Stela – Privacy Policy

Effective Date: 16 July 2025

Da Vinci Software Bilişim A.Ş. ("Da Vinci Software", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your information when you use the Stela mobile application, website, and related services (collectively, the "Services"). By using the Services, you agree to this Privacy Policy.

1. Information We Collect

Category Examples Purpose
Information You Provide • Selfie photos and image prompts
• Style selections
• Account details (name, email, password)
• Payment information processed by Apple IAP
Provide and personalize the Service, generate Outputs, account management
Automatically Collected • Device identifiers (IDFV, IP address)
• Log data and diagnostics
• Usage statistics
• Approximate location (city/region)
Analytics, crash reporting, app performance, fraud prevention
Tracking & Advertising (with consent) • Identifier for Advertisers (IDFA)
• SKAdNetwork conversion data
Ad attribution and marketing effectiveness
Third-Party Data • Apple "Sign in with Apple" email hash
• Firebase Cloud Messaging token
Authentication, push notifications

We do not create or store face recognition templates. All biometric analyses are performed on-device (where possible) or on secure servers and are discarded once Outputs are generated.

2. How We Use Your Information

3. Legal Bases for Processing (GDPR)

We rely on: (i) Contract – processing necessary to provide the Services; (ii) Consent – optional tracking/marketing; (iii) Legitimate Interest – security, fraud prevention; and (iv) Legal Obligation – tax and accounting requirements.

4. Face Data

4.1 Face Data Collection & Storage

The selfie JPEG you voluntarily upload is stored in an encrypted bucket in Google Cloud Storage (Firebase) at a path scoped to your authenticated user ID (users/<uid>/images/<file>.jpg). Your private Firebase Storage security rules ensure that no other user or service can access these files.

4.2 Face Data Processing

When you request an AI transformation, the original image is transmitted via TLS 1.3 to our inference endpoint hosted by OpenAI. The image is used solely to generate your requested Output and to compute a temporary face embedding that guides the model. The embedding and the original image are permanently deleted within 30 days (see Section 7). We do not share face data with advertising networks, analytics platforms, or any third party other than OpenAI acting as a processor under strict confidentiality.

5. Sharing & Disclosure

We do not sell or rent your personal data to third parties.

6. International Transfers

Data may be processed outside your country of residence, including the United States. Whenever we transfer personal data internationally, we rely on Standard Contractual Clauses or equivalent safeguards approved by the European Commission.

7. Data Retention

Face images and embeddings are retained for up to 30 days after your Output is delivered, enabling you to re‑download or request corrections. You may erase them earlier using Settings → Delete My Data, which triggers immediate deletion within five seconds. All other account data is retained while your account is active and as required by applicable law.

8. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or port your data; object to or restrict processing; and withdraw consent at any time. To exercise these rights, use the in‑app Settings → Privacy tools or contact us at support@davincisoft.co.

9. Account Deletion (Apple Guideline 5.1.1‑v)

You can delete your account from Settings → Delete Account. All personal data will be permanently removed from our servers within 30 days, except where retention is required by legal obligations.

10. Children’s Privacy

The Services are not directed to children under 13 years (or the minimum age in your jurisdiction). We do not knowingly collect personal data from children. If we learn that we have done so, we will delete it.

11. Security

We employ administrative, technical, and physical safeguards to protect your data, including TLS 1.2+ encryption in transit, AES‑256 encryption at rest, and least‑privilege access controls. No system is 100% secure, and we cannot guarantee absolute security.

12. App Tracking Transparency (ATT)

We request your permission via Apple’s ATT prompt before accessing IDFA for advertising or analytics that may track you across apps. If you decline, we will rely on SKAdNetwork and aggregated analytics that do not track you.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the App or other means. Continued use after the effective date indicates acceptance.

14. Contact Us

If you have questions about privacy or this Policy, contact our Data Protection Officer at support@davincisoft.co or write to: