Politica de Privacidade

Última atualização: 12 de agosto de 2026

1. Information We Collect

When you use Photta, we collect the following types of information:

  • Account Information: Email address, full name, password (encrypted and hashed), profile image, and language preference.
  • Payment Information: Processed securely through our payment provider. We do not store your credit card details on our servers.
  • Content: Images, photos, and files you upload for AI processing, as well as AI-generated content created through our services.
  • Usage Data: Credits consumed, generations created, features used, subscription history, templates saved, and interaction patterns.
  • Technical Data: Browser type and version, IP address, device information, operating system, screen resolution, and referring URLs.
  • Location Data: Approximate geolocation derived from your IP address, used for currency detection and service optimization.

2. How We Use Your Information

  • Providing, maintaining, and improving our AI-powered fashion photography services
  • Processing payments, managing subscriptions, and allocating credits
  • Storing, delivering, and enabling downloads of your generated content
  • Communicating with you about your account, service updates, and promotional offers (with your consent)
  • Preventing fraud, detecting misuse, and ensuring platform security
  • Enforcing our Acceptable Use Policy and moderating content
  • Analyzing platform usage to improve performance, features, and user experience

3. Lawful Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:

  • Consent: For marketing communications, analytics cookies, and optional data processing. You can withdraw consent at any time.
  • Contractual Necessity: To provide our services, process payments, manage subscriptions, and deliver AI-generated content as agreed in our Terms of Service.
  • Legitimate Interests: For fraud prevention, platform security, service improvement, and enforcing our policies against misuse.
  • Legal Obligation: To comply with applicable laws, regulations, and legal processes, including tax and accounting requirements.

4. Third-Party Services

To provide our services, we share your data with the following categories of third-party providers:

  • Payment Processor: Handles subscription and credit pack payments securely. We use industry-standard payment processors that are PCI DSS compliant.
  • Cloud Storage (AWS): Amazon Web Services stores your uploaded images and generated content securely with encryption at rest and in transit.
  • AI Processing Services: Third-party AI providers process your images to generate fashion photos, videos, upscaling, background removal, and other AI enhancements.
  • Provedores de processamento de IA: Suas imagens são processadas por Kie.ai, Google (Gemini), fal.ai, Replicate e ApiMart. Esses provedores agem apenas sob nossas instruções para gerar o resultado solicitado e não usam seu conteúdo para treinar seus modelos.
  • Authentication Provider: Google OAuth for optional social sign-in functionality.
  • Analytics Services: Google Analytics (GA4), Vercel Analytics, and Vercel Speed Insights for understanding platform usage and performance. Meta Pixel for advertising measurement.

Important: When you use our AI features, your images are transmitted to third-party AI processing services to generate results. By using our services, you consent to this processing.

Your uploaded images and generated content are NOT used to train AI models. Third-party AI providers process your data solely to deliver the requested service and do not retain your content for training purposes.

5. Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your experience. You can manage your preferences through our cookie consent banner.

5.1 Essential Cookies (Always Active)

  • Authentication session cookies to keep you logged in
  • Language and locale preference cookies
  • Security cookies for fraud prevention (CSRF tokens)

5.2 Analytics Cookies (Requires Consent)

  • Google Analytics (GA4): Measures site usage, page views, and user journeys. Data retained for 14 months.
  • Vercel Analytics: Collects anonymized performance and usage metrics.
  • Vercel Speed Insights: Monitors Core Web Vitals and page load performance.

5.3 Marketing Cookies (Requires Consent)

  • Meta Pixel: Measures advertising effectiveness and enables retargeting on Meta platforms (Facebook, Instagram).

Você pode alterar suas preferências de cookies a qualquer momento, sem limpar os dados do seu navegador. Neste site, abra o link "Preferências de cookies" disponível em nossas páginas para exibir novamente o banner de consentimento e alterar sua escolha. No aplicativo Photta, os mesmos ajustes ficam em Configurações, na seção Preferências.

