INKBEAST
Startseite Legal Notice Privacy Policy
App laden
Legal

Privacy Policy

Last updated: August 2026

This privacy policy informs you, in accordance with Art. 13 and 14 GDPR, which personal data we process when you use the INKBEAST mobile application (the “App”) and the website inkbea.st, for which purposes we do so, and which rights you have.

1. Controller

The controller within the meaning of the GDPR is:
Moritz Runge
Kolpingstr. 38
83278 Traunstein
Germany
Email: inkbeast@gmx.de

A data protection officer is not required by law (§ 38 BDSG).

2. What INKBEAST does

INKBEAST is a tattoo preview app. You photograph a part of your body — typically an arm, leg, back, chest, or hand — or pick an existing photo from your photo library. The App then renders a tattoo design onto that skin so you can see how it would look before getting tattooed.

3. Overview of the data we process

When you use the App, we process the following categories of personal data:

  • Account and sign-in data: email address, display name (when signing in with Apple, optionally first and last name), Firebase user ID, account creation timestamp.
  • Content data: photos you upload (in particular of body parts such as arm, leg, back, chest), image URLs imported from Pinterest, text prompts you enter, and the tattoo designs generated from them by AI.
  • Contract and usage data: the status of your Pro subscription, studio tokens consumed, number of stored uploads, timestamps.
  • Technical data: IP address, device and operating system identifiers, error logs (each within the server logs of our processors).

4. Photos and face data

Because the App works with photographs of your body, we want to be explicit about faces. The following applies without exception:

  • Your photo may contain a face. You are free to upload any photo you like, and a face may be visible in the frame — for example when you photograph your neck, shoulder, or chest. This is possible, but it is never required by the App.
  • We do not collect, generate, or analyse face data or any other biometric information. The App contains no face detection, face recognition, face tracking, or face-landmark functionality. It does not use ARKit face tracking, the Apple Vision framework, CIDetector, Face ID / LocalAuthentication, ML Kit, MediaPipe, or any comparable technology. No faceprint, face template, face embedding, face geometry, or any other biometric identifier is ever created, derived, or stored — neither on your device, nor on our servers, nor by any third party.
  • We never use photos to identify or recognise anyone. We do not match faces against each other, against any database, or against other users. A face in one of your photos is simply pixels in a picture, treated no differently from the background.
  • Photos are used exclusively for the core function of the App — rendering the tattoo preview you requested — and for the automated content moderation described in section 6.3, which is required by law. Photos are never used for advertising, profiling, analytics, or to train AI models, and they are never sold.
  • Photos are stored securely. All transmissions between the App, our backend, and our processors are encrypted with TLS (HTTPS). Images are held in access-controlled cloud storage, are reachable only through short-lived authenticated requests tied to your account, and are not publicly listable or browsable.
  • Photos are deleted when you delete them. You can delete any individual image at any time from within the App; it is then removed from our cloud storage. When you delete your account, all of your photos and generated designs are deleted along with it (see section 9).
  • No face data is shared with anyone. There is no face data to share, because none is ever created. Your photographs are transmitted only to the processors listed in section 8, exclusively so that they can return the requested result. None of them performs facial recognition for us, and none receives any biometric identifier. Photos are never shared with advertising networks, data brokers, or analytics providers.

We also confirm compliance with Sections 3.3.3(C) and 3.3.3(K) of the Apple Developer Program License Agreement: no face data is collected, no biometric data is used for identification, and nothing of the kind is shared with or sold to third parties.

5. Special categories of personal data (Art. 9 GDPR)

Independently of the clarification above, we take a deliberately conservative approach under European law. Because you may upload any photo, the photos you upload could contain special categories of personal data, in particular:

  • biometric data, in the sense that a face, iris, or uniquely identifying feature may be recognisable in the image — noting that we do not analyse, measure, or otherwise process such features, and do not use them to identify anyone; and
  • health data, where conclusions could be drawn from the images about scars, illnesses, existing tattoos, or other physical characteristics.

