Picty — Privacy Policy

_Last updated October 6, 2026_

How Picty collects, uses and protects your data — especially your photos.

1. Who we are

This Privacy Policy explains how Picty handles your personal data. The data controller is Ulrich Reuther (Germany), operator of the Picty app. Full contact and Impressum details are in Section 18. We take the privacy of your photos especially seriously, because Picty is built around them.

2. Age requirement

Picty is for users aged 13 and over (and at least the minimum digital-consent age in your country, up to 16 in the EU). We do not knowingly collect personal data from children under 13. If you believe a child has given us data, contact hello@picty.app and we will delete it.

3. The data we collect

Data you give us

  • Account data: email address and/or name, depending on how you sign in (Apple, Google or email). As a guest you give us neither; we only create a random account ID.
  • Photos you upload of yourself, and any reference or outfit photos you add.
  • Onboarding answers you choose to give: gender (or “prefer not to say”), age (optional), your goals and style preferences. We use them to suggest scenes and looks; gender also decides which version of a scene preview you see. You can change gender and age in Settings › About you.
  • Profile data: optional username, display name, avatar and the content you choose to make public.
  • Reports you send about content or other users (the reason and any details you add).
  • Messages you send us for support or feedback, including screenshots you attach.

Data created when you use the app

  • Generated images and the settings used to create them.
  • Purchase data: your subscription status and credit purchases (processed by Apple/Google and RevenueCat).
  • Usage and diagnostics: device platform, app version, language, screen visits and foreground-visible screen time, generation outcomes, saves, exports, sharing actions, paywall interactions and subscription lifecycle. Foreground time is not a measurement of attention. We use these events to understand onboarding drop-off, feature usage and retention. Session and installation identifiers are pseudonymous and may be linked to your account when you sign in; they are not anonymous data.
  • Identifiers: an account ID and device/app identifiers.
  • Abuse prevention: a server-keyed fingerprint (HMAC) of your normalized email address and the dates of your one-time starter-credit grant and account deletion. This is pseudonymous personal data, not an anonymous record.
  • Your choices: when you agreed to the community rules (and which version), and whether you allowed AI photo processing and usage analytics.

Guest accounts

You can use Picty without an email address. Picty then creates a guest account with a random account ID on your device and stores the same kinds of data as for any account — the photos you add, the images you create, your purchases and settings. If you sign out of a guest account or delete the app before adding a login, you can no longer access it. You can delete a guest account and all of its data at any time in the app under Settings › Delete Account — no email address or sign-in needed. Guest accounts you no longer use are deleted under the rules in Section 11.

4. Your photos & facial data

Picty processes photos of your face to generate your portraits. Depending on where you live, facial images can be considered biometric or special-category personal data, so we treat them with extra care.

  • We process your face photos only to provide the service — to generate and edit the images you ask for.
  • We do not use facial recognition to identify you, build a searchable faceprint, or track you across other services.
  • We do not sell, rent or trade your photos or any biometric data, ever.
  • We process face photos on the basis of your explicit consent, which you can withdraw at any time in Settings › AI photo processing, or by deleting your photos or your account.
  • We keep your photos only as long as needed for the service and delete them when you remove them or close your account (see Section 11).

5. How we use your data

We use your data to:

  • Generate and edit your AI images and run the core features of the app;
  • Create and secure your account and authenticate you;
  • Process subscriptions and credit purchases;
  • Operate optional social features you turn on;
  • Keep the service safe — moderation, abuse prevention and enforcing our Terms;
  • Provide support and respond to your requests;
  • Comply with our legal obligations.

6. Legal bases (GDPR)

  • Your explicit consent — for processing your face photos to generate images (Art. 6(1)(a) and Art. 9(2)(a) GDPR). You can withdraw it at any time.
  • Your consent — for optional product-usage analytics in app builds that offer the Usage analytics control (Art. 6(1)(a)). This separate, device-local choice is off until you agree and does not affect access to app features.
  • Performance of a contract — to provide the account, generations and purchases you request (Art. 6(1)(b)).
  • Our legitimate interests — to keep the service secure, prevent abuse and improve it (Art. 6(1)(f)).
  • Legal obligation — where the law requires us to process or retain data (Art. 6(1)(c)).

