1. Scope and Controller
This Privacy Policy applies to the dermink.org website and the tattoo-concept image generation, image editing, account, credit, and paid features DermInk makes available through it. The operator of the DermInk service is the controller of the personal information described in this Policy. "DermInk," "we," "us," and "our" refer to that operator. Privacy questions and personal-information requests may be sent to support@dermink.org. Our Terms of Service also govern your use of the Service.
DermInk is an independent product. It is not an OpenAI product and is not affiliated with, endorsed by, sponsored by, or officially partnered with OpenAI. Some features use third-party AI and infrastructure services, as described below.
2. Information We Collect
Depending on the features you use, we may process the following information.
- Account and authentication information: name, email address, profile image, account identifiers, email verification status, login method, and session or OAuth information needed to maintain login and account security.
- AI content: prompts, reference images, other materials you choose to submit, and images generated or edited by the Service.
- Generation records: selected model, generation mode, resolution, aspect ratio, background setting, task status, generation time, error information, provider task identifiers, and related file URLs.
- Transaction and credit information: subscription plan, order number, payment and renewal status, credit balance, credit issuance and usage, refunds, and billing errors. The payment provider identified at checkout generally collects full card details directly. We do not store full card numbers in our own database.
- Device and log information: IP address, browser and device type, operating system, language, user agent, access time, request records, pages visited, referring page, errors, and security events. We may also derive an approximate region from your IP address.
- Preference, attribution, and security information: language and analytics choices, consent version and timestamps, UTM or advertising-attribution parameters, rate-limit and CAPTCHA results, abuse reports, content-safety decisions, and related records.
- Communications: support requests, privacy requests, feedback, email content, and related handling records.
Prompts and images may contain personal information about you or others. Do not submit identity documents, financial information, medical records, intimate images, or other sensitive information that is not necessary for a generation request. Before submitting content depicting an identifiable person, make sure you have the necessary rights and consent.
3. How We Collect Information
We obtain information:
- Directly from you when you create an account, upload a file, enter a prompt, make a payment, or contact us.
- Automatically from your browser, server requests, cookies, local storage, and security logs when you use the website.
- From Google when you choose Google sign-in, according to the permissions you grant.
- From payment, email, AI, hosting, analytics, and other providers when they return information needed to complete a transaction, request, or security check.
- From security tools such as Cloudflare Turnstile when they assess whether a request is made by a person and help prevent abuse.
4. How We Use Information
We use information to:
- Create accounts, authenticate users, maintain sessions, and provide support.
- Receive prompts and reference images, call AI services, deliver results, and maintain generation history.
- Manage subscriptions, orders, refunds, credits, and the customer portal.
- Send login, security, transaction, service-change, and other necessary notices.
- Monitor performance, fix errors, and analyze aggregated usage trends.
- Improve the product experience.
- Prevent fraud, abuse, unauthorized access, and violations of our Terms.
- Meet legal, tax, accounting, regulatory, and dispute-resolution obligations.
- Process information with your consent or as otherwise permitted by law.
5. AI Inputs and Outputs
When you submit an image generation or editing request, the prompt and interface language are first sent to Waffo Pancake's content-safety service for a compliance check. If the request is allowed, we send the prompt, reference images, selected settings, task identifiers, and callback address needed to fulfill the request to third-party AI infrastructure providers. We do not intentionally attach your name, email address, or payment information to those requests. If you place such information in a prompt or image, however, it is processed as part of that content. The relevant providers and the necessary infrastructure they use process the information and return the result. We store task status, prompts, settings, and result records in our database, and store reference images and generated results in object storage used by the Service.
DermInk does not operate its own generation model and does not use your prompts, reference images, or results to train a DermInk model. We do not intentionally submit your content for third-party model training unrelated to fulfilling your request. Third-party AI providers may retain necessary content or logs under their applicable agreements, technical requirements, and legal obligations. Public information may not fully describe every underlying model's retention or training treatment, so do not submit highly confidential, strictly regulated, or unnecessary personal information.
