Privacy Policy – Tattvue
Last updated: 5 October 2026
This policy explains in plain language which data the Tattvue app and the tattvue.com website process, why that happens and what rights you have.
1. Controller
Theodor Staubach
An der Bogenheide 45
16348 Wandlitz
Germany
Email: contact@tattvue.com
For users in Brazil we have additionally appointed an "Encarregado" (data protection officer under art. 41 of the Brazilian data protection act, LGPD): Theodor Staubach, address and email as above. This is a role under Brazilian law. It does not constitute the appointment of a data protection officer under art. 37 GDPR – and we are not required to appoint one, neither under art. 37 GDPR nor under section 38 of the German Federal Data Protection Act. We do not employ twenty people on data processing, and according to our documented assessment our processing is not subject to a data protection impact assessment under art. 35 GDPR.
2. What data we process
2.1 Account data
When you register (email and password, or sign-in via Google or Apple) we store:
- your email address
- your password, exclusively as a cryptographic hash (bcrypt) – we cannot see your actual password at any time
- if you sign in via Google: a unique identifier issued by Google for your Google account (no other Google account data)
- if you sign in via Apple ("Continue with Apple"): a unique identifier issued by Apple for your Apple account and the email address contained in the signed proof from Apple. If you use Apple's "Hide My Email", we only receive an anonymous forwarding address from Apple, not your actual address. We do not ask for your name and do not store it
- the time at which you created your account
- your current credit balance (how many images and motifs you have left)
- for every one of your image creations one technical row: time, duration, number of internal attempts, which model did the computing, whether it was a free or a paid image, the verdict of our automatic quality check and whether the authenticity check of your device succeeded. What the image shows is not recorded there. We need this row for two things: to count your credit and the daily limits, and to know what operating each image costs us and where quality drops off
2.2 Device identifier
We store an identifier of your device (on the iPhone the so-called "Identifier for Vendor", IDFV for short). This identifier is issued by the operating system, applies only to our app and does not allow any conclusion about you as a person. If you delete the app, your device issues a new identifier on reinstalling. This does not affect the marker that Apple places on the device for our app at our request (section 8): it survives a reinstall and even a reset of the device. It contains at most two pieces of information: whether the free trial image (up to version 1.1) has already been used and – once we switch this on for it – whether the personal motif from the introduction (section 2.13) has already been created.
We need it for four things:
- so that the free trial image (offered up to version 1.1) cannot be obtained over and over again by creating new accounts
- so that the credit for an invitation (section 2.5) cannot be claimed more than once on the same device
- to count the requests per device with which we curb excessive use (section 2.7)
- so that the personal motif from the introduction (section 2.13) is created only once per device – for this we do not store the identifier itself but a check value derived from it (hash)
Besides this identifier, the app stores three further items on the device itself for the purpose of verifying that your app is genuine – exactly what they are is set out in section 2.12.
We no longer use it for the usage statistics under section 2.8; that has been the case since 21 August 2026. What is recorded there instead is an identifier that lives only for as long as the app is open.
2.3 Your photos and the generated images
The body photo you upload and the tattoo motif are processed exclusively in the memory of our server and are not stored. As soon as generation is complete, they no longer exist on our side.
While generating, our server evaluates the spot you marked on your photo. Three things are determined, and all three are pure image measurements: how bright the area is – a dark background needs different contrasts than a light one, otherwise the design is barely visible; how much of the area is already tattooed – over an existing tattoo we have to draw differently so the new design does not disappear into it; and how strongly the area curves – for this a program on our server computes a depth map of the crop, that is an estimate of which pixels are nearer and which are further away, so that the design follows the curve of your arm instead of looking stuck on flat. The values control three things: which drawing instructions we start the generation with; whether we warn you beforehand that a coloured design may look stuck on; and – if you continue after that warning – whether the drawing instruction additionally asks for the light on fair skin to be respected. So the “light” or “dark” classification affects the instruction that goes to Google with your photo at both ends of the scale. The warning itself goes back to you and to nobody else. The measurements themselves are used solely during the ongoing generation; they are not stored and are linked to no account. We name one exception on passing data on: to detect whether the spot you marked is already tattooed, the marked crop may additionally go to Google – with exactly that question. The result ('tattooed' or 'bare skin') then appears in our operational log, with no link to your account. Beyond that, no measurement about your skin goes to Google, only the drawing instruction that follows from it.
To be honest about it: a body photo may show scars, birthmarks or skin conditions, and how bright a skin area measures depends on your skin tone as well as on light, shadow and camera. That is why we deliberately keep the measurement as narrow as possible and evaluate none of it: we recognise no people, derive no health characteristics and store nothing on any of these points. For the duration of a single generation we use the measured brightness value to tell lighter skin from darker skin, so that the design also looks right on dark skin. Why we do not regard this as a special category of personal data within the meaning of Art. 9 GDPR: what is measured is an image value across an area, not a statement about your origin. No category arises from it that would be stored, linked to your account or disclosed to a third party – the distinction exists for the duration of a single generation and not afterwards. The German supervisory authorities apply the same standard: under their decision of 27 September 2023, Art. 9 GDPR does not apply as long as material is not processed in order to infer special categories of data. The legal basis for processing your photo is set out in section 6.
