Privacy Policy

Effective date: 25 June 2026

Your privacy matters to us. This policy explains what data we collect, why we collect it, and what happens to it when you use InkCraft.

1. What We Collect

Information you provide

Information collected automatically

Information you upload

2. How We Use Your Data

| Data | Purpose | |------|---------| | Account data | Authenticate you and sync your saved designs across devices | | Usage analytics | Understand which features are used so we can improve them | | Device metadata | Diagnose compatibility issues, personalise language and region defaults | | Try-on photos | Render the tattoo placement preview — nothing else | | Purchase records | Activate subscriptions, credit packs, and manage billing |

We do not sell your data. We do not use your photos or designs to train AI models.

3. Legal Basis for Processing (GDPR)

If you are in the European Economic Area, we process your data on the following bases:

4. Photo Processing in Detail

When you use the web or app try-on:

  1. Your photo is loaded and displayed locally in your browser or device.
  2. EXIF metadata (including GPS location) is stripped before any data leaves your device.
  3. The photo is transmitted over an encrypted HTTPS connection to our processing server.
  4. Our server renders the tattoo placement and returns the preview image.
  5. The uploaded photo is deleted from server memory at the end of the request. It is not written to persistent storage, logged, or retained in any form.

This is the same posture described in our Terms of Service §5.

5. Data Sharing

We share data with:

All sub-processors are bound by contracts prohibiting them from using your data for their own purposes.

6. Your Rights

Depending on your location, you may have the right to:

To exercise any of these rights, email [email protected]. We will respond within 30 days.

7. Data Retention

8. Security

We use TLS for all data in transit. Firebase security rules restrict access to your data to your own account. Our server infrastructure is access-controlled and audited periodically.

9. Children

The Service is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has provided us data, contact us and we will delete it promptly.

10. Changes to This Policy

We may update this policy. If changes are material, we will notify you via in-app notice or email at least 14 days before they take effect.

11. Contact

Data protection questions: [email protected]