TPS_OPERATOR_NAME, TPS_CONTACT_EMAIL, TPS_JURISDICTION), so this document is provided for review only and no agreement is formed by using the service.the operator of this service is the data controller for Tattoo Planning Suite. Questions and requests go to (contact address not published yet).
1. The short version
- Projects are private by default. Only you, the artist you invite, and our administrators (for safety and support) can open them.
- Body photos are stored privately, served through short-lived signed links, never used to train models, never used in marketing, and never sent to third-party AI providers. You can delete them in one click.
- Your brief text is sent to an image-model provider to generate concepts, when a real model is configured. Photos are not.
- We use first-party analytics only. No advertising trackers, no third-party analytics scripts, no ad cookies.
- Anonymous projects lose their access link after 24 hours unless you claim them with your email.
2. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Brief | Your idea text, story or meaning, subject, style, placement, size range, colour, budget range, must-include and must-avoid notes, plus each saved version. | Typed by you; an idea entered on a landing page is parsed into a first draft. |
| Body photos sensitive | Up to 3 photos of the body area where you want the tattoo, and the placement snapshots you save on top of them. These can reveal skin, existing tattoos, scars or other health-related detail. | Uploaded by you, with your confirmation that you own the image. |
| Reference images | Up to 8 inspiration images and the file name you uploaded them with. | Uploaded by you. |
| Email address | The address you use to claim a project or sign in, and — for artists — the display name, studio and external booking links you add to your profile. | Entered by you or by the client who invited you. |
| Age confirmation | The time you confirmed you are 18 or over, and the terms version you accepted. | Recorded when you tick the confirmation. |
| Concepts and workflow | Generated concept images and their metadata, artist comments (including private artist notes), decisions, information requests, revision requests, checklist notes, quotes and status changes. | Created by the service and by project members. |
| Analytics events | Named product events (for example a brief was submitted, generation started, an external booking link was clicked) with the project ID, your user ID if signed in, and small non-identifying properties. Landing page, referrer and UTM tags are stored with the project. We never put prompt text, comment bodies, emails, photos or file names into analytics. | Generated by your use of the service. |
| Audit trail | An append-only record of who did what in a project (e.g. photo deleted, direction approved, download unlocked). It stores IDs and small metadata, never image content. | Generated by the service. |
| Server logs | IP address, browser user-agent, requested URL and timestamps, in the standard logs of our hosting provider. We do not copy these into our application database. | Collected automatically by the hosting infrastructure. |
| Support email | Anything you send to our contact address, including deletion or content reports. | Sent by you. |
3. Why we use it and on what basis
Where GDPR or a similar law applies, we rely on the legal bases below. In other places the same purposes apply.
| Purpose | Data used | Legal basis |
|---|---|---|
| Running your consultation: saving the brief, generating three concept directions, watermarking, try-on preview, artist review, quotes and status tracking. | Brief, reference images, concepts, workflow data, email. | Performance of a contract (the Terms of Service). |
| Placement preview and artist review on your body photo. | Body photos and placement snapshots. | Your explicit consent, given when you upload. Withdraw it at any time by deleting the photo. |
| Signing you in, claiming anonymous projects, delivering artist invitations, and sending project notifications. | Email address, session and magic-link records. | Performance of a contract; legitimate interest in account security. |
| Content safety: checking briefs against our Content & AI Policy, handling reports, pausing generation, keeping an audit trail. | Brief text, workflow data, audit trail, reports. | Legitimate interest in a safe service; legal obligation where applicable. |
| Security and abuse prevention: detecting forged links, blocked access attempts and misuse. | Server logs, audit trail, session records. | Legitimate interest. |
| Understanding and improving the product: funnel metrics, generation cost and duration, artist time spent. | First-party analytics events, generation job records. | Legitimate interest. Events are pseudonymous and never contain content. |
| Confirming you are an adult. | Age confirmation record. | Legal obligation and legitimate interest. |
4. Who processes it for us
We use a small number of service providers. Each only receives what it needs for its job.
| Provider | What it does | What it receives |
|---|---|---|
| Hosting provider | Runs the application, the database and the private file store. | All service data, in encrypted storage; standard server logs including IP address. |
| Resend | Delivers magic-link sign-in emails, invitations and notifications when email sending is configured. | Your email address, the subject line, a short message and a secure link. Emails never contain photos or artwork. |
| OpenRouter, routing to Google (Gemini image model) | Generates concept images when a real image model is configured. Otherwise a built-in renderer on our own server produces the concepts and nothing leaves it. | A generated text prompt built from your brief: main subject, style, must-include and must-avoid notes, body part and size range. It does not include your email, your name, your reference images or your body photos. |
We do not sell personal data and we do not share it with advertisers or data brokers. We may disclose data if the law requires it, to enforce our terms, or to protect someone’s safety.