The finished result image is placed in our database for a maximum of 24 hours. The reason protects you: a generation takes 60 to 90 seconds. Without this temporary storage your image would be lost if the app crashed or you closed it during that time – and your credit would have been used up regardless. This way it is offered to you the next time you open the app.
The following applies:
- We delete the image as soon as your app confirms that it has been received in full – usually therefore after a few minutes.
- An exception applies to the free trial image: for it we additionally store the version without the watermark. It stays in place even after receipt has been confirmed so that we can supply it to you without a new generation if you decide to buy afterwards. It too is deleted after 24 hours at the latest – and immediately once it has been supplied.
- If you do not collect it, it is deleted automatically after 24 hours at the latest.
- It can only be retrieved with a random, unguessable collection number that your app generates itself, and only from your own account.
- If an image expires without you having seen it, we return the credit that was used (a maximum of three times per account). This does not apply to the free trial image: there is no return for it, because no credit was used.
We do not create an image gallery on our servers, and no human being here looks at your images. They are checked automatically: before generation, a Google program judges every uploaded image on whether it shows permitted content – see section 2.9.
The app additionally stores your finished result on your device so that you can find it again later. That copy stays with you: it is not transferred to us, we have no access to it, and you can delete it in the app at any time. You can also move it to your device's photo library using "Save to Photos" or pass it on using "Share" – both of which happen exclusively on your device and in your hands.
The app’s access to your camera and your photos is managed by the operating system and granted by you there. You can withdraw it at any time in your device settings.
2.4 Your text input for motif and lettering
If you have a tattoo motif or lettering generated from a text description in the app, that text is transmitted to Google (Gemini API) for processing. We do not store your descriptions ourselves; Google retains them for up to 55 days to detect abuse (details in section 5). This applies only to generation inside the app: the lettering preview on the tattvue.com website does not use Google or any other AI model (section 2.14).
For voice input (dictation button), we use Apple's speech recognition exclusively on your device. Your voice does not leave your device and is not sent to Apple or to us. If recognition is not available on your device or in your language, or if the language of the app does not match the language of your iPhone, the dictation button will not work – you can type your text as usual or use your iPhone keyboard's own dictation feature instead; Apple's own privacy policy then applies, because Apple carries out that processing itself.
The first time you tap the dictation button, your iPhone shows a fixed, generic notice from Apple stating that speech data may be sent to Apple. iOS shows this text for every app that uses Apple's speech recognition at all – regardless of whether an individual request actually leaves your device. For Tattvue's dictation button, the commitment above still applies: we only start the recording if recognition is possible on your device. If it is not, we record nothing and send nothing to Apple.
2.5 Invitation and gift codes
Every account receives a personal invitation code. If somebody redeems your code, we store the link between your account and the account of the invited person – solely in order to pay out the promised credit exactly once.
For a gift code we store which account redeemed it and when, so that the same code cannot be used more than once.
2.6 Feedback and ratings
Both are voluntary:
- Thumbs up/down beneath a result image: we store the rating and the time. The image itself is not stored.
- Star rating of the app (1–5) with optional free text: we store the stars and your text. Please do not enter any personal data there, you do not have to.
Both are linked to your account so that the same feedback is not counted twice.
2.7 Technical data and protection against misuse
So that the computing costs do not explode through misuse, we keep count of:
- requests per IP address, for a maximum of 24 hours. What is stored is your IP address together with a number – no image data and no link to your account. The same applies to sign-in, password reset, the contact form, cutting out a motif before sign-in, the personal motif from the introduction (section 2.13), counting the usage steps under section 2.8 and the web lettering preview on the website (section 2.14): there too we count per IP address.
- requests per account, per calendar day and per hour. These counters delete themselves – after two days at the latest, or after three hours respectively.
- requests per device identifier, per hour and per calendar day. These counters also delete themselves, after three hours or two days respectively.
- requests across all users combined, as an emergency brake, and the number of free trial images per hour. These numbers are not assigned to any person.
2.8 Usage statistics
We only count if you have allowed us to. When you create your account we ask you with a tick box that you are free to leave empty – you get your account either way, and then we count nothing at all. If you already had your account before that tick box existed, we do not ask you again afterwards: in that case we only start counting once you turn on the “Usage statistics” switch yourself, in Settings under “Privacy”. Until you have agreed, not a single counting entry of this measurement leaves your device; the one exception is the counting of the eight screens, described in the last paragraph of this section. You can change your decision at any time in Settings under “Privacy”.
So that we can see where in the app people get stuck, we count which steps are completed. For each step we store the name of the step, the time, and a random identifier for your current session – for signed-in users, the account as well.
This session identifier is expressly NOT the device identifier from section 2.2. It is created afresh the moment you open the app and lives only in memory – nothing is stored on your device. Close the app and it is gone; the next time you start it, you get a different one. It only holds the steps of a single run together; across several app starts we cannot recognise you by it. That costs us accuracy – we see how many runs there were, not how many people used the app – and it is a price we pay deliberately. Until 21 August 2026 the device identifier stood here; entries from before that date still carry it and are deleted, like all the others, after six months at the latest.
The steps that are counted are defined conclusively. They are: photo chosen, motif generated, motif uploaded, continued with the motif, motif moved, preview seen, create pressed, result seen, thumb given, offer page seen, purchase completed, screen opened.
