Tattoo·Planning·Suite

Legal

Privacy Policy

A tattoo consultation involves personal things: your idea, your reasons, and photos of your body. This page explains exactly what we collect, what we do with it, who else touches it, and how to make us delete it.

Last updated: 4 September 2026

the operator of this service is the data controller for Tattoo Planning Suite. Questions and requests go to (contact address not published yet).

1. The short version

  • Projects are private by default. Only you, the artist you invite, and our administrators (for safety and support) can open them.
  • Body photos are stored privately, served through short-lived signed links, never used to train models, never used in marketing, and never sent to third-party AI providers. You can delete them in one click.
  • Your brief text is sent to an image-model provider to generate concepts, when a real model is configured. Photos are not.
  • We use first-party analytics only. No advertising trackers, no third-party analytics scripts, no ad cookies.
  • Anonymous projects lose their access link after 24 hours unless you claim them with your email.

2. What we collect

CategoryWhat it includesWhere it comes from
BriefYour idea text, story or meaning, subject, style, placement, size range, colour, budget range, must-include and must-avoid notes, plus each saved version.Typed by you; an idea entered on a landing page is parsed into a first draft.
Body photos sensitiveUp to 3 photos of the body area where you want the tattoo, and the placement snapshots you save on top of them. These can reveal skin, existing tattoos, scars or other health-related detail.Uploaded by you, with your confirmation that you own the image.
Reference imagesUp to 8 inspiration images and the file name you uploaded them with.Uploaded by you.
Email addressThe address you use to claim a project or sign in, and — for artists — the display name, studio and external booking links you add to your profile.Entered by you or by the client who invited you.
Age confirmationThe time you confirmed you are 18 or over, and the terms version you accepted.Recorded when you tick the confirmation.
Concepts and workflowGenerated concept images and their metadata, artist comments (including private artist notes), decisions, information requests, revision requests, checklist notes, quotes and status changes.Created by the service and by project members.
Analytics eventsNamed product events (for example a brief was submitted, generation started, an external booking link was clicked) with the project ID, your user ID if signed in, and small non-identifying properties. Landing page, referrer and UTM tags are stored with the project. We never put prompt text, comment bodies, emails, photos or file names into analytics.Generated by your use of the service.
Audit trailAn append-only record of who did what in a project (e.g. photo deleted, direction approved, download unlocked). It stores IDs and small metadata, never image content.Generated by the service.
Server logsIP address, browser user-agent, requested URL and timestamps, in the standard logs of our hosting provider. We do not copy these into our application database.Collected automatically by the hosting infrastructure.
Support emailAnything you send to our contact address, including deletion or content reports.Sent by you.

3. Why we use it and on what basis

Where GDPR or a similar law applies, we rely on the legal bases below. In other places the same purposes apply.

PurposeData usedLegal basis
Running your consultation: saving the brief, generating three concept directions, watermarking, try-on preview, artist review, quotes and status tracking.Brief, reference images, concepts, workflow data, email.Performance of a contract (the Terms of Service).
Placement preview and artist review on your body photo.Body photos and placement snapshots.Your explicit consent, given when you upload. Withdraw it at any time by deleting the photo.
Signing you in, claiming anonymous projects, delivering artist invitations, and sending project notifications.Email address, session and magic-link records.Performance of a contract; legitimate interest in account security.
Content safety: checking briefs against our Content & AI Policy, handling reports, pausing generation, keeping an audit trail.Brief text, workflow data, audit trail, reports.Legitimate interest in a safe service; legal obligation where applicable.
Security and abuse prevention: detecting forged links, blocked access attempts and misuse.Server logs, audit trail, session records.Legitimate interest.
Understanding and improving the product: funnel metrics, generation cost and duration, artist time spent.First-party analytics events, generation job records.Legitimate interest. Events are pseudonymous and never contain content.
Confirming you are an adult.Age confirmation record.Legal obligation and legitimate interest.

4. Who processes it for us

We use a small number of service providers. Each only receives what it needs for its job.

ProviderWhat it doesWhat it receives
Hosting providerRuns the application, the database and the private file store.All service data, in encrypted storage; standard server logs including IP address.
ResendDelivers magic-link sign-in emails, invitations and notifications when email sending is configured.Your email address, the subject line, a short message and a secure link. Emails never contain photos or artwork.
OpenRouter, routing to Google (Gemini image model)Generates concept images when a real image model is configured. Otherwise a built-in renderer on our own server produces the concepts and nothing leaves it.A generated text prompt built from your brief: main subject, style, must-include and must-avoid notes, body part and size range. It does not include your email, your name, your reference images or your body photos.
Body photos are never sent to any AI provider. Concept generation works from text only.

We do not sell personal data and we do not share it with advertisers or data brokers. We may disclose data if the law requires it, to enforce our terms, or to protect someone’s safety.

