Unempty Privacy Policy
Summary
This table is a plain-language overview. The full sections below control if there is any difference.
| Question | Short answer |
|---|---|
| What is Unempty? | An iPhone app that turns a photo of a room into a virtually staged, restyled or decluttered version using AI. |
| Do I need an account? | No. The app creates an anonymous account on your device. Sign in with Apple is optional. |
| What do you collect? | Your room photos and the text you type about them, the results we generate, an anonymous account id, purchase records (from Apple via RevenueCat), and app-usage events (which screens you use, not the pictures). |
| Where does my photo go? | To our servers (Supabase, hosted in Ireland, EU) and, after you tap Allow on the consent sheet, to Google's Gemini API, which generates the image. |
| Does Google train its AI on my photos? | No. We use Google's paid API. Google states it does not use paid-API prompts or responses to improve its products. Google keeps a short-term log for abuse detection. |
| Do you train AI on my photos? | No. |
| Do you sell my data or show ads? | No, never. No advertising, no data sale, no cross-app tracking. |
| How long do you keep my photos? | Originals and results you do not keep in a project: 30 days, then deleted automatically. Originals and results in a project: until you delete the project or your account. |
| How do I delete everything? | Settings → Delete account & data. Everything is purged from our systems within 24 hours. |
| Who can I contact? | [FILL: privacy contact email]. EU/UK residents can also contact our representative [FILL / LAWYER: see §12]. |
| Minimum age | 13, or 16 where your country requires it (see §10). |
1. Who we are
Photoreal3d LLC ("Photoreal3d", "we") operates the Unempty iOS app and the website unempty.app. We are the data controller for the personal data described in this policy (under GDPR and UK GDPR terminology) and the "business" under the California Consumer Privacy Act.
- Registered office: [FILL: RAKEZ address, Ras Al Khaimah, UAE]
- Privacy contact: [FILL: email]
- [LAWYER] Data Protection Officer: we believe no DPO is mandatory under GDPR Art. 37 (no large-scale monitoring or special-category processing), under UAE PDPL (Art. 10 requires a DPO for high-risk / large-scale processing) or under KSA PDPL. Confirm, and decide whether to appoint one voluntarily.
- [LAWYER] EU representative (GDPR Art. 27) and UK representative (UK GDPR Art. 27): we are established outside the EU/UK and offer the app to people there. Unless the "occasional processing" exemption applies, we must name a representative here. See §12.
2. What we collect, and where it comes from
We collect only what the app needs to work. We never ask for your name, phone number or address.
| Category | What exactly | Source | Why |
|---|---|---|---|
| Account identifiers | A random account id created on first launch (anonymous account); if you use Sign in with Apple: the Apple user identifier and, if you choose to share it, your name and email or Apple's private relay email address; your app language | Your device; Apple | To keep your credits and projects together; to restore purchases; to give you the one-time sign-in credits |
| Sign-in bonus record | A one-way hash (SHA-256) of your Apple user identifier | Derived on our server | To grant the +2 free credits once per Apple ID. This hash is kept after you delete your account so the bonus cannot be claimed again (see §7). [LAWYER] confirm legitimate-interest basis and disclosure wording |
| Room photos | The photo you choose or take, resized to at most 2048 px on the long edge. Location (GPS) metadata is removed on your device before upload. Other camera metadata may remain | You (Photos picker or in-app camera) | To generate the result |
| Your inputs | Detected room type (which you can change), the mode (Stage / Restyle / Declutter / Refine), the style you pick, optional notes (up to 300 characters), Refine instructions | You; our room-type detection | To build the instruction for the AI model |
| Generated results | The images we generate, their versions, and technical scores (the "structure check" comparing the result with your photo) | Generated by us via Google | To show, save, refine and export your results |
| Job records | For each generation: time, mode, style, your notes, which AI model was used, prompt version, cost, duration, structure score, error messages | Our servers | To run the queue, charge credits correctly, refund failed jobs, and measure quality |
| Credits and purchases | Credit ledger (grants and debits), your plan, renewal date, RevenueCat's app-user id, Apple transaction/receipt identifiers. We never see your card number. | Apple (via RevenueCat) | To deliver what you bought, restore purchases, handle refunds |
| Reports | If you tap Report on a result: the job id and the reason you select | You | To review problems and keep bad results out of our quality tests |
| Usage analytics | App events such as install, first result, paywall viewed, purchase, refine, export; app version, device model, OS version, country/language; an analytics identifier. Never your photos or results. | Your device (PostHog SDK) | To understand which steps work and which do not |
| Ad attribution | If you installed the app after tapping an Apple Search Ads ad, an Apple "AdServices" attribution token | Apple | To know which campaigns work. This is not cross-app tracking; no advertising identifier (IDFA) is used and no App Tracking Transparency prompt is needed [LAWYER] confirm |
| Crash and diagnostics | Crash reports and performance logs from Apple (only if you opted in to share analytics with developers in iOS settings); [FILL/OWNER: Sentry crash reports if T-056 ships — include stack traces, device model, OS, app version, no photos] | Apple; the app | To fix bugs |
| Server logs | IP address, request time, endpoint, response code; a per-device identifier used to rate-limit anonymous sign-ups | Your device / network | Security, abuse prevention, rate limiting |
| Support | Whatever you send us by email, and our replies | You | To help you |
| Launch list (website) | The email address you type into “Notify me” on unempty.app, the plan you had selected, and the time | You | To send one email when the app is on the App Store. Nothing else; reply to unsubscribe |
We do not collect: your photo library (we use Apple's out-of-process picker, so the app never sees photos you did not pick), your contacts, precise or coarse location, your device's advertising identifier, or any health, financial or biometric data.
