Privacy Policy
Effective date: September 30, 2026
Last updated: September 30, 2026
This policy explains what personal data TatuaIA and its website tatuaia.app process, why, for how long, who helps us do it and what rights you have. TatuaIA is our iOS and Android app for creating tattoo designs with artificial intelligence; it is listed as «Tattoo AI: Maker & Creator» on the App Store and «Tattoo AI» on Google Play, and shows as «Tattoo Gen» on your phone. We have tried to keep this policy short and plain.
1. Who is responsible
The data controller is Roberto Díaz Badra – Disruptive Normality, a self-employed developer based in Spain.
Contact for anything related to privacy: disruptivenormality@gmail.com
2. The short version
- TatuaIA does not ask for your name or email to work. It uses an anonymous app ID.
- Your descriptions, and the photo you add if you use a photo to create or edit a design, are sent to our servers and to our AI provider (Google Gemini) only to create your design.
- The photos you add are not saved in our storage. The designs we create are saved on our servers, together with their description, so the app can deliver them to you and show them in your history.
- We do not use your descriptions, photos or designs to train AI models, and we do not sell your data or show you ads.
- Payments are handled by Apple or Google. We never see your card details.
3. What data we process
Content you submit
- The descriptions you write, the style you choose and the changes you ask for.
- Photos you pick from your gallery to turn into a tattoo or to use as a reference (only after you allow access).
- The designs we create for you.
This content may contain personal data (for example, a photo in which a person appears, or a name you ask to include). You decide what you submit.
App and device data
- An anonymous user ID created by the app (Firebase Authentication). It is not linked to your name or email.
- Device and app information: device model, operating system, app version, language, country or region, currency and time zone.
- Usage events: for example, when you open the app, create or download a design, view a subscription screen or use a feature, and the answers you give in the welcome questions (such as how you found the app or which styles interest you).
- Crash reports and diagnostic logs.
- The notice that your design is ready is a local notification scheduled on your device, only if you allow notifications.
Purchases
- Your subscription status, product, trial and renewal dates, and an anonymous purchase identifier. Apple or Google processes the payment; we do not receive or store your payment card details.
Feedback you send us
- Content reports (with the reason and any comment you add), answers to in-app surveys, feature votes, comments and emails you send us.
4. Why we use it and on what legal basis
- To provide TatuaIA (create and edit your designs, deliver them to you, show your history and keep your subscription in sync): performance of our contract with you (Article 6(1)(b) GDPR).
- To notify you when a design is ready: your consent, given through the permission of your device. You can turn notifications off at any time in your device settings.
- To keep the app working and secure (crash reports, diagnostics, reviewing content reports, preventing abuse): our legitimate interest in offering a reliable and safe service (Article 6(1)(f) GDPR).
- To understand how the app is used and improve it (product analytics, subscription screen tests, your feedback): our legitimate interest in improving TatuaIA. We use pseudonymous IDs, not your name or email. You can object at any time by writing to us.
- Website analytics on tatuaia.app: your consent (see section 10).
- To comply with legal obligations (for example, tax and accounting rules, or answering requests from authorities): legal obligation (Article 6(1)(c) GDPR).
We do not use your data for advertising, we do not sell it, and we do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.
5. Who helps us (service providers)
We share data only with the providers we need to run TatuaIA. They process the data on our behalf and may only use it to provide their service to us.
- Google Firebase and Google Cloud (Google): anonymous sign-in, database, file storage for the designs, the servers and queue that process your requests, remote configuration, Firebase Analytics and Crashlytics. Servers mainly in the United States.
- Google Gemini (Google): the AI model that creates and edits the designs from your description and, if you add one, your photo. United States.
- RevenueCat: manages subscription status. United States.
- Superwall: shows subscription screens and measures how they perform. United States.
- Amplitude: product analytics. United States.
- Apple and Google: App Store and Google Play distribution and payments. They act as independent controllers for your purchases; see their privacy policies.
- Google Analytics (tatuaia.app website only, with your consent).
We may also disclose data when the law requires it, or to protect our rights or the safety of users.
6. AI processing
To create or edit a design we send your description, the chosen style and, if you add one, your photo to Google's Gemini model, which returns the image to us. The photo passes through our processing queue only for as long as it takes to create the design and is not saved in our storage. Google processes the content to return the result and may keep it for a limited time under its own terms. We do not use your descriptions, photos or designs to train AI models.
AI-generated designs can contain mistakes or unexpected elements. Check the design carefully, and with your tattoo artist, before getting tattooed.
7. How long we keep data
- Photos you add: used only to create the design and not saved in our storage.
- Designs and their descriptions: saved on your device (in your history and wherever you choose to save them) and on our servers, linked to your anonymous ID, so the app can deliver them to you. We do not currently delete them from our servers automatically: you can ask us by email to delete them at any time (see section 9). Deleting the app removes the copy on your device, not the one on our servers.
- Anonymous ID and basic app data (creation and last session dates, platform, language, country, subscription flag): kept while you use TatuaIA, or until you ask us to delete them.
- Subscription data: while your subscription is active and afterwards for as long as needed for accounting, tax and legal claims (generally up to 6 years under Spanish law).
- Analytics and crash data: for the retention period set in each tool, after which it is deleted or anonymized.
- Content reports, feedback and emails: for as long as needed to review them, answer you and improve the app.
Our providers may keep data for short periods under their own policies, after which they delete it.
8. International transfers
Several providers are based in the United States, so your data may be transferred outside the European Economic Area. When this happens, transfers are made with appropriate safeguards, such as the European Commission's Standard Contractual Clauses or the EU–U.S. Data Privacy Framework. You can ask us for more information about these safeguards.
9. Your rights
You can ask us to access, correct or delete your data, to restrict or object to its processing, and to receive it in a portable format. Where we rely on your consent, you can withdraw it at any time without affecting earlier processing.
To exercise your rights, email disruptivenormality@gmail.com. Because TatuaIA does not use names or emails, we may ask for details that help us find your data (for example, the approximate date and description of a design, or your App Store or Google Play purchase receipt). We will reply within one month.
If you are not satisfied with our answer, you can file a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or with the data protection authority of your country.
10. The tatuaia.app website and cookies
The website does not require any personal data from you. We use:
- Google Analytics 4, only if you accept analytics cookies in the banner (in the European Economic Area, the United Kingdom and Switzerland it stays off until you accept). It tells us how many people visit and which pages they view. Google Analytics cookies (such as _ga) last up to 2 years.
- dl_attr: our own first-party cookie that remembers how you arrived at the site (for example, the campaign or referring website). It is set only if you accept analytics cookies and lasts 90 days.
- Local storage in your browser to remember your cookie choice and your preferred language. This is strictly necessary and does not track you.
You can change your choice at any time with the «Cookie settings» button at the bottom of every page, or by deleting cookies in your browser.
11. Children
TatuaIA is not intended for users under the age of 18. We do not knowingly collect personal data from people under 18. If you believe a minor has used TatuaIA and shared personal data with us, contact us and we will delete it.
12. Security
We use encrypted connections, access controls and signed requests between the app and our servers, and we do not keep the photos you add. No system is completely secure, but we work to protect your data and will notify you and the authorities of a breach when the law requires it.
13. Changes to this policy
We may update this policy when TatuaIA or the law changes. We will publish the new version here with its date and, if the changes are significant, we will also let you know in the app or on the website.
14. Contact
Roberto Díaz Badra – Disruptive Normality
Email: disruptivenormality@gmail.com
