This Privacy Policy (Policy) applies to all information, including personal data within the meaning of applicable law (Information), which Kernelics LLP, address: 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX, registration number OC448443 (Operator or We, Us, or Our) and/or its affiliates may obtain about you in the course of your use of the mobile app Tattoo Daddy (the Application, "Tattoo Daddy") and of our website, including the contact form published there.
Tattoo Daddy designs tattoos with artificial intelligence. It can generate a design from a written brief, turn a picture into a stencil, and place a design on a photograph of your body so you can see how it might look. Because some of that involves photographs of you, this Policy is more specific than most. It explains what we collect, what leaves our systems, and what we cannot promise. You can contact us about privacy at legal@kernelics.com.
Information We Collect
We process Information that you freely provide or generate when you use the Application, or in any other way when you contact us, including:
- account information, such as your email address, your name if your sign-in provider gives us one, whether your email has been verified, your chosen language, and the sign-in method you used;
- your design brief, such as your idea, what the design means to you, the main object, things it must include, extra elements, the exact lettering you want inked, things to avoid, and your choices of style, placement, size, shape and colour, together with the English prompt we assemble from all of it;
- pictures you add, such as reference photographs, pictures you convert into stencils, and try-on images, which are described in the next section;
- your designs and the images produced from them, plus which catalogue designs you liked;
- subscription and allowance information, such as your plan, its status and period, how many generations you have left, and a record of each completed purchase;
- device and technical information collected by our analytics, such as app version, device type, operating system, language and time zone;
- support requests, if you write to us through the contact form on our website: the email address and message you submit, together with your IP address, your browser's user agent string and the time of submission.
If you sign in with Apple or Google, that provider authenticates you and shares basic account information with us. We never see your Apple or Google password. Sign in with Apple may give us a private relay address instead of your real one, and that works fine. When you sign in with Apple we also keep a refresh token issued by Apple, for one purpose only: so that we can ask Apple to revoke your sign-in if you delete your account.
The contact form does not require an account, and we do not try to match a support request to one. We keep the IP address and user agent for two reasons: to answer you, and to limit how many submissions one sender can make in a short window, which is what keeps the form from being used to spam us. Support requests are stored in our Convex database and are read only by people at Kernelics LLP who handle support. They are not linked to your account, so deleting your account does not remove them. They are deleted automatically 3 months after you send them, by a job that runs every day. If you want one removed sooner, write to legal@kernelics.com and tell us which one.
If you browse without an account, we create no account record for you in our database. The designs you like, the wizard drafts you start, and your settings stay on your device and are sent to us only if you later create an account. Analytics events are the exception, and are described under Analytics and Experiments below.
Tattoo Daddy does not access your contacts and does not ask for your device location. The app requests the camera and photo library so you can add pictures. Your phone may also show Face ID and microphone permission strings: those are added automatically by the secure-storage and photo-picker components we use. The app never records audio, and it does not currently ask you for Face ID or use it to unlock anything.
Photos and Try-On
Some parts of Tattoo Daddy work on photographs. You can add a picture as a reference for a design, turn a photograph into a stencil, or use try-on, which places a design on a photograph of your own body.
Try-on is the most sensitive thing you can do in this app, so here is exactly what happens. You take or choose the photo, and the design is positioned over it on your device. When you tap Save, or when you ask for the AI try-on, the app flattens the photo and the design into a single new image and uploads that image to our storage. The photograph of your body therefore leaves your phone in both cases, not only when you use the AI. We say this plainly because it would be easy to imply otherwise.
Those images are held in private storage that is not open to the internet. Each account's files sit in their own area, and an image is served only after we have checked that you are signed in and that the file belongs to you, through a link that expires within a few minutes. No other user of Tattoo Daddy can see them.
We do not analyse these pictures to work out who you are. We do not use facial recognition, we do not measure or record facial or bodily features, we do not build a biometric template, and we do not compare your photographs with anyone else's. We do not read the technical details your camera may record inside a photo, such as when or where it was taken, and we do not try to locate you from them.
Please do not upload photographs of other people without their agreement, and please do not upload photographs of children.
AI Generation and the Models We Use
Tattoo Daddy does not run its own AI models. When you generate a design, convert a stencil or run an AI try-on, we send your request to fal.ai, which routes it to an image model operated by another company. We send fal.ai the English prompt assembled from your answers and, where the feature needs a picture, a temporary link to the image in our storage, which the model provider then downloads directly. That link expires after a few minutes. It contains an internal identifier for your account, but not your name and not your email address.
fal.ai is the only AI supplier we have a relationship with. It handles your prompts and pictures as our processor, under a data processing addendum that forms part of the terms governing our use of its service: it may process them only on our instructions and must delete them when our agreement with it ends. The addendum separately permits fal.ai to use de-identified information — information that can no longer be linked to any person — to improve its own service; that permission is written in the addendum's California section, so for data protected by UK and EU law we rely on the narrower instruction-only rule above rather than on it.
