Privatlivspolitik
Senest opdateret: 12. august 2026
1. Information We Collect
When you use Photta, we collect the following types of information:
- Account Information: Email address, full name, password (encrypted and hashed), profile image, and language preference.
- Payment Information: Processed securely through our payment provider. We do not store your credit card details on our servers.
- Content: Images, photos, and files you upload for AI processing, as well as AI-generated content created through our services.
- Usage Data: Credits consumed, generations created, features used, subscription history, templates saved, and interaction patterns.
- Technical Data: Browser type and version, IP address, device information, operating system, screen resolution, and referring URLs.
- Location Data: Approximate geolocation derived from your IP address, used for currency detection and service optimization.
2. How We Use Your Information
- Providing, maintaining, and improving our AI-powered fashion photography services
- Processing payments, managing subscriptions, and allocating credits
- Storing, delivering, and enabling downloads of your generated content
- Communicating with you about your account, service updates, and promotional offers (with your consent)
- Preventing fraud, detecting misuse, and ensuring platform security
- Enforcing our Acceptable Use Policy and moderating content
- Analyzing platform usage to improve performance, features, and user experience
3. Lawful Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
- Consent: For marketing communications, analytics cookies, and optional data processing. You can withdraw consent at any time.
- Contractual Necessity: To provide our services, process payments, manage subscriptions, and deliver AI-generated content as agreed in our Terms of Service.
- Legitimate Interests: For fraud prevention, platform security, service improvement, and enforcing our policies against misuse.
- Legal Obligation: To comply with applicable laws, regulations, and legal processes, including tax and accounting requirements.
4. Third-Party Services
To provide our services, we share your data with the following categories of third-party providers:
- Payment Processor: Handles subscription and credit pack payments securely. We use industry-standard payment processors that are PCI DSS compliant.
- Cloud Storage (AWS): Amazon Web Services stores your uploaded images and generated content securely with encryption at rest and in transit.
- AI Processing Services: Third-party AI providers process your images to generate fashion photos, videos, upscaling, background removal, and other AI enhancements.
- AI-behandlingsleverandører: Dine billeder behandles af Kie.ai, Google (Gemini), fal.ai, Replicate og ApiMart. Disse leverandører handler udelukkende efter vores instruks for at skabe det resultat, du har bedt om, og bruger ikke dit indhold til at træne deres modeller.
- Authentication Provider: Google OAuth for optional social sign-in functionality.
- Analytics Services: Google Analytics (GA4), Vercel Analytics, and Vercel Speed Insights for understanding platform usage and performance. Meta Pixel for advertising measurement.
Important: When you use our AI features, your images are transmitted to third-party AI processing services to generate results. By using our services, you consent to this processing.
Your uploaded images and generated content are NOT used to train AI models. Third-party AI providers process your data solely to deliver the requested service and do not retain your content for training purposes.
5. Cookies & Tracking Technologies
We use cookies and similar technologies to enhance your experience. You can manage your preferences through our cookie consent banner.
5.1 Essential Cookies (Always Active)
- Authentication session cookies to keep you logged in
- Language and locale preference cookies
- Security cookies for fraud prevention (CSRF tokens)
5.2 Analytics Cookies (Requires Consent)
- Google Analytics (GA4): Measures site usage, page views, and user journeys. Data retained for 14 months.
- Vercel Analytics: Collects anonymized performance and usage metrics.
- Vercel Speed Insights: Monitors Core Web Vitals and page load performance.
5.3 Marketing Cookies (Requires Consent)
- Meta Pixel: Measures advertising effectiveness and enables retargeting on Meta platforms (Facebook, Instagram).
Du kan til enhver tid ændre dine cookieindstillinger uden at rydde dine browserdata. På dette website kan du åbne linket "Cookieindstillinger", som findes på vores sider, for at få samtykkebanneret frem igen og ændre dit valg. I Photta-appen finder du de samme indstillinger under Indstillinger i afsnittet Præferencer.
6. Data Retention
- Account Data: Opbevares, så længe din konto er aktiv. Når du lukker din konto, slettes dine data straks, bortset fra din e-mailadresse, som vi opbevarer på ubestemt tid som dokumentation for, at kontoen har eksisteret, så den ikke gentagne gange kan lukkes og oprettes igen for at opnå nye startkreditter. Navn, adgangskode, profilbillede og betalingsidentifikatorer slettes ved lukningen.
- Generated Content: Opbevares, så længe din konto er aktiv. Du kan når som helst slette enkelte kreationer; slettede elementer bliver i papirkurven i 30 dage, før de fjernes permanent. Når du lukker din konto, slettes alle uploadede billeder og genereret indhold straks.
- Payment Records: Opbevares, så længe din konto er aktiv, og slettes, når du lukker den. Vi opbevarer ikke din faktureringshistorik efter lukningen. Oplysninger, som vores betalingsudbyder opbevarer, er omfattet af udbyderens egen opbevaringspolitik.
