Picky

Privacy Policy

Last Updated: February 15, 2026

This Privacy Policy explains how Picky (“we,” “us,” or “our”) collects, uses, and protects your information when you use our mobile application and related services (collectively, the “Service”). By using the Service, you agree to the collection and use of information in accordance with this policy.


1. Information We Collect

1.1 Information You Provide Directly

  • Account information: Email address, display name, and profile picture
  • Photos: Images you upload for AI analysis, ranking, or editing
  • Text content: Chat messages, image editing instructions, comments, and custom prompts you submit to the AI
  • Preferences: Language, notification settings, and analysis category preferences (e.g., “Which photo makes me look the hottest”)

1.2 Information We Generate

  • AI analysis results: Scores, rankings, feedback, and suggestions generated by our AI based on your photos
  • Edited images: Modified versions of your photos created through our editing features
  • Thumbnails: Sticker-style thumbnails generated from your images for use in voting links

1.3 Information Collected from Voters

When someone votes on your images through a shared voting link, we collect:

  • Their votes and optional comments
  • Their country (derived from IP address — we do not store the full IP address)
  • Basic device information (browser type, operating system)

Voters are not required to create an account to participate.

1.4 Information Collected Automatically

  • Device tokens for push notifications
  • Basic server logs (request timestamps, error information)
  • Usage data (number of analyses performed, edits used, voting links created)
  • Attribution data (link tokens via Airbridge for measuring how users discover Picky — no personal data is shared)

We do not collect precise geolocation, contacts, health data, financial information, or browsing history.


2. How We Use Your Information

We use the information we collect to:

  • Provide the Service: Analyze your photos using AI, generate feedback and rankings, enable image editing, and power the social voting feature
  • Send notifications: Alert you when someone votes on your images, when you hit milestones, or when there are important updates
  • Manage your account: Handle authentication, subscriptions, usage limits, and purchase history
  • Maintain and improve the Service: Monitor for errors, prevent abuse, improve performance, and develop new features
  • Comply with legal obligations: Respond to valid legal requests and enforce our Terms of Service

What We Do NOT Do

  • We do not sell your personal information to anyone
  • We do not use your photos for advertising or marketing purposes
  • We do not train our own AI models on your images
  • We do not create advertising profiles based on your data
  • We do not share your personal information with data brokers

3. Legal Basis for Processing (For EEA/UK Users)

If you are located in the European Economic Area or United Kingdom, we process your personal data based on the following legal grounds:

  • Performance of a contract: Processing necessary to provide you with the Service you have requested (photo analysis, editing, voting)
  • Legitimate interests: Improving the Service, preventing fraud, and ensuring security, where these interests are not overridden by your rights
  • Consent: Where you have given us specific consent, such as for push notifications or optional marketing communications
  • Legal obligation: Where processing is required to comply with applicable law

You may withdraw your consent at any time through the app settings or by contacting us.


4. Third-Party Services

We use trusted third-party services to operate Picky. We only share the minimum data necessary for each service to function:

ServiceWhat They ProcessPurpose
Google Gemini AIPhotos, prompts, and chat messagesAI analysis, chat responses, and image editing
Cloudflare R2Photos and edited imagesSecure image storage and delivery
Google Cloud PlatformApp data and server logsDatabase hosting and infrastructure
FirebaseEmail, device tokens, and analytics eventsAuthentication, push notifications, and usage analytics
ReplicateThumbnail imagesBackground removal for sticker-style thumbnails
RevenueCatAnonymous user identifierSubscription and in-app purchase management
AirbridgeLink tokens (no personal data)Attribution tracking for shared voting links

Important note about AI processing: When you submit photos or prompts to our AI features, this data is sent to Google's Gemini API for processing. Google's API data usage policies govern how they handle this data. We use the paid API tier, which means your inputs are not used by Google to train their general models. Please refer to Google's API Terms of Service for full details.

Each third-party service is governed by their own privacy policies. We encourage you to review them.