Which model actually runs your request is fal.ai's to arrange. Some of the models it offers are operated by other companies, and where that is the case fal.ai governs that onward routing under its own terms and publishes the suppliers it relies on at https://trust.fal.ai/subprocessors. We do not hold separate agreements with those model operators, so we cannot tell you how long they keep what they receive, we cannot shorten it on your behalf, and we cannot promise that your prompts or your photographs are never used to develop their models. We would rather say that plainly than imply a control we do not have. Please treat anything you send into generation accordingly.
Two smaller steps stay inside fal.ai's own service rather than going to another company's model: naming the main object in a reference picture you upload, and removing the white background from a finished design. The first of these receives the picture you uploaded.
How We Use and Process Your Information
We use your Information for a variety of reasons, depending on how you interact with the Application, including:
- create and manage your account;
- generate designs, stencils and try-on images from what you give us;
- keep your gallery available to you across your devices;
- count your generation allowance and process subscriptions and top-up purchases;
- screen prompts for prohibited content before they reach a model;
- send transactional emails, such as password recovery messages;
- diagnose failures and fix bugs;
- measure which parts of the app work, and run limited experiments on layout.
We process your Information to provide access to the Application, to improve and administer it, to communicate with you, to provide security and fraud prevention, and to comply with applicable laws. We may also process your Information for other purposes with your consent.
For the content you bring — your brief, your prompts, and the pictures you upload — the purposes above are the whole list. That matches the licence you grant us in section 2 of our Terms of Use: we store your content, process it, show it back to you, pass it to the AI providers named above, and use it for the supporting work described in this Policy. We do not use your content for anything else: we do not publish it, sell it, use it to advertise, or train models of our own with it.
We do not process your Information without a legally sufficient reason. Depending on the purpose, we rely on one of the following:
- performance of our contract with you, for running your account, generating what you ask for, counting your allowance and handling subscriptions;
- compliance with statutory obligations, for keeping records we are required by law to keep, such as those relating to payments;
- our legitimate interests, for keeping the app secure, preventing abuse, diagnosing failures and measuring how the app is used, where such processing doesn't have a significant impact on your interests, your fundamental rights and freedoms. When processing your Information on this ground, the Operator will always endeavor to maintain a balance between its legitimate interests and the protection of your privacy;
- your consent, for anything you opt into, such as access to your camera or photo library, and marketing where we ask for it. Where we rely on consent you can withdraw it at any time, which does not affect processing already carried out.
We do not ask you for special category information, such as your health, your beliefs, your ethnicity, your sex life or your political opinions. We have no use for it, and the examples we show in the brief fields are deliberately neutral so that nothing in the app invites it. Our lawful basis for processing a brief is Article 6(1)(b), performance of our contract with you. Please keep details of that kind out of a brief. If you do include something you would rather we did not hold, you can remove it at any time by deleting the design or your account — though, as explained under Retention and Account Deletion, that removal cannot reach copies already held by an AI provider, analytics events already sent, or server logs.
Analytics and Experiments
We use PostHog, on its European infrastructure, to understand how the app is used. Once you sign in, analytics events are linked to your account identifier, so they are pseudonymous rather than anonymous. Before you sign in they are not linked to an account, but they are still recorded: they carry an identifier PostHog generates for your installation, together with the device details described below. So while we create no account record for a visitor, using the app without an account is not invisible to our analytics.
Event properties are filtered before they are sent. Only true or false values, numbers, and short plain codes without spaces are allowed through, which means free text cannot reach our analytics by that route. When you search the catalogue we record how many characters you typed, never the words.
Two things you should know, because we would rather be exact than flattering:
- PostHog also receives your app version, device type, operating system, language and time zone, and records when the app is installed, updated, opened and sent to the background — that is how we count how many people use Tattoo Daddy on a given day. We switch off its location lookup, so no location is derived from your IP address and none is stored against your events;
- when a generation fails on our servers, we record the error message returned by the AI provider so we can diagnose it, and we do not control the wording of that message.
We run two experiments: which onboarding you see, and which layout the subscription screen uses. They change how the app looks, never what it costs and never what we collect.
When the app hits an unexpected error — a screen that fails to render, or a request that throws where it should not — we report that error to PostHog so we can fix it. The report carries the error type, its message and the technical stack trace, not a copy of your content; it is linked to your account identifier once you are signed in. This covers errors inside the app's own code. Tattoo Daddy does not record your screen or your session, does not use an advertising identifier, and does not track you across other apps or websites.