- Server Logs & Analytics: API-anmodningslogfiler slettes efter 31 dage. Forbrugs- og aktivitetsregistreringer, aggregeret forbrugsstatistik og serverlogfiler har ingen fast frist; de registreringer, der er knyttet til dig, slettes eller adskilles fra din identitet, når du lukker din konto. Analysedata, som vores analyseudbydere opbevarer, gemmes i 14 måneder.
- Supportkorrespondance: E-mails sendt til vores supportadresse samt vores svar herpå opbevares i 4 år. Derefter slettes beskedernes indhold og eventuelle vedhæftede filer, mens der bevares en registrering af, at korrespondancen har fundet sted, og hvornår. Du kan til enhver tid bede om at få dem slettet tidligere.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right of Access: Request a copy of all personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data ("Right to be Forgotten"). Note: some data may be retained for legal obligations.
- Right to Data Portability: Anmod om en kopi af dine personoplysninger i et struktureret og almindeligt anvendt format. Der findes ingen selvbetjeningseksport; skriv til [email protected], og vi udleverer dine data inden for 30 dage.
- Right to Object: Object to processing of your personal data for direct marketing or based on legitimate interests.
- Right to Restrict Processing: Request that we limit how we use your data in certain circumstances.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
If you are located in the European Economic Area (EEA), you have the right to lodge a complaint with your local data protection supervisory authority.
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know what personal information we collect, use, and disclose
- Right to request deletion of your personal information
- Right to opt-out of the sale or sharing of personal information
- Right to non-discrimination for exercising your privacy rights
Photta does not sell your personal information. We do not share personal information for cross-context behavioral advertising purposes.
9. Acceptable Use & Content Moderation
Photta is designed for professional fashion and product photography. We monitor and enforce content guidelines to maintain a safe and appropriate platform for all users.
9.1 Prohibited Content
- Pornographic, sexually explicit, or obscene content
- Content depicting or promoting violence, gore, or self-harm
- Child sexual abuse material (CSAM) or any content involving minors in inappropriate contexts
- Hate speech, discriminatory content, or content promoting terrorism
- Content that infringes on intellectual property rights, trademarks, or copyrights of others
- Fraudulent, deceptive, or misleading content designed to deceive consumers
- Any content that violates applicable local, national, or international laws
9.2 Enforcement Actions
Photta reserves the right to take the following actions, with or without prior notice, if violations are detected:
- Issuing a warning notification to the account holder
- Reducing or revoking the user's remaining credits
- Temporarily suspending account access
- Permanently deleting the account and all associated data
- Reporting illegal content to relevant law enforcement authorities
In cases of severe violations (such as CSAM, terrorism, or illegal activity), Photta may immediately and permanently terminate the account without prior warning and report the incident to appropriate authorities.
10. Automated Decision-Making
Photta may use automated systems to detect content policy violations and prevent platform misuse. These systems analyze uploaded content and generated results for compliance with our Acceptable Use Policy.
If your account is affected by an automated decision, you have the right to request a human review by contacting [email protected]. We will review your case within 5 business days.
11. Data Security
We implement industry-standard security measures to protect your personal data:
- HTTPS/TLS encryption for all data transmitted between your device and our servers
- Encrypted and hashed password storage using modern cryptographic algorithms
- Kryptering i hvile af uploadede billeder og genereret indhold, der opbevares i Amazon Web Services' objektlagring
- JWT-based authentication with automatic token rotation and multi-tab session management
- Regular security audits and vulnerability assessments
12. International Data Transfers
Dine data opbevares på servere i Tyrkiet. Uploadede billeder og genereret indhold opbevares hos vores cloud-lagringsudbyder på servere i Den Europæiske Union. Hvis du tilgår Photta uden for disse regioner, vil dine oplysninger blive overført til og behandlet i Tyrkiet og Den Europæiske Union.
For users in the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for international data transfers.
For at kunne frembringe de resultater, du beder om, videresendes dine billeder til de AI-behandlingsleverandører, der er nævnt i afsnit 4. Nogle af disse leverandører samt de dér nævnte analyse- og fejlovervågningstjenester opererer uden for Tyrkiet og Den Europæiske Union, herunder i USA.
13. Progressive Web App & Offline Data
Photta offers Progressive Web App (PWA) functionality for an enhanced mobile experience. When installed:
- A service worker caches static assets (images, scripts, styles) on your device for faster loading and offline access.
- Your authentication session and user preferences are stored locally on your device.
- No personal content or generated images are cached offline. All generated content remains on our secure cloud servers.
14. Children's Privacy
Photta is not intended for users under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected data from a child under 18, we will promptly delete that information. If you believe a child has provided us with personal data, please contact us at [email protected].
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated policy on our website and updating the "Last Updated" date. For significant changes, we may also notify you via email or in-app notification. Your continued use of Photta after changes are posted constitutes acceptance of the updated policy.