Privacy Policy

Last updated: August 30, 2026

1. What we collect

  • Account data: your email address, display name, and authentication records (including your Google account email if you sign in with Google), managed by Supabase Auth.
  • Reference photos: up to three photos you upload for a generation (one is enough), stored in a private bucket and used only to create your requested image.
  • Generated photos: stored privately in your gallery until you delete them or delete your account.
  • Usage and billing records: generation history, credit ledger entries, and purchase records (payment card details are handled entirely by Stripe; we never see your card number).

2. Face & photo data

DatifyAI processes the photos you upload (which include images of your face) solely to generate the AI photos you request. We ask for your explicit consent to this processing when you create your account, and each generation additionally requires you to confirm that you have the right to use the photos you upload.

  • We do not use your photos to identify or authenticate anyone, and we do not build face-recognition profiles or templates.
  • We do not use your photos or generated images to train AI models, ours or anyone else's.
  • We do not sell, lease, or otherwise profit from your photos or any data derived from them.
  • You can withdraw this consent at any time by deleting your photos or your account (see sections 6 and 7). Withdrawing consent means we can no longer generate photos for you.

3. Why we process it

Solely to provide the service: authenticating you, generating your photos, showing your gallery, maintaining an accurate credit balance, preventing abuse, and meeting our legal obligations for payment records.

4. Data retention

  • Reference photos: removed automatically after a short retention window (24 hours by default) once a generation finishes.
  • Generated photos: kept until you delete them or delete your account.
  • Account data: kept while your account exists; deleted when you delete your account.
  • Purchase records: retained as required by tax and accounting law, in anonymized form after account deletion.

5. Third-party processing

Third-party infrastructure providers process submitted content only as required to provide the service: Google (Gemini API) processes your reference photos and prompt to generate images; Google (Sign in with Google) processes your sign-in when you choose it; Supabase hosts our database, authentication, and file storage; Stripe processes payments; Cloudflare serves the application. We do not sell your data or use your photos for advertising or model training, and we do not permit our providers to do so.

5a. Analytics and advertising tools

Our public pages and conversion path load third-party measurement tools so we can tell which ads bring people who actually sign up. Meta Pixel (Meta Platforms) records page views, leads, completed registrations, checkout starts and purchases. Google Tag Manager (Google) loads the tags we configure in that container, including Google Analytics 4 page views. These tools set cookies and may receive your IP address and browser details. They load whether or not you click the cookie banner, because ad measurement has to work on the first visit.

Microsoft Clarity (Microsoft) records anonymized page interactions and heatmaps. Clarity is the only tool gated behind the banner: it loads after "Accept" and never after "Decline". Regardless of your choice, session recording is never loaded on the sign-in, sign-up, password-reset, photo-upload, generation, gallery or account pages, so your reference photo, your generated photos and your sign-in codes are never captured. You can change the Clarity choice by clearing this site's data in your browser, which brings the banner back.

6. Deleting your images

Every photo in your gallery has a delete action that removes both the record and the stored file. Reference photos are removed automatically under the retention policy above.

7. Deleting your account

Account → Danger zone → “Delete my account” immediately and permanently deletes your account, stored photos, generation history, and credit balance. Purchase records that we must retain for tax and accounting law are kept in anonymized form.

8. Age requirement

DatifyAI is for adults. You must be at least 18 years old to create an account, and we require you to confirm this at signup. No part of the service is directed to children.

9. Your rights

Depending on where you live (for example under the GDPR or the CCPA), you may have rights to access, correct, delete, or export your personal data, and to withdraw consent. Most of these are available directly in the app; for anything else, email us and we will respond.

Contact

Privacy questions: support@manna.moda