Legal
Privacy Policy
Effective: September 13, 2026
How Zero to AI Artist handles personal information
This Privacy Policy explains how Cyril Nima Creative collects, uses, shares, retains, and protects personal information through zerotoaiartist.com, Zero to AI Artist accounts, the course, purchases, and the members-only Member Hub.
1. Who We Are
Zero to AI Artist is operated by Cyril Nima Creative, located in Montréal, Québec, Canada.
Privacy questions and requests may be sent to support@zerotoaiartist.com. The person responsible for privacy at Cyril Nima Creative can be reached through that email address.
2. Scope
This Policy applies to:
- zerotoaiartist.com and related Zero to AI Artist pages;
- Free and Full Access accounts;
- Passwordless sign-in and account settings;
- Course viewing, progress, and completion tracking;
- Purchases, taxes, receipts, refunds, and payment disputes;
- The members-only Member Hub and uploaded content;
- Support and privacy requests;
- In-app and email notifications;
- Marketing communications; and
- Cookies, analytics, and security logs.
3. Information We Collect
Account and profile information
- Name, email address, permanent user handle, display name, and account identifier;
- Optional profile photo, biography, and links you choose to add;
- Account status, Full Access status, and settings; and
- Verified email changes and active-session information.
Passwordless authentication information
- Email address used to request a sign-in code;
- Sign-in-code request, delivery, verification, expiry, and failure information;
- Session identifiers and active sessions;
- IP address, browser, device, date, time, and security signals; and
- Records needed to detect abuse, automated requests, or unauthorized access.
Zero to AI Artist does not create or store a traditional account password. Sign-in uses a six-digit code sent by email. Never send a sign-in code to support or another person.
Purchase and billing information
- Name, email address, billing country, region, and address provided at checkout;
- Product, amount, currency, taxes, purchase date, and payment status;
- Transaction, receipt, refund, and dispute identifiers;
- Payment-method type and limited card details supplied by Stripe, such as brand and last four digits; and
- Information needed to investigate duplicate charges, billing mistakes, or exceptional access issues.
Stripe processes complete payment-card information. Cyril Nima Creative does not receive or store your complete card number or security code. Stripe acts as the payment processor and handles payment and applicable tax information under its own privacy terms.
Course and usage information
- Episodes viewed, playback progress, and completion status;
- Resources opened and features used;
- Video and technical events needed to provide playback;
- Pages visited, buttons selected, referring page, device, browser, operating system, and approximate region; and
- Errors, support codes, and performance information.
Member Hub information
- Posts, questions, replies, comments, reactions, and reports;
- Images, video, links, prompts, screenshots, and other permitted attachments;
- Editing and deletion activity;
- Moderation actions, warnings, restrictions, and appeals; and
- Profile information visible to Full Access members.
Member Hub identity and content are visible only according to eligibility: Free members may read Announcements published to All members, while Full Access members may access Full-only areas and participation features. Authorized administrators may access content as needed to operate the service. Member Hub content is not intended for logged-out visitors or public search indexing. Private messaging is not included.
Communications and preferences
- Support messages, privacy requests, refund requests, and files you send us;
- Announcement, resource, reply, service, and marketing email preferences;
- Marketing consent, source, date, and unsubscribe status; and
- Email delivery, bounce, and engagement information where enabled.
4. How We Collect Information
We collect information:
- Directly from you when you create an account, purchase, post, upload, change settings, or contact us;
- Automatically through the website, authentication, course, video, Member Hub, security, and analytics systems;
- From Stripe in connection with payments, taxes, refunds, receipts, fraud prevention, and disputes;
- From service providers that help operate the website and course; and
- From other members or administrators when they reply to you or report content.
5. Why We Use Information
We use personal information to:
- Create, authenticate, secure, and manage accounts;
- Send sign-in codes and maintain sessions;
- Provide Episode One and Full Access;
- Process payments, taxes, receipts, refunds, and disputes;
- Track course progress and show where you left off;
- Operate the members-only Member Hub and display content to members;
- Deliver videos, subtitles, resources, notifications, and support;
- Respond to privacy, billing, and account requests;
- Moderate content and enforce the Terms and Community Guidelines;
- Detect account sharing, fraud, spam, piracy, security threats, and technical abuse;
- Understand and improve the website, course, and user experience;
- Send optional marketing where permitted;
- Maintain financial, tax, legal, and compliance records; and
- Establish, exercise, or defend legal claims.
6. Legal Bases Where Applicable
Where European, UK, or similar data-protection laws apply, we rely on one or more of the following legal bases:
- Contract: to create your account, provide purchased access, operate the Member Hub, and respond to support requests;
- Legitimate interests: to secure the service, prevent fraud and abuse, improve the product, and protect legal rights, where those interests are not overridden by your rights;
- Consent: for optional analytics, optional marketing, and other uses that require consent;
- Legal obligation: for tax, accounting, consumer, privacy, regulatory, or law-enforcement requirements; and
- Legal claims or vital interests: where necessary and permitted by law.
7. Member Hub Content and Visibility
Your Member Hub profile, posts, replies, and attachments may be viewed by other Full Access members, administrators, moderators, and service providers needed to operate or secure the Member Hub.
Members are prohibited from reposting another member’s content or personal information outside the Member Hub without permission. However, no online Member Hub can guarantee that another user will never make an unauthorized copy. Share only content you are comfortable showing to the member Member Hub.