6. How long we keep it
| Data | Retention |
|---|---|
| Anonymous project (not claimed) | Its access link expires 24 hours after creation. After that nobody can open it, and we may delete it at any time. Email us to have it removed sooner. |
| Claimed project: brief, references, concepts, comments, quotes | Kept while the project is active so both you and your artist can refer back to it. Deleted the moment the client deletes the project or closes their account, or when we retire the pilot. |
| Body photos and placement snapshots | Kept only until you delete them or the project is deleted. Deleting a photo removes the file and revokes every link to it immediately. |
| Magic links | Valid for 24 hours and for a single use; used or expired links are inert. |
| Artist invitations | Expire after 7 days or when you revoke them. |
| Sessions | Up to 30 days, or until you sign out. |
| Analytics events and audit trail | Kept for the life of the pilot to measure the product and investigate issues. They contain no content. |
| Server logs | Per our hosting provider's standard rotation, typically days to a few weeks. |
| Backups | Deleted data may persist in routine backups for a short period before being overwritten. |
7. How we protect it
- Files never live in a public folder. Every image read goes through a signed link that is tied to one file and one variant, and expires after 15 minutes. Links are only issued after the server checks you are a member of the project.
- Deleting a photo marks it deleted and removes the object. Any signed link that is still in someone's browser stops working at once.
- Concept images are always delivered with a server-side watermark reading "AI CONCEPT — NOT FINAL TATTOO ART" plus a short project ID, so a leaked image is traceable and clearly not finished work. Full-resolution originals are refused unless the artist has approved that direction and explicitly unlocked download.
- Emails contain secure links only, never images.
- Session cookies are HTTP-only and same-site. Sessions, signed links and magic links are signed with a server secret.
- The audit trail is append-only and never stores image content.
No system is perfectly secure. If we discover a breach affecting your data we will tell you and, where required, the relevant authority.
8. Your rights and in-app controls
Depending on where you live you may have rights to access, correct, delete, restrict or export your data, to object to processing based on legitimate interest, to withdraw consent, and to complain to a supervisory authority. We honour these for everyone, wherever they are.
Things you can do yourself, right now:
- Delete a photo. Hover or tap any reference or body photo in the project and use the “Delete photo” button. Removal and link revocation are immediate.
- Export your brief. The project’s Export page produces a printable Artist Brief containing your brief, the selected direction, your preferred placement and the artist’s checklist notes. Client email, internal notes, raw body photos and unselected directions are excluded by default.
- Edit your brief. Drafts autosave; each submission is kept as a numbered version so you and your artist can see what changed.
- Download everything in a project. “Download project data” on the project page returns one JSON file with every brief version, concept record, placement, comment, decision and quote we hold for it. Your artist’s private notes are not in your copy, and yours are not in theirs.
- Delete a whole project. “Delete project” on the project page removes the brief, concepts, placements, comments, quotes and every uploaded image immediately and irreversibly, for you and for your artist. Only the client can do this.
- Close your account. From your dashboard. It deletes the projects you own and all their files, removes your account, sessions and pending sign-in links, and steps you out of any project you only joined as an artist — that project stays with its client, without your name, comment attribution or private notes.
- Sign out to end your session, or let an anonymous project expire.
Deleting a project or an account does not erase the content-free analytics and audit records described in section 6: they hold ids, counts and timings, never brief text, comments or images. For anything else — a correction, a copy of data outside a project, or help if you cannot reach your account — email (contact address not published yet) from the address on the account. We answer within 30 days and usually much sooner. We may ask you to confirm your identity by replying from that address.
10. Children
The service is for adults only. We do not knowingly collect data from anyone under 18, and we ask every user to confirm their age before generation. If you believe a minor has used the service, email (contact address not published yet) and we will delete the project.
11. International transfers
Our hosting provider, Resend, OpenRouter and Google may process data in countries other than yours, including the United States. Where data protection law requires it we rely on the provider’s standard contractual clauses or an equivalent safeguard. Remember that body photos are not sent to AI providers at all; only brief text is.
12. Changes and contact
We will update this policy when the product or our providers change; the date at the top shows the current version. Material changes will be announced in the app or by email to account holders.