Privacy Policy

Last updated: March 2026

1. Information We Collect

We collect the following information when you use Mazoon:

  • Account data: name, email, phone number, Mazoon ID, profile photo, bio, and professional details
  • AI generation data: prompts, inputs, and generated outputs (images, video, audio, text) stored in your account
  • Chat messages: end-to-end encrypted message content between users
  • Usage analytics: device type, browser, IP address, pages visited, feature usage, and session data
  • Payment data: billing information processed by Stripe (we never store card numbers)

2. How We Use Your Information

Your information is used to provide and improve Mazoon's services, including account management, AI content generation across 6 sections (Image, Video, Audio, Text, Chat, Learning), social features, and customer support.

AI prompts and outputs are stored per user account to enable history and re-generation. They are not shared with third parties or used to train AI models.

We do not sell your personal information to third parties.

3. Data Storage & Security

Your data is stored using Google Firebase infrastructure (Firestore for structured data, Firebase Storage for media files) with encryption at rest (AES-256) and in transit (TLS 1.3).

Chat messages are end-to-end encrypted. Passwords are hashed using bcrypt (12 rounds). Authentication uses Firebase Auth tokens verified on every request. Socket connections require authenticated Firebase ID tokens.

We implement rate limiting, input validation, CORS protection, and Content Security Policy headers to safeguard against common attack vectors.

4. Third-Party Services

Mazoon integrates with the following third-party services:

  • Google Firebase — Authentication, Firestore database, Cloud Storage, hosting
  • Stripe — Payment processing, subscription management, identity verification for Mazoon ID (PCI DSS compliant)
  • AI Infrastructure Providers — We use multiple cloud AI providers for content generation, including image, video, audio, text, and avatar processing. Your prompts and uploaded media are sent to these providers for processing and are not stored by them beyond the generation session.
  • Socket.IO — Real-time messaging and WebRTC signaling (authenticated connections only)

5. Your Rights

You have the right to:

  • Access your personal data via your account settings
  • Correct inaccurate information at any time
  • Request deletion of your account and associated data
  • Export your data in a standard format
  • Opt out of non-essential communications

6. Cookies & Local Storage

We use essential cookies for authentication and session management. We also use localStorage to maintain your preferences, theme settings, and authentication tokens. No tracking cookies are used for advertising purposes.

7. Children's Privacy

Mazoon is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us for removal.

8. Data Retention

Account data is retained for the duration of your active account. Upon account deletion, your personal data is purged within 90 days, except where retention is required by law (e.g., billing records). AI-generated content associated with your account is deleted with your account.

9. GDPR & CCPA Compliance

If you are located in the EU (GDPR) or California (CCPA), you have additional rights including the right to data portability, the right to restrict processing, and the right to object to automated decision-making. To exercise any data rights, contact amrbakry@mazoonai.com and we will respond within 30 days.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notification. Continued use of the platform after changes constitutes acceptance of the updated policy.

11. Contact

For questions about this Privacy Policy or your data, contact us at:

amrbakry@mazoonai.com

Mazoon Inc., Delaware, USA