You retain ownership of original content you upload. We use it only as needed to host, display, process, back up, moderate, and operate the Member Hub. We will ask for permission before featuring your work publicly and will credit you as agreed.
8. Service Providers and Recipients
We share information only as reasonably necessary with categories of providers such as:
- Payment, tax, receipt, refund, and fraud-prevention services, including Stripe;
- Website hosting, database, storage, and content-delivery providers;
- Passwordless authentication and transactional email providers;
- Video hosting and playback providers;
- Basic product analytics providers;
- Email marketing and notification providers;
- Developers, moderators, and administrators with authorized access;
- Accountants, lawyers, insurers, security specialists, and other professional advisers; and
- Public authorities or other parties when required or permitted by law.
We do not sell or rent personal information to data brokers or advertisers. We do not use private Member Hub content to train AI models or feature it publicly without separate permission.
9. International Processing
Our business is located in Canada, and service providers may process or store information in Canada, the United States, Europe, or other countries where they operate. Information processed outside your country may be subject to the laws of that location.
We use contractual, organizational, and technical measures appropriate to the information and the provider. Where required, we assess cross-border transfers and use recognized transfer safeguards.
10. Cookies and Analytics
We use necessary cookies and similar technologies for sign-in, sessions, security, checkout, video playback, preferences, and account functionality. We may use basic PostHog analytics to understand and improve the service.
Optional analytics are controlled through Cookie Settings and remain off unless you opt in. We do not use advertising or retargeting cookies at launch, and basic analytics is not intended to record sign-in codes, payment details, private form content, or uploaded Member Hub files.
See the Cookie Policy for more information and controls.
11. Marketing and Notifications
Creating an account or purchasing Full Access does not automatically require you to receive optional marketing. Marketing consent is managed separately and may be withdrawn at any time.
You may still receive essential communications such as sign-in codes, receipts, security notices, and account changes. Eligible members can manage announcement/resource and reply/mention email preferences through Settings. Marketing consent is separate and optional.
12. Retention
We retain each category only for the approved period below, subject to mandatory law and a documented legal, security, payment, tax, or moderation hold that legitimately requires an extension while the matter remains active.
| Information | Approved launch retention rule |
|---|---|
| Account, profile, and progress information | Immediate deletion cleanup applies. Only a minimum opaque account tombstone remains for 24 months unless an active documented hold applies. |
| Deleted Member Hub revision bodies and attachment files | 90 days, except while an active moderation, legal, or security hold applies. Active preserved contributions may remain under Deleted Member in de-identified form. |
| Contact and support submissions | 24 months after case closure unless an active documented hold applies. |
| Admin and private notes | 24 months after account or case closure unless an active documented security, payment, or legal matter requires extension. |
| OTP and rate-limit privacy keys | 48 hours through the existing deterministic expiry behavior. |
| Ordinary audit and security events | 24 months. |
| Incident-linked records | While the documented incident or matter remains active, plus the applicable approved follow-up period. |
| Cookie and optional analytics identifiers | No more than 12 months. |
| Minimal consent and withdrawal evidence | 6 years after the last relevant action, subject to mandatory-law requirements. |
| Stripe, payment, and financial-reference records | 6 years after the end of the last tax year they relate to, with longer retention only for an active documented dispute, legal, or tax hold. |
13. Account Deletion
You can request or initiate account deletion through Account Settings. Account deletion is intended to be permanent and cannot be reversed.
When an account is deleted, direct identifiers are removed promptly. Existing Member Hub contributions may remain under “Deleted Member” in de-identified form to preserve useful discussions. You may delete your own posts and comments before deleting the account if you want them removed from the visible Member Hub.
Some purchase, tax, dispute, security, moderation, or legal records may remain where required or permitted. Account deletion ends course and Member Hub access and does not automatically create a refund right.
14. Security
We use reasonable safeguards designed to protect personal information, including passwordless authentication, restricted administrative access, secure transmission, role-based permissions, provider security controls, session management, monitoring, and backups.
No system can guarantee absolute security. Protect your email account and devices, do not share sign-in codes, and use the “log out from all devices” option if you suspect unauthorized access.
15. Your Privacy Rights
Depending on the law that applies to you, you may have the right to:
- Know whether we hold personal information about you and access it;
- Correct inaccurate or incomplete information;
- Request deletion in appropriate circumstances;
- Receive a portable copy of eligible information;
- Withdraw consent for optional processing;
- Object to or request restriction of certain processing;
- Unsubscribe from marketing;
- Ask how information is used, shared, or retained; and
- Complain to a privacy regulator with jurisdiction.
To make a request, email support@zerotoaiartist.com from your registered address. We may take reasonable steps to verify your identity. We respond within the period required by applicable law.
16. Minors
Zero to AI Artist is intended for adults who are 18 or older. We do not knowingly offer accounts or Member Hub access to children. If we learn that an ineligible person created an account, we may close it and delete the information, subject to required retention.
17. Privacy Incidents
If a confidentiality or security incident occurs, we will investigate, contain it, reduce the risk of harm, keep required records, and notify affected people and regulators where applicable law requires notification.
18. Changes to This Policy
We may update this Policy when our service, providers, data practices, or legal obligations change. The effective date at the top identifies the current version. Material changes will be communicated through the website, account, or email where appropriate.
19. Contact
Privacy Officer Cyril Nima Creative Montréal, Québec, Canada Email: support@zerotoaiartist.com