Last updated: 2025-08-04
1. Information We Collect
Personal Information
- Email address (for account access via magic links and communication)
- Usage data and preferences
Content Data
- Images you upload for sketch generation
- Generated sketches and processing metadata
- Usage patterns and service interactions
2. How We Use Your Information
- Process your images to generate step-by-step sketches
- Store and retrieve your images and generated content
- Send magic links for secure account access
- Provide customer support and respond to inquiries
- Improve our service through aggregated, anonymized analytics
- Send essential service communications
3. Data Storage and Location
Your data is stored and processed using the following infrastructure:
- Server Hosting: Linode (EU data centers)
- Database Backups: Backblaze (EU region)
- Image Storage: Cloudflare R2 (EU data residency)
- DNS & CDN: Cloudflare (EU-based infrastructure)
- Error Monitoring: Sentry (with EU data residency options)
4. Data Sharing and Third Parties
We share your data only with essential service providers:
EU-Based Providers
- MailGun: For sending magic links and essential communications
- Linode: For server hosting and data processing
- Backblaze: For secure data backups
- Cloudflare: For DNS, CDN, and image storage
- Sentry: For error monitoring and service reliability
Non-EU Providers (with Adequate Safeguards)
-
OpenAI:
For AI-powered image processing and sketch generation (covered by data processing agreements)
-
Stripe:
For secure payment processing (certified under Privacy Shield successor frameworks)
We do not sell or share your personal data with third parties for marketing purposes. All data transfers to non-EU providers are protected by appropriate safeguards including Standard Contractual Clauses.
5. Data Retention
- Uploaded images and generated sketches are retained while your account is active
- Account data is retained until you request deletion
- Backups may retain data for up to 90 days after deletion
- Aggregated, anonymized analytics data may be retained indefinitely
6. Your Rights (GDPR)
As an EU data subject, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to certain types of processing
7. Data Security
- All data transmission is encrypted using HTTPS/TLS
- Secure magic link authentication (no passwords stored)
- Regular security updates and monitoring
- Automated backups with encryption at rest
- Access controls and audit logging
8. Cookies and Tracking
We use essential cookies for service functionality (session management, authentication). We do not use tracking cookies or third-party analytics that collect personal data.
9. Children's Privacy
Our service is not directed to children under 16. We do not knowingly collect personal information from children under 16.
10. Changes to This Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. We will notify users of significant changes via email or service notifications.
11. Contact Us
For privacy-related questions, data requests, or to exercise your rights, please contact us at [email protected].
12. Legal Basis for Processing
We process your data based on:
- Contract: To provide the sketch generation service you requested
-
Legitimate Interest:
To improve our service and provide customer support
-
Consent: For optional features or communications (where applicable)