Terms of Service
Welcome to Noryn Studio. By using our service, you agree to these Terms of Service. Please read them carefully. Noryn is operated by Roxana Tudoran, Romania. Contact: [email protected].
1. Service Description
Noryn Studio is an AI-powered social media content generator. We offer three tiers:
- Guest: 3 free text generations per month (no account required)
- Basic ($9.99/month): 100 text generations/month + 30 images/month + 15 short videos/month (Flux + ElevenLabs voiceover) + 100 exports/month
- Pro ($89/month): 100 text generations/month + 80 images/month + 320 seconds of HeyGen avatar video/month (8 × 40s) + 8 reels/month + 8 slideshows/month + 300 exports/month + Brand Profiles + advanced tools
Quotas are system-enforced and reset monthly.
2. Payment Terms & Cancellation
All payments are processed securely through Gumroad. Subscriptions renew automatically monthly.
How to Cancel Your Subscription:
Option 1: Gumroad Library (recommended)
Open your Gumroad Library → click Noryn → Manage membership → Cancel membership.
Option 2: From your Gumroad email
Search your inbox for Gumroad or "Noryn". The receipt email includes a Cancel subscription button.
Option 3: Email Gumroad Support
Contact [email protected]
Option 4: Email Noryn Support
Contact [email protected]
Important Information:
- Access continues until end of billing period
- No refunds for partial periods
- Brand Profiles retained while account is active
- Generated media retention is plan-based: Pro has no fixed expiry (EXCEPT HeyGen avatar videos, which expire 30 days after generation; download them to keep them), Basic up to 180 days, Guest up to 90 days
- After your paid quota is exhausted, you can continue using Noryn as a Guest (3 free generations/month)
For GDPR data deletion requests, see our GDPR Compliance Guide.
3. Acceptable Use
You may NOT use Noryn Studio to:
- Generate spam, misleading, or fraudulent content
- Violate third-party intellectual property rights
- Promote illegal activities, hate speech, or violence
- Abuse the service through automation or reverse engineering
Report content: if you believe content created or uploaded through Noryn violates these rules, the law, or your rights, report it at [email protected] with the subject "Content report". We review every report and act on confirmed violations (removal, account measures).
4. Content Ownership
You own the generated output content, subject to AI provider terms. Noryn is not liable for copyright claims arising from generated content. You are responsible for verifying content before publication.
5. Limitation of Liability
Noryn Studio is provided "as is" without warranties. Our total liability is limited to the amount you paid in the last 12 months. We are not liable for indirect or consequential damages.
6. GDPR & User Rights
EU users have additional rights under GDPR (access, deletion, portability). Signed-in users can download a copy of their personal data (data export) and erase their uploaded media directly from their account; for anything else, or if you prefer, email [email protected]. See our GDPR Compliance Guide for details.
7. Minimum Age
Noryn Studio is not directed at children. You must be at least 16 years old (the GDPR consent age in Romania) to use the service. By using Noryn Studio you confirm that you meet this minimum age requirement.
8. AI-Generated Content
Outputs produced by Noryn Studio are AI-generated content. When you publish them, you are responsible for complying with any platform or legal labeling requirements that apply to AI-generated content, including the transparency obligations of the EU AI Act (Article 50).
9. Consumer Dispute Resolution (Romania)
If you are a consumer in Romania, you can use the alternative dispute resolution (SAL) procedure of the National Authority for Consumer Protection (ANPC). Details: anpc.ro and anpc.ro/ce-este-sal.
For questions about these Terms of Service, contact [email protected].
Privacy Policy
At Noryn Studio, we respect your privacy and are committed to protecting your personal data.
Who We Are (Data Controller)
Noryn is operated by Roxana Tudoran, Romania, who acts as the data controller. Contact: [email protected]. For all privacy matters, data requests, or questions about this policy, contact us at [email protected] (single point of contact; we respond to data requests within 30 days as required by GDPR).
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Romanian supervisory authority, ANSPDCP ( www.dataprotection.ro), or with the supervisory authority in your own EU member state. These Terms and this Policy are governed by Romanian law and applicable EU regulations.