For four of these steps exactly one single technical detail is added: the chosen motif style, whether the thumb was up or down, which product was purchased – and the name of the screen. Nothing more.
For the step "screen opened" we additionally store which screen it was. That list is defined conclusively as well; our server accepts no other name. They are: start screen, introduction page 1, 2 and 3, the questions of the introduction (three names are reserved for them), "personal motif being created", personal motif result, offer page 1 and 2, tour stop 1, 2 and 3, motif selection, placement, sign-in, instructions. All that is stored is one of these eighteen names – no text you type, nothing from your images and not what you tapped in the questions of the introduction. Screens with legal texts, your gallery and the settings are not counted.
Expressly NOT stored:
- your photos or generated images
- your motif descriptions or any other text you type
- your IP address – the misuse limiter described in section 2.7 counts it separately, but it is not stored with your counting entry
- your location
These figures serve solely to improve the app. We do not build advertising profiles from them, we do not show you anything personalised based on these figures and we do not pass anything on to advertising networks. The adaptation of the purchase screen under section 2.13 does not rely on these statistics, only on your answers on your device.
Entries are deleted automatically after six months at the latest. If you delete your account, the link to your account disappears with it immediately. If you withdraw your permission, we immediately cut the entries created up to then loose from your account – details in section 6.
Eight screens are counted without consent – and without any identifier: the three pages of the introduction, the start screen, the motif choice, the placement, the sign-in screen, and the purchase page. Yes, the sign-in screen and the purchase page are included too. This is the same exception announced at the start of this section, and it stays just as narrow as before: some of these screens you see before your account exists and before you have even laid eyes on the tick box; if we only measured what consent allows, we would never know at which point people drop off. What goes out is, per visit to one of these screens, exactly one request carrying one of eight fixed names. No account, no device identifier, no session identifier, no time, no text, no image. On our side all that arises is a number per screen and day; we do not keep individual requests, and we do not store your IP address with them either. We cannot attribute these figures to anyone – not to you either – and can therefore neither hand them out nor delete them individually (Art. 11(2) GDPR). The "Usage statistics" switch has no effect on this counting; it switches the measurement described above.
2.9 Automatic content check of your images
Before we create a preview, a Google program checks every image you upload – your body photo and your design. It judges one thing only: whether the image shows permitted content.
The result is a single word: either fine, or a note about which limit was crossed. We receive nothing else and we store none of it. No human being here looks at your image.
Why it exists: without this check, content could be created through the app that we are neither allowed nor willing to create – for example unconstitutional symbols or depictions of children. The legal basis is our legitimate interest in running a lawful service (Art. 6(1)(f) GDPR); without the check we would have to switch off image uploads entirely.
If your image is rejected we tell you why and you can choose another one. Your credit is not charged for this.
2.10 Age check via Apple
The app is for people aged 18 and over. In addition to your own confirmation, we ask your iPhone whether Apple holds an age indication for this device.
We do not receive a date of birth or an age. The app learns exactly one of three results: of age, under age, or no information. That result never leaves your device, is not sent to our server and is stored nowhere – it decides in that same moment whether an account can be created.
If Apple reports an age below 18, we do not create an account. If Apple reports nothing, in most countries your own confirmation alone still applies; in individual regions with a statutory age-verification duty we cannot create an account without an indication.
The basis is our legal obligation to verify age (Art. 6(1)(c) GDPR) and, where no such obligation exists, our legitimate interest in keeping minors away from a service not intended for them (Art. 6(1)(f) GDPR).
2.11 App updates
So that faults disappear quickly, the app can reload parts of its program without you having to install a new version from the App Store. To do so, once at every start it asks the update service of our provider Expo (650 Industries, Inc., USA) whether something new is available. This happens in the background and does not hold up the start.
This request transmits:
- your IP address – technically unavoidable for any request on the internet
- a random identifier of your installation, created at the first start and stored on your device
- the entry "iOS", which version of the app is running on your device, and through which channel it receives updates
- the internal reference numbers of the program version currently running and of the one that most recently failed to start
If the app crashed the last time it started, the error message of that crash is sent as well, truncated to 1024 characters. Its purpose is to prevent a faulty update from being delivered again.
The random identifier contains no reference to you, to your account or to any Apple device number. If you delete the app it is gone – a new one is created on reinstallation. It is not the same as the marker Apple stores on your device for us (section 8): that one survives a reinstallation, this one does not.
We receive no analysis about you from these requests. They do not feed into the usage statistics under section 2.8, they are not linked to your account, and they serve no advertising purpose.
If a new version is available, the app downloads it over the same network; your IP address is technically involved in that too. Expo does not publicly state how long it keeps logs of these requests, so we cannot give you a period for it.
2.12 Verifying that your app is genuine (App Attest)
So that nobody can tap into our image generation with a rebuilt program, the app has Apple confirm that it is the genuine, unmodified Tattvue app on a genuine iPhone. Apple calls this procedure App Attest.
What is stored on your device: the app places three items in your iPhone's key store (Keychain) and reads them again on later launches:
- the identifier of the key your iPhone created for this proof – the key itself never leaves your device and is not readable by us either
- the note that this device has already been verified with us once – it saves an additional request to Apple on every launch
- where applicable, a point in time until which no new request is made after a failed attempt
These three items contain neither your name nor your email address nor any Apple device number. If you delete the app, they are gone.
