Privacy Policy
Last updated: 2026-07-01
A plain-language summary — not a substitute for formal legal advice.
Who we are (data controller)
PlateRefresh is operated by Visual crafts, established in Lithuania (business code 307005405, VAT LT100020321317), registered address Povilo Matulionio g. 10, Akademija, LT-53348 Kauno r., Lithuania. We are the data controller for the personal data described below. For any privacy matter, contact privacy@platerefresh.com.
1. What we collect
- Account data — name, email, hashed password (Supabase Auth).
- Uploaded photos — the original phone photo and the AI-enhanced output, both stored on Vercel Blob.
- Usage — job records (tier, prompt, seed, credits used, timestamps) stored in Supabase Postgres.
- Payment data — Stripe customer ID and subscription status; we do not store full card numbers (Stripe handles those).
- Cookies — only the Supabase session cookie required to keep you signed in. No advertising or tracking cookies.
2. How we use it
- To run the AI pipeline on your photos.
- To bill you accurately and apply your credit balance.
- To respond to support requests.
- To prevent abuse and protect the Service.
- To showcase before/after results on PlateRefresh's own social media — anonymously by default (food only, your restaurant never named; naming requires your explicit opt-in). Controls: Account → Social sharing, plus a per-photo exclusion in the Gallery. Legal basis: legitimate interest for anonymous showcasing, consent for named posts.
We do not use your uploaded photos to train AI models. We do not sell your data to third parties. For the full detail on which AI models run, exactly what they receive, our no-training guarantee, and the EU AI Act Article 50 disclosure embedded in every output, see our AI usage & disclosure page.
3. Legal basis for processing (GDPR Art. 6)
- Providing the Service — running the AI pipeline on your photos and managing your account: performance of our contract with you (Art. 6(1)(b)).
- Billing, invoicing & tax records: performance of a contract (Art. 6(1)(b)) and compliance with a legal obligation (Art. 6(1)(c)).
- Security, fraud & abuse prevention, and keeping the Service reliable: our legitimate interests (Art. 6(1)(f)).
- Any marketing email we send: your consent (Art. 6(1)(a)), which you can withdraw at any time.
4. Third parties we share data with
- Supabase — authentication and Postgres database.
- Vercel — application hosting and Blob storage.
- fal.ai — AI image-edit endpoint. Your uploaded photo is sent here for processing; the output URL is fetched back and re-saved to our storage.
- Stripe — payment processing.
- Inngest — async job orchestration metadata only (no image content).
Each third party has its own privacy policy. We use only providers with current GDPR-compliant data-processing agreements. The full, authoritative list — with the data each one handles and its region — lives on our sub-processors page.
5. International data transfers
Some of our processors operate, or may process data, outside the European Economic Area (EEA) — in particular in the United States (for example Stripe, Vercel, and our AI-processing provider). Where personal data is transferred outside the EEA, we rely on an adequacy decision, the EU–US Data Privacy Framework, and/or the European Commission's Standard Contractual Clauses so that your data keeps an equivalent level of protection. You can ask us for details of the safeguards in place at privacy@platerefresh.com.
6. Data retention
- Uploaded photos and AI outputs: retained while your account is active.
- On account deletion: photos are removed within 30 days; account metadata may be retained up to 12 months for legal and audit reasons.
- Invoicing and payment records: retained for as long as Lithuanian tax and accounting law requires (currently up to 10 years).
7. Your rights
You can request access, correction, export (portability), restriction, objection, or deletion of your personal data, and withdraw any consent, at any time — email privacy@platerefresh.com. We do not make decisions with legal or similarly significant effects about you by solely automated means. CA residents have equivalent rights under CCPA; we do not sell or “share” personal data.
You also have the right to lodge a complaint with your local data protection authority. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI — vdai.lrv.lt).
8. Security
All traffic is encrypted in transit (HTTPS). Database access uses row-level security so you only ever see your own data. We do not store unencrypted credentials.
9. Children
The Service is not intended for users under 18. We do not knowingly collect data from minors.
10. Changes
We may update this policy; material changes will be notified by email at least 14 days in advance.
11. Contact
Privacy questions and data-subject requests: privacy@platerefresh.com. Given the nature and scale of our processing, we are not required to appoint a Data Protection Officer under GDPR Article 37; the address above reaches the person responsible for privacy at PlateRefresh.
See also our Terms of Service, our AI usage & disclosure page, and the full sub-processor list.