What Data We Collect
- Guest users: Browser cookies (quota tracking), IP address (rate limiting)
- Paid users: Email address (authentication), usage statistics, Brand Profiles (Pro only)
- Uploaded media (Bring Your Own Media): photos and video clips you choose to upload as source material, which may contain images of identifiable people
We do NOT collect passwords, credit card numbers, or content you publish to third-party platforms.
Media You Upload (Bring Your Own Media)
If you use Bring Your Own Media, you can upload your own photos and video clips as source material for generation. These files may contain personal data, including images of identifiable people. We use them only to produce the content you request.
Uploaded media is stored privately. Files are held in a private storage bucket that is not publicly listable, and access runs through an authenticated, access-controlled proxy, so only you and the systems needed to generate your content can retrieve them.
Your uploaded photos and clips are composited into your deliverables on our own servers. The only third party that receives your uploaded photos is OpenAI: when you use Bring Your Own Media, your photos may be sent to OpenAI to produce short visual descriptions, so the generated text matches your photos. You are responsible for the media you upload. By uploading, you confirm you have the right to use it, that you have the consent of any identifiable people shown in it, and that it contains no minors.
How We Use Your Data
- Authenticate you via magic link email
- Enforce monthly quota limits (Guest: 3 text; Basic: 100 text + 30 images + 15 short videos; Pro: 100 text + 80 images + 320s HeyGen avatar video + 8 reels + 8 slideshows)
- Generate AI-powered content using your inputs
- Store Brand Profiles for future generations (Pro only)
Legal Bases for Processing (GDPR Article 6)
We process personal data under the following GDPR Article 6 legal bases:
- Contractual necessity (Art. 6.1b): authentication (magic link), quota enforcement, payment processing via Gumroad, and transactional service emails
- Legitimate interest (Art. 6.1f): aggregated, cookieless analytics (our own, plus Cloudflare Web Analytics) and security monitoring
- Legal obligation (Art. 6.1c): legal compliance (for example tax records)
- Consent (Art. 6.1a): not currently used for marketing; we do not send marketing emails
Third-Party Services
We integrate with:
- Gumroad (payment processing)
- Resend (transactional emails)
- OpenAI (AI text and image generation; when you use Bring Your Own Media, also receives your uploaded photos to produce short visual descriptions; US-based)
- HeyGen (AI video generation for Pro plan)
- fal.ai (AI image and image-to-video generation; receives generation prompts and AI-generated start images, never your uploaded media; US-based)
- ElevenLabs (AI voice and text-to-speech; US-based)
- Cloudflare (network in front of this site, media storage including the private Bring Your Own Media bucket, and cookieless traffic measurement; Global, EU/US)
- Railway (application and database hosting; US-based)
The full, dated subprocessor list, including what data each provider receives and our 30-day notice policy for future changes, is at /legal/subprocessors.
Update, July 8, 2026: when you use Bring Your Own Media, your uploaded photos may be sent to OpenAI to produce short visual descriptions, so the generated text matches your photos. Effective July 8, 2026.
Data Retention
Export bundles are retained based on your plan:
- Pro: Up to 365 days
- Basic: Up to 180 days
- Guest: Up to 90 days
Generated media (images, videos) is retained based on your plan: Pro has no fixed automatic expiry, with one exception: HeyGen avatar videos expire 30 days after generation on every plan, so download them to keep them. Basic media is retained up to 180 days, and Guest/fallback up to 90 days.
Generated media files (never your Bring Your Own Media uploads) are served through public, unguessable links so you can post and share them on social platforms; anyone who has such a link can view that file.
Uploaded media (Bring Your Own Media) is kept until you ask us to delete it or delete your account. You can erase all your uploaded media yourself at any time from your signed-in account (self-service erasure), or by emailing [email protected]; either way we permanently delete the stored files and keep only a minimal erasure record (without the media) for audit purposes.
Account data is retained while your account is active.
- Server, audit, and webhook logs: kept approximately 90 days, then deleted automatically
- Analytics events: kept 12 months, then deleted automatically
- Brand Profiles: kept until you delete them or delete your account
- Records of acceptance of the Terms and related account records: retained while your account exists; removed on full account deletion (a manual process, email [email protected])
Cookies
We use essential cookies only. No third-party tracking or advertising cookies, no analytics cookies, no cross-site tracking. Every cookie below is strictly necessary for the service to function, and the traffic measurement described in the next section is cookieless: it stores nothing on your device and reads nothing from it. Because nothing non-essential is stored on or read from your device, no cookie consent banner is required under the ePrivacy rules.
