Privacy policy
Last updated: 28 July 2026
This policy covers two different products with two different data flows. Part A covers the web studio at datingimagepro.com, where your photographs leave your device and are processed on our servers and by AI providers. Part B covers the iOS app, which behaves differently. Read the part that applies to you.
Controller within the meaning of Art. 4 (7) GDPR: Pascal Lindenau, Forddamm 7, 12107 Berlin, Germany, support@lindenau.cloud. We have not appointed a data protection officer; we are not required to.
Part A — The web studio
A1. Your photographs are special-category data
To generate images of you, we process photographs of your face. Because those images are processed for the purpose of producing a likeness of a specific identified person, we treat them as biometric data within the meaning of Art. 9 (1) GDPR and apply the stricter regime, whether or not that classification is ultimately required.
Legal basis: your explicit consent under Art. 9 (2) (a) GDPR, given in combination with Art. 6 (1) (a) GDPR, before any upload is possible. The wording you accept is:
“I confirm I am 18 or older, consent to AI processing of the photos I submit, and understand that face, full-body, and reference inputs become inaccessible 120 hours after their original upload and are physically deleted within 15 minutes after expiry.”
Each acceptance is stored in our web_consents record with its version identifier, a hash of the exact text you saw, a timestamp and a hashed IP address, so we can show later which version applied to your upload. The upload endpoint refuses to issue an upload URL when no matching consent exists.
Withdrawing consent is possible at any time with effect for the future: delete the images in your account or delete the account entirely. Withdrawal does not affect the lawfulness of processing already carried out, and it cannot undo a generation that has already run.
We do not build faceprints, facial templates or embeddings for recognition, we do not identify or authenticate anyone, and we do not use your images for advertising, profiling or model training.
A2. What we process, and on what basis
- Your uploaded photographs (face angles, optional full-body and reference images) — to generate your results. Art. 9 (2) (a) explicit consent.
- Your generated images — to deliver them and keep them in your gallery until you delete them. Art. 6 (1) (b) performance of the contract.
- Your style choices and prompts — to run the generation. Art. 6 (1) (b).
- Your email address and account — to sign you in, tie credits to you and send transactional mail. Art. 6 (1) (b).
- Purchase and credit records — to fulfil the order and meet commercial and tax record-keeping duties. Art. 6 (1) (b) and (c).
- Consent records (version, text hash, timestamp, hashed IP) — to demonstrate compliance. Art. 6 (1) (c) with Art. 7 (1) GDPR.
- Server logs and bot-protection signals — to keep the service available and prevent abuse. Art. 6 (1) (f), our legitimate interest in a secure service.
Providing this data is not a statutory requirement, but without your photographs and email address the service cannot be performed.
A3. How long we keep it
- Uploaded inputs: inaccessible exactly 120 hours after upload, physically deleted within 15 minutes of expiry.
- Generated results: until you delete them, or until you delete your account.
- Sign-in sessions: 30 days.
- Magic sign-in links: 20 minutes.
- Account and email address: until you delete the account.
- Purchase, invoice and consent records: retained for the statutory commercial and tax retention periods (up to 10 years under §§ 147 AO, 257 HGB), even after account deletion. These records do not contain your photographs.
A4. Who else processes your data
We use the following providers. Those acting on our instructions are bound by data processing agreements under Art. 28 GDPR. We never sell your data and we never share your photographs with advertisers or social networks.
- Stripe Payments Europe, Ltd. (Ireland) — Payment processing and receipts. Stripe receives your email address and payment details; we never see your card number.
- Replicate, Inc. (USA) — Hosting of the image models that generate your photos. Receives your uploaded photographs and the prompt. Inputs and outputs are auto-deleted by Replicate within roughly one hour and are not used for training.
- OpenAI, L.L.C. (USA) — Image generation for some styles, and text features on this site. Data submitted through the API is not used to train models.
- Lindenau Cloud (self-hosted, Germany) — Our own backend: credit accounting, generation orchestration and delivery. Operated by us on servers in the EU.
- MinIO object storage (self-hosted, Germany) — Temporary storage of your uploaded inputs and of your generated results. Operated by us on servers in the EU.
- Resend, Inc. (USA) — Sending sign-in links and transactional email. Receives your email address only.
- Google Ireland Ltd. — Optional "Sign in with Google". Only used if you choose it; we receive your email address and Google account identifier.
- Cloudflare, Inc. — Turnstile bot protection on sign-in and upload endpoints. Processes technical request data, no photographs.