Subscriptions and Payments
Paid plans are sold through the App Store. Apple takes the payment, and we never see your card number, billing address or any other payment details. We use RevenueCat to manage subscriptions; it receives your account identifier and the details of the purchase from the store. On our side we store the state of your plan, and, for each completed top-up pack, a short record of that purchase, which is how we make sure a pack is credited once and only once. Subscription purchases do not produce such a record: their state is held on your subscription row, which is deleted with your account.
Sharing and Service Providers
Different recipients hold your Information on different terms, so we describe them separately rather than making one promise that would not be true of all of them.
Suppliers that process your Information on our instructions, under a data processing agreement that limits them to what we ask for and requires them to protect it and to delete or return it when our contract ends:
- Convex, which runs our database, server functions and support-request storage, and which does not receive your Information for any purpose of its own;
- Amazon Web Services, which stores and delivers your images from a private bucket, and which does not read them;
- PostHog, which receives analytics events and error reports and keeps them for 12 months, the retention configured on our project;
- RevenueCat, which receives your account identifier and purchase details and keeps a customer record for as long as we keep the account with them;
- Resend, which receives your email address and the text of transactional messages so it can deliver them;
- fal.ai, which runs the AI generation pipeline as our processor under its data processing addendum: it acts only on our instructions, must delete our data when the agreement ends, and publishes its own subcontractors at https://trust.fal.ai/subprocessors.
Platforms that act on their own account rather than on our instructions, and whose handling is governed by their own terms and privacy policies, not ours:
- Apple, for app distribution, sign-in, payments, subscriptions and refunds, which is an independent controller of what it collects from you;
- Google, for sign-in, which is likewise an independent controller of the account information you authorise it to share;
- the operators of the models fal.ai routes your request to, where those models are run by another company. We have no agreement of our own with them; fal.ai arranges that routing under its own terms. They are described under AI Generation and the Models We Use above, and the paragraph about instructed suppliers does not describe them.
Inside Kernelics LLP, access to your Information is limited to the people who need it to run and support the service. Staff with administrative access can see account data, briefs, designs and uploaded pictures, including try-on images, through our database console, and can adjust a plan or allowance to resolve a support issue. We do not browse this content for any other reason.
Separately, and not as service providers, we may disclose Information to our professional advisers, such as lawyers and accountants, where they need it to advise us, and to courts, regulators or law enforcement where the law requires it or where we need to establish or defend a legal claim.
Error reports go to PostHog, the same processor that receives analytics, and to no one else. The app also bundles a separate crash-reporting library (Firebase Crashlytics) that is not connected and never runs; if we ever switch it on, we will say so here first.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
What Tattoo Daddy Does Not Do
It is often clearer to say what an app does not do, so:
- it shows no advertising, contains no advertising SDK, and uses no advertising identifier;
- it does not track you across other apps or websites, and asks for no tracking permission;
- it sends no push notifications and never asks for notification permission;
- it has no public feed, no profiles, no comments and no way for one user to find, follow or message another;
- it does not make your designs visible to any other user;
- it does not use facial recognition or build a biometric template from your photographs;
- it does not access your contacts or your device location;
- it does not record your screen or your session;
- it does not sell your personal information.
Retention and Account Deletion
We do not delete your content on a timer. Your designs, briefs, uploaded pictures, try-on images, likes and account details stay with us until you delete them or delete your account, because keeping your gallery available to you is the point of the app. We would rather tell you that than quote a retention period we do not actually apply. The one scheduled deletion we do run is for support requests, which are removed 3 months after you send them.
You can delete your account at any time in the app, under Profile, or by writing to legal@kernelics.com. Deleting your account removes your account record and sign-in details, your generated designs and the images behind them, your briefs, your likes, your uploaded pictures and try-on images, your generation allowance and its history, and your subscription record, and it wipes the whole storage area holding your files. If you signed in with Apple, we also ask Apple to revoke the sign-in token we hold.
Some things survive account deletion, and you should know which:
- a short record of each completed top-up purchase, which is what stops the same pack being credited twice, and which we may also need for tax and accounting. It holds the store's transaction identifier, the product bought, how many generations it granted, when it was processed, and whether it was refunded. The internal identifier of the account that bought it is erased when you delete your account, so what survives is no longer linked to you; the store's transaction identifier is what keeps the record unique;
- analytics events and error reports already sent to PostHog, which expire on their own 12-month retention, and the customer record held by RevenueCat, which is not deleted automatically today;
- our server logs, which hold technical records of requests and errors and are kept for the rolling window our hosting provider retains them for, which is measured in days rather than months;
- support requests you sent through the contact form, which are not linked to your account and are therefore not reached by account deletion; they are deleted automatically 3 months after you send them;
- copies that an AI provider may still hold, which we cannot reach or delete.