What is transmitted: your iPhone creates a confirmation for this proof, which we pass on to Apple and which Apple checks for us. From this we receive only the answer "genuine" or "not genuine" plus the identifier of the key. On our server we store, alongside that identifier, the public part of the key and a counter that lets us tell whether a proof is being reused; both are linked to your account and are deleted with the account. For every image creation we record whether the proof succeeded (section 2.1). If it fails, we additionally note the technical reason – for example that the device is not an iPhone, or that our server could not be reached for the check.
The proof is currently voluntary: if it fails, the app still works. We then only see that none was provided.
The legal basis is our legitimate interest in a working and affordable service (Art. 6(1)(f) GDPR) – every image creation costs us money, and without this protection it could be tapped from outside the app.
2.13 Your personal motif from the introduction
At the end of the introduction you can have a motif created that matches your answers – even before there is an account. For this the app sends to our server: your chosen tattoo styles – at most three short codes from a fixed selection –, plus, only if you enter it, your own description of the motif (at most 300 characters), and the device identifier from section 2.2. From the answers we build the description with which the AI creates the motif; what section 2.4 says about motif creation applies. We deliver the finished motif directly to your app; there is no permanent storage location for it on our server.
You answer the other questions of the introduction – how many tattoos you have, why you downloaded the app, how much you plan to spend and whether you already have a design in mind – only on your device. Those answers are stored only there, never leave your device and only control which texts the purchase screen shows you; the preselected subscription does not depend on your answers, and you can choose any subscription. The legal basis is our legitimate interest in showing you the offer in a way that matches your answers (Art. 6(1)(f) GDPR); you may object (section 8). We delete these answers from your device as soon as you sign out or delete your account.
So that the personal motif is created only once per device, we store a check value (hash) of the device identifier together with the time. We do not store your answers. The check value is calculated from your device's identifier. On its own it does not reveal who you are; but if you later create an account on this device, we could assign it to your account. You can therefore also request access to and erasure of this value (section 8). It remains stored for as long as the feature exists, because otherwise the "once per device" limit would not hold. If the creation fails, the entry is deleted again immediately and you can try again. We do not currently use the Apple marker from section 2.2 (DeviceCheck, recipient in section 4) for this. We also count the requests per IP address (section 2.7).
For this one-time limit we read the identifier that your iPhone issues only for our app (section 2.2) and send it to our server. Under § 25(2) No. 2 TDDDG (German Telecommunications Digital Services Data Protection Act) this is permitted without consent, because otherwise we could not offer the free personal motif.
The legal basis for the creation and for the check value is our legitimate interest in demonstrating the app to you on a motif of your own and in protecting the computing costs against misuse in the process (Art. 6(1)(f) GDPR).
2.14 Visiting the tattvue.com website and its tools
This policy also applies to the tattvue.com website. Visiting it generates the following data:
Server logs: like any website, tattvue.com automatically processes technical connection data when it is accessed – IP address, time, the address requested and browser identifier. Our hosting provider Vercel handles this to operate and secure the website (Art. 6(1)(f) GDPR); a website cannot technically be delivered without this data. For the retention period, see section 4 (Vercel).
Web lettering preview: if you type text on tattvue.com to see it set as lettering, your website session sends that text to our own server. There, a program – without AI and without Google/Gemini – sets it in the chosen font and sends you back the finished image. We do not store the text you entered, either with us or with any third party. We do count your IP address for this, to limit requests (section 2.7); there is no link to your text or to an account.
Size finder, pain map and aftercare plan: these three tools run entirely in your browser. No data is transmitted to our server or to any third party.
Google Search Console: a technical verification tag in the page source proves to Google that we own the website. No data flows to Google from visiting the website because of this.
The website uses no cookies and no tracking; no fonts or other content are loaded from third-party servers.
3. What we use your data for
- administration of your account (registration, sign-in, password reset)
- provision of the actual app function (generating a tattoo preview)
- checking your credit (how many images you have left)
- handling invitations and gift codes
- improving the app on the basis of your voluntary feedback and the usage statistics under section 2.8
- protection against misuse and excessive use
We do not sell your data, we do not pass it on for advertising purposes and we do not create advertising profiles. The only thing we adapt is the purchase screen in the app: its texts follow your answers from the introduction, which never leave your device (section 2.13). The app contains no advertising components and no components of third-party analytics or advertising networks; it does not track you across other apps or websites. The only third-party component that opens a connection of its own is the update function described in section 2.11 – it measures no usage behaviour. The usage statistics under section 2.8 run exclusively on our own server.
