Legal

Privacy Policy

Tatwise turns a tattoo idea into AI design concepts you can try on a photo of your own skin. This policy explains what data the app and this website use, why, who processes it, how long it is kept, and how to delete it.

Version 1Effective October 3, 2026

Who we are

Tatwise is published by Atekian (atekian.com), "we" in this policy. Contact us about privacy at privacy@tatwise.app.

[[OWNER: EU representative (GDPR art. 27) or data protection officer, if one is required]]

What we collect and why

An anonymous account

A random user ID, created when you first open the app.

Why
To keep your designs and projects yours, and to apply generation limits.
Where it goes
Supabase (EU).

Your tattoo brief

The idea you type, its meaning and any lettering, and your choices: style, placement, size, color, detail and mood.

Why
To generate designs. It is saved with your project so you can come back to it.
Where it goes
Supabase (EU); sent to OpenAI (US) for each generation.

A reference photo, if you add one

We keep only a fingerprint (a hash) and its size, never the photo. Its metadata, such as location, is removed before it leaves your phone.

Why
To guide one generation.
Where it goes
OpenAI (US), for that generation only.

Generated designs

Why
So you can see, refine, save, try on and share them.
Where it goes
Supabase (EU), private storage.

Body photos for try-on

Why
To show a design on your skin.
Where it goes
Your phone only. Never uploaded. An exported preview goes only where you share it.

Purchases, if you subscribe

Why
To give you Tatwise Pro and keep it working across reinstalls.
Where it goes
Apple or Google process the payment. RevenueCat (US) receives the purchase record with your anonymous user ID. We never see your payment details.

Usage events

For example "a design was generated" or "the paywall was opened", with your anonymous user ID and app and device information (app version, operating system, device model). Never your photos, your brief's text or any link. Your IP address is not stored.

Why
To understand what works and improve the app.
Where it goes
PostHog (EU).

Crash reports

What went wrong, with app and device information (app version, operating system, device model) and your anonymous user ID.

Why
To fix bugs.
Where it goes
Sentry (EU).

Emails you send us

Why
To answer you.
Where it goes
Forwarded by Cloudflare to our mailbox at Gmail (Google).

We don't sell your data, we don't use it for advertising, and we don't use advertising identifiers (IDFA or similar). We don't collect your contacts or your location.

Legal bases (EU and UK). Providing the app and your purchases: performance of our contract with you. Usage events and crash reports: our legitimate interest in running and improving the app. [[OWNER: legal review: whether app analytics needs consent in some countries]]

AI processing

Designs are made by an AI model from OpenAI. For each generation we send OpenAI your brief and, if you added one, your reference photo. We don't send your body photos. OpenAI does not use data sent through its API to train its models. It may keep it for up to 30 days to detect abuse, and its safety systems may block some requests.

We ask first. Before your first design, the app shows what it sends to OpenAI and asks for your permission. If you choose "Not Now", nothing is sent. You can withdraw your permission in Settings → Your data → Sending Ideas to OpenAI; the app then asks again before your next design. Designs you already made stay until you delete them.

AI designs are concepts, not finished tattoo artwork. Review any design with a professional tattoo artist before getting inked. We make no claim that a design is safe or suitable to tattoo, or about how it will look or heal on skin.

Images the app produces (designs, a design you share, the artist brief and the try-on image you export) are marked as AI-generated inside the file, using the IPTC "digital source type" standard. The marking contains no personal data.

Who processes your data

ServiceWhat forWhere
SupabaseAccount, database, private file storageEU (Frankfurt)
OpenAIGenerating designsUS
RenderRuns our server that talks to the AIEU (Frankfurt)
PostHogUsage analyticsEU (Frankfurt)
SentryCrash reportsEU (Frankfurt)
RevenueCatPurchases and subscription statusUS
CloudflareThis website and email forwardingGlobal network
Google (Gmail)Our mailbox for emails you send usGlobal network

Apple and Google run the app stores and payments under their own privacy policies. Transfers outside the EU and EEA rely on the European Commission's Standard Contractual Clauses or an adequacy decision. Each provider processes data only on our instructions under a data processing agreement.

How long we keep it

  • Designs, projects and briefs: until you delete them, or all your data.
  • Your account and usage records: until you delete your data.
  • Reference photos: not kept by us. OpenAI may keep them for up to 30 days.
  • Usage events: up to 1 year.
  • Crash reports: up to 30 days.
  • Purchase records at RevenueCat: until you delete your data. Apple and Google keep their own records under their own policies.
  • Emails you send us: [[OWNER: how long support emails are kept]].
  • On your phone: the try-on photo and your draft stay until you remove them or delete your data. Uninstalling the app removes them.

Deleting your data and your rights

  • Delete a project: in the Library, swipe a project left. It and its designs are deleted from our servers.
  • Delete everything: Settings → Delete My Data. We delete your account, designs, projects and usage records, and ask RevenueCat to delete your purchase record. Usage events already sent to PostHog are linked only to your anonymous ID and are kept for up to 1 year. The app also clears the try-on photo, drafts and exported images on your phone. This can't be undone.
  • Subscriptions continue until you cancel them with Apple or Google: deleting your data doesn't cancel billing. Cancel first in your App Store or Google Play account settings.

You can also ask us for a copy of your data, or ask us to correct it, restrict or object to its processing, or move it to another service. Write to privacy@tatwise.app. You can complain to your data protection authority.

Children

Tatwise is not meant for anyone under 16. We don't knowingly collect data from them. If you believe a child has used the app, contact us and we will delete their data.

Security

Data travels encrypted (HTTPS). Designs sit in private storage that only your account can read, and downloads use links that expire after 10 minutes. AI provider keys stay on our server, never in the app.

This website

  • No cookies, no local storage, no ads and no third-party embeds. Fonts are served from this site.
  • Cloudflare hosts the site. To deliver and protect it, it processes your IP address, your browser's user agent and the page you ask for.
  • If we turn on visit statistics, they use PostHog (EU) in cookieless mode: page views and clicks on our links, with the referring site, campaign tags, browser and device type. Visitors are counted by a server-side hash that stores nothing on your device. Links are stripped to their path. Statistics never load when your browser sends Global Privacy Control or Do Not Track.

Changes

If we change this policy, we update the version and the effective date above and list the change at the bottom of this page.

Contact

Atekian. privacy@tatwise.app

Changes to this page

  • Version 1, October 3, 2026: First published version.