If you want any of these removed as far as we are able, write to legal@kernelics.com.
Deleting Tattoo Daddy or deleting your account does not cancel an active App Store subscription. You must cancel subscriptions through your App Store account settings.
Your Rights and Choices
In the app you can change your language, your password and your subscription, and you can delete any design or your whole account. Your email address cannot currently be changed in the app.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information. To exercise privacy rights, contact us at legal@kernelics.com.
Where UK or EU data protection law applies, we rely on the following legal bases: contract, to provide Tattoo Daddy and manage accounts and subscriptions; legitimate interests, to keep the app secure, improve reliability, and prevent abuse; consent, where required for optional permissions or marketing; and legal obligation, where we must keep or disclose information by law.
If you are in the UK and are unhappy with how we handle your personal information, you can complain to the UK Information Commissioner's Office at https://ico.org.uk, but we ask that you contact us first so we can try to resolve your concern.
International Transfers
Our database, our image storage and our analytics are hosted in Europe. Several of the companies involved are nonetheless based in the United States, so some Information leaves the United Kingdom and the European Economic Area. We do not ask you to consent to that by using the app; instead each transfer rests on a specific mechanism:
- for Convex, Amazon Web Services, PostHog, RevenueCat and Resend, on the safeguards in our data processing agreement with each of them, which incorporate the UK International Data Transfer Addendum and the European Commission's standard contractual clauses, and, where the supplier is certified, the EU-US Data Privacy Framework and its UK extension;
- for Apple and Google, on the transfer terms in their own published agreements, which apply to them as independent controllers;
- for fal.ai, on its data processing addendum, which forms part of the terms under which we use its service and which incorporates the European Commission's standard contractual clauses (Module 2, controller to processor) and the UK International Data Transfer Addendum;
- for the operators of models that fal.ai runs on another company's service, we hold no transfer safeguard of our own: fal.ai arranges that routing, and any safeguards for it sit in fal.ai's own terms with those operators rather than in ours. Which operator receives a given request depends on the model configured for that feature and on which fallback runs, so the destination can change without notice to you. We name that plainly rather than paper over it, and we do not rely on the Article 49(1)(b) derogation here: generation, stencil and try-on are routine and repeated, and that derogation is meant for occasional transfers rather than the ordinary running of a service.
If you would rather your pictures and prompts were not sent outside the United Kingdom and the European Economic Area, do not use the generation, stencil or try-on features; browsing the catalogue does not involve any of these transfers.
Security
We take technical, organizational and legal measures to ensure the protection of your Information from unauthorized or accidental access to it, destruction, alteration, blocking, copying, distribution, as well as from other unlawful actions. In particular:
- all connections between the app and our servers use HTTPS;
- your images are kept in private storage that is not publicly readable, and each account's files sit in their own area;
- an image is released only through a link that expires within a few minutes, and only after we have checked that the file belongs to the signed-in account;
- your sign-in tokens are stored in your device's secure keychain, not in ordinary app storage;
- passwords are never stored as text, only as a cryptographic hash.
No service can be guaranteed to be completely secure, and we cannot promise that it will be.
Children
Tattoo Daddy is not intended for anyone under 18. Tattooing a minor is an offence in Great Britain under the Tattooing of Minors Act 1969, except where the tattoo is performed for medical reasons by a qualified medical practitioner, and comparable restrictions apply in many other countries. That exception is for clinicians, not for this app: Tattoo Daddy is for users aged 18 or over in every case, not least because it sends photographs to third-party AI providers. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with personal information, please contact us so we can delete it.
Policy Updates and Changes
This Policy may be updated. The Operator has the right to make changes at its own discretion, including, but not limited to, in cases when the relevant changes are related to changes in the applicable law, as well as when the relevant changes are related to changes in the operation of the Application. If we make material changes, we will take reasonable steps to notify you, such as by updating the effective date, posting a notice, or notifying you in the app. We will also update this Policy when the AI providers we use change.
We welcome your questions and suggestions regarding the implementation or modification of this Policy. You may contact us at the e-mail address legal@kernelics.com for feedback. You may also use this address to submit requests to exercise your rights or complaints regarding the incorrectness of your Personal Information or the unlawfulness of its processing.
Contact
Kernelics LLP
27 Old Gloucester Street, London, United Kingdom, WC1N 3AX
Privacy and support contact: legal@kernelics.com