3. How we use your data, and on what legal basis
| Use | Data | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Creating and running your account, generating images, keeping projects and versions | Account, photos, inputs, results, job records | Contract (Art. 6(1)(b)) — this is the service you asked for |
| Sending your photo and inputs to Google to generate the image | Photos, inputs | Consent (Art. 6(1)(a)) given on the in-app consent sheet before your first upload; you can withdraw it in Settings (§5). [LAWYER] Apple requires explicit permission; under GDPR the sharing is also necessary for the contract — confirm which basis we state, because "consent" implies the service stops when withdrawn (which is what the app does: generation is blocked, browsing is not) |
| Charging credits, delivering subscriptions and packs, restoring purchases | Purchases, credit ledger | Contract |
| Preventing abuse: rate limits, one-free-grant-per-account, blocked prompts, safety filters | Server logs, device identifier, sign-in bonus hash | Legitimate interest (Art. 6(1)(f)) in keeping the service safe and fair |
| Product analytics | Usage analytics | [LAWYER — decision A2 in apple-review-checklist.md] Either legitimate interest (first-party, no cross-app tracking, no photos) or consent via a Settings toggle. For EU/UK users ePrivacy rules on storing identifiers on the device may require opt-in. The draft assumes a "Share usage analytics" toggle, on by default, disclosed in onboarding, off = no events — confirm or change |
| Ad campaign measurement | AdServices token | Legitimate interest [LAWYER] |
| Fixing crashes | Crash data | Legitimate interest |
| Answering support and reports; removing content that breaks our Terms | Support, reports, results | Legitimate interest; legal obligation where a law requires removal |
| Keeping accounting and tax records | Purchase records (not photos) | Legal obligation (Art. 6(1)(c)) |
What we never do: train or fine-tune AI models on your photos or results; use your rooms in our marketing or screenshots (our marketing images come from rooms we photographed ourselves); sell or rent your data; show advertising; build profiles for advertising; share your photos with anyone except the processors in §4.
Quality testing. Our internal quality test set ("eval set") contains only photos we took ourselves. We do not add users' photos or results to it. If we ever want to, we will ask you separately with a clear opt-in that is not bundled with anything else. (Spec 001 FR-20 says reported results are "excluded from any future eval set"; that wording must not be read as permission to include unreported ones — flagged as item A6 in apple-review-checklist.md.)
4. Who we share data with (processors)
We share data only with the companies below, each of which processes it on our instructions under a data-processing agreement. None of them may use your data for their own purposes except as stated.
| Processor | What they receive | Purpose | Where | Their commitments (as read on the date shown) |
|---|---|---|---|---|
| Google LLC — Gemini API (Gemini 3.1 Flash Image, Gemini 3 Pro Image and Gemini Flash for room-type detection and quality judging) | Your resized, GPS-stripped photo; the intermediate decluttered image when Stage runs on a furnished room; the previous result when you Refine; detected room type; mode; style; your notes; our prompt text. Not your account id, email or name | Generating the image; detecting room type; checking that the structure was preserved | "Any country in which Google or its agents maintain facilities" (Google's words), which includes the United States | Paid Services: "Google doesn't use your prompts (including associated system instructions, cached content, and files such as images, videos, or documents) or responses to improve our products." "Google logs prompts and responses for a limited period of time, solely for detecting and preventing violations of the Prohibited Use Policy to maintain the safety and security of the Services." — Gemini API Additional Terms of Service, last updated 2026-04-28. [LAWYER] confirm that our account is on the paid tier at launch (the unpaid tier *does* allow Google to use content "to provide, improve, and develop Google products … and machine learning technologies" and human review), confirm the length of the abuse log, and confirm the transfer mechanism (§6) |
| Supabase, Inc. | Everything in §2 except analytics and crash data: account rows, photos (bucket originals), results (results), exports (exports), job records, credit ledger, reports, server logs |
Database, file storage, authentication and our server-side functions | EU — AWS region eu-west-1 (Ireland) (our project unempty, docs/ops/environments.md). Supabase's own staff and sub-processors may access data from other countries for support |
Acts "primarily as a processor … on behalf of and under the instructions of the relevant customer" (Supabase Privacy Notice, read 2026-09-05). DPA with EU SCCs Module Two, UK Addendum and Swiss Addendum, accepted with the service agreement (Supabase DPA, last updated 2026-08-01). Sub-processor list: PDF updated 2026-06-01 [unverified — PDF not read] |
| RevenueCat, Inc. | RevenueCat app-user id (a random id we assign, or your account id), Apple receipt / transaction data, device type and OS, last-seen time, your plan and renewal state. Not your photos | Validating purchases with Apple, managing entitlements, restoring purchases, sending purchase events to our server | United States ("Customer data sent to RevenueCat from around the world is sent to AWS data centers located in the United States") | "We are not the Data Controllers of this data and act as Data Processors." — RevenueCat Privacy Policy, last updated June 2026 |
| PostHog, Inc. | Usage analytics events (§2), analytics identifier, device model, OS, app version, locale. Not your photos or results | Product analytics | [OWNER decision, FILL] PostHog offers US hosting or EU hosting in Germany. This draft assumes EU (Germany). Choose EU when creating the project (T-046) | DPA available on request (privacy@posthog.com); no sale of data (PostHog Privacy Policy, read 2026-09-05, no visible last-updated date) |
| Apple Inc. | Purchases are made through your Apple account; Sign in with Apple identity; AdServices attribution token; crash/diagnostic data if you opted in with Apