Widemile Privacy Policy
Last updated: 24 July 2026
This Privacy Policy explains how Widemile collects, uses, discloses and protects personal data when you visit widemile.ai, create an account or use Widemile services, including Creative Studio, Pro Studio, Director, AI agents, collaboration tools, integrations, subscriptions and related support.
1. Data Controller
The data controller is Centola Engineering S.r.l., registered office at Contrada Ponzanello Mamurrano 35, 04023 Formia (LT), Italy, VAT number 03343570598, REA LT-332215, share capital EUR 10,000.
Privacy contact: info@centolaengineering.com.
When Widemile processes personal data solely on the documented instructions of a business customer, that customer acts as controller and Centola Engineering S.r.l. acts as processor under the applicable data processing agreement.
2. Scope
This Policy applies to Widemile websites, web applications, APIs and services operated by Centola Engineering S.r.l. It does not govern third-party websites or services that you choose to connect to Widemile or visit through external links.
3. Personal data we process
Account and contact data
- Name, surname, email address, telephone number, account identifier, profile image, language and account preferences.
- Authentication data and information received from sign-in providers, such as Google, when you choose social login.
- Organisation, workspace, team membership, roles, invitations and collaboration settings.
Billing and transaction data
- Billing name and address, tax information, subscription plan, purchased credits, transaction identifiers, payment status and invoices.
- Payment card details are collected directly by Stripe. Widemile does not receive or store the complete card number or security code.
User content and AI data
- Prompts, instructions, messages, agent configurations, documents, datasets and knowledge-base content.
- Images, video, audio, voice recordings, likenesses, faces, reference media, project files and other materials you upload.
- Generation settings, model selections, technical metadata, intermediate processing data and AI-generated outputs.
- Feedback, moderation signals, support requests and information you submit when reporting a problem.
Media may contain personal data about other people. Visual or voice characteristics may be processed to create or edit content, maintain character consistency or provide the requested generation. Widemile does not use these characteristics for identity verification or biometric authentication unless a specific feature expressly states otherwise and provides any additional notice required by law.
Integrations and connected services
- The identity of connected applications, authorisation tokens, scopes, connection status and actions requested through integrations such as Google, Gmail, Slack, Telegram or other services selected by you.
- Data returned by connected services when necessary to perform your instructions.
Public and shared content
- Content, prompts, profile information and metadata that you deliberately publish in the community gallery or share through a public link.
- Public content may be viewed, copied or redistributed by other people. You can change the visibility of eligible content through the available product controls.
Technical, usage and security data
- IP address, browser and device type, operating system, language, approximate location derived from IP, referrer, visited pages, timestamps and interaction events.
- Authentication events, API activity, security logs, error reports, fraud indicators and diagnostic information.
- Cookie and local-storage identifiers, but only as described in our Cookie Policy.
- Consent evidence: a random browser consent identifier or account/contact identifier, purpose, current and previous choice, policy version, interaction source, language and server timestamp. The consent log does not contain a full IP address, user agent or device fingerprint.
Marketing data
- Marketing subscription status, consent record, campaign attribution, referral or affiliate identifiers and interaction with communications.
4. How we collect data
We collect data directly from you, automatically from your device, from organisations that invite you to a workspace, from services you connect, from payment and authentication providers and from partners that measure referrals or advertising where you have consented.
5. Purposes and legal bases
Providing the service — performance of a contract
We process account data, user content, prompts, files, generation settings, outputs and workspace information to create and administer your account, execute your instructions, provide AI generation, store projects, enable collaboration, supply support and deliver purchased services.
Payments and accounting — contract and legal obligation
We process billing and transaction data to complete purchases, administer subscriptions and credits, prevent payment fraud, issue invoices and comply with tax, accounting and other legal requirements.
Security and abuse prevention — legitimate interests and legal obligation
We process technical logs, authentication events, content signals and limited account information to secure Widemile, prevent fraud and misuse, investigate incidents, enforce our Terms and protect users, Centola Engineering S.r.l. and third parties.
Service communications — contract and legitimate interests
We send transactional messages about authentication, purchases, service status, security, support and material changes. These communications are not marketing messages.
Product analytics and improvement — consent
Where required by law, optional analytics technologies are activated only after your consent. We use analytics to understand feature adoption, diagnose problems and improve performance and usability. You may withdraw consent at any time through Cookie Settings.
Marketing and advertising — consent
We send optional marketing communications and activate advertising, conversion or affiliate trackers only after the relevant consent. Refusing or withdrawing consent does not affect access to the core service.
Legal claims and compliance — legal obligation and legitimate interests
We may process and preserve data where reasonably necessary to respond to lawful requests, establish or defend legal claims, comply with court or authority orders and document compliance.
6. Service providers and recipients
We disclose only the data reasonably necessary for each provider to perform its service. Depending on the features used and current configuration, recipients may include:
- Supabase for authentication, databases and application infrastructure.
- Cloudflare, including R2, for content delivery, security and object storage.