6. Storage and Content Visibility
Prompts, reference images, and generated results are private by default and are kept in the workspace associated with your account. We do not intentionally publish them to a public gallery. Normal workspace access requires authentication and an ownership check. To provide a reference image to an AI provider, the Service may create a time-limited, hard-to-guess, or purpose-limited asset URL. While that URL remains usable, a provider or other holder of the complete URL may be able to access the file.
"Private generations" means that we do not intentionally publish the content to a public showcase. It does not mean end-to-end encryption and does not prevent disclosure to providers needed to fulfill a request. Reference images and results for free accounts are generally retained for 30 days after upload or creation. After any valid purchase, existing unexpired assets and future assets no longer expire under the 30-day rule. They are generally kept until you delete them, request deletion, the purchase is fully refunded with no other valid purchase remaining, or retention is no longer reasonably necessary. Unattached uploads are generally cleared after about 24 hours.
7. Cookies and Analytics
We use cookies needed for login, security, language preferences, and your analytics choice. We may also use browser local storage for limited interface state and initial attribution. Analytics-consent cookies currently last for up to 180 days, and we ask again when the policy version changes. Disabling necessary cookies may prevent login or language settings from working correctly.
We enable PostHog, Google Analytics 4, Microsoft Clarity, Vercel Analytics, and Vercel Speed Insights only after you select “Allow analytics.” These tools measure product journeys, acquisition, feature use, traffic, page performance, and masked clicks, scrolling, heatmaps, and session replays. We do not intentionally send prompt text, image content, filenames, names, email addresses, full card numbers, security codes, or payment authentication data to them. Sign-in, account, creation, checkout, and administration areas are additionally forced to be masked. After consent, other analytics events may include an internal user identifier, standardized routes, model and generation settings, feature actions, product, amount, currency, payment or refund status, and performance or error information.
You can choose “Necessary only” on the first-visit panel and may later withdraw or grant consent through “Privacy settings” in the footer. Refusing or withdrawing does not affect generation, account, or payment features. Necessary registration, generation, credit, order, and refund records remain in our business database for contract performance, accounting, security, and troubleshooting, but are not thereby sent to the optional analytics providers above. See our Cookie Policy for a detailed inventory of cookies, browser storage, durations, and providers.
8. How We Disclose Information
We do not sell your personal information or use it for cross-site targeted advertising. We may disclose necessary information to the following recipients.
- AI processing providers: third-party AI generation and infrastructure providers, together with necessary subprocessors they use for image generation, image editing, task callbacks, and result delivery.
- Content-safety provider: Waffo Pancake receives the prompt and interface language before generation and returns a safety decision, request identifier, and any matched safety categories.
- Authentication providers: Google when you choose Google sign-in.
- Payment provider and merchant of record: Waffo Pancake receives the buyer email, internal buyer identifier, product, currency, order and checkout identifiers, and necessary promotion metadata. Waffo may act as an independent controller for card, billing, tax, fraud-prevention, refund, chargeback, and compliance information.
- Email provider: Brevo for account, transaction, lifecycle-offer, and service messages.
- Infrastructure and security providers: Vercel, Cloudflare Turnstile, and providers of database, object-storage, hosting, logging, and security services.
- Optional analytics providers: PostHog, Google Analytics 4, Microsoft Clarity, Vercel Analytics, and Vercel Speed Insights after you consent.
- Professional advisers and parties subject to confidentiality in a merger, financing, reorganization, or asset transfer.
- Law-enforcement, regulatory, or other authorities when necessary to comply with legal process or protect users, the public, our rights, safety, or Service integrity.
- Other recipients at your direction or with your separate consent.
Third-party services have their own privacy practices. Policies for services you directly choose or interact with are provided at the relevant point of interaction. You may also contact us for information about providers involved in a specific processing activity. You can review the Google Privacy Policy, and Vercel Privacy Notice, the Microsoft Privacy Statement, and the Waffo Privacy Policy. The seller, payment party, and transaction terms shown at checkout and on the receipt apply to a specific purchase.