7. How your images are generated (AI processing)

With your explicit permission, we send the photos you select (including faces), prompts and edit instructions to OpenAI and/or Google Gemini to analyze scenes, perform safety checks and create or edit the images you request. The in-app consent explains this sharing before processing starts; you may decline and still use the app without AI features. Photos are stored using Supabase. You can withdraw this permission at any time in Settings › AI photo processing; Picty then stops sending your photos and prompts to these providers until you allow it again. To also remove the photos themselves, delete them or your account.

  • Under OpenAI’s API data-usage policy, data sent through the API is not used to train OpenAI’s models.
  • AI providers may retain inputs and outputs for safety, abuse monitoring or legal obligations. Standard OpenAI abuse-monitoring retention is up to 30 days, with exceptions; Google Gemini abuse-monitoring retention is 55 days. Deleting a Picty photo does not instantly erase provider safety logs.
  • Google Gemini paid API services do not use prompts and responses to improve Google products. Picty must use a billing-enabled project for this processing; we do not opt user photos into model-training datasets.
  • We use AI only to generate the images you request, plus automated safety checks — not to identify or profile you.

8. Who we share data with

We do not sell your personal data. We share it only with service providers (“processors”) that help us run Picty, under contracts that require them to use it only for us and to protect it with the same or an equivalent level of protection as this Privacy Policy:

  • OpenAI (United States) — AI image generation, image analysis and safety moderation. Shared: selected photos, faces, edit instructions and generation prompts.
  • Supabase (European Union (eu-west-1)) — Database, file storage and authentication. Shared: account data (including guest accounts), photos, generated images, usernames, onboarding answers and reports.
  • RevenueCat (United States) — Subscription and credit-purchase management. Shared: purchase history, app-user and device identifiers.
  • PostHog (EU Cloud, when enabled) (European Union) — Product analytics: funnels, retention and feature usage. Shared: pseudonymous account/session identifiers, app events and subscription lifecycle; no photos, prompts, names or email addresses.
  • Apple (United States / global) — App distribution, payments, Sign in with Apple. Shared: purchase data, authentication tokens.
  • Google (United States / global) — Gemini AI image generation and analysis; Google sign-in. Shared: selected photos, faces, prompts and edit instructions; authentication tokens if you sign in with Google.
  • Expo (650 Industries) (United States) — Delivering app updates (EAS Update). Shared: technical data such as app and runtime version, device platform, an update installation ID and IP address; no photos or account content.
  • Voyage AI (United States) — Image embeddings that help sort and recommend scenes in Discover. Shared: scene images from the Picty catalogue, which can include scenes users publish; never the photos of yourself that you add as references.
  • ALL-INKL.COM – Neue Medien Münnich (Germany) — Hosting of the picty.app website and email for support and in-app feedback. Shared: messages, contact details and screenshots you send us; website server logs.

We may also disclose data where required by law, to protect our rights or users’ safety, or in connection with a business transfer, in which case we will notify you.

9. Public & social features

If you set a public username, make your profile public, or publish uploads, that information becomes visible to other users and through people-search. Public content is not private — please don’t publish anything you wouldn’t want others to see. You can make content private again or delete it at any time.

10. International data transfers

Your account data and images are stored in the European Union (Supabase, eu-west-1). Some providers, including OpenAI, Google, RevenueCat, Apple, Expo and Voyage AI, process data in the United States. Where data leaves the EU/EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