We process this data exclusively on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR, which you give in a separate dialog when you first start the App. You may withdraw this consent at any time with effect for the future by deleting your account in the App under “Profile → Manage Account → Delete Account”, or by contacting us informally by email at inkbeast@gmx.de. Withdrawal does not affect the lawfulness of the processing carried out up to that point.

6. Purposes of processing and legal bases

6.1 Provision and use of the App (Art. 6(1)(b) GDPR)

Processing your account and content data is technically necessary for registration, sign-in, authentication, and for providing the core App functions (image upload, gallery, AI generation, storage of your designs). The legal basis is the performance of the usage contract between you and us.

6.2 AI-assisted tattoo generation (Art. 6(1)(b) and Art. 9(2)(a) GDPR)

The photos and inputs you provide are transmitted to external AI service providers (see section 8) in order to generate tattoo previews. Insofar as special categories of personal data are processed in the course of this, it happens exclusively on the basis of your explicit consent.

6.3 Content moderation and protection of minors (Art. 6(1)(c) and (f) GDPR)

Every uploaded image is checked by an automated moderation service before it is stored, in order to detect and block illegal content (in particular depictions of violence subject to reporting obligations, sexualised content, and CSAM). This processing is necessary to comply with legal obligations (including § 184b German Criminal Code and the Digital Services Act) and to protect our legitimate interest in operating the App lawfully.

6.4 Billing of Pro subscriptions (Art. 6(1)(b) GDPR)

In-app purchases are handled by the Apple App Store or Google Play. We ourselves receive no payment data from these providers, only a pseudonymised identifier reflecting the status of your subscription (via RevenueCat, see section 8).

6.5 Security, fraud prevention, error analysis (Art. 6(1)(f) GDPR)

To ensure IT security, to detect abuse (e.g. excessive use, bot traffic), and to fix errors, we process technical data and log files on the basis of our legitimate interest in the secure and stable operation of the App.

7. Transfers to third countries (USA)

Some of the service providers named in section 8 process data in the United States of America or in other third countries outside the European Economic Area. These countries do not generally offer an adequate level of data protection within the meaning of the GDPR; in particular, public authorities may access data under relaxed conditions.

We base transfers to the USA on:

  • an adequacy decision of the EU Commission (EU-US Data Privacy Framework) for certified recipients (e.g. Google/Firebase, RevenueCat), Art. 45 GDPR;
  • the EU Commission’s Standard Contractual Clauses (controller-to-processor module) pursuant to Art. 46(2)(c) GDPR for all other recipients; and
  • your explicit consent to the third-country transfer pursuant to Art. 49(1)(a) GDPR, which you give when you first start the App.

8. Recipients and processors

To provide the App we use the following service providers, which process your data on our behalf or act as controllers in their own right:

Google Firebase Authentication

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA). Purpose: management of your user account, sign-in via email/password and “Sign in with Apple”. Data processed: email, display name, user ID, device and connection data. Third country: USA (DPF-certified). Privacy policy: policies.google.com/privacy.

Apple Sign In

Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Purpose: sign-in via Apple ID. Data processed: email (anonymised via “Hide My Email” where applicable), first and last name (only on first sign-in). Privacy policy: apple.com/legal/privacy.

Backblaze B2 Cloud Storage

Backblaze, Inc., 201 Baldwin Avenue, San Mateo, CA 94401, USA. Purpose: storage of your uploaded and generated images. Data processed: image files, file IDs, your user ID as part of the file name. Third country: USA (Standard Contractual Clauses).

Own database server (IONOS / hosted in Germany)

Storage of account metadata, upload index, subscription and token status. No images are stored here. Processing takes place in a data centre within the EU.

Hive AI (content moderation)

Hive Technology, Inc., 575 Market Street, Floor 16, San Francisco, CA 94105, USA. Purpose: automated detection of unlawful image content (CSAM, extreme violence, illegal pornography). Data processed: the uploaded image file (transient; not permanently stored by the provider under its contract). Third country: USA (Standard Contractual Clauses).