- Ahrefs Pte. Ltd. (Singapore) — Cookieless website analytics on the public marketing and blog pages. Aggregated page-view counts only; no cookies, no cross-site tracking, no personal profiles.
- Apple Inc. — iOS app only: purchases via the App Store and, if you opt in, de-identified crash diagnostics.
A5. Transfers outside the EU
Our own servers and object storage are in Germany. Some processors listed above are established in the United States or elsewhere outside the EEA. Transfers to them are safeguarded by the European Commission's Standard Contractual Clauses under Art. 46 (2) (c) GDPR and, where the provider is certified, by the EU–US Data Privacy Framework under Art. 45 GDPR. You should be aware that US authorities may in principle have access rights that do not have an equivalent in EU law, and that your explicit consent under A1 also covers the transfer of your photographs to the model providers named above.
A6. Cookies and analytics
- Strictly necessary only. We set a session cookie so you stay signed in and a draft cookie so your studio progress survives a reload. Both are required for the service you asked for, so no consent banner is shown for them (§ 25 (2) TDDDG).
- Analytics: Ahrefs Web Analytics on the public marketing and blog pages. It is cookieless, sets no identifiers, and produces aggregate page-view counts only. Art. 6 (1) (f).
- No advertising or tracking cookies are used anywhere on this site, and no data is shared with ad networks.
A7. Your rights
Under the GDPR you have the right to access your data (Art. 15), to rectify it (Art. 16), to have it erased (Art. 17), to restrict processing (Art. 18), to receive it in a portable format (Art. 20), to object to processing based on legitimate interests (Art. 21) and to withdraw consent at any time (Art. 7 (3)).
- Delete individual photos from your gallery — removal is immediate and irreversible.
- Delete your account and all associated data with the delete button on your account page.
- Access, export or any other request: email support@lindenau.cloud. We respond within one month.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, Germany (https://www.datenschutz-berlin.de). You may also complain to the authority where you live.
A8. Security
All traffic is TLS-encrypted. Uploads go to storage we operate, addressed by unguessable object keys, and every read is checked against the requesting account. Expiry and deletion are enforced by the server, not by the client. Access to production systems is limited to the operator. No automated decision-making with legal effect within the meaning of Art. 22 GDPR takes place.
A9. Children
The studio is for adults. You must be at least 18 to create an account, and you confirm this before uploading. We do not knowingly process data of minors; if you believe a minor has used the service, write to us and we will delete the data.
Part B — The iOS app
B1. What the app processes
- Photos you choose: images you capture or select, which may include faces.
- Generated images and saved projects: stored in the app's private container on your device, and in your own iCloud if you enable it.
- Generated image for delivery (temporary): after the model finishes, our server briefly holds the result so your device can download it. It is deleted after delivery or, if undelivered, within 48 hours.
- Purchase records: Apple provides an anonymised transaction receipt so the app can unlock paid features.
- Diagnostics (optional): if you opt in to Apple's “Share With App Developers”, Apple may send de-identified crash logs.
B2. Face data in the app
- We process only the photos you choose, which may include faces.
- We do not create or store biometric identifiers such as faceprints, facial templates, embeddings or depth maps.
- Any on-device face detection used for cropping or alignment is ephemeral.
- Face images are used for the sole purpose of generating dating profile images at your request — never for identification, authentication, tracking, advertising or profiling.
B3. Where app data lives, and for how long
- Your device: originals, generated images and saved projects live in the app's private SwiftData container, kept until you delete them.
- Your iCloud (optional): if enabled, app data syncs through your private CloudKit database tied to your Apple ID. We cannot access it.
- Model provider (temporary): images are sent over HTTPS solely to generate results. For API predictions, inputs, outputs and file links are automatically deleted within about one hour.
- Our server (temporary delivery only): only generated outputs are stored, deleted immediately after your device downloads them or automatically within 48 hours. We do not store your input photos on our servers in the app flow.
B4. Your choices in the app
- Remove images or projects in the app or in Photos; deleting the app removes local data. iCloud data can be removed in iOS Settings → Apple ID → iCloud → Manage Storage.
- Purchases can be restored on the same Apple ID; receipts are stored locally to recognise what you bought.
- Diagnostics sharing can be turned off in iOS Settings → Privacy & Security → Analytics & Improvements.
- The rights described in A7 apply equally here; write to support@lindenau.cloud.
Changes to this policy
We update this policy as the products evolve and change the date at the top when we do. Where a change materially affects processing based on your consent, we ask for consent again rather than relying on the old version.