This Privacy Policy explains what personal data we collect when you use the MiniMe mobile apps for iPhone and Android (the “Apps”) and the AI Family Maker website at aifamilymaker.com (the “Website”), why we collect it, who we share it with, and the choices you have. Together we call the Apps and the Website the “Services”.
Who is who
- APPVISION YAZILIM HİZMETLERİ LİMİTED ŞİRKETİ (Turkey) runs the MiniMe mobile apps for iOS and Android and the website aifamilymaker.com, where the service is called “AI Family Maker”. It is the data controller for your personal data. In these documents, “we”, “us” and “our” mean this company.
- Vision Innovations, LLC sells and processes the payment for purchases made on aifamilymaker.com, through Stripe. Its name appears on your card statement and receipts for web purchases.
- Apple (App Store) and Google (Google Play) sell and bill purchases made inside the MiniMe apps, under their own terms and refund processes.
- Contact for everything, including privacy requests: contact@vision-innovations.com
The short version
- You choose the photos. We use them only to create the images you ask for.
- The parent photos you upload are deleted from our storage after processing. The images we create stay in your album until you delete your account or ask us to delete them.
- The face check in the Apps runs only on your phone. We do not create, store or share face templates, face geometry or any other biometric identifiers.
- We do not sell your personal data. There are no ads in the Services and no advertising SDKs in the Apps.
- We do not collect your precise location.
- You can ask us for a copy of your data, or to correct or delete it, at contact@vision-innovations.com.
What we collect
Photos you choose
To create an image, you give us a photo of each “parent”: one you take with the camera, pick from your photo library, or upload on the Website. In the Apps, the camera screen can show your recent photos if you allow photo library access. Those stay on your device; only the photos you pick are uploaded.
Images we create for you
The images generated from your photos, any in-progress preview images the image engine produces while it works, and the settings you chose, such as the theme, the composition (child only, with mom, with dad or the whole family), boy or girl, and image quality.
Account information
- Apps: you don’t need to sign up. The App creates an account linked to a device identifier that your phone’s operating system provides to our app, together with your language setting.
- Website: you sign in with Google or Apple. We receive your name, your email address (Apple may give us a private relay address instead), whether the email is verified, and an account ID from Google or Apple. We use a sign-in cookie to keep you signed in.
The Apps and the Website use separate accounts. We do not link an App account to a Website account.
Credits and purchases
Your credit balance, which credits paid for which image, your subscription status and renewal dates, and product and transaction IDs from Apple, Google or Stripe. We never receive your full card number or bank details.
App and device information
App version and build, device model, operating system and version, language, and the device identifier above. We also collect how you use the Services, for example the screens you open, the buttons you tap, when an image starts and finishes, the star rating you give a result and whether you save or share it, plus crash and error reports. Our analytics provider may work out your approximate location, such as your country or city, from your IP address.
Ad attribution
If you installed an App after tapping one of our ads, we learn which campaign it came from: on iPhone through the Apple Ads attribution token, which RevenueCat collects, and on Android through the Google Play Install Referrer (campaign, ad group and keyword IDs). We use this only to measure our own ad campaigns. We do not use it to show you ads, and the Apps do not use your device’s advertising identifier (IDFA or Google Advertising ID).
Device integrity checks
When an App gives you free credits, it asks Apple (App Attest and DeviceCheck) or Google (Play Integrity) to confirm that the request comes from our genuine app on a real device. This stops people from claiming free credits again and again. We store a one-way hash of a device identifier (the App Attest key ID on iPhone, the Android ID on Android), and on iPhone Apple keeps a small flag for your device through DeviceCheck.
Notifications
If you allow notifications, we store a push token so we can tell you when your image is ready. These messages go through Firebase Cloud Messaging and may show a small preview of the result. The Apps also schedule reminder notifications for people without a subscription. These are scheduled on your phone, not sent from our servers, and you can turn them off in the App’s Settings.
Support messages
If you contact us, we keep your message, your email address and anything you send us. When you open support from inside an App, it adds your account ID, device identifier, app version, device model, operating system, credit balance and subscription status so we can help faster.
What we don’t collect
We don’t collect your precise (GPS) location, your contacts, audio from your microphone, or your device’s advertising identifier. We don’t ask for your date of birth, address or phone number.
How your photos are processed
- The photos you choose are sent over an encrypted connection to our servers and stored in Cloudflare R2, our cloud storage. On the Website they pass through our website host, Vercel, on the way.
- Our servers send the two photos, with instructions for the chosen theme, to OpenAI’s image generation service. If OpenAI is unavailable, we use Google’s Gemini image generation service instead.
- The generated image is stored in Cloudflare R2 and shown in your album or account.
- Once processing is finished, the parent photos are deleted from our storage.
We do not use your photos or results to train AI models. Under their business API terms, OpenAI and Google may keep what we send them for a limited time to detect abuse, and do not use it to train their models. Their safety systems may refuse some requests; when that happens, the image is not created and your credits are returned.
On-device face check and biometric data
When you pick a photo in an App, the App uses Apple’s Vision framework (iPhone) or Google ML Kit (Android) to check that the photo shows exactly one face and to frame the crop around it. This check:
- runs entirely on your device, and the photo is not sent anywhere for it;
- only finds where a face is in the picture (and, on iPhone, a photo quality score), which the App uses to crop the photo and then discards;
- is never used to recognise or identify anyone. The only thing we learn from it is whether the check passed and how many faces were found, as part of app analytics.
