This Privacy Policy explains how Viral Apps Labs LLC ("we," "us," or "our") collects, uses, shares, and protects your personal data when you use the Artia mobile application and the website at getartia.app (collectively, the "Service"). Artia is an AI-powered photo generation app that transforms selfie photos into professional aesthetic images.
By using the Service, you agree to the collection and use of your data as described in this policy. If you do not agree, please do not use the Service.
1. Who We Are
Artia (formerly Aesthia) is operated by Viral Apps Labs LLC, a company registered in the United States. We act as the data controller for your personal data under the EU General Data Protection Regulation (GDPR) and applicable data protection laws.
For any privacy-related questions or requests, you can reach us at [email protected].
2. Data We Collect
We collect only the data necessary to provide, improve, and secure the Service. Below is a summary of the categories of data we process.
2.1 Account Information
- Authentication data: When you sign in with Apple Sign In or Google Sign In, we receive your name (if you choose to share it) and email address. We do not receive or store your Apple or Google account passwords.
- User ID: A unique identifier assigned to your account within our system.
2.2 Photos & Facial Data
- Selfie photos: When you use the Service, you upload selfie photos that are sent to our servers for AI processing. These photos contain your facial features and likeness.
- Generated images: The AI-generated photos created from your selfie are stored in your account gallery until you delete them or your account.
- Reference images: If you use our Pinterest Reference Mode, the reference image you provide is processed temporarily and is not permanently stored.
For comprehensive details about how we handle facial imagery, including biometric law disclosures (BIPA, GDPR Article 9), see our Face Data Policy.
2.3 Device & Technical Data
- Device information: Device model, operating system version, unique device identifiers (for fraud prevention via Apple DeviceCheck), and app version.
- Usage data: Feature usage, session duration, generation counts, and interaction patterns within the app.
- Log data: IP address, access timestamps, and error logs for debugging and security purposes.
2.4 Payment Information
- In-app purchases: Subscription and credit pack purchases are processed by Apple (via App Store In-App Purchase) and Stripe. We do not collect or store your credit card numbers, bank account details, or other financial instruments. We receive transaction confirmations, plan type, and purchase dates.
2.5 Communications
- If you contact us via email, we retain the correspondence and your email address to respond to your inquiry and improve our Service.
3. How We Use Your Data
We use your personal data for the following purposes:
- Provide the Service: Process your selfie photos through our AI pipeline to generate styled images, manage your account, deliver your generated photos, and manage subscriptions and credits.
- Improve the Service: Analyze usage patterns (in aggregate) to improve features, fix bugs, and optimize performance. We do not use your personal photos for AI model training.
- Security & fraud prevention: Detect and prevent abuse, unauthorized access, and fraudulent activity, including trial abuse via Apple DeviceCheck.
- Customer support: Respond to your inquiries, troubleshoot issues, and provide account assistance.
- Legal compliance: Comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
Important: We do not sell your personal data to third parties. We do not use your uploaded photos to train AI models. Your selfie photos are used solely to generate your requested images.
4. AI Photo Processing
Artia uses third-party AI image generation services to transform your selfie photos into styled images. Here is how the process works:
- Upload: You upload a selfie photo from your device to our backend servers.
- Prompt generation: Our system generates a text prompt describing the desired style, which is processed by Google Gemini to create a detailed instruction for the image model.
- Image generation: Your selfie and the generated prompt are sent to Wavespeed API, a third-party AI image generation service, which produces the styled output images.
- Delivery: The generated images are stored on Cloudflare R2 (cloud storage) and delivered to your device.
Throughout this process, your facial data is processed solely to produce the images you requested. The third-party AI services process your data as our data processors under contractual obligations that restrict them from using your data for any other purpose.
We do not use biometric identification or facial recognition technology. The AI model processes your photo as a visual input to generate a new image — it does not extract, store, or compare biometric templates or identifiers.
5. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data on the following legal bases:
- Consent (Art. 6(1)(a) GDPR): For processing your selfie photos through AI services. You provide consent each time you upload a photo for generation. You may withdraw consent at any time by discontinuing use of the generation feature and requesting deletion of your data.
- Contract performance (Art. 6(1)(b) GDPR): To provide the Service you have requested, including account management, subscription handling, and delivery of generated images.
- Legitimate interests (Art. 6(1)(f) GDPR): For fraud prevention, security, service improvement (using aggregated and anonymized data), and customer support, where these interests are not overridden by your rights.
- Legal obligation (Art. 6(1)(c) GDPR): To comply with applicable laws, such as tax and accounting requirements for payment records.
6. Third-Party Services
We share personal data with the following categories of third-party service providers, who act as data processors on our behalf:
AI Processing
- Wavespeed API: Processes selfie photos and text prompts to generate styled AI images. Receives your uploaded photo and style prompt.
- Google Gemini: Generates descriptive text prompts for image generation. Does not receive your photos directly.