6. Data Retention

  • Account Data: Mantidos enquanto sua conta estiver ativa. Ao encerrar sua conta, seus dados são excluídos imediatamente, exceto seu endereço de e-mail, que mantemos por tempo indeterminado como registro de que a conta existiu, para que ela não possa ser encerrada e reaberta repetidamente a fim de obter novamente os créditos de nova conta. Seu nome, senha, imagem de perfil e identificadores de pagamento são apagados no encerramento.
  • Generated Content: Armazenado enquanto sua conta estiver ativa. Você pode excluir criações individuais a qualquer momento; os itens excluídos permanecem 30 dias na Lixeira antes da remoção definitiva. Ao encerrar sua conta, todas as imagens enviadas e o conteúdo gerado são excluídos imediatamente.
  • Payment Records: Mantidos enquanto sua conta estiver ativa e excluídos quando você a encerra. Não mantemos seu histórico de faturamento após o encerramento. Os registros mantidos pelo nosso provedor de pagamentos estão sujeitos à política de retenção desse provedor.
  • Server Logs & Analytics: Os registros de solicitações da API são excluídos após 31 dias. Os registros de uso e atividade, as estatísticas de uso agregadas e os logs do servidor não têm prazo fixo; os registros vinculados a você são excluídos ou desvinculados da sua identidade quando você encerra sua conta. Os dados analíticos mantidos por nossos provedores de análise são retidos por 14 meses.
  • Correspondência de suporte: Os e-mails enviados ao nosso endereço de suporte, e as nossas respostas, são mantidos por 4 anos. Após esse prazo, o conteúdo das mensagens e eventuais anexos são excluídos, enquanto é mantido um registro de que a conversa ocorreu e de quando ocorreu. Você pode solicitar a exclusão antecipada a qualquer momento.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Right of Access: Request a copy of all personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data ("Right to be Forgotten"). Note: some data may be retained for legal obligations.
  • Right to Data Portability: Solicite uma cópia dos seus dados pessoais em um formato estruturado e de uso comum. Não há exportação de autoatendimento; escreva para [email protected] e forneceremos seus dados em até 30 dias.
  • Right to Object: Object to processing of your personal data for direct marketing or based on legitimate interests.
  • Right to Restrict Processing: Request that we limit how we use your data in certain circumstances.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting prior processing.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

If you are located in the European Economic Area (EEA), you have the right to lodge a complaint with your local data protection supervisory authority.

8. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to know what personal information we collect, use, and disclose
  • Right to request deletion of your personal information
  • Right to opt-out of the sale or sharing of personal information
  • Right to non-discrimination for exercising your privacy rights

Photta does not sell your personal information. We do not share personal information for cross-context behavioral advertising purposes.

9. Acceptable Use & Content Moderation

Photta is designed for professional fashion and product photography. We monitor and enforce content guidelines to maintain a safe and appropriate platform for all users.

9.1 Prohibited Content

  • Pornographic, sexually explicit, or obscene content
  • Content depicting or promoting violence, gore, or self-harm
  • Child sexual abuse material (CSAM) or any content involving minors in inappropriate contexts
  • Hate speech, discriminatory content, or content promoting terrorism
  • Content that infringes on intellectual property rights, trademarks, or copyrights of others
  • Fraudulent, deceptive, or misleading content designed to deceive consumers
  • Any content that violates applicable local, national, or international laws

9.2 Enforcement Actions

Photta reserves the right to take the following actions, with or without prior notice, if violations are detected:

  • Issuing a warning notification to the account holder
  • Reducing or revoking the user's remaining credits
  • Temporarily suspending account access
  • Permanently deleting the account and all associated data
  • Reporting illegal content to relevant law enforcement authorities

In cases of severe violations (such as CSAM, terrorism, or illegal activity), Photta may immediately and permanently terminate the account without prior warning and report the incident to appropriate authorities.

10. Automated Decision-Making

Photta may use automated systems to detect content policy violations and prevent platform misuse. These systems analyze uploaded content and generated results for compliance with our Acceptable Use Policy.

If your account is affected by an automated decision, you have the right to request a human review by contacting [email protected]. We will review your case within 5 business days.

11. Data Security

We implement industry-standard security measures to protect your personal data:

  • HTTPS/TLS encryption for all data transmitted between your device and our servers
  • Encrypted and hashed password storage using modern cryptographic algorithms
  • Criptografia em repouso para as imagens enviadas e o conteúdo gerado, armazenados no armazenamento de objetos da Amazon Web Services
  • JWT-based authentication with automatic token rotation and multi-tab session management
  • Regular security audits and vulnerability assessments

12. International Data Transfers

Seus dados são armazenados em servidores localizados na Turquia. As imagens enviadas e o conteúdo gerado são armazenados em nosso provedor de armazenamento em nuvem, em servidores localizados na União Europeia. Se você acessar a Photta de fora dessas regiões, suas informações serão transferidas e processadas na Turquia e na União Europeia.

For users in the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for international data transfers.

Para produzir os resultados que você solicita, suas imagens são transmitidas aos provedores de processamento de IA indicados na seção 4. Alguns desses provedores, assim como os serviços de análise e de monitoramento de erros ali indicados, operam fora da Turquia e da União Europeia, inclusive nos Estados Unidos.

13. Progressive Web App & Offline Data

Photta offers Progressive Web App (PWA) functionality for an enhanced mobile experience. When installed:

  • A service worker caches static assets (images, scripts, styles) on your device for faster loading and offline access.
  • Your authentication session and user preferences are stored locally on your device.
  • No personal content or generated images are cached offline. All generated content remains on our secure cloud servers.

14. Children's Privacy

Photta is not intended for users under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected data from a child under 18, we will promptly delete that information. If you believe a child has provided us with personal data, please contact us at [email protected].

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated policy on our website and updating the "Last Updated" date. For significant changes, we may also notify you via email or in-app notification. Your continued use of Photta after changes are posted constitutes acceptance of the updated policy.

16. Contact Us

Privacy Questions: [email protected]

General Support: [email protected]

Website: photta.app

Photta - Fotografia de Moda com IA & Manequins Virtuais