5. Data Storage and Security

We implement appropriate technical and organizational measures to protect your personal data:

  • All data is transmitted using encryption (HTTPS/TLS)
  • Image access uses time-limited secure URLs that expire after 1 hour
  • Authentication is verified on every API request
  • Rate limiting protects against abuse and unauthorized access
  • Access to production systems is restricted to authorized personnel only

Data locations: Your data is primarily stored on Google Cloud Platform (United States) and Cloudflare (distributed globally via their CDN network).

While we strive to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.


6. Data Retention

We retain your data only as long as necessary to provide the Service and fulfill the purposes described in this policy:

Data TypeRetention Period
Account and profile informationUntil you delete your account
Photos and AI analysis resultsUntil you delete the analysis or your account
Chat and editing historyUntil you delete your account
Push notification history90 days
Voting data (votes, comments, stats)Until you permanently delete the voting link or your account
Server logs30 days
Attribution data90 days

When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are legally required to retain certain information.


7. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal data. We honor these rights for all users regardless of location where technically feasible:

Access and Portability

You can request a copy of your personal data at any time through the app or by contacting us.

Deletion

You can delete your account at any time through the app. This permanently removes your profile, all analyses, uploaded photos, chat history, edit history, voting links, and notifications.

Delete Voting Data

You can permanently delete all voting data for any of your shared links, including all votes, comments, and statistics. This action is irreversible.

Notification Controls

You can choose which types of push notifications you receive or disable them entirely in the app settings.

Correction

You can update your account information (display name, profile picture) at any time through the app.

Opt Out of Analytics

You can opt out of non-essential analytics data collection by contacting us.


8. California Residents — Your CCPA/CPRA Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: You can request details about the categories and specific pieces of personal information we have collected about you, the sources of that data, our business purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: You can request deletion of the personal information we have collected from you, subject to certain exceptions.
  • Right to Correct: You can request correction of inaccurate personal information.
  • Right to Opt Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising. There is no need to opt out because we do not engage in these practices.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.

Categories of personal information collected: Identifiers (email, display name), internet or electronic network activity information (usage data, device information), and audio/visual information (photos you upload).

How to exercise your rights: Contact us at thegoodtayeb23@gmail.com or through the app. We will verify your identity before fulfilling any request and respond within 45 days.


9. European Economic Area and United Kingdom Residents — Your GDPR Rights

If you are located in the EEA or UK, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of Access: Obtain confirmation of whether we process your personal data and request a copy.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your personal data in certain circumstances.
  • Right to Restriction: Request that we restrict processing of your data in certain circumstances.
  • Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or for direct marketing.
  • Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: File a complaint with your local data protection authority.

Data Controller: Picky is the data controller for the personal data processed through the Service.

International Transfers: Your data may be transferred to and processed in the United States. We rely on standard contractual clauses and other appropriate safeguards to ensure your data is protected during such transfers.

To exercise any of these rights, contact us at thegoodtayeb23@gmail.com. We will respond within 30 days.


10. Children's Privacy

Picky is not directed at children under the age of 13 (or under 16 in the EEA/UK where applicable). We do not knowingly collect personal information from children under these ages.

If we become aware that we have collected personal data from a child under the relevant age without appropriate parental consent, we will take immediate steps to delete that information.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at thegoodtayeb23@gmail.com and we will promptly delete it.


11. International Data Transfers

Picky is operated from the United States. If you are accessing the Service from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States and other countries where our service providers operate.

By using the Service, you consent to the transfer of your information to these countries, which may have different data protection laws than your country of residence.

For EEA/UK users, we ensure appropriate safeguards are in place for international transfers as described in Section 9.


12. Do Not Track Signals

Some browsers transmit “Do Not Track” (DNT) signals. Because there is no common industry standard for interpreting DNT signals, the Service does not currently respond to DNT signals. We will update this policy if a standard is established.


13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you through one or more of the following methods:

  • A prominent notice within the app
  • A push notification (if you have notifications enabled)
  • An update to the “Last Updated” date at the top of this policy

We encourage you to review this policy periodically. Your continued use of the Service after any changes constitutes acceptance of the updated policy.


14. Contact Us

If you have questions about this Privacy Policy, want to exercise your data rights, or have concerns about how we handle your information, contact us at:

Email: thegoodtayeb23@gmail.com

We aim to respond to all inquiries within 30 days.