Infrastructure & Storage
- Hetzner (Germany/EU): Hosts our backend API servers. Your account data and uploaded photos are processed on EU-based servers.
- Cloudflare R2: Stores generated images and serves them to your device.
- Vercel: Hosts our website (getartia.app).
Authentication
- Apple Sign In: Provides secure authentication. We receive your name and email (or a relay email if you choose to hide your address).
- Google Sign In: Provides authentication via your Google account. We receive your name and email.
Payments
- Apple In-App Purchase: Processes subscriptions and credit pack purchases on iOS. Apple handles all payment information directly.
- Stripe: Processes web-based payments. Stripe is PCI-DSS Level 1 compliant and handles payment card data directly. We do not store your card details.
Fraud Prevention
- Apple DeviceCheck: Used to prevent free trial abuse. We send an opaque device token to Apple to check and set two per-device bits. No personal information is shared beyond the device token.
We require all third-party service providers to process your data only in accordance with our instructions and applicable data protection laws. We do not share your data with advertisers or data brokers.
7. Data Storage & Security
Our backend servers are hosted by Hetzner in Germany (EU), meaning your account data and uploaded photos are stored and processed within the European Union.
We implement appropriate technical and organizational measures to protect your data:
- All data in transit is encrypted using TLS 1.2 or higher (HTTPS).
- Database access is restricted and authenticated.
- Generated images are stored on Cloudflare R2 with unique, non-guessable URLs.
- Authentication is handled via industry-standard protocols (OAuth 2.0 / OpenID Connect through Apple and Google).
- Payment processing is delegated to PCI-DSS compliant providers (Apple, Stripe).
- Regular security reviews and dependency updates.
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
8. Data Retention
- Account data: Retained for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where retention is required by law (e.g., financial records).
- Uploaded selfie photos: Retained on our servers during the generation process. Original uploads are purged within 72 hours after generation is complete.
- Generated images: Stored in your gallery until you delete them or delete your account.
- Usage and log data: Retained for up to 12 months for security and debugging purposes, then deleted or anonymized.
- Payment records: Retained for up to 7 years as required by tax and accounting laws.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data ("right to be forgotten").
- Restriction: Request restriction of processing in certain circumstances.
- Data portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or within the timeframe required by applicable law). We may ask you to verify your identity before processing your request.
If you are in the EEA, you have the right to lodge a complaint with your local data protection authority (e.g., CNIL in France, BfDI in Germany, ICO in the UK).
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you additional rights:
- Right to know: You may request the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the third parties with whom we share it.
- Right to delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to opt out of sale/sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
- Right to correct: You may request correction of inaccurate personal information.
- Right to limit use of sensitive personal information: We use selfie photos (which may constitute sensitive personal information) solely to provide the image generation service you requested.
To submit a verifiable consumer request, email us at [email protected] with the subject line "CCPA Request." You may also designate an authorized agent to make a request on your behalf.
Categories of personal information collected (in the preceding 12 months): Identifiers (name, email, device ID), internet activity (usage data, log data), photos and visual data (selfie uploads, generated images), and commercial information (purchase history).
11. International Data Transfers
Our primary backend servers are located in the EU (Hetzner, Germany). However, some of our third-party service providers may process data outside the EEA:
- Wavespeed API and Google Gemini may process image and prompt data in the United States or other jurisdictions.
- Cloudflare R2 may store generated images across its global network.
- Stripe and Apple process payment data in the United States.
Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on the service provider's participation in recognized data transfer frameworks (e.g., the EU-U.S. Data Privacy Framework).
12. Children's Privacy
Artia is rated 17+ on the Apple App Store and is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use the Service or provide any personal information.
If we become aware that we have collected personal data from a child under 13 without parental consent, we will take steps to delete that information as quickly as possible. If you believe a child under 13 has provided us with personal data, please contact us at [email protected].
For users between 13 and 17, we recommend parental or guardian involvement in the use of the Service. The AI photo generation features involve uploading personal photos, and we encourage parents to discuss appropriate use with their children.
13. Cookies & Tracking
The Artia website (getartia.app) may use the following technologies:
- Essential cookies: Required for basic website functionality, such as authentication state and session management.
- Analytics: We may use privacy-respecting analytics to understand aggregate traffic patterns (e.g., page views, device types). This data is collected in aggregate and does not identify individual users.
The Artia iOS app does not use third-party tracking SDKs or advertising identifiers. We comply with Apple's App Tracking Transparency (ATT) framework and do not track users across other apps or websites.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Notify you via email or an in-app notice if the changes are significant (e.g., new categories of data collection or new third-party processors).
Your continued use of the Service after the effective date of a revised policy constitutes your acceptance of the changes.
If you have any questions about this Privacy Policy, your data, or your rights, please contact us:
For GDPR-related inquiries, you may also contact your local data protection authority. A list of EEA supervisory authorities is available at edpb.europa.eu.