Last updated: February 3, 2023

Privacy Policy

This Privacy Policy ("Privacy Policy") governs the collection, use, and processing of personal data of users (the "User" or "You") by Genova AI Technologies AG, (the "Company," "We," or "Us"), when the User utilizes our mobile application (the "App") or interacts with the Company in any other manner. This Policy is presented in compliance with the General Data Protection Regulation (GDPR) and any other relevant local laws as amended or replaced (collectively referred to as "Applicable Privacy Laws").

Pursuant to California Civil Code Section 1798.83, residents of the State of California may request certain information regarding the disclosure of personal information to third parties for direct marketing purposes. Additional information for California consumers can be found in Section 12 of this Privacy Policy.

1. Data Controller and Data Protection Officer

The Data Controller responsible for the processing of personal data is Genova AI Technologies AG, with a registered office located at Seestrasse 153A, 8802 Kilchberg, Switzerland, VAT UID: CHE-401.837.824. Any inquiries or requests regarding the processing of personal data should be directed to [email protected].

For matters related to the processing of personal data or this Privacy Policy, the Data Protection Officer can be reached by sending an email to [email protected].

2. Face data processing

This section of our privacy policy specifically addresses the collection and handling of face data, which is considered a sensitive data category. We understand the concerns that users may have regarding the use of their facial information, and we are committed to protecting the privacy and security of our users' face data. In this section, we will outline the reasons why we collect face data, how we collect it, and how we use it to provide our services to our users. We will also explain the measures we take to protect users' face data and how users can control and manage their own face data.

  1. Legal Basis: The processing of face data is necessary for the execution of our contractual obligations as outlined in Article 6(1)(b) of the General Data Protection Regulation (GDPR).
  2. Face data categories: Our app processes three main categories of face data:
    1. User input images. These are images uploaded by the user (including images of your face).
    2. User AI (artificial intelligence) model. This is a personalized AI model that the user can train with their input images in order to generate output images.
    3. Avatar images. These are the AI avatar images that users can generate using their personal AI model. AI avatar images are images that look like you, but that are newly generated using machine learning, meaning that, for example, they may have very different styles or backgrounds than the images you originally uploaded. Since we generate the AI avatar images automatically, there can sometimes be AI avatars that do not closely resemble you.
  3. Processing purposes: The app stores and processes face data, including all specified categories of face data, for the only purpose of generating AI avatars for users.
    1. Input image: Regarding user input images, we process them for the purpose of training your personal AI model that we will use for image generation. This is required because we need to teach the AI what your face looks so that you can use it to generate avatar images that look like you.
    2. AI model: Regarding the user AI model, we create and use it for the purpose of letting users generate AI avatar images of themselves. We need to train a custom AI model for you as a user so that the avatar images look like you.
    3. Avatar images: Regarding the user’s avatar images, we process them only for the purpose of making them available to users in the app.
  4. Storage purposes:
    1. Input image storage: We store user input images for a limited time frame for the purpose of optimizing the quality of the avatar images that we serve users. To optimize the avatar image quality, we continuously refine users’ personal AI model, which requires that we retrain it from scratch using your images.
    2. AI model storage: We store your personal AI avatar model for a limited time frame for the purpose of allowing you to generate new avatar images of yourself so long as you want to use the app.
    3. Avatar image storage: We store your avatar images for the purpose of making them available to you in a gallery so that you can access them, store them and share them so long as you use the app.
  5. Data deletion time frames:
    1. Input image deletion: We automatically delete the user’s input images 90 days after the user last uses the app. This allows us to ensure that we can offer users who may still want to use the app to get the highest quality avatars possible since we can continuously improve their model. We wait for 90 days because we assume that users who have last used the app within that time period may still be interested in generating more images, whereas users who have not used the app in 90 days will not want to use the app again.
    2. AI model deletion: We automatically delete the user’s AI model 90 days after the user last used the app. This allows users to continue generating avatars. We wait for 90 days because we assume that users who just recently used the app will want to do so again, whereas users the app to do so again, whereas users who have not used the app in 90 days will not to want to use the app again.
    3. Avatar image deletion: We automatically delete the user’s avatar images 6 months (182 days) after the user last used the app. We store avatar images for longer than user input images or the user AI model to ensure that users can keep accessing the avatar photos that they paid for. We assume that a user who has not opened the app in 6 months is no longer interested in retrieving the photos.
  6. Access consent: In order to be able to generate AI avatars the app needs access to your photo library and to your camera, but this access will only be granted upon receipt of your explicit consent, which will be requested via a prompt on your mobile device.
  7. Deletion request: Users may at any time request to have any face data deleted earlier than the above timeframes by contacting [email protected]. We will promptly handle such requests.
  8. Third party face data sharing with AWS: We share user face data with only one third party, our cloud computing service provider, Amazon Web Services (AWS), which processes and stores user input images, user AI models and AI avatars for us. Our AWS servers are located in Europe.
    1. Justification: The legal basis for data processing and storage by AWS is Article 6(1)(f) of GDPR. The legitimate interest is to ensure error-free functioning of the app and not to operate a cloud computing service ourselves.
    2. Equal protection: AWS offers equal protection of user data as stated in this privacy policy. This includes the time frames with which AWS deletes user face data. We have set up automated systems to ensure that data that we store with AWS is deleted according to the terms specified in this policy, and AWS is contractually obliged to process and delete data according to these systems.
    3. AWS storage purposes: The reasons we temporarily store face data with AWS are identical to the ones specified in paragraph 2.4:
      1. Input image storage: We store user input images with AWS for a limited time frame for the purpose of optimizing the quality of the avatar images that we serve users. To optimize the avatar image quality, we continuously refine users’ personal AI model, which requires that we retrain it from scratch using your images.
      2. AI model storage: We store your personal AI avatar model for a limited time frame for the purpose of allowing you to generate new avatar images of yourself so long as you want to use the app.
      3. Avatar image storage: We store your avatar images for the purpose of making them available to you in a gallery so that you can access them, store them and share them so long as you use the app.
    4. Data deletion time frames and justification: We have set up systems to automatically delete face data from our AWS servers. The length and justification of those time frames is identical to those specified in paragraph 2.5:
      1. Input image deletion: We automatically delete the user’s input images 90 days after the user last uses the app. This allows us to ensure that we can offer users who may still want to use the app to get the highest quality avatars possible since we can continuously improve their model. We wait for 90 days because we assume that users who have last used the app within that time period may still be interested in generating more images, whereas users who have not used the app in 90 days will not want to use the app again.
      2. AI model deletion: We automatically delete the user’s AI model 90 days after the user last used the app. This allows users to continue generating avatars. We wait for 90 days because we assume that users who just recently used the app will want to do so again, whereas users the app to do so again, whereas users who have not used the app in 90 days will not to want to use the app again.
      3. Avatar image deletion: We automatically delete the user’s avatar images 6 months (182 days) after the user last used the app. We store avatar images for longer than user input images or the user AI model to ensure that users can keep accessing the avatar photos that they paid for. We assume that a user who has not opened the app in 6 months is no longer interested in retrieving the photos.
    5. Additional information on AWS privacy handling: For more information on how AWS handles user privacy, please refer to the AWS Privacy Policy: https://aws.amazon.com/de/privacy/?nc1=f_pr
  9. Prohibited uses of face data: Regarding the use of your face images and AI avatars, it is important to note the following:
    1. We do not share or transfer user photos or avatars to third parties except for temporarily storing them on our secure cloud provider, Amazon Web Services, for online processing and then deleting them in accordance with this Privacy Policy.
    2. We do not utilize users' photos or avatars for authentication, advertising, marketing, or targeted advertising purposes. The technologies implemented in the app do not allow unique identification or authentication of a single user starting from the images uploaded to the app or from the AI avatars generated by the app, nor is it our intention to train the technologies to do so.
    3. We do not use users’ photos or Avatars to create a user profile or assist in identifying anonymous users or reconstructing user profiles.
    4. We do not transfer, share, sell, or provide users’ photos or Avatars to any advertising platforms, analytics providers, data brokers, information resellers, or any other third party.

3. Personal Data Categories, Processing Purposes and Legal Justifications

The company collects, uses and processes certain personal information for specific purposes and in accordance with applicable laws and regulations. It is important to note that the classification of personal data may vary depending on the jurisdiction in which it is collected.