HomeLegalPrivacy Policy
Privacy & Data Protection

Privacy Policy

Last Updated: October 2026 • Effective Date: October 2026

At Designer You AI("we", "our", or "us"), your privacy is a paramount priority. This Privacy Policy details how we collect, use, store, share, and protect your information across our web platform and associated mobile applications.

1. Account and Authentication Data

To create and administer your account, we collect necessary identifying information:

  • Email Address: Required to establish your unique account, deliver transactional communications, and facilitate password recovery.
  • Profile Details: Optional full name and profile avatar provided during registration or retrieved via third-party login providers.
  • Authentication Credentials: Managed securely via Supabase Auth using encrypted hash algorithms for email/password authentication or tokenized handshakes for OAuth providers (Google OAuth and GitHub OAuth). We never store plaintext passwords.
  • Session Information: Authenticated tokens, IP addresses, and device user-agents strictly for session authorization and security auditing.

You can browse public pages of our website without creating an account or providing any personal identifying information.

2. Uploaded Room Images

Our core service allows you to redesign your living spaces by uploading photographs of rooms, architecture, or interior layouts:

  • Purpose of Collection: Uploaded images are ingested solely for the purpose of analyzing architectural boundaries, lighting, geometry, and generating the requested redesign variants.
  • Private Storage: Uploaded images are stored in protected, private cloud storage buckets with access controls bound directly to your authenticated user account.
  • No Public Exposure: We never make your uploaded room photos publicly visible without your explicit consent.
  • No Commercial Resale: Your photos are never sold, rented, or licensed to third-party advertisers or data brokers.

3. AI Image Processing & Model Usage

When you initiate an interior redesign request, our automated pipeline processes your images and style preferences:

  • Inference Pipelines: Images and text prompts (style, room type, color themes) are transmitted via encrypted API endpoints to state-of-the-art vision and generative AI models (including OpenAI and Google Cloud AI services).
  • Zero Model Training on User Data: By default under our commercial API agreements, your uploaded personal room images are processed strictly for real-time inference and are not utilized by foundation model providers to train or improve generalized public AI models.
  • Automated Processing Only: Image transformation is performed programmatically by automated systems without human inspection, unless an error report or legal violation investigation is explicitly requested.

4. Generated Images

Images produced by the AI engine based on your prompts and uploads:

  • User Ownership & Access: Generated designs are associated with your account and presented in your private Gallery. You retain the freedom to download, share, or delete them at will.
  • Resolution & Quality: Renderings are stored at the resolution requested (Standard, HD, or Ultra) in dedicated storage volumes.
  • Immediate Removal: Deleting an image from your Gallery immediately deletes the asset link and queues the underlying file for permanent erasure from cloud storage.

5. Credits and Purchases

We maintain an internal credit balance and ledger to manage service usage:

  • Credit Balances: We record purchased credits, bonus credits, and free daily reward claims (such as rewarded ad views) to calculate your available balance.
  • Payment Processing: All financial transactions are securely handled by certified, PCI-DSS compliant payment providers (such as Paddle, Apple App Store, and Google Play Store).
  • No Stored Payment Credentials: Designer You AI never receives, handles, or stores full credit card numbers, CVV security codes, or banking details on our servers.
  • Transaction Logs: We retain order timestamps, plan tiers, transaction references, and amount figures strictly for financial accounting, dispute resolution, and tax obligations.

6. Third-Party Service Providers

We partner with select industry-leading infrastructure providers to deliver reliable and scalable services:

Supabase

Provides enterprise PostgreSQL database storage, secure authentication, and private cloud storage buckets with Row Level Security (RLS).

OpenAI & Google AI

Provides generative AI APIs and computer vision models for rendering architectural room transformations.

Paddle & App Stores

Handles end-to-end checkout, credit card billing, subscriptions, invoices, and applicable sales tax collection.

Render & Cloudflare

Provides global application hosting, TLS/SSL certificate management, DDoS mitigation, and edge caching.

7. Data Storage and Security

We employ comprehensive technical and organizational safeguards to shield your data against unauthorized access, loss, or alteration:

  • Encryption in Transit: All web and API traffic is encrypted end-to-end using TLS 1.3 / HTTPS.
  • Encryption at Rest: Database records and object storage volumes are encrypted at rest using industry-standard AES-256 encryption.
  • Row Level Security (RLS): Granular PostgreSQL security policies ensure that database queries executed on behalf of a user can only access records belonging to that user.
  • Secure Access Tokens: Sessions are authenticated using signed JWT tokens with automated expiration and refresh cycles.

8. Data Retention and Deletion

We adhere to strict data minimization principles:

  • Active Account Lifetime: Account records, credits, and generation histories are maintained as long as your account remains open.
  • Manual Image Deletion: You may delete any image generation directly from your account gallery at any time. When deleted, the image and metadata are permanently removed.
  • Statutory Financial Retention: Purchase receipt references and payment histories are retained for mandatory legal, tax, and audit retention periods (typically up to 7 years) as required by financial regulations.

9. Account Deletion

You have the absolute right to terminate your account and erase all associated personal data permanently.

How to Request Deletion:

  • Dedicated Deletion Page: Submit an automated deletion request via our public Account Deletion Portal
  • Mobile Application: Navigate to Account → Delete Account within the Designer You AI mobile app.
  • Direct Email: Send an email from your registered address to support@designeryouai.com.

Upon deletion, your profile, authentication records, uploaded photos, AI-generated images, and active credit balances are irreversibly purged.

10. Privacy Requests & Your Legal Rights

Regardless of your geographic location (including under GDPR, UK GDPR, and CCPA / CPRA), we uphold your fundamental privacy rights:

Right to Access:Request a copy of the personal information we hold about you.
Right to Rectification:Request corrections to any inaccurate or incomplete personal details.
Right to Erasure:Request complete deletion of your personal records ("Right to be Forgotten").
Right to Data Portability:Receive your personal information in a structured, commonly used format.
Right to Restrict Processing:Limit how we process your information under specific circumstances.
Right to Non-Discrimination:We will never discriminate against you for exercising your privacy rights.

To exercise any of these rights, email us at support@designeryouai.com. We verify requests and respond within 30 days.

11. Children's Privacy

Designer You AI does not knowingly collect, solicit, or maintain personal information from individuals under the age of 13 (or under 16 where required by European Union member state legislation). If you believe a minor has provided us with personal information, please notify us immediately at support@designeryouai.com, and we will promptly purge such data.

12. Changes to This Privacy Policy

We may revise this Privacy Policy periodically to reflect technological enhancements, legal mandates, or product updates. The latest version will always be available at /privacy-policywith the "Last Updated" date clearly displayed. Material changes will be communicated via in-app banner or email notification.

13. Contact Information

If you have questions, feedback, or privacy-related requests regarding this Privacy Policy or our data handling practices, please contact our data protection team: