trendy.ai Privacy Policy
This policy explains how Appera ("we", "us") handles personal data when you use the trendy.ai app for iOS and Android and the services behind it (the "Service"). Questions: support@appera.io.
1. Who is responsible
Appera is the controller of the personal data described here. You can reach us at support@appera.io.
2. What we collect
Account
When you sign in with Apple or Google we receive a unique account identifier from that provider and, if it is shared, your email address. We do not receive your password, and we do not store your name or profile picture on our servers.
Photos you add
The photos of faces you add to use with trends, and any names or labels you give to the people in them (for example "Me").
Face data derived from your photos
To use your photos with trends, we analyse each one: we detect faces and estimate details such as the number of faces, head angle, image quality and an approximate age range, and we create a numerical face template (an "embedding") that lets us recognise which of your photos show the same person. A face template is biometric data. We use it only to provide the Service to you. We never use it for advertising or to identify you anywhere else.
Creations
The trends you choose, any text you add, the images and videos generated for you, and your choices about favourites and sharing.
Credits and purchases
Your credit balance and history (credits granted, spent, returned or earned from ads) and, for purchases, the product, subscription status, renewal dates and transaction identifiers we receive from the App Store or Google Play through our billing provider RevenueCat. We never receive your card or other payment details.
Rewarded ads
If you choose to watch an ad for credits, the Google AdMob SDK in the app collects device and advertising identifiers, an approximate location derived from your IP address and information about your interaction with the ad. We receive a confirmation linked to your account so we can add the credits.
Notifications
If you allow notifications: your device's push token, platform, app version and language.
Technical and safety information
Our servers log requests, including IP addresses, for security and troubleshooting. Server errors are reported to our error-monitoring service with personal details removed. If you report content we keep the reason and any note you write; if you are not signed in we store a one-way hash of your IP address instead of the address.
3. How we use it
- To provide the Service (performance of our contract with you): your account, photos, generating and storing creations, sharing, notifications, credits and purchases.
- Face data (your explicit consent): analysing your photos and creating face templates. You give this consent when you add photos, and you can withdraw it at any time by deleting the photos or your account.
- Safety (our legitimate interests and legal obligations): reviewing content that is reported to us, preventing abuse and enforcing our terms.
- Rewarded ads (your consent where the law requires it): showing ads you choose to watch and crediting your account.
- Security and improvement (our legitimate interests): protecting accounts, preventing fraud and fixing problems.
- Legal requirements: complying with applicable law, tax and store rules.
We do not sell your personal data. We do not use your photos, face data or creations to train AI models.
4. Who we share it with
We share personal data only with service providers that process it for us, and only as needed for the purposes above:
- Hosting and storage: Railway (servers and file storage, Netherlands) and Supabase (database, Germany).
- AI generation: fal.ai and the AI models we run through it (and, when used, Replicate, Kling or Runway). For each creation they receive short-lived links to up to five of your photos and the trend's instructions, and they return the result to us. They do not receive your face templates or email address.
- Sign-in, purchases and notifications: Apple, Google (including Google Play and Firebase Cloud Messaging) and RevenueCat.
- Advertising: Google AdMob, for rewarded ads you choose to watch.
- Error monitoring: Sentry.
We may also disclose data when required by law or to protect people's safety, and to a successor if our business is sold or reorganised.
What you make public: if you share a creation on a trend page, anyone can see it, without your name. A share link can be opened by anyone who has it until it expires.
5. International transfers
Our main servers are in the European Union. Some providers may process data in other countries, including the United States. Where required, we rely on safeguards such as the European Commission's standard contractual clauses.
6. How long we keep it
- Photos and face templates: until you delete the photo or your account. Deleting a photo removes the file and its face template straight away. Details from its analysis, such as image quality and the estimated age range, are kept until you delete your account.
- Creations: until you delete them. Deleted creations are erased permanently after 30 days.
- In-app notifications: up to 90 days.
- Push tokens: until you sign out, turn off or uninstall the app, the token stops working, or you delete your account.
- Your account: until you delete it. See section 8.
Copies may remain for a limited time in backups and server logs before they are overwritten. App stores and RevenueCat keep purchase records under their own policies.
7. Your rights
Depending on where you live, you have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive a copy of it, and to withdraw consent at any time without affecting earlier processing. You can do most of this in the app: delete photos, delete creations, stop sharing and delete your account. For anything else, email support@appera.io. You can also complain to a data protection authority, such as the Personal Data Protection Authority (KVKK) in Türkiye or your local authority in the EU or UK.
8. Deleting your account
Go to Profile → Delete account. Your account is signed out everywhere and scheduled for deletion. If you sign in again within 30 days, the deletion is cancelled. After 30 days we permanently delete your account, photos, face data, creations, credit history and related records, and revoke your Sign in with Apple authorisation. Deleting your account does not cancel an App Store or Google Play subscription; cancel it in your store account settings. More at delete-account.
9. Children
The Service is only for people aged 18 or over. Do not add photos of anyone under 18 unless you are their parent or legal guardian. Creations that may show a minor cannot be shared publicly. If we learn that a person under 18 is using the Service, we will delete the account.
10. Security
We protect data with encryption in transit, access controls, short-lived links for photos and encrypted storage of sign-in tokens. No system is completely secure, but we work to protect your information and will notify you and the authorities of a breach where the law requires.
11. Changes
We will post updates on this page and change the effective date. If a change is significant, we will tell you in the app before it takes effect.
12. Contact
Appera · support@appera.io