Skip to main content
Legal

Privacy Policy

Last updated: May 6, 2026

This Privacy Policy explains how Viral Apps Labs LLC ("we," "us," or "our") collects, uses, shares, and protects your personal data when you use the Artia mobile application and the website at getartia.app (collectively, the "Service"). Artia is an AI-powered photo generation app that transforms selfie photos into professional aesthetic images.

By using the Service, you agree to the collection and use of your data as described in this policy. If you do not agree, please do not use the Service.

Table of Contents
  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. AI Photo Processing
  5. Legal Basis for Processing (GDPR)
  6. Third-Party Services
  7. Data Storage & Security
  8. Data Retention
  9. Your Rights
  10. California Privacy Rights (CCPA/CPRA)
  11. International Data Transfers
  12. Children's Privacy
  13. Cookies & Tracking
  14. Changes to This Policy
  15. Contact Us

1. Who We Are

Artia (formerly Aesthia) is operated by Viral Apps Labs LLC, a company registered in the United States. We act as the data controller for your personal data under the EU General Data Protection Regulation (GDPR) and applicable data protection laws.

For any privacy-related questions or requests, you can reach us at [email protected].

2. Data We Collect

We collect only the data necessary to provide, improve, and secure the Service. Below is a summary of the categories of data we process.

2.1 Account Information

2.2 Photos & Facial Data

For comprehensive details about how we handle facial imagery, including biometric law disclosures (BIPA, GDPR Article 9), see our Face Data Policy.

2.3 Device & Technical Data

2.4 Payment Information

2.5 Communications

3. How We Use Your Data

We use your personal data for the following purposes:

Important: We do not sell your personal data to third parties. We do not use your uploaded photos to train AI models. Your selfie photos are used solely to generate your requested images.

4. AI Photo Processing

Artia uses third-party AI image generation services to transform your selfie photos into styled images. Here is how the process works:

  1. Upload: You upload a selfie photo from your device to our backend servers.
  2. Prompt generation: Our system generates a text prompt describing the desired style, which is processed by Google Gemini to create a detailed instruction for the image model.
  3. Image generation: Your selfie and the generated prompt are sent to Wavespeed API, a third-party AI image generation service, which produces the styled output images.
  4. Delivery: The generated images are stored on Cloudflare R2 (cloud storage) and delivered to your device.

Throughout this process, your facial data is processed solely to produce the images you requested. The third-party AI services process your data as our data processors under contractual obligations that restrict them from using your data for any other purpose.

We do not use biometric identification or facial recognition technology. The AI model processes your photo as a visual input to generate a new image — it does not extract, store, or compare biometric templates or identifiers.

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data on the following legal bases:

6. Third-Party Services

We share personal data with the following categories of third-party service providers, who act as data processors on our behalf:

AI Processing

  • Wavespeed API: Processes selfie photos and text prompts to generate styled AI images. Receives your uploaded photo and style prompt.
  • Google Gemini: Generates descriptive text prompts for image generation. Does not receive your photos directly.

Infrastructure & Storage

  • Hetzner (Germany/EU): Hosts our backend API servers. Your account data and uploaded photos are processed on EU-based servers.
  • Cloudflare R2: Stores generated images and serves them to your device.
  • Vercel: Hosts our website (getartia.app).

Authentication

  • Apple Sign In: Provides secure authentication. We receive your name and email (or a relay email if you choose to hide your address).
  • Google Sign In: Provides authentication via your Google account. We receive your name and email.

Payments

  • Apple In-App Purchase: Processes subscriptions and credit pack purchases on iOS. Apple handles all payment information directly.
  • Stripe: Processes web-based payments. Stripe is PCI-DSS Level 1 compliant and handles payment card data directly. We do not store your card details.

Fraud Prevention

  • Apple DeviceCheck: Used to prevent free trial abuse. We send an opaque device token to Apple to check and set two per-device bits. No personal information is shared beyond the device token.

We require all third-party service providers to process your data only in accordance with our instructions and applicable data protection laws. We do not share your data with advertisers or data brokers.

7. Data Storage & Security

Our backend servers are hosted by Hetzner in Germany (EU), meaning your account data and uploaded photos are stored and processed within the European Union.

We implement appropriate technical and organizational measures to protect your data:

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

8. Data Retention

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or within the timeframe required by applicable law). We may ask you to verify your identity before processing your request.

If you are in the EEA, you have the right to lodge a complaint with your local data protection authority (e.g., CNIL in France, BfDI in Germany, ICO in the UK).

10. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you additional rights:

To submit a verifiable consumer request, email us at [email protected] with the subject line "CCPA Request." You may also designate an authorized agent to make a request on your behalf.

Categories of personal information collected (in the preceding 12 months): Identifiers (name, email, device ID), internet activity (usage data, log data), photos and visual data (selfie uploads, generated images), and commercial information (purchase history).

11. International Data Transfers

Our primary backend servers are located in the EU (Hetzner, Germany). However, some of our third-party service providers may process data outside the EEA:

Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on the service provider's participation in recognized data transfer frameworks (e.g., the EU-U.S. Data Privacy Framework).

12. Children's Privacy

Artia is rated 17+ on the Apple App Store and is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use the Service or provide any personal information.

If we become aware that we have collected personal data from a child under 13 without parental consent, we will take steps to delete that information as quickly as possible. If you believe a child under 13 has provided us with personal data, please contact us at [email protected].

For users between 13 and 17, we recommend parental or guardian involvement in the use of the Service. The AI photo generation features involve uploading personal photos, and we encourage parents to discuss appropriate use with their children.

13. Cookies & Tracking

The Artia website (getartia.app) may use the following technologies:

The Artia iOS app does not use third-party tracking SDKs or advertising identifiers. We comply with Apple's App Tracking Transparency (ATT) framework and do not track users across other apps or websites.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

Your continued use of the Service after the effective date of a revised policy constitutes your acceptance of the changes.

15. Contact Us

If you have any questions about this Privacy Policy, your data, or your rights, please contact us:

Viral Apps Labs LLC
Email: [email protected]
Website: getartia.app

For GDPR-related inquiries, you may also contact your local data protection authority. A list of EEA supervisory authorities is available at edpb.europa.eu.