This policy explains how [LEGAL_ENTITY_NAME] (we, us, the operator) processes personal data when you use Photique. The Russian version is available here.
1. Controller
Controller: [LEGAL_ENTITY_NAME], registration number [COMPANY_REGISTRATION_NUMBER], [BUSINESS_ADDRESS], [COUNTRY]. Privacy requests: [PRIVACY_EMAIL].
2. Data we process
- Google account ID, email address, and display name used for sign-in and account isolation.
- Uploaded photos and their filename, format, dimensions, hashes, and any embedded EXIF/GPS or information about people and places.
- User prompts, context, instructions, selected models, and run parameters.
- AI critiques, scores, edit recipes, generated images, provider responses, and saved run artifacts.
- If you separately publish a photo to a cross-user gallery: author display name, approved original/derivative, score, grade, verdict, and publication status.
- Session, CSRF token, timestamps, run and provider request IDs, operational logs, usage and cost metadata, errors, and abuse-prevention data.
- If paid features are introduced: product, purchase channel, entitlement, transaction/refund status, and billing support history. We do not receive full payment-card details.
- Support messages and information you voluntarily include in them.
We currently use no advertising SDK, do not sell personal data, and do not use it for cross-app tracking.
3. Purposes and legal bases
- Performing the service contract: authentication, private library, critique, remix, and results.
- Legitimate interests: security, abuse prevention, diagnostics, and cost/accounting integrity.
- Contract and legal obligations: billing, refunds, taxes, and required records.
- Separate consent, if introduced: marketing, case studies, external expert review, or training our own models.
- Fresh, versioned public-web per-photo consent: displaying a user photo and critique to anonymous gallery visitors, revocable without deleting the entire account.
The current localhost beta gallery is anonymously readable and always shows four explicitly approved, curated, metadata-stripped examples. User projects remain private by default and appear only after a fresh, versioned public-web per-photo opt-in that expressly covers anonymous access; older authenticated-gallery consent is not grandfathered. External public-community deployment remains blocked until moderation, reporting, and blocking controls exist.
4. AI processing and recipients
Photos and related prompts are processed off-device. Before the first transfer, the app must name the active third-party AI providers and obtain explicit permission. Depending on the production configuration, recipients may include:
- OpenRouter and the selected model provider for vision critique.
- WaveSpeedAI and the selected model provider for image editing.
- Anthropic for an optional direct critique route.
- Google Gemini API for an optional image route, and Google Identity Services for sign-in.
- Production hosting, database, backup, support, and payment providers disclosed before launch.
- Anonymous gallery visitors, only for content that the owner explicitly chose to publish and only within the fresh selected public-web publication scope.
We require service providers to protect personal data consistently with this policy, our contracts, and applicable law. Endpoint-specific retention and training settings are reviewed before release.
5. Retention
- Application session: currently up to 8 hours or until logout.
- Account profile, originals, prompts, critiques, and generated artifacts: while the account is active or until a verified deletion request. The current build has no automatic retention expiry.
- Gallery publication: until unpublish, account deletion, or an approved publication expiry; unpublish revokes new access through the app without requiring deletion of the private original, but cannot recall copies that visitors already saved.
- Temporary upload staging: best-effort deletion after a run; crash residue may remain until cleanup.
- Security, accounting, transaction, refund, and audit records: for dispute, fraud-prevention, and mandatory legal periods, with content removed or separated when no longer needed.
- Provider copies: under the active provider terms and endpoint settings.
6. Cookies and browser storage
We use a strictly necessary signed HttpOnly session cookie and a Google CSRF cookie for authentication and security. The production cookie is sent only over HTTPS. Session storage may temporarily hold a safe relative return path. We currently use no optional analytics or marketing cookies.
7. International transfers
AI, authentication, and hosting providers may process data outside your country, including the United States and Singapore. Before EEA/UK release, the operator must document hosting regions, processor contracts, and applicable safeguards such as an adequacy decision or Standard Contractual Clauses.
8. Your rights and deletion
Depending on applicable law, you may request access, a copy, correction, deletion, restriction, portability, or object to processing, and may withdraw consent. Required accounting or legal records may be retained where the law permits or requires it.
Before an iOS release, the app must allow users to initiate full account deletion from Account settings without requiring an email to support. Until that flow exists, beta deletion requests may be sent to [PRIVACY_EMAIL]; this temporary process is not App Store-ready. A separate in-app gallery unpublish/report flow is also required.
9. Age, content, and security
The service is for adults. Upload content only when you have the necessary rights and permissions. Illegal, exploitative, non-consensual intimate, impersonation, and sexual content involving minors are prohibited. We use per-user isolation, signed sessions, same-origin CSRF checks, upload limits, and access controls, but no system can guarantee absolute security.