4. Recipients of your data (processors)
We use the following service providers. Each receives only the data it needs for its task:
| Service | Purpose | What is transferred |
|---|---|---|
| Google (Gemini API) | Generating the motif and tattoo preview | body photo, motif image, position data, motif description and the drawing instructions for the generation as well as – to detect whether the spot you marked is already tattooed – the marked crop with the question whether ink is already there (section 2.3). How bright your skin measured, Google does not learn; that measurement never leaves our server. The drawing instruction that follows from it does differ depending on the background, however. We use the Gemini API on the paid tier for this (billed through Google AI Studio), not the free tier. For the paid tier, Google commits not to use your prompts, uploaded files or the responses to them to improve its own products. To detect abuse, Google retains the request and result for up to 55 days; flagged content may be reviewed by specially authorised Google staff. Google's "Data Processing Addendum for Products Where Google is a Data Processor" applies to the processing; the basis for the transfer is the European Commission's standard contractual clauses, which Google incorporates in its data processing terms – where the processing actually takes place in the United States, Google is additionally certified under the EU-US Data Privacy Framework. |
| Google (Sign-In) | Sign-in via "Continue with Google" | confirmation of your Google identity, only if you use this option |
| Apple (Sign in with Apple) | Sign-in via "Continue with Apple" | confirmation of your Apple identity and your email address – with "Hide My Email" only an anonymous forwarding address; only if you use this option |
| Apple (DeviceCheck, USA) | Protection against misuse of the free trial image (up to version 1.1) and for the limit on the personal motif (section 2.13) | a device token generated by your iPhone that we cannot read. On that basis Apple stores at most two pieces of information on your device for our app: whether the free trial image has already been used and – once we switch this on – whether the personal motif has already been created. We receive no device number, no Apple ID and no link to you as a person. This information survives a reinstall and a reset of the device and cannot be deleted by us (section 8). |
| Resend (sending from Ireland, administration in the USA) | Sending the code for "forgot password" and the messages from the contact form | your email address, only for these processes. Sending happens from Ireland; the administrative data about it – account data, email metadata and logs – is held by Resend in the USA regardless of the sending region, by its own account (section 5). |
| Neon | Database for the account data and the 24-hour temporary storage of result images | see sections 2.1, 2.2, 2.3, 2.5 and 2.6 |
| Vercel | Operation of the server (app and website) | technically necessary connection data, e.g. your IP address during the request; as a server log, Vercel retains it according to its own statements for up to 1 day on our plan (Pro) (vercel.com/docs/logs/runtime, accessed 1 October 2026) |
| Upstash | Counters for protection against misuse (app and website) | IP address and account identifier, for the periods named in section 2.7 – at most 24 hours per counter, most much shorter |
| Apple or Google (app store) | Handling of purchases | The purchase runs entirely within the app store on your device. We receive only the confirmation that a package was purchased – no payment data, no credit card number, no billing address. That confirmation does not reach us directly but through our service provider RevenueCat (next entry) |
| RevenueCat (USA) | Allocating your purchases and subscriptions to your Tattvue account and unlocking your credit | your Tattvue user identifier, a device identifier, your IP address, the app version and your purchase history (which product was bought, renewed, cancelled or refunded and when) – no payment data |
| Expo (650 Industries, Inc., USA) | Downloading program updates for the app (section 2.11) and delivering the "your image is ready" notification, if you have allowed it | your IP address, a random identifier of your installation, the entry "iOS", which version of the app is running and through which channel it receives updates, the internal reference numbers of the program versions – and, if the app previously crashed, the error message of that crash truncated to 1024 characters. No image, account or payment data. Delivery runs over the networks of Cloudflare and Google, which Expo uses for this. If you allow notifications, a delivery token for your device is added for the duration of one image creation, together with the title and text of the notification ("Your image is ready"). Apple itself delivers the notification to your device. |
All of the service providers named are bound to confidentiality (processing on our behalf pursuant to Art. 28 GDPR, where applicable). For Apple and Google this holds only in so far as they act for us: for sign-in, for the purchase flow in the app store and for the device marker in the "Apple (DeviceCheck)" entry, those companies determine the purposes and means themselves and are, to that extent, controllers in their own right rather than our processors. The same applies to Upstash: that provider's data processing agreement expressly excludes its own service analytics. For that part Upstash is a controller in its own right; for the counters we keep there it remains our processor. For the processing by Google, Google's "Data Processing Addendum for Products Where Google is a Data Processor" applies – the basis for the transfer is the European Commission's standard contractual clauses, which Google incorporates in its data processing terms; where the processing actually takes place in the United States, Google is additionally certified under the EU-US Data Privacy Framework. This is processing on our behalf under Art. 28 GDPR.
5. Where your data is processed
Some of our service providers work within the European Union, some in the United States - and one processing operation takes place worldwide:
- server of the app: EU – Vercel, region Frankfurt ("fra1")
- database with the account data and the 24-hour temporary storage: EU – Neon, region Frankfurt ("eu-central-1")
- counters for protection against misuse: EU – Upstash, region Frankfurt ("fra1")
- generation of motif and preview and the automated content check: worldwide – Google
- allocation of your purchases to your account: USA – RevenueCat
- protection against misuse of the trial image and the personal motif: USA – Apple (DeviceCheck)
- downloading program updates: USA – Expo, delivered over the networks of Cloudflare and Google
- sending of our emails: Ireland – Resend, dispatched from the region Ireland ("eu-west-1"); the administration of that service sits in the USA
Since 24 August 2026 the server, the database and the counters are located in Frankfurt am Main, Germany. Until then they were in the United States. The old US stores have been disconnected from the app since the move and are no longer written to; a copy of the data as it stood on 24 August 2026 is still held there; we will delete it by 24 February 2027.