WaveSpeed AI (image generation)

WaveSpeed AI Inc. (USA). Purpose: generation of tattoo designs and editing of your photos using the “Flux-Dev” and “Flux-Kontext-Dev” models. Data processed: your photo or the URL of your uploaded image, your text prompt. Third country: USA (Standard Contractual Clauses). The provider processes the data solely to produce the result and not to train its own models.

ModelsLab (image composition)

ModelsLab. Purpose: composition processing (“genink”) — transferring a tattoo motif onto your body photo. Data processed: your body photo and the tattoo image. Third country: USA / India (Standard Contractual Clauses).

Hugging Face (depth map computation)

Hugging Face, Inc., 20 Jay Street, Suite 620, Brooklyn, NY 11201, USA. Purpose: computation of depth and normal maps from your photo so that tattoo placement looks more realistic. Data processed: the uploaded image. Third country: USA (Standard Contractual Clauses).

RevenueCat (subscription management)

RevenueCat, Inc., 153 Townsend Street, Suite 600, San Francisco, CA 94107, USA. Purpose: management and verification of your Pro subscription. Data processed: your Firebase user ID, App Store transaction IDs, subscription status, device identifier. No images. Third country: USA (DPF-certified). Privacy policy: revenuecat.com/privacy.

Apple App Store / Google Play

Payment processing and distribution of the App. The privacy terms of Apple and Google apply. We receive no cleartext payment data.

Pinterest (inbound image import)

If you paste a Pinterest link into the App, our server fetches the relevant page in order to read the image URL. Pinterest only receives the IP address of our server, not yours. No direct data transfer takes place between you and Pinterest.

9. Retention periods and deletion

  • Account and content data are stored for as long as your account exists.
  • Uploads are limited to a maximum of 200 per account; older images, and images you delete yourself, are removed promptly.
  • Individual images can be deleted by you at any time inside the App. Deleting an image removes the file from our cloud storage.
  • Account deletion can be carried out by you at any time inside the App under “Profile → Manage Account → Delete Account”. Doing so immediately deletes every photo and generated design you stored, all database records relating to you, and your authentication account. This is a permanent deletion, not a deactivation — the account cannot be recovered.
  • Log files are generally deleted after 30 days, unless required to investigate a specific incident.
  • After account deletion we remove all data concerning you from our systems within 30 days at the latest, unless statutory retention obligations (e.g. § 257 German Commercial Code, § 147 German Fiscal Code for Pro billing records) apply. Data may remain in encrypted backup copies for up to 90 days.

10. Your rights

You have the following rights in relation to us:

  • access to the data processed about you (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (“right to be forgotten”, Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • objection to processing based on legitimate interests (Art. 21 GDPR),
  • withdrawal of consent with effect for the future (Art. 7(3) GDPR).

An informal message to inkbeast@gmx.de is enough to exercise your rights. You can also delete your account, including all linked content, yourself at any time in the App under “Profile → Manage Account → Delete Account”.

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for our place of business is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach, Germany
www.lda.bayern.de

11. Automated decision-making

No automated decision-making within the meaning of Art. 22 GDPR producing legal effects concerning you takes place. The AI-assisted image generation merely produces a visual preview and makes no decisions about you.

12. Data security

All transmissions between the App, our backend, and third-party providers are encrypted exclusively via TLS (HTTPS). We take technical and organisational measures — access restrictions, authentication via short-lived Firebase tokens, separated storage areas — to protect your data against loss, manipulation, and unauthorised access.

13. Changes to this privacy policy

We reserve the right to adapt this privacy policy if the legal situation, the service providers used, or the functionality of the App changes. The current version is always available in the App and at inkbea.st/privacy. We will inform you in the App before any material change affecting your consents takes effect.

← Back to home
INKBEAST

KI-Tattoo-Studio für dein Smartphone. Entwirf und platziere dein Tattoo, bevor du dich entscheidest.

Produkt

So geht's Funktionen Pro

Laden

App Store Google Play

Rechtliches

Legal Notice Privacy Policy
© 2026 INKBEAST · inkbea.st Made with ink & pixels.