9. Legal Bases
Where the GDPR, UK GDPR, or similar laws apply, we rely on the following legal bases as appropriate.
- Performance of a contract, such as creating an account, generating images, providing a subscription, and processing payment.
- Our legitimate interests, such as protecting the Service, preventing fraud, diagnosing errors, and improving aggregated performance that does not identify an individual.
- Compliance with legal obligations, such as retaining transaction records and responding to valid legal requests.
- Your consent, such as for legally consented cookies, marketing communications, or future optional data uses.
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal.
If lifecycle emails are enabled and applicable law permits them, new accounts may receive welcome-credit and limited-time offer reminders. We rely on consent where required or, where permitted, our legitimate interest in promoting similar services. Every promotional message includes an unsubscribe option. We retain the minimum opt-out record needed to stop later promotions; login, security, payment-receipt, and account-service messages may still be sent.
10. Retention and Deletion
We keep information only for as long as needed to provide the Service, fulfill the purposes in this Policy, resolve disputes, and meet legal obligations. The exact period depends on the type of information, account status, content sensitivity, security needs, and applicable tax, accounting, or other legal requirements.
- Login sessions are retained until they expire, you sign out, or they are revoked for security.
- Reference images and results for free accounts are generally retained for 30 days. Unattached uploads are generally cleared after about 24 hours.
- After a valid purchase, existing unexpired assets and future assets have no scheduled expiry until you delete them, make a valid deletion request, the purchase is fully refunded with no other valid purchase remaining, or retention is no longer reasonably necessary.
- Prompts, task settings, generation status, and failure information are generally retained with the account and generation history. Server, security, and diagnostic logs are generally kept for less time, but may be retained longer for an abuse, security, or dispute investigation.
- Order, credit, refund, and transaction records may remain after account deletion for financial, tax, anti-fraud, and dispute obligations.
- After a deletion request is completed, information may remain temporarily in restricted backups until overwritten through the normal backup cycle.
Deleting a completed result removes workspace access, requests deletion of its result file from object storage, and marks that task as deleted. It does not necessarily delete a reference image reused by another task, the prompt, a limited task record, or a billing record. The Service does not currently provide a complete in-account deletion control. You may use the email below to request deletion of your account, prompts, reference images, or other personal information. We verify the request against the account and respond within the period required by applicable law by deleting or de-identifying the information, or explaining why limited information must remain.
11. International Transfers
We and our providers may process information outside your country or region, including in the United States, Hong Kong, and other places where providers or their subprocessors operate. Local data-protection laws may differ. Where applicable law requires it, we take the required contractual, technical, or organizational steps and limit provider access to what is needed for the relevant purpose. Contact us for information about recipients and safeguards relevant to a specific processing activity.
12. Security
We use administrative, technical, and access controls appropriate to the Service, including encryption in transit, authentication, access restrictions, and security monitoring. No internet transmission, third-party API, or electronic storage can be guaranteed completely secure. If a personal-data incident requires notice under applicable law, we will notify affected individuals or authorities as required.
13. Your Rights and Choices
Your privacy rights depend on where you live. You may have the right to know about, access, correct, delete, or receive a copy of your personal information. You may also have the right to restrict or object to certain processing, withdraw consent, and complain about our processing. Applicable law may provide data-portability rights, a right to appeal a denied privacy request, and protection from discrimination for exercising privacy rights.
Email support@dermink.org with the associated account and your specific request. To prevent unauthorized access or deletion, we may ask you to verify identity through the account email. You may also complain to a data-protection authority with jurisdiction where you live.
14. Children
The Service is intended only for users who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a minor has submitted personal information, contact us and we will take reasonable steps to delete it after verification.
15. Changes and Contact
We may update this Policy when our product, providers, legal obligations, or data practices change. We will give reasonable notice of material changes through the website, your account, or email and state the new effective date at the top of this page. If a change introduces a new content use, model-training purpose, or other material risk, we will obtain consent where applicable law requires it.
For questions about this Policy, our data practices, or a privacy request, email support@dermink.org.