"Worldwide" is not caution, it is accuracy: we address Google through its global endpoint because the image model is offered only there. Google distributes the request across its own data centres and states expressly that data may be stored transiently or cached in any country in which Google or its agents maintain facilities. The place of processing is therefore not fixed to one country. We cannot tell you where your body photo is computed at the moment you tap "Generate". Google retains the request and result for up to 55 days to detect abuse; flagged content may be reviewed by Google staff. Google does not use the data to train its models.
For email delivery we have to name a limitation. Our provider Resend dispatches the emails from Ireland but keeps the data about them in the United States. Resend states this itself: the choice of sending region does not control where customer data is stored – account data, email metadata, logs and API records reside in the US regardless of the region selected. Your email address therefore does leave the European Union for "forgot password" and for the contact form. We would rather tell you that than give the impression everything stays in Europe.
For the processing in the USA the following applies: the USA does not automatically count as a country with an equivalent level of data protection. Transfers there are therefore based on Art. 44 et seq. GDPR, specifically on the adequacy decision of the EU Commission on the EU-US Data Privacy Framework of 10 July 2023 (in so far as the respective provider is certified under it) and additionally on the standard contractual clauses of the EU Commission.
For the transfer to Google we do not rely on the adequacy decision on the EU-US Data Privacy Framework: that decision covers the United States only, and here it is precisely the place of processing that is not fixed. The basis is therefore the standard contractual clauses of the EU Commission, which Google incorporates in its data processing terms; where the processing actually takes place in the United States, Google is additionally certified under the EU-US Data Privacy Framework.
To be honest nonetheless: it cannot be entirely ruled out that US authorities access data processed there. Affected are your email address from the delivery via Resend, your user and device identifier together with your purchase history at RevenueCat, and the data from the update requests described in section 2.11. Your credit balance and your finished result image have been held in Frankfurt since 24 August 2026 and are no longer affected. We do not store your body photo or your motif.
And one limitation remains for the systems in Frankfurt too, which we will not conceal: Vercel, Neon and Upstash are companies based in the United States. Your data sits in Frankfurt, but access to it from the USA – during maintenance, for example – is technically possible. The same standard contractual clauses of the EU Commission apply to such access.
6. Legal bases
Account, image generation, credit, purchases: performance of the contract of use, Art. 6(1)(b) GDPR. This also covers sign-in via Google or Apple if you choose that route.
Body photos and the measurements taken from them (section 2.3): performance of the user contract, Art. 6(1)(b) GDPR. Without your photo the app cannot deliver its only function – the preview on your own skin. The same applies to the three measurements at the marked area: they are not a separate analysis alongside the preview, they are computing steps inside it. From them comes the drawing instruction for exactly your image – and from the brightness comes, in addition, the warning you have to confirm before the start if a coloured design might look stuck on a light area. Without the measurement you would not get the same service in poorer quality, you would get a different one: a preview that ignores the background. We do not process any special category of personal data under Art. 9(1) GDPR in doing so; the reasons are set out in section 2.3.
Protection against misuse, device identifier, counters: legitimate interest in a functioning and affordable service, Art. 6(1)(f) GDPR.
Personal motif from the introduction (section 2.13): legitimate interest in demonstrating the app to you on a motif of your own and in protecting the computing costs against misuse, Art. 6(1)(f) GDPR. Reading the device identifier for this is permitted without consent under § 25(2) No. 2 TDDDG, because otherwise the free personal motif could not be offered.
Adapting the purchase screen to your answers from the introduction (section 2.13): legitimate interest in showing you the offer in a way that matches your answers, Art. 6(1)(f) GDPR. The answers stay on your device; you may object under Art. 21 GDPR.
Downloading program updates (section 2.11): legitimate interest in closing faults and security gaps quickly without having to wait for a new version in the App Store, Article 6(1)(f) GDPR. You may object to this processing under Article 21 GDPR; however, the update check cannot be switched off for individual devices – all we could then point you to is the route via App Store updates.
Usage statistics (section 2.8): your consent, Art. 6(1)(a) GDPR and § 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act). This measurement does not begin before you tick the corresponding box while creating your account; if you leave it empty, you get your account all the same and we measure nothing. If you already had your account before, you give this consent through the same switch with which you can also withdraw it. You can withdraw this consent at any time and without any disadvantage (Art. 7(3) GDPR): the app settings contain a switch called “Usage statistics” under “Privacy”. Turn it off and your app stops sending a single counting entry of this measurement; that setting is kept until you change it again. Withdrawal takes effect immediately: your app stops sending a single counting entry of this measurement, and at that same moment we cut the link between your account and the entries created up to then. What remains is a row we can no longer attribute to you – the name of the step, the time, and the session identifier that no longer exists after your next app start. We delete those rows too, after six months at the latest. Because the link is gone, we can no longer pick them out individually for you afterwards (Art. 11(2) GDPR). As long as you have not withdrawn, we will delete the entries stored under your account on request to contact@tattvue.com. Your withdrawal takes effect through that switch, and an email to us cannot replace it – without an account the entries only carry a session identifier that no longer exists after the next app start, so we cannot attribute them to you (Art. 11(2) GDPR). Not covered by this consent is the counting of the eight screens described in the last paragraph of section 2.8 (introduction, start, motif choice, placement, sign-in, purchase page): opening one of those screens raises a counter for that screen by one. Nothing else leaves your app and nothing else is stored – neither an identifier nor a time. Details in the last paragraph of section 2.8; the switch has no effect on it.