5. Who can see your project

  • You, through your session or the anonymous link.
  • The artist you invite. Before accepting, an artist sees only a minimal summary. After accepting they see the brief, reference images, concepts and any body photos and placement snapshots in the project. Artists may keep private notes you cannot see.
  • Our administrators, for safety, support and abuse investigation. Admin dashboards list projects and metrics, not body photos, and administrators cannot approve designs on an artist’s behalf.

A project is never public and is not indexed by search engines. Project, dashboard, invitation and file routes are excluded from crawling.

6. How long we keep it

DataRetention
Anonymous project (not claimed)Its access link expires 24 hours after creation. After that nobody can open it, and we may delete it at any time. Email us to have it removed sooner.
Claimed project: brief, references, concepts, comments, quotesKept while the project is active so both you and your artist can refer back to it. Deleted the moment the client deletes the project or closes their account, or when we retire the pilot.
Body photos and placement snapshotsKept only until you delete them or the project is deleted. Deleting a photo removes the file and revokes every link to it immediately.
Magic linksValid for 24 hours and for a single use; used or expired links are inert.
Artist invitationsExpire after 7 days or when you revoke them.
SessionsUp to 30 days, or until you sign out.
Analytics events and audit trailKept for the life of the pilot to measure the product and investigate issues. They contain no content.
Server logsPer our hosting provider's standard rotation, typically days to a few weeks.
BackupsDeleted data may persist in routine backups for a short period before being overwritten.

7. How we protect it

  • Files never live in a public folder. Every image read goes through a signed link that is tied to one file and one variant, and expires after 15 minutes. Links are only issued after the server checks you are a member of the project.
  • Deleting a photo marks it deleted and removes the object. Any signed link that is still in someone's browser stops working at once.
  • Concept images are always delivered with a server-side watermark reading "AI CONCEPT — NOT FINAL TATTOO ART" plus a short project ID, so a leaked image is traceable and clearly not finished work. Full-resolution originals are refused unless the artist has approved that direction and explicitly unlocked download.
  • Emails contain secure links only, never images.
  • Session cookies are HTTP-only and same-site. Sessions, signed links and magic links are signed with a server secret.
  • The audit trail is append-only and never stores image content.

No system is perfectly secure. If we discover a breach affecting your data we will tell you and, where required, the relevant authority.

8. Your rights and in-app controls

Depending on where you live you may have rights to access, correct, delete, restrict or export your data, to object to processing based on legitimate interest, to withdraw consent, and to complain to a supervisory authority. We honour these for everyone, wherever they are.

Things you can do yourself, right now:

  • Delete a photo. Hover or tap any reference or body photo in the project and use the “Delete photo” button. Removal and link revocation are immediate.
  • Export your brief. The project’s Export page produces a printable Artist Brief containing your brief, the selected direction, your preferred placement and the artist’s checklist notes. Client email, internal notes, raw body photos and unselected directions are excluded by default.
  • Edit your brief. Drafts autosave; each submission is kept as a numbered version so you and your artist can see what changed.
  • Download everything in a project. “Download project data” on the project page returns one JSON file with every brief version, concept record, placement, comment, decision and quote we hold for it. Your artist’s private notes are not in your copy, and yours are not in theirs.
  • Delete a whole project. “Delete project” on the project page removes the brief, concepts, placements, comments, quotes and every uploaded image immediately and irreversibly, for you and for your artist. Only the client can do this.
  • Close your account. From your dashboard. It deletes the projects you own and all their files, removes your account, sessions and pending sign-in links, and steps you out of any project you only joined as an artist — that project stays with its client, without your name, comment attribution or private notes.
  • Sign out to end your session, or let an anonymous project expire.

Deleting a project or an account does not erase the content-free analytics and audit records described in section 6: they hold ids, counts and timings, never brief text, comments or images. For anything else — a correction, a copy of data outside a project, or help if you cannot reach your account — email (contact address not published yet) from the address on the account. We answer within 30 days and usually much sooner. We may ask you to confirm your identity by replying from that address.

9. Cookies

We set only the cookies needed to run the service. There are no advertising or third-party cookies.

CookiePurposeLifetime
tps_sessionIdentifies your session, whether anonymous or signed in.30 days
tps_anon_<project>Lets your browser open an anonymous project you started without an account.24 hours
tps_age_<project>Remembers that you confirmed you are 18 or over for that project.30 days

All three are HTTP-only and same-site, so scripts on other sites cannot read them. Blocking them means you cannot keep a project between page loads.

10. Children

The service is for adults only. We do not knowingly collect data from anyone under 18, and we ask every user to confirm their age before generation. If you believe a minor has used the service, email (contact address not published yet) and we will delete the project.

11. International transfers

Our hosting provider, Resend, OpenRouter and Google may process data in countries other than yours, including the United States. Where data protection law requires it we rely on the provider’s standard contractual clauses or an equivalent safeguard. Remember that body photos are not sent to AI providers at all; only brief text is.

12. Changes and contact

We will update this policy when the product or our providers change; the date at the top shows the current version. Material changes will be announced in the app or by email to account holders.

Operator

Name
the operator of this service
Contact
Governing law
the operator's home jurisdiction