Privacy Policy

Effective Date: April 28, 2026  ·  Version: 1.0

This Privacy Policy ("Policy") describes how PinaKoala LLC ("we", "us", or "our") collects, uses, and protects your personal information when you use the PinaKoala mobile application (the "App") and our website at pinakoala.ai.

This Policy complies with the General Data Protection Regulation (GDPR) (EU), the California Consumer Privacy Act (CCPA) (US), and other applicable data protection laws.

Data Controller

PinaKoala LLC

Email: privacy@pinakoala.ai

Website: pinakoala.ai

This Policy is publicly available within the App and on our website. We may update this Policy from time to time as described in Section 11.

Contents
  1. Definitions
  2. Principles of data processing
  3. Information we collect
  4. How we use your information
  5. Legal basis (GDPR)
  6. Data sharing and disclosure
  7. Third-party AI services
  8. Data retention
  9. Your rights (GDPR / CCPA)
  10. Security
  11. International data transfers
  12. Changes to this Policy
  13. Contact us

1. Definitions

Service-specific terms

2. Principles of data processing

We process personal data in accordance with the following principles:

3. Information we collect

Information you provide

Automatically collected information

Purchase information

We do not receive or store your credit card, bank account, or other payment instrument details. Payments are processed entirely by Apple.

Data we do not collect

We do not process special categories of personal data (race, ethnicity, political opinions, religious beliefs, health data) without your explicit consent or as required by law. The Service is not intended for children under 13 (or 16 in the EU), and we do not knowingly collect their data.

4. How we use your information

We use your personal data for the following purposes:

We process your personal data based on the following legal grounds:

You may withdraw your consent at any time by contacting us at privacy@pinakoala.ai.

6. Data sharing and disclosure

We do not sell your personal data. We share your data only with the third-party providers listed below, each of whom processes data on our behalf or as an independent controller, subject to its own privacy policy.

Provider Purpose Data shared
Apple Inc. Sign in with Apple, App Store, In-App Purchases Email (relay or real, your choice), purchase tokens
Supabase Authentication, database, edge functions Email, account ID, generation metadata
Google Cloud Platform Cloud storage of uploaded and generated images, backend hosting Product photos, generated images, server logs
Google Gemini API AI image generation Your uploaded product photo and prompt parameters
Google Cloud Vision API Automated safety check of uploaded images Your uploaded product photo
RevenueCat In-app purchase entitlement management Anonymous user identifier, purchase events

We may also disclose your data when required by law, court order, or other legal obligation; to enforce our Terms of Use; to protect the rights, property, or safety of PinaKoala, our users, or others; or in connection with a merger, acquisition, or sale of all or part of our business, in which case we will notify you and ensure your information remains protected.

7. Third-party AI services

To provide AI-powered generation, we send your uploaded photo and prompt parameters to third-party AI services.

Data we send

Data we do not send

Service providers

Data retention by AI providers

We do not store the prompts we send to AI providers on our own servers beyond what is needed to deliver your generated image. Third-party providers retain data per their respective policies. Google's policies govern any retention by Gemini and Vision APIs.

User consent and control

8. Data retention

9. Your rights (GDPR / CCPA)

You have the following rights:

California residents (CCPA). You have the right to know what personal information we collect, delete your personal information, and opt-out of the sale of personal information (we do not sell personal information).

To exercise any of these rights, email us at privacy@pinakoala.ai. We will respond within one month. You may also delete your account and associated data directly from the App settings.

10. Security

We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (HTTPS/TLS) and at rest, role-based access controls, RLS-protected database tables, and audit logging. No method of transmission or storage is perfectly secure, however, and we cannot guarantee absolute security.

11. International data transfers

PinaKoala LLC is operated from the United States, and our service providers (Google Cloud, Supabase, RevenueCat, Apple) may process data in the United States and other countries. When we transfer data out of the European Economic Area (EEA), we rely on Standard Contractual Clauses approved by the European Commission to ensure adequate protection.

12. Changes to this Policy

We may update this Policy from time to time. We will notify you of material changes by posting the new Policy in the App and on our website, and, where feasible, by sending you an email. The "Effective Date" at the top indicates when it was last revised.

13. Contact us

For questions about this Policy or to exercise your rights, contact us:

PinaKoala LLC

Privacy: privacy@pinakoala.ai

General: hello@pinakoala.ai

Support: support@pinakoala.ai

Website: pinakoala.ai