- noryn_user: keeps you signed in (cryptographically signed; expires after 30 days, or when you sign out, whichever comes first)
- noryn_guest: tracks the free guest quota (3 generations/month) without an account; stored for 12 months
- noryn_magic_state: binds a sign-in link to your browser for security; expires after 10 minutes
- noryn_csrf: protects forms against cross-site request forgery (security)
- noryn_ops_session: internal operations console session, used only by Noryn staff; never set for regular users
Analytics, Traffic Measurement and Local Storage
Privacy-safe first-party analytics: in our own analytics store we record only the event name, the page path, the user type (guest, basic, or pro), and a timestamp. No IP address, no cookies, and no personal identifier are stored with those events.
Traffic measurement (Cloudflare Web Analytics), in use since August 26, 2026: Cloudflare, already a subprocessor for this site, measures page views, the page path, the country, the device type, and the site you arrived from. It is cookieless, it stores nothing on your device, and it does not track you across other websites or feed any advertising. Country is derived by Cloudflare from the connection it already handles as the network in front of this site; we do not receive or store your IP address with these measurements. See the subprocessor list for the full record.
Browser local storage: for convenience, your browser stores your email address locally (noryn_email), plus UI preference flags, cross-tab sign-in and sign-out signals (noryn_login, noryn_logout), kit progress flags, and saved Brand Profile drafts. This data stays on your device, is not transmitted as tracking data, and is removed when you clear your browser's site data.
Your Rights (GDPR)
EU users can request data access, deletion, or export by contacting [email protected]. See our GDPR Compliance Guide for detailed workflows.
For questions about this Privacy Policy, contact [email protected].
GDPR Compliance Guide
This guide explains how Noryn Studio complies with the General Data Protection Regulation (GDPR) and how EU residents can exercise their data subject rights.
Your GDPR Rights
Right to Access (Article 15)
Request a copy of your personal data. Signed-in users can download their personal data directly (self-service data export on /help/subscription). For anything else, email [email protected] with subject "Subject Access Request (SAR)". We respond within 30 days.
Right to Deletion (Article 17)
Request deletion of your account and associated data. Signed-in users can erase all their uploaded media themselves (self-service erasure on /help/subscription). For full account deletion, email [email protected] with subject "Account Deletion Request". We respond within 30 days. Note: Generated media retention is plan-based (Pro has no fixed expiry except HeyGen avatar videos, which expire after 30 days; Basic up to 180 days; Guest up to 90 days).
Right to Portability (Article 20)
Export your Brand Profiles and usage data in JSON format. Signed-in users can download this via the self-service data export on /help/subscription; or email [email protected] with subject "Data Portability Request". We respond within 30 days.
Right to Rectification (Article 16)
Correct inaccurate data (e.g., wrong email address). Email [email protected] with correction details. We respond within 30 days.
Right to Restriction of Processing (Article 18)
Request that we restrict the processing of your personal data (for example while a dispute about accuracy or an objection is being resolved). Email [email protected] with subject "Restriction Request". We respond within 30 days.
Right to Object (Article 21)
Object to specific data processing (e.g., analytics). Email [email protected] with objection details. We respond within 30 days.
Right to Withdraw Consent (Article 7(3))
Where processing is based on your consent, you can withdraw that consent at any time; withdrawal does not affect the lawfulness of processing before withdrawal. Email [email protected] with subject "Consent Withdrawal". We respond within 30 days.
Right to Lodge a Complaint (Article 77)
File a complaint with your national Data Protection Authority (DPA). You can find your local DPA at edpb.europa.eu.
Data Security
We use industry-standard security measures to protect your data:
- Encryption: HTTPS/TLS for data in transit
- Cookies: Cryptographically signed for integrity
- Access controls: Server-side API keys only
International Data Transfers
Our service uses infrastructure and third-party providers located in various regions. Data may be processed outside your country of residence. If you have questions about data transfers, contact [email protected].
For GDPR-related questions, contact [email protected].
Last updated: August 26, 2026
For any questions (legal, privacy, or support), contact [email protected].
Under the EU Digital Services Act, [email protected] is our single electronic point of contact for users and for authorities, including reports of illegal content.