Feedback and ratings: your consent, Art. 6(1)(a) GDPR – you give it voluntarily.
Access to camera and photos: your permission in the operating system, revocable at any time.
Access to microphone and speech recognition (section 2.4): your permission in the operating system, revocable at any time.
7. Storage period
- Account data is stored for as long as your account exists.
- Body photos and motifs are not stored at all (section 2.3).
- Finished result images are deleted as soon as your app confirms receipt, and after 24 hours at the latest (section 2.3).
- For the free trial image, the version without the watermark stays until it is supplied afterwards, at most likewise 24 hours (section 2.3).
- Codes for "forgot password" expire after a short time and are invalidated afterwards.
- Counters for protection against misuse delete themselves after two days at most.
- Feedback and ratings are kept for as long as your account exists; if you delete your account, they disappear with it.
- The technical rows about your image creations (section 2.1) are kept for as long as your account exists; if you delete your account, they disappear with it.
- Usage statistics entries (section 2.8) are deleted automatically after six months at the latest. That also applies to entries with no link to an account; they do not go with an account deletion.
- The check value for the personal motif (section 2.13) remains for as long as the feature exists. On its own it is not assigned to any person; we could assign it to an account created later on the same device, so we delete it at your request (section 8).
- The data for verifying that your app is genuine (section 2.12) is kept for as long as your account exists; if you delete your account, it disappears with it.
- The note that a free trial image has already been used on your device (section 8) is deleted after 24 months.
- The update requests described in section 2.11 are held by our provider Expo, not by us. Expo does not publicly state how long it logs them, so we cannot give you a period. The random identifier on your device disappears as soon as you delete the app.
8. Your rights
You have the right of access to your data, to rectification, to erasure, to restriction of processing and to data portability. You can also object to processing that is based on our legitimate interest, and withdraw consent you have given at any time with effect for the future.
Deleting your account: you can delete your account yourself in the app at any time – under Settings, "Delete account". Deletion happens immediately. It covers your account data, your image creations, your feedback and ratings, all result images still held in temporary storage and the link between your purchases and your account. Any remaining credit expires and is not refunded by us; you can, however, have paid, unused credit refunded by Apple before deletion – via "Report a Problem" at https://reportaproblem.apple.com. Alternatively a short email to contact@tattvue.com is sufficient; we then delete your account within 30 days and confirm this to you.
Three things remain, and deliberately so: first, we still remember that a free trial image has already been used on your device – without that note the free image could be obtained any number of times by deleting the account and signing up again. What is stored for this is a device identifier and up to three points in time: when the free image was used, when an invite bonus was credited and when an invite code was redeemed. Your name and your email address are not stored alongside it. We do not, however, claim that no link to you can be established at all: the same device identifier may also appear in older usage statistics entries under section 2.8. We delete this row after 24 months. Second, usage statistics entries that are not linked to any account remain – either because they were created before you signed in, or because the link was severed when consent was withdrawn. They hang on a device or session identifier, not on your account, and therefore do not go with the account deletion; we delete them at the latest six months after they were created. Entries still linked to your account are deleted together with the account. Third, at our request Apple places a marker on your device that prevents the same thing. That marker sits with Apple, not with us, and we cannot delete it – not even if you ask us to.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is: Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany.
8.1 Automated decisions
In three places in this app a program decides on its own, without anyone here looking at it. Two of those decisions determine whether you can use the app at all. So here is how they work, what they mean for you and how you can challenge them (Art. 13(2)(f) and Art. 22 GDPR).
First: whether we create an account for you. When you create an account, the app asks your device for its age signal (section 2.10). In two cases we then do not create an account: if your device explicitly reports an age below 18 – and if your device reports no age at all but your operating system explicitly tells us that it is located in a region where an age check is required by law. In both cases no contract with us comes into being. If your device reports nothing, nothing happens: sign-up simply continues as normal.
Second: whether an existing account may still be used. Every time the app starts we ask for the same signal again. If your device now explicitly reports an age below 18, we sign you out and block access. We do not delete your account or your credit in doing so: access is merely suspended. If your device reports an age of 18 or over again, everything is there unchanged – your account, your credit and your subscription allowance. If you are of age and blocked nonetheless, a person will look at your case (see below, "Your right to a human being"); if you would rather have paid, unused credit refunded, you request that from Apple via "Report a Problem" at https://reportaproblem.apple.com. Only an explicit "under 18" blocks here; a missing signal does not.
Third: whether we process your image. Before every preview a program checks your body photo and your motif (section 2.9). If it rejects them, we do not create a preview. This decision affects only that single attempt: your account remains, your credit is not charged, and you can pick another image straight away.
What does not happen: we do not build a profile of you. (Adapting the purchase screen under section 2.13 is not such a decision: it only changes texts, and every subscription remains freely selectable.) None of these decisions take into account your name, your behaviour in the app, your purchases or your earlier images. There is no score, no prediction and no assessment of you as a person. Each of the three decisions evaluates exactly one value: your device signal, or the verdict on that one image.
