browser and device information, and timestamps of activity.
Photos, Text Descriptions, and AI Processing
A core feature of On Air Kit is generating a likeness-preserving image from a photo of a real person — yourself, or someone else whose likeness you have the right to use. This section explains specifically what happens to that photo.
What's uploaded and why. You may attach one or more reference photos together with a text description when you want the generated output to resemble a specific real person rather than a generic character. This input is used solely to generate the image(s) you requested in that session.
Sent to a sub-processor. Uploaded photos and text descriptions are sent to fal.ai, our third-party AI image-generation sub-processor, to produce the requested output. fal.ai may in turn route the request to underlying model providers — for example, Google's image-generation models — depending on which model is used for a given generation. We require that images sent for processing are not retained or used by fal.ai or its underlying providers for any purpose beyond fulfilling your request.
Retention. Reference photos and generated images are retained for as long as your account and the associated project remain active, so you can revisit, re-download, or reuse them. If you delete your account, we delete your stored photos and generated images within 30 days.
Because this feature accepts photographs of real people, we treat uploaded reference photos as sensitive and limit access to what is technically necessary to generate your output — see Section 10 (Data Security) and Section 11 (Children's Privacy).
How We Use Your Data
- To provide, operate, and maintain the Service, including generating your images.
- To process credit purchases and maintain accurate billing records.
- To provide customer support and respond to your requests.
- To detect, prevent, and respond to fraud, abuse, and violations of our Terms of Service, including attempts to generate content prohibited under its Acceptable Use section.
- To maintain the security and reliability of the Service.
- To comply with our legal and tax obligations.
Legal Basis for Processing (GDPR)
- Performance of a contract — processing your input and generating images is the service you asked us for.
- Legitimate interests — for fraud prevention, abuse detection, and improving the reliability of the Service, balanced against your rights.
- Legal obligation — for retaining billing and accounting records as required by Estonian law.
- Consent — where we ask for it separately, such as for optional communications, and which you may withdraw at any time.
Third-Party Services
We share data with a small number of sub-processors, only as necessary to run the Service:
- Supabase — authentication, database, and private file storage.
- fal.ai — AI image-generation processing (see Section 3), which may route requests to underlying model providers such as Google depending on the model used.
- Stripe — payment processing for credit purchases.
- Our hosting and infrastructure providers, to run the Service itself.
Each processes data only as necessary to provide their part of the Service, under their own privacy policies and, where applicable, a data processing agreement with us. We do not sell your personal data.
Data Retention
- Account data is deleted within 30 days of account deletion.
- Uploaded reference photos and generated images are retained while your account is active and deleted within 30 days of account deletion (see Section 3).
- Billing and payment records are retained for 7 years, as required by Estonian accounting law.
- Server and application logs are retained for up to 90 days.
- Credit and billing history. When you delete your account, we sever your identity from your credit ledger entries rather than deleting them outright — the financial record survives so our accounts remain reconcilable and auditable, but it can no longer be linked back to you.
Your Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data (“right to erasure”).
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent, where processing is based on consent.
- Lodge a complaint with a supervisory authority — in Estonia, the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
To exercise any of these rights, contact us at rmtsolutions@gmail.com.
Data Security
Uploaded photos and generated images are stored in a private file storage bucket; nothing is publicly accessible, and anything a browser displays is served through a short-lived signed link. Data is encrypted in transit. Access to production data is limited to what is technically necessary to operate the Service. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
Children's Privacy
The Service is not directed at children under 13, and we do not knowingly collect personal data from anyone under that age. Because likeness-preserving generation from photographs is a core feature (Section 3), please do not upload a reference photo of anyone under 13. If we learn that we have collected data from a child under 13, we will delete it.
Changes to This Policy
We may update this Policy from time to time. We will update the “Last updated” date above when we do, and material changes will be highlighted on the Service.
Contact
Questions about this Policy, or requests relating to your data, can be sent to rmtsolutions@gmail.com.