Skip to content

Privacy Policy

Effective from [EFFECTIVE DATE]

What personal data Generatifiy collects, why, who receives it, how long it is kept and how to use your rights. It also serves as the information notice required by the Turkish Personal Data Protection Law (KVKK).

Draft, pending completion and legal review

This document is a draft and is not yet in force. Details shown in [SQUARE BRACKETS] are still to be filled in, and the text has not been reviewed by a lawyer. It is not legal advice.

1. Who is responsible for your data

Generatifiy (https://generatifiy.com) is operated by [OPERATOR LEGAL NAME], a sole proprietorship established in Türkiye, trading as [OPERATOR TRADE NAME] ("we", "us"). We are the data controller for the personal data described in this policy.

This policy covers the Generatifiy website and web application. It applies to visitors and to people who create an account, whether they act for a business or for themselves.

2. The data we collect

We collect only what the service needs. We do not buy data about you, and we do not build advertising profiles.

Account data

  • Your name and email address, which you give when you sign up.
  • Your password, stored only as a salted hash. We cannot read it. When you ask to reset it, a single-use reset token is stored until it is used or expires, together with a count of the reset emails sent to your account recently, which limits how many can be sent.
  • If you choose to sign in with Google: your Google account identifier, name, email address and profile picture address as Google sends them, and the tokens Google issues for that sign-in.
  • The language you use the service in, and whether analytics is switched on for your account.

Sign-in sessions

Each time you sign in we store a session record: a random session token, when it was created and when it expires, and the IP address and browser identification (user agent) the sign-in came from. We also keep short-lived counters per IP address to slow down repeated sign-in attempts.

Product photos you upload

The photos you upload, an optional product name, and the technical properties of the file (format, size, dimensions). Before a photo leaves your device, your browser re-encodes it, which removes embedded metadata such as location and camera details; our server refuses files that still contain metadata. Product photos are meant to show products. Please do not upload photos that show people or other personal data.

Generated images

The images generated for you, with the scene, format and model you chose, the credits charged, the outcome, timestamps, how often you downloaded the image, and whether you reported it as wrong. When a generation fails we keep a technical error message for troubleshooting.

Subscription and credits

Payments are handled by Polar (see section 5). We never receive or store your card number or other payment credentials. We store: your plan, the subscription status, the start and end of the paid period, the amount and currency you pay, whether a cancellation or plan change is scheduled, the identifiers Polar gives your subscription, orders and checkouts, and a ledger of every credit added to or taken from your balance with its reason. When you open a checkout we send Polar your account identifier, your name and your email address so that the purchase can be tied to your account.

Technical and usage data

  • Request logs. Our servers log each request: time, address requested, outcome, duration and technical request headers (such as browser identification, language, the referring page and the IP address the request came from; never cookies or passwords). For signed-in requests the log also holds your account identifier, your name, a masked form of your email address, and the identifier, IP address and browser identification of your session. Logs are used to keep the service running and secure.
  • Product analytics, only when you are signed in and only while it is switched on: see section 4.
  • Cookies and browser storage needed to run the service: see the Cookie and Tracking Notice.

Messages you send us

When you write to us by email we keep the message, your email address and our reply for as long as needed to deal with the matter and keep a record of it.

We do not intentionally collect special categories of personal data (such as health data or biometric data).

The table states each purpose with its legal basis under the EU General Data Protection Regulation (GDPR) and under the Turkish Personal Data Protection Law No. 6698 (KVKK).

PurposeDataGDPRKVKK
PurposeCreating and running your account, keeping you signed inDataAccount data, sessionsGDPRArt. 6(1)(b): performance of a contractKVKKArt. 5/2(c): necessary for a contract
PurposeGenerating images from your photos and keeping them available to youDataProduct photos, generated imagesGDPRArt. 6(1)(b)KVKKArt. 5/2(c)
PurposeManaging your subscription and credits; working with Polar on payments, refunds and disputesDataSubscription and credit dataGDPRArt. 6(1)(b); Art. 6(1)(c) where records must be kept by lawKVKKArt. 5/2(c); Art. 5/2(ç): legal obligation
PurposeService emails (welcome, password reset, notices about your account)DataName, email address, languageGDPRArt. 6(1)(b)KVKKArt. 5/2(c)
PurposeKeeping the service secure and working: logs, rate limits, abuse prevention, troubleshootingDataSessions, request logs, technical dataGDPRArt. 6(1)(f): our legitimate interest in a secure, reliable serviceKVKKArt. 5/2(f): legitimate interest
PurposeUnderstanding how the product is used in order to improve it (product analytics, signed-in users only)DataAnalytics events tied to your account identifierGDPRArt. 6(1)(f): our legitimate interest in understanding and improving the service. You can object at any time by switching analytics offKVKKArt. 5/2(f): legitimate interest
PurposeAnswering your requests and handling legal claimsDataMessages you send us, relevant account dataGDPRArt. 6(1)(b), Art. 6(1)(f)KVKKArt. 5/2(c), Art. 5/2(e): establishing, exercising or protecting a right

We do not use your data for automated decisions that produce legal or similarly significant effects, and we do not send marketing emails. If we ever want to, we will ask for your consent first.

How we collect the data (KVKK Art. 10). We collect it by automated means: through the forms you fill in on the website, the files you upload, the technical records our servers create when you use the service, and the notifications Polar sends us about your subscription.

4. Product analytics

  • No analytics on public pages. The landing page, the sign-in page and the legal pages load no analytics code and send no analytics data, and visitors who are not signed in are never measured.
  • Signed-in users only, first-party. When you are signed in, we record which features are used: pages of the app viewed, uploads, generations requested and their outcome, downloads, reports, language changes and subscription events. We use this only to understand and improve Generatifiy.
  • No cookies, no device storage. The analytics code keeps its state in memory only. It writes nothing to cookies, localStorage or sessionStorage.
  • What an event carries. Each event is tied to our internal identifier for your account. It never carries your name, email address, file names, image addresses or anything you typed. Besides the event itself (for example which scene, format and model a generation used, or which plan a subscription is on) and its time, your browser sends: the app page as a fixed route name without identifiers, the site's address, the referring domain, the name of your browser and operating system, the kind of device, the name and version of the analytics code, and two random identifiers that exist in memory only (one for the visit, one used until your account is recognised). Campaign tags in links (utm parameters) are not sent. As with any internet request, the analytics provider's servers receive your IP address when your browser contacts them; we instruct the provider not to derive a location from it.
  • No advertising, no cross-site tracking, no session recording.
  • You can switch it off. Go to Account and set Product analytics to Off. It stops at once in that browser, in every tab you have open, even before the choice is saved. Once saved, the choice is stored with your account: events our servers would record about your account are no longer sent, and your other browsers and devices follow the next time they load a page of the app or its tab comes back into view. If the choice cannot be read, analytics does not run. You can switch it back on at any time.
  • Global Privacy Control. If your browser sends the Global Privacy Control signal and you have not made a choice yourself, we treat that as Off and store it as your choice until you switch analytics on.

The analytics provider is PostHog (see section 5). Switching analytics off does not affect billing records or security logs, which are not analytics.

5. Who receives your data

We do not sell personal data. We share it only with the providers that run parts of the service for us, and with authorities where the law requires it.

RecipientWhat forData involvedRole and location
RecipientCloudflare, Inc.What forHosting of the website and API, file storage, image resizing, sending service emails, network securityData involvedAll data that passes through the service; stored product photos and generated imagesRole and locationProcessor. United States company with a global network; storage location to be confirmed
RecipientPlanetScale, Inc.What forDatabaseData involvedAccount, session, product, generation, subscription and credit recordsRole and locationProcessor. United States company; database region to be confirmed
RecipientFeatures & Labels, Inc. (fal.ai)What forRunning the AI image modelsData involvedThe product photo you chose and a fixed scene description written by us. Nothing you typed, and no account detailsRole and locationProcessor. United States. See section 6
RecipientPolar Software, Inc.What forCheckout, payments, invoices, taxes, refundsData involvedYour account identifier, name and email address from us; payment and billing details you give Polar directlyRole and locationIndependent controller (merchant of record). United States
RecipientAxiom, Inc.What forStoring server logsData involvedRequest logs as described in section 2Role and locationProcessor. United States company; storage region to be confirmed
RecipientPostHogWhat forProduct analytics, only for signed-in users with analytics switched onData involvedAnalytics events as described in section 4Role and locationProcessor. EU hosting (Frankfurt, Germany) by default
RecipientGoogle Ireland Ltd. / Google LLCWhat forOnly if you choose to sign in with GoogleData involvedGoogle learns that you sign in to Generatifiy; we receive your basic profileRole and locationIndependent controller

Polar is the merchant of record for every purchase: it sells the subscription to you, takes the payment, calculates and remits taxes and issues your invoice. It handles your payment data under its own privacy policy, which you see at checkout.

We may disclose data to courts, regulators or law-enforcement authorities when the law obliges us to, and to professional advisers where needed to establish or defend legal claims.

6. AI image generation

  • Images are generated by third-party AI models reached through fal.ai: FLUX Kontext (Black Forest Labs), Nano Banana (Google's Gemini image model), Seedream 4 (ByteDance) and GPT Image 2 (OpenAI). The model used is the one you pick for each generation.
  • What is sent: the product photo you selected and a scene description from our own fixed list. Text you type (such as a product name) is never sent, and neither is your name, email address or account identifier.
  • How it is sent, and what we ask of fal.ai with every generation: we upload the photo to fal.ai's storage and ask for that copy, and for fal.ai's copy of the result, to expire after 60 minutes; and we ask fal.ai not to keep the contents of the request (the scene description and the addresses of the two files) in its request history. We then download the result and store it in our own private storage.
  • We do not use your photos or generated images to train AI models, and we do not allow others to do so on our behalf.
  • What fal.ai's documentation and terms say: files expire after the period requested and are then permanently deleted. Request contents are kept for 30 days by default; with the setting we send, they are not stored. Its terms allow it to use anonymised or aggregated usage data, which may be derived from customer inputs, to develop its products and AI models. Its terms also say that models hosted by third parties may be subject to those third parties' own terms. We have no information from the model developers about what they retain beyond that.

