This policy explains how Устинов Данил Романович (we, us, the operator) processes personal data when you use Photique.
1. Controller
Controller: Устинов Данил Романович, an individual applying Russia's special Professional Income Tax regime (NPD), Russian taxpayer identification number (INN) 742210078001, Russian Federation. Privacy requests: privacy@photique.app.
2. Data we process
- Google account ID, email address, and display name used for sign-in and account isolation.
- Uploaded photos and their filename, format, dimensions, hashes, and any embedded EXIF/GPS or information about people and places.
- User prompts, context, instructions, service-selected models, and run parameters.
- AI critiques, scores, edit recipes, generated images, service responses, and saved run materials.
- If you separately publish a photo to a cross-user gallery: author display name, approved original/derivative, score, grade, verdict, and publication status.
- Session, CSRF token, timestamps, run and provider request IDs, operational logs, usage and cost metadata, errors, and abuse-prevention data.
- Cookieless Plausible analytics: normalized page path, referrer/UTM attribution, browser, operating system, device type, country/region/city, and selected product events with allowlisted scalar properties. Plausible transiently uses the request IP and User-Agent for coarse location and a per-site daily visitor hash, but states that it does not store the raw values. We do not send account/user IDs, filenames, photo/media URLs, prompts, critiques, EXIF/GPS, or free-form search text to Plausible.
- Product, purchase channel, purchased access, YooKassa order/payment identifiers, transaction/refund status, and billing support history. We do not receive full payment-card details. Under the NPD regime, income and receipt data are registered in «Мой налог».
- Support messages and information you voluntarily include in them.
We currently use no advertising SDK, do not sell personal data, and do not use it for cross-app tracking.
3. Purposes and legal bases
- Performing the service contract: authentication, private library, critique, remix, and results.
- Legitimate interests: security, abuse prevention, diagnostics, and cost/accounting integrity.
- Legitimate interests: privacy-preserving aggregate measurement of product usage and conversion through cookieless Plausible analytics without persistent identifiers or cross-day, cross-site, or cross-device profiles.
- Contract and legal obligations: billing, refunds, taxes, and required records.
- Separate consent, if introduced: marketing, case studies, external expert review, or training our own models.
- Separate consent for each gallery publication: displaying the selected photo and critique to visitors who may not be signed in. You can withdraw this consent without deleting your account.
The public gallery can be viewed without signing in and shows only projects their owners explicitly publish. Projects remain private by default. Each publication requires a new, recorded choice that clearly permits access by visitors who are not signed in; consent previously given for a private gallery does not apply. Owners can remove their own publications. To report content or request removal, email privacy@photique.app. The app does not currently offer dedicated reporting, user-blocking, or moderation tools.
4. AI processing and recipients
Photos and related prompts are processed by external services. Before the first transfer, the app identifies the active AI providers and asks for your explicit permission. Depending on the services used for your request, recipients may include:
- OpenRouter and the selected model provider for vision critique.
- WaveSpeedAI and the selected model provider for image editing.
- Anthropic for an optional direct critique route.
- Google Gemini API for an optional image route, and Google Identity Services for sign-in.
- Self-hosted Plausible CE for aggregate pageviews and a limited set of product events on infrastructure controlled by the operator. Project and gallery identifiers and user content are removed before transmission. Using the open-source CE software alone does not transmit analytics data to Plausible Insights OÜ.
- Hosting, database, backup, support, and payment providers identified in this policy before they begin processing personal data.
- Anonymous gallery visitors, only for content that the owner explicitly chose to publish and only for the specific photo and details covered by that publication choice.
We require service providers to protect personal data consistently with this policy, our contracts, and applicable law. We review each service's retention and model-training settings before sending it personal data.
5. Retention
- Application session: currently up to 8 hours or until logout.
- Account profile, originals, prompts, critiques, and generated materials: while the account is active or until a verified deletion request. These items do not currently expire automatically.
- Gallery publication: until unpublish, account deletion, or an approved publication expiry; unpublish revokes new access through the app without requiring deletion of the private original, but cannot recall copies that visitors already saved.
- Temporary upload staging: best-effort deletion after a run; crash residue may remain until cleanup.
- Security, accounting, transaction, refund, and audit records: for dispute, fraud-prevention, and mandatory legal periods, with content removed or separated when no longer needed.
- Copies held by external services: under their applicable terms and settings.
- Self-hosted Plausible CE does not store raw IP addresses, User-Agent values, or a persistent visitor ID; its daily visitor salt is deleted every 24 hours. Aggregate site statistics remain until removed under the operator's documented retention schedule.
6. Cookies and browser storage
We use a strictly necessary signed HttpOnly session cookie and a Google CSRF cookie for authentication and security. The session cookie is sent only over HTTPS when the service is accessed over the public internet. Session storage may temporarily hold a safe relative return path. The language preference is stored in local storage under photique:locale and in the photique_locale preference cookie for up to one year; both contain only ru or en. Plausible analytics sets no cookies, local storage values, or persistent visitor identifiers. We use no marketing cookies.
7. International transfers
AI, authentication, and hosting providers may process data outside your country, including the United States and Singapore. Self-hosted analytics is stored in the region used by our host. Where EEA or UK data is transferred internationally, we use the safeguards required by applicable law, such as an adequacy decision or Standard Contractual Clauses.
8. Your rights and deletion
Depending on applicable law, you may request access, a copy, correction, deletion, restriction, portability, or object to processing, and may withdraw consent. Required accounting or legal records may be retained where the law permits or requires it.
You cannot yet start full account deletion inside the app. For now, send deletion requests to privacy@photique.app. Owners can already remove their own gallery publications. Reports and other publication-removal requests are also accepted by email while dedicated in-app reporting is unavailable.
9. Age, content, and security
The service is for adults. Upload content only when you have the necessary rights and permissions. Illegal, exploitative, non-consensual intimate, impersonation, and sexual content involving minors are prohibited. We use per-user isolation, signed sessions, same-origin CSRF checks, upload limits, and access controls, but no system can guarantee absolute security.