Legal
Privacy Policy
Tatwise turns a tattoo idea into AI design concepts you can try on a photo of your own skin. This policy explains what data the app and this website use, why, who processes it, how long it is kept, and how to delete it.
Who we are
Tatwise is published by Atekian (atekian.com), "we" in this policy. Contact us about privacy at privacy@tatwise.app.
[[OWNER: EU representative (GDPR art. 27) or data protection officer, if one is required]]
What we collect and why
An anonymous account
A random user ID, created when you first open the app.
- Why
- To keep your designs and projects yours, and to apply generation limits.
- Where it goes
- Supabase (EU).
Your tattoo brief
The idea you type, its meaning and any lettering, and your choices: style, placement, size, color, detail and mood.
- Why
- To generate designs. It is saved with your project so you can come back to it.
- Where it goes
- Supabase (EU); sent to OpenAI (US) for each generation.
A reference photo, if you add one
We keep only a fingerprint (a hash) and its size, never the photo. Its metadata, such as location, is removed before it leaves your phone.
- Why
- To guide one generation.
- Where it goes
- OpenAI (US), for that generation only.
Generated designs
- Why
- So you can see, refine, save, try on and share them.
- Where it goes
- Supabase (EU), private storage.
Body photos for try-on
- Why
- To show a design on your skin.
- Where it goes
- Your phone only. Never uploaded. An exported preview goes only where you share it.
Purchases, if you subscribe
- Why
- To give you Tatwise Pro and keep it working across reinstalls.
- Where it goes
- Apple or Google process the payment. RevenueCat (US) receives the purchase record with your anonymous user ID. We never see your payment details.
Usage events
For example "a design was generated" or "the paywall was opened", with your anonymous user ID and app and device information (app version, operating system, device model). Never your photos, your brief's text or any link. Your IP address is not stored.
- Why
- To understand what works and improve the app.
- Where it goes
- PostHog (EU).
Crash reports
What went wrong, with app and device information (app version, operating system, device model) and your anonymous user ID.
- Why
- To fix bugs.
- Where it goes
- Sentry (EU).
Emails you send us
- Why
- To answer you.
- Where it goes
- Forwarded by Cloudflare to our mailbox at Gmail (Google).
We don't sell your data, we don't use it for advertising, and we don't use advertising identifiers (IDFA or similar). We don't collect your contacts or your location.
Legal bases (EU and UK). Providing the app and your purchases: performance of our contract with you. Usage events and crash reports: our legitimate interest in running and improving the app. [[OWNER: legal review: whether app analytics needs consent in some countries]]
AI processing
Designs are made by an AI model from OpenAI. For each generation we send OpenAI your brief and, if you added one, your reference photo. We don't send your body photos. OpenAI does not use data sent through its API to train its models. It may keep it for up to 30 days to detect abuse, and its safety systems may block some requests.
We ask first. Before your first design, the app shows what it sends to OpenAI and asks for your permission. If you choose "Not Now", nothing is sent. You can withdraw your permission in Settings → Your data → Sending Ideas to OpenAI; the app then asks again before your next design. Designs you already made stay until you delete them.
AI designs are concepts, not finished tattoo artwork. Review any design with a professional tattoo artist before getting inked. We make no claim that a design is safe or suitable to tattoo, or about how it will look or heal on skin.
Images the app produces (designs, a design you share, the artist brief and the try-on image you export) are marked as AI-generated inside the file, using the IPTC "digital source type" standard. The marking contains no personal data.
Who processes your data
| Service | What for | Where |
|---|---|---|
| Supabase | Account, database, private file storage | EU (Frankfurt) |
| OpenAI | Generating designs | US |
| Render | Runs our server that talks to the AI | EU (Frankfurt) |
| PostHog | Usage analytics | EU (Frankfurt) |
| Sentry | Crash reports | EU (Frankfurt) |
| RevenueCat | Purchases and subscription status | US |
| Cloudflare | This website and email forwarding | Global network |
| Google (Gmail) | Our mailbox for emails you send us | Global network |
Apple and Google run the app stores and payments under their own privacy policies. Transfers outside the EU and EEA rely on the European Commission's Standard Contractual Clauses or an adequacy decision. Each provider processes data only on our instructions under a data processing agreement.
How long we keep it
- Designs, projects and briefs: until you delete them, or all your data.
- Your account and usage records: until you delete your data.
- Reference photos: not kept by us. OpenAI may keep them for up to 30 days.
- Usage events: up to 1 year.
- Crash reports: up to 30 days.
- Purchase records at RevenueCat: until you delete your data. Apple and Google keep their own records under their own policies.
- Emails you send us: [[OWNER: how long support emails are kept]].
- On your phone: the try-on photo and your draft stay until you remove them or delete your data. Uninstalling the app removes them.
Deleting your data and your rights
- Delete a project: in the Library, swipe a project left. It and its designs are deleted from our servers.
- Delete everything: Settings → Delete My Data. We delete your account, designs, projects and usage records, and ask RevenueCat to delete your purchase record. Usage events already sent to PostHog are linked only to your anonymous ID and are kept for up to 1 year. The app also clears the try-on photo, drafts and exported images on your phone. This can't be undone.
- Subscriptions continue until you cancel them with Apple or Google: deleting your data doesn't cancel billing. Cancel first in your App Store or Google Play account settings.
You can also ask us for a copy of your data, or ask us to correct it, restrict or object to its processing, or move it to another service. Write to privacy@tatwise.app. You can complain to your data protection authority.
Children
Tatwise is not meant for anyone under 16. We don't knowingly collect data from them. If you believe a child has used the app, contact us and we will delete their data.
Security
Data travels encrypted (HTTPS). Designs sit in private storage that only your account can read, and downloads use links that expire after 10 minutes. AI provider keys stay on our server, never in the app.
This website
- No cookies, no local storage, no ads and no third-party embeds. Fonts are served from this site.
- Cloudflare hosts the site. To deliver and protect it, it processes your IP address, your browser's user agent and the page you ask for.
- If we turn on visit statistics, they use PostHog (EU) in cookieless mode: page views and clicks on our links, with the referring site, campaign tags, browser and device type. Visitors are counted by a server-side hash that stores nothing on your device. Links are stripped to their path. Statistics never load when your browser sends Global Privacy Control or Do Not Track.
Changes
If we change this policy, we update the version and the effective date above and list the change at the bottom of this page.
Contact
Atekian. privacy@tatwise.app
Changes to this page
- Version 1, October 3, 2026: First published version.