Privacy Policy
Last updated: October 6, 2026
This policy explains how the Digiglow mobile app (the "App") processes your personal data. Data controller: Buğra Harım, Türkiye, bugraharim364@gmail.com.
1. In short
- Your photos are processed only to apply the effect you choose and are not stored permanently on our servers.
- The photos you create are stored on your phone.
- No account is required. We do not sell your photos, use them for advertising, or use them to train AI models.
2. What data we process
| Data | Why | Where and for how long |
|---|---|---|
| The photo you choose for an AI effect | To apply the effect | Only while it is being processed, in server memory and at the AI provider. Not stored on our servers. |
| The generated result photo | To deliver it to you, and to let you get it again for free if the connection drops | In a private (non-public) storage bucket for at most 24 hours, then deleted automatically. The permanent copy lives only on your phone (the app gallery) and is removed when you delete the app. |
| An anonymous user ID (randomly generated) | To keep your credit balance and purchases | On our servers while your account is active. |
| Credit and purchase records (product, date, status) | To manage subscriptions and credits, refunds and fraud prevention | On our servers and with our payment infrastructure (RevenueCat), for the legally required retention periods. |
| Generation records (which effect, date, result status; no photo) | Charging and refunding credits, never charging the same request twice, rate limiting | On our servers for at most 30 days. |
| Content reports ("Report result": which generation, effect, chosen reason; no photo) | Reviewing inappropriate or broken results, improving effects, complying with AI content policies | On our servers for at most 180 days; deleted immediately with "Delete my data". |
| IP address and device/browser signals | Bot and abuse protection (Cloudflare Turnstile, new anonymous user limits) | In our providers' security logs, for their own retention periods. |
The App contains no advertising, no ad tracking and no analytics or crash-reporting tools. If this changes, we will update this policy and our store disclosures.
We do not extract biometric templates (face prints) from your photos and do not use face recognition to identify you.
3. Your photos are sent to a third-party AI
To create an effect, your photo is sent through OpenRouter, Inc. (USA) to Google LLC's Gemini AI model. OpenRouter forwards the request to Google and returns the result to us. Request logging is turned off in our OpenRouter account and requests are not routed to providers that train on request data. Google processes the data to provide the service; under its paid API terms, this data is not used to train Google's models.
Before you use an AI effect for the first time, the App asks for your explicit consent to this transfer. If you do not consent, you can still use the free on-device filters.
4. Other service providers
- Supabase, Inc.: anonymous sign-in, database, server functions and the 24-hour private result storage (servers in London, United Kingdom).
- Cloudflare, Inc.: Turnstile bot protection (when a new anonymous user is created).
- RevenueCat, Inc., Apple App Store, Google Play: subscriptions and purchases. RevenueCat receives your anonymous user ID and purchase history. We never see your payment (card) details.
5. International transfers
The servers of the providers above are located outside Türkiye (United Kingdom and USA). Transfers are made with the safeguards required by Article 9 of Turkish Law No. 6698 (KVKK) and the GDPR (standard contractual clauses, explicit consent).
6. Your rights
Under KVKK Article 11 and the GDPR you have the right to access, correct and delete your data, to object to processing and to withdraw your consent. You can delete your server-side records (credits, generation records, content reports, anonymous account) with Settings → Delete my data in the App, or write to bugraharim364@gmail.com. We answer requests within 30 days. You also have the right to lodge a complaint with your data protection authority (in Türkiye, the Personal Data Protection Board).
7. Children
The App is not intended for children under 13 (under 16 in the EU). We do not knowingly collect data from children below these ages.
8. Security
Data is encrypted in transit (HTTPS). Server access is restricted by authorization and security rules. Photos are never written to logs.
9. Changes
If we update this policy, we will let you know in the App. For material changes we will ask for your consent again.
10. Contact
bugraharim364@gmail.com · Türkiye