Privacy Policy
Template: replace every [bracketed] item and have a lawyer review before launch. Last updated [date].
This policy explains what [Company name, LLC] ("we") collects when you use Rembrandt and how we use it. The short version: no ads, no tracking, and AI runs on your device.
What stays on your device
Photos you import, their edits, albums, and AI analysis (subject detection, depth, refocus) are processed and stored on your device. We never see them unless you turn on sync or share a link.
What we collect when you use online features
- Account: your email address and, if you add one, your name.
- Synced library (Cloud sync): edit settings, ratings, flags, album names and small thumbnails.
- Originals (Cloud plans): the original photo files you choose to back up, stored with Backblaze B2.
- Share links: the photos you share, rendered as JPEG, plus a view counter.
- Reports: if someone reports a share link, we keep the report, the optional email they give, and a salted hash of their IP address (to stop abuse of the report form).
- Purchases: Cloud plans bought on the web are handled by Paddle.com as merchant of record; we receive your plan, status and a customer ID, never your card details. The phone apps and any in-app subscriptions are sold by Apple or Google, who don't share your payment details with us.
What we don't do
We don't sell your data, show ads, use third-party trackers or analytics cookies, or use your photos to train AI models.
Processors
- Supabase (accounts and database)
- Backblaze (photo storage)
- Paddle (payments, tax and invoices)
- Cloudflare (website hosting)
Each processes data only to provide its service to us.
Safety and the law
Every photo uploaded to Cloud is checked automatically against databases of known child sexual abuse images, using a digital fingerprint of the image (Microsoft PhotoDNA); nobody looks at your photos to do this. Photos in a new share link are also checked for sexually explicit content (Google Cloud Vision SafeSearch) before the link is created; Google processes them only to return the result. Photos that stay on your device are never checked by us. Before syncing, the app checks each photo for sexually explicit content on your device; that check runs entirely on the device, and its result isn't sent to us. If we find or are told about apparent child sexual abuse material, US law requires us to report it, with the account details involved, to the National Center for Missing & Exploited Children (NCMEC), which may pass it to law enforcement. We otherwise disclose data to authorities only when legally required or to prevent imminent harm.
Retention
We keep your data while your account is open. Files and records connected to a safety report may be kept for up to a year, as the law requires, even if the account is deleted. When you delete your account (Account → Data & privacy), we delete your online data within [30] days, except records we must keep by law, such as invoices held by Paddle.
Your rights
You can download your data and delete your account at any time in Account → Data & privacy. Depending on where you live (for example under the GDPR or CCPA) you may also have rights to access, correct or object; contact us to exercise them.
Contact
[Company name, LLC], [address]. Email: [privacy email].