7. Transfers to other countries

We are established in Türkiye, and the providers listed in section 5 are established mainly in the United States and the European Union. Your data is therefore processed outside the country you live in, including in countries whose data-protection laws differ from those of Türkiye or of the European Economic Area.

For these transfers we rely on the data-processing terms our providers offer, which include contractual safeguards for international transfers, and, for payments, on the fact that you enter into the purchase with Polar directly. Where the law requires a specific transfer mechanism, we will put it in place before relying on the provider for personal data covered by that law.

8. How long we keep data

DataHow long it is kept
DataAccount dataHow long it is keptFor as long as you have an account. There is no self-service deletion yet: write to us to have your account deleted (section 10)
DataSign-in sessionsHow long it is keptUntil they expire or you sign out. A session lasts up to 7 days; when you use the service more than 24 hours after it was last extended, it is extended to 7 days again. Expired session records may remain until they are cleaned up
DataProduct photosHow long it is keptFor as long as you have an account, or until you delete the product. Deleting a product that no image was generated from erases its stored photo and its record at once. Deleting a product that images were generated from removes it from your products, but its stored photo and record are kept, because those images refer to it and are shown next to it; they are erased when your account is deleted or when you ask us to erase them. To limit how many photos can be uploaded within an hour and within a day, we record the time of each upload; such a record is removed at your next upload once it is more than a day old
DataGenerated imagesHow long it is keptFor as long as you have an account, including after your subscription ends, so that you can still view and download them. Individual images cannot yet be deleted from within the app: write to us
DataSubscription and credit recordsHow long it is keptFor as long as you have an account, and afterwards for as long as tax, accounting and consumer law require us to keep transaction records
DataCopies at fal.aiHow long it is keptFiles: expiry requested after 60 minutes. Request contents: we ask fal.ai not to store them (its default would be 30 days)
DataServer logsHow long it is keptAccording to the retention period of our log provider's plan (to be confirmed)
DataAnalytics eventsHow long it is keptAccording to the retention period of our analytics provider's plan (to be confirmed). Switching analytics off stops new events; write to us to have past events deleted
DataSupport emailsHow long it is keptFor as long as needed to handle the matter, and afterwards as a record for up to the limitation period for legal claims

When you ask us to delete your account we erase your account, sessions, product photos, generated images and credit history from our systems, and ask our providers to do the same, except for records we are legally required to keep.

9. How we protect data

  • All traffic to the service is encrypted in transit (HTTPS).
  • Product photos and generated images are kept in private storage with no public address. Every request for a file is checked against the signed-in account, and a file is served only to its owner.
  • Passwords are stored only as salted hashes.
  • The session cookie is first-party, cannot be read by scripts (HttpOnly), is sent only over HTTPS and is not sent on cross-site requests that could be forged (SameSite=Lax).
  • Uploaded files are checked by their content, not their name, and metadata is refused.
  • Payment credentials never reach our systems.

No system is perfectly secure. If a breach affects your personal data we will notify you and the competent authorities as the law requires.

10. Your rights and how to use them

If the GDPR applies to you

You have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict its processing (Art. 18), to receive it in a portable format (Art. 20), and to object to processing based on legitimate interests, including product analytics (Art. 21). You are not subject to decisions based solely on automated processing that have legal or similarly significant effects (Art. 22). Where processing is based on consent you may withdraw it at any time.

If the KVKK applies to you

Under Article 11 of the KVKK you have the right to:

  • learn whether your personal data is processed;
  • request information about the processing if it is;
  • learn the purpose of the processing and whether the data is used in line with that purpose;
  • know the third parties, in Türkiye or abroad, to whom the data is transferred;
  • request correction of incomplete or inaccurate data;
  • request erasure or destruction of the data under the conditions of Article 7;
  • request that correction, erasure or destruction be notified to third parties to whom the data was transferred;
  • object to a result against you arising from analysis of the data solely by automated systems;
  • claim compensation if you suffer damage because of unlawful processing.

How to make a request

Write to privacy@generatifiy.com from the email address of your account, or by post to the registered address above. Tell us which right you want to use. We may ask for information to confirm your identity. We answer free of charge and as soon as possible, at the latest within one month under the GDPR and within thirty days under the KVKK. There is no self-service export or account deletion in the app yet, so these requests are handled by a person.

To object to product analytics you do not need to write to us: switch it off in Account.

11. Complaints

Please contact us first so that we can put things right. You also have the right to complain to a supervisory authority:

  • In Türkiye: the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), kvkk.gov.tr, after applying to us first, as the KVKK requires.
  • In the European Economic Area: the data-protection authority of the country where you live or work, or where you think the infringement took place.

12. Children

Generatifiy is a tool for businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has created an account, write to us and we will delete it.

13. Changes to this policy

We will update this policy when the service or the law changes. The date at the top shows when it last changed. If a change is significant we will tell account holders by email or in the app before it takes effect.