11. How long we keep your data

  • Uploaded photos and generated images: kept while your account is active; deleted when you remove them or delete your account.
  • Face/biometric data: never kept longer than needed for the service, and in any case destroyed when you delete your photos or account, or within three years of your last use, whichever is first.
  • Account and profile data, including onboarding answers and your community-rules acceptance: kept for the life of your account.
  • Guest accounts: kept while you use them. A guest account you no longer use is deleted, with its photos and images, at the latest three years after its last use. You can delete it yourself at any time in the app.
  • Reports you send: kept while they are reviewed and as long as needed to protect users; removed when you delete your account.
  • Onboarding preview originals and results: expire after 24 hours. Claimed copies are retained in your Gallery; temporary originals are queued for removal after claiming. Scheduled cleanup runs every 15 minutes and retries failures.
  • One-time starter-credit abuse prevention: the keyed email fingerprint and minimal grant/deletion timestamps remain after account deletion while the one-time credit offer operates, solely to prevent repeated claims. They are not used for advertising or to recover your deleted photos. You may contact us to object to or request review of this limited retention.
  • Purchase and transaction records: kept as long as required by tax and accounting law (generally up to 10 years in Germany).
  • Product analytics in our database: retained for up to 180 days. Events awaiting delivery are buffered on the device for up to 7 days; server delivery copies are kept for up to 7 days. Account deletion removes associated analytics, including linked events from before sign-in. If PostHog EU is enabled, deletion requests also cover analytics already sent there.
  • In app builds with Settings > Usage analytics, you can turn off new optional screen and feature events at any time. Turning it off discards unsent device events and attempts to stop an in-flight transfer; it does not automatically erase data already received. Contact us or delete your account to request deletion of associated data. The preference applies to this device, including subsequent sign-ins. Records required for accounts, purchases, service security and legal obligations are separate. Older builds do not have this control; update when an updated build is available.
  • Analytics does not contain your photos, image prompts, email address, name or typed search terms. Screen recording and session replay are disabled. A daily keyed IP digest may be kept for up to 2 days solely to rate-limit analytics ingestion; raw IP addresses are not written to our analytics tables.
  • Other diagnostics and security logs: kept for a short period for security and troubleshooting.

12. How we protect your data

We use encryption in transit, access controls and reputable infrastructure providers to protect your data. Each user’s photos and content are isolated by row-level security so other users cannot access them. No system is perfectly secure, but we work to keep your data safe and will notify you and the authorities of a breach where the law requires.

13. Your rights

Everyone

You can delete your account and all associated personal data at any time in the app under Settings › Delete Account (or Help & Support › Delete Account). This also works for guest accounts — no email address or sign-in needed. You can also delete individual photos and generations, and switch AI photo processing and usage analytics off in Settings.

EU/EEA & UK (GDPR)

  • Access, rectify, erase or restrict processing of your data;
  • Data portability;
  • Object to processing based on legitimate interests;
  • Withdraw consent at any time, without affecting prior processing;
  • Lodge a complaint with your data-protection authority.

California (CCPA/CPRA)

  • Know, access, correct and delete your personal information;
  • Limit the use of sensitive personal information (including biometric data);
  • Opt out of “sale” or “sharing” — note we do not sell or share your personal information, and never your biometric data;
  • Non-discrimination for exercising your rights.

To exercise any right, use the in-app controls or email hello@picty.app.

14. We do not sell or share your data

We do not sell your personal information and do not share it for cross-context behavioral advertising. We honor recognized opt-out preference signals, such as Global Privacy Control, where they apply.

15. Tracking & advertising identifiers

Picty does not track you across other companies’ apps or websites for advertising. If we ever ask to access your device’s advertising identifier, iOS will show you the App Tracking Transparency prompt first, and you can decline. We use only the analytics and diagnostics needed to run and improve the app.

16. Children’s privacy

Picty is not intended for children under 13, and we do not knowingly collect their data. Parents or guardians who believe their child has used the app can contact hello@picty.app to have the data deleted.

17. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app or by other appropriate means. The “last updated” date below always reflects the current version.

18. Contact & Impressum

For privacy questions or to exercise your rights, email hello@picty.app. For general help, email hello@picty.app.

Impressum (§5 DDG / §18 MStV)

  • Ulrich Reuther
  • Willibald-Alexis-Straße 25
  • 10965 Berlin
  • Germany
  • Email: hello@picty.app

Responsible for content under §18 (2) MStV: Ulrich Reuther. Operator and data controller for the purposes of the GDPR: Ulrich Reuther.