- Stripe for payments, subscriptions, invoicing and fraud prevention.
- Resend for transactional and consented marketing email.
- PostHog for consented product analytics and error diagnostics.
- Google, including Google Ads and Google Cloud Vertex AI, for consented conversion measurement and selected AI features.
- OpenAI, Microsoft Azure and Azure OpenAI, fal.ai, Kie.ai and ByteDance or Volcano Engine Ark for selected AI generation and processing features.
- LangChain or LangSmith, Tavily and E2B for agent orchestration, tracing when enabled, web search and isolated code execution.
- Composio and the third-party applications selected by you for connected-service functionality.
- X Ads, TradeDoubler and Mediavine Grow for consented advertising, referral, affiliate or audience-measurement features.
- Professional advisers, auditors, insurers, authorities and courts where necessary for compliance or legal claims.
- A buyer, investor or successor in the context of a corporate transaction, subject to appropriate confidentiality and data-protection safeguards.
The provider used for a particular generation can depend on the model or feature you select. Inputs and outputs required to perform that request may be sent to that provider. We do not authorise service providers to use personal data for their own unrelated purposes.
7. International data transfers
Some providers may process data outside the European Economic Area. Depending on the provider and destination, transfers are based on an adequacy decision, the EU-US Data Privacy Framework where applicable, Standard Contractual Clauses approved by the European Commission or another valid mechanism under Chapter V of the GDPR. Information about the mechanism applicable to a specific provider is available on request.
8. Data retention
We retain personal data only for as long as necessary for the purposes described above:
- Account and workspace data: while the account or workspace is active and for the time reasonably needed to close it and resolve outstanding matters.
- User content and AI outputs: until you delete them, the workspace owner deletes them or the account is closed, subject to limited backup, security and provider-deletion cycles.
- Billing and accounting records: for the statutory retention period applicable to Centola Engineering S.r.l.
- Security and operational logs: for the period needed to protect the service and investigate incidents. Audit records may be retained longer in anonymised or restricted form where needed to document security and compliance.
- Marketing data: until consent is withdrawn, followed by a limited suppression record to respect the opt-out.
- Consent records: for as long as reasonably necessary to demonstrate the choice made and until related legal limitation periods expire.
- Public content: until you make it private or delete it, subject to copies already lawfully made by others and normal cache expiry.
Data may be retained longer when required by law, a court order or the establishment, exercise or defence of legal claims. When the purpose ends, data is deleted or irreversibly anonymised.
9. AI processing and automated decisions
Widemile uses artificial intelligence to generate, analyse or transform content at your request. AI outputs are probabilistic and may be inaccurate. You should review outputs before relying on or publishing them.
Widemile does not use solely automated decision-making that produces legal effects or similarly significant effects on users. Automated systems may help detect abuse, malware or prohibited content; material restrictions can be reviewed through the contact or appeal channel made available with the decision.
10. Content concerning other people
Before uploading content that identifies another person, you must have a valid legal basis and all permissions required for the requested processing and use. Additional care is required for children, voice cloning, realistic likenesses, sensitive contexts and public sharing. Do not upload identity documents, medical information or other highly sensitive data unless the feature expressly requires it and Widemile has provided specific instructions.
11. Children
Widemile is intended exclusively for adults aged 18 or over. People under 18 may not create an account or use the Services, even with permission from a parent or guardian.
We do not knowingly offer the Services to or collect account data from people under 18. If you believe a person under 18 has provided personal data or opened an account, contact us so that we can investigate, close the account and delete the data where appropriate.
12. Security
We use technical and organisational measures designed to protect personal data, including access controls, encrypted transmission, service isolation, logging, backups and least-privilege access. No system is completely secure, and users remain responsible for protecting their credentials and selecting appropriate sharing settings.
13. Your rights
Subject to the conditions of the GDPR, you may request:
- access to your personal data and a copy;
- correction of inaccurate or incomplete data;
- deletion of data;
- restriction of processing;
- data portability;
- objection to processing based on legitimate interests;
- withdrawal of consent at any time, without affecting prior lawful processing;
- information about safeguards used for international transfers.
You may exercise product-level controls in account settings or contact info@centolaengineering.com. We may need to verify your identity. We normally respond within one month, subject to extensions permitted by law.
You may lodge a complaint with the Italian Data Protection Authority or the supervisory authority of your habitual residence, workplace or place of the alleged infringement.
14. Cookies and tracking choices
Details of cookies, local storage, pixels, their durations and available choices are in the Cookie Policy. You can accept, reject or modify optional categories through Cookie Settings in the site footer. Withdrawing consent stops future optional tracking; technologies already stored can also be removed through your browser settings.
15. Changes to this Policy
We may update this Policy when services, providers or legal requirements change. We will publish the new date above and provide additional notice where a change materially affects users or requires a new consent.
16. Contact
Centola Engineering S.r.l.
Contrada Ponzanello Mamurrano 35
04023 Formia (LT), Italy