Hypedit – Privacy Policy

Effective Date: September 17, 2025

Da Vinci Software Bilişim A.Ş. ("Da Vinci Software", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your information when you use the Hypedit mobile application, website, and related services (collectively, the "Services"). By using the Services, you agree to this Privacy Policy.

1. Information We Collect

Category Examples Purpose
User-Provided Data • Selfie photos and image prompts
• Style/outfit selections
• Account info (name, email, password)
• Payment info via Apple/Google IAP
Provide, personalize, and generate AI outputs; manage accounts and subscriptions
Automatically Collected • Device identifiers (IDFV, IP)
• Logs and diagnostics
• App usage statistics
• Approximate location
Analytics, crash reporting, performance monitoring, fraud prevention
Tracking & Advertising (with consent) • IDFA (Apple)
• SKAdNetwork conversion data
Ad attribution and marketing effectiveness
Third-Party Data • "Sign in with Apple" email hash
• Firebase Cloud Messaging token
Authentication, push notifications

We do not create or store face recognition templates. All biometric or facial analyses are done on-device or on secure servers and deleted after generating the Outputs.

2. How We Use Your Information

3. Legal Bases for Processing (GDPR)

We rely on: (i) Contract – processing necessary to provide the Services; (ii) Consent – optional tracking/marketing; (iii) Legitimate Interest – security, fraud prevention; (iv) Legal Obligation – tax and accounting compliance.

4. Face Data

4.1 Collection & Storage

Uploaded selfies are stored in encrypted Firebase Storage paths scoped to your user ID. Security rules ensure only your account can access your files.

4.2 Processing

Images sent for AI transformations are transmitted via TLS 1.3 to our inference endpoint (OpenAI). Data is used solely to generate Outputs and temporary face embeddings. Both the original image and embeddings are permanently deleted within 30 days or immediately if requested via Settings → Delete My Data. Face data is not shared with advertisers or analytics services.

5. Sharing & Disclosure

We do not sell or rent your personal data.

6. International Transfers

Your data may be processed outside your country, including the United States. Transfers rely on Standard Contractual Clauses or equivalent safeguards.

7. Data Retention

Face images and embeddings are retained up to 30 days after Output delivery. Account data is retained while your account is active and as required by law.

8. Your Rights

Depending on your jurisdiction, you may access, correct, delete, port, or restrict processing of your data, or withdraw consent. Exercise rights via in-app Settings → Privacy or by contacting support@davincisoft.co.

9. Account Deletion

Delete your account via Settings → Delete Account. All personal data will be permanently removed within 30 days, except as legally required.

10. Children’s Privacy

The Services are not directed to children under 13 years (or local minimum age). We do not knowingly collect data from children. If detected, data is deleted.

11. Security

We use technical, administrative, and physical safeguards, including TLS 1.2+, AES-256 encryption at rest, and least-privilege access. Absolute security cannot be guaranteed.

12. App Tracking Transparency (ATT)

We request your permission via Apple ATT before accessing IDFA. If declined, we rely on SKAdNetwork and aggregated non-identifiable analytics.

13. Changes to This Policy

Material updates will be notified in-app or by other means. Continued use indicates acceptance.

14. Contact Us

Questions or privacy concerns? Contact our Data Protection Officer at support@davincisoft.co.