We do not create, collect, store, share or sell face templates, face geometry, faceprints or any other biometric identifiers or biometric information, and we don’t use any technology to recognise or identify people from their photos. This applies to the face check and to the photos you upload.
How we use your information
- To create your images, store them and show them to you.
- To run your account, credits, purchases and subscriptions, including restoring purchases and returning credits when an image fails.
- To keep the Services safe and prevent abuse, for example limiting free credits to one per device and blocking accounts that break our Terms of Use.
- To send the notifications you allowed.
- To find and fix bugs and crashes, and to understand how the Services are used so we can improve them.
- To measure how well our own ad campaigns work.
- To answer your messages and handle refunds.
- To follow the law and enforce our Terms of Use.
We do not sell your personal data, and we do not use it for targeted advertising.
Legal bases (EEA, UK and Turkey)
Where the GDPR, the UK GDPR or Turkey’s Personal Data Protection Law No. 6698 (KVKK) applies, we rely on these legal bases:
- Contract: creating your images and running your account, credits and purchases.
- Legitimate interests: security and abuse prevention, error monitoring, analytics to improve the Services, and measuring our ad campaigns. We balance these interests against your rights, and you can object at any time.
- Consent: camera, photo library and notification access, which you control in your device settings.
- Legal obligation: tax and accounting records, and answering lawful requests from authorities.
We don’t process your photos with technology meant to identify people, so we don’t treat them as biometric data.
International transfers
We are based in Turkey, and our service providers process data in the United States, the European Union and other countries. When we transfer personal data out of Turkey, the EEA or the UK, we use the safeguards the law requires, such as standard contractual clauses.
How long we keep your information
- Parent photos: deleted from our storage automatically after processing. The image providers may keep them for a limited time for abuse monitoring, as described above.
- Generated images and previews: kept so you can see them in your album until you delete your account. You can also ask us to delete specific images.
- Account, credit and subscription data: until you delete your account.
- Website sign-in cookie: up to 180 days, or until you sign out.
- Analytics and error reports: for the retention periods set in Google Analytics and our Sentry server, after which they are deleted or kept only in aggregated form.
- Support emails: as long as needed to help you and keep a record of the conversation.
When you delete your account, we keep only what we must or need to keep:
- the one-way hash of your device identifier, no longer linked to you, so the same device can’t claim free credits again;
- payment and invoice records that Stripe, Vision Innovations, LLC, Apple and Google keep under tax and accounting laws.
Deleted data may stay in routine backups for a limited time before it is overwritten.
Deleting your account and data
- Website: open your Account page and choose to delete your account. This immediately cancels a Website subscription and deletes your images, remaining photos, credits and account.
- Apps: email us at contact@vision-innovations.com and ask us to delete your App account. App accounts have no email address, so we may ask for details that help us find your account, such as your account ID from the App’s support screen.
Deleting an App from your phone does not delete your data on our servers and does not cancel an App Store or Google Play subscription. Cancel App subscriptions in your App Store or Google Play settings.
Your choices
- Reminders: turn them off in the App’s Settings.
- Push notifications: turn them off in the App’s Settings or in your device settings.
- Camera and photos: allow or remove access at any time in your device settings.
- Analytics: block Website analytics cookies as described above, or ask us to delete the analytics data linked to your App’s device identifier.
Your rights
Depending on where you live, you may have the right to:
- know what personal data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we use it, including processing based on legitimate interests;
- receive your data in a portable format;
- withdraw your consent at any time, without affecting earlier processing;
- complain to a data protection authority.
To use any of these rights, email contact@vision-innovations.com. We’ll reply within 30 days, and we may ask you to confirm that the account is yours before we act.
Turkey: you have the rights listed in Article 11 of the KVKK, and you can complain to the Personal Data Protection Authority (KVKK) if you are not satisfied with our answer.
EEA and UK: you can complain to the data protection authority where you live or work, or, in the UK, to the Information Commissioner’s Office.
United States: depending on your state, you may have the right to know, access, correct and delete your personal information, and to opt out of its sale or its sharing for targeted advertising. We do not sell or share personal information for those purposes, and we will not treat you differently for using your rights. You can use an authorised agent, and we may need to verify your request.
Children
The Services are only for adults aged 18 or over. They are not directed at children, and we do not knowingly collect personal data from anyone under 18. Our Terms of Use do not allow photos of anyone under 18 as a parent photo. If you believe a child has used the Services or that a child’s photo was uploaded, contact us and we will delete it.
Security
We protect your data with encrypted connections (HTTPS), restricted access to our systems, and a Website sign-in cookie that scripts on the page can’t read. Photos and images are stored at long, random web addresses. Anyone who has the exact address of an image could open it, so be careful where you paste image links. No system is completely secure, but we work to protect your data and will tell you and the authorities about a breach when the law requires it.
Changes to this policy
We may update this policy when the Services or the law change. We’ll post the new version here with a new “Last updated” date and, for important changes, let you know in the Apps or on the Website before they take effect.
Contact us
For any question about this policy or your personal data, email contact@vision-innovations.com.