Why this runs automatically: we may not conclude a contract about this app with minors (section 9), and we may not create certain content. Checking by hand is not possible in an app that answers within seconds. We therefore base the two age decisions on Art. 22(2)(a) GDPR: they are necessary for entering into and performing the contract with you.
Your right to a human being: if you were blocked although you are of age, write to contact@tattvue.com or use the contact form at tattvue.com/en/contact. A human being will then look at your case, not another program. You may put your point of view to us and contest the decision; that is your right under Art. 22(3) GDPR. The same applies if you believe an image was rejected wrongly. We answer within one month (Art. 12(3) GDPR).
Said honestly, so you know what to expect: the age signal is produced on your device and does not leave it (section 2.10). So we can neither look up what your device reported nor overwrite it – we have no switch that simply lifts a block. What we can do is work out with you what causes the block and tell you how it can be resolved. The lever is almost always yours, in your iPhone settings: under your Apple Account, "Age Range for Apps" decides whether your device shares your age range with apps at all; the date of birth behind it belongs to your Apple Account and can be changed there. We never get to see your date of birth itself.
9. Minimum age
The app is intended for people aged 18 and over. It is directed neither at children nor at teenagers. We only process your data if you are of full age; consent given by a parent or guardian is not provided for, because the app is not open to minors. If we learn that an account was created by a minor, we delete it together with the associated data – as soon as a person or a piece of evidence tells us so. The automatic age block described in section 8.1, by contrast, deletes nothing: it only signs you out and blocks access; account and credit remain.
Please also note that actual tattooing is subject to its own age limits in Germany and in most other countries – a preview in this app does not replace any such rule.
10. Changes to this policy
If the app changes, we adapt this policy. The version that applies is the one available in the app and on our website. In the event of substantial changes we will point this out to you in the app.
11. Users in the United Kingdom
If you use the app in the United Kingdom, the UK GDPR together with the Data Protection Act 2018 applies to you. Everything described above applies unchanged – the same data, the same purposes, the same storage periods. Two points differ:
Supervisory authority: you can lodge a complaint with the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk. The German authority named in section 8 is not responsible for you.
Transfers out of the United Kingdom: the adequacy decision of the EU Commission does not apply automatically to them. Such transfers are based on the UK International Data Transfer Agreement (IDTA) or on the UK Addendum to the standard contractual clauses of the EU Commission, and, where the provider is enrolled in the UK Extension of the Data Privacy Framework, on that extension. For the generation of motif and preview at Google there is no fixed country of processing (section 5), so neither the Data Privacy Framework nor its UK Extension can carry that transfer; it rests on the IDTA or the UK Addendum alone.
12. Users in the United States
There is no general federal data protection law in the United States. We nevertheless want to state clearly what we do and do not do:
- We do not sell your personal information and we do not share it for cross-context behavioural advertising.
- We do not create advertising profiles. The app contains no advertising components and no components of third-party analytics or advertising networks, and it does not track you across other apps or websites. The only third-party component that opens a connection of its own is the update function described in section 2.11, which measures no usage behaviour. The usage statistics under section 2.8 run on our own server and are used solely to improve the app.
- Beyond what is described in section 2, we do not collect sensitive personal information. Section 2.3 explains what we measure from your photo and why we consider it an image measurement rather than a statement about you; if a state law nevertheless treats it as sensitive data, the safeguards in that section apply.
Your rights, wherever you live in the United States. Regardless of which state law applies to us, you may ask us to tell you which data we hold about you, to correct it, to delete it, or to give you a copy. Send a short email to contact@tattvue.com; we answer within 45 days and may extend that once by another 45 days if a request is complex. We do not charge for this and we do not treat you differently for asking.
If we turn a request down. You may appeal our decision within a reasonable time by replying to the same address with the word "appeal". We will review it and write back within 60 days with the outcome and our reasons. If we still turn it down, you may complain to the attorney general of your state; where your state provides an online complaint form, we will include the link in that reply.
What we do not do. We do not sell your personal information, we do not share it for targeted or cross-context behavioural advertising, and we do not profile you for decisions that produce legal or similarly significant effects. That is true in every state and does not depend on any threshold.
The California Consumer Privacy Act (CCPA/CPRA) does not currently apply to us: we are below all of its thresholds and we do not sell data. The same is true of the comparable laws in other states, most of which start at 25,000 to 100,000 residents of a single state. We grant the rights above voluntarily anyway. Should a threshold ever be crossed, we will adapt this policy.
Minimum age: as stated in section 9, the app is intended for people aged 18 and over and is directed neither at children nor at teenagers. We do not knowingly collect data from anyone under 18, and in particular not from children under 13 within the meaning of COPPA. If you believe that a minor has nevertheless created an account, please write to us and we will delete it.
13. Users in Switzerland
If you use the app in Switzerland, the revised Federal Act on Data Protection (revFADP) applies to you. Everything described above applies unchanged – the same data, the same purposes, the same periods. Two points differ:
Supervisory authority: the competent authority is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, edoeb.admin.ch. The German authority named in section 8 is not competent for you.
Wording: the revFADP speaks of processing in its own terms; the meaning is the same as in this policy.
Your rights under the revFADP correspond in substance to those in section 8: information, rectification, erasure, release or transfer of your data, and objection to processing. A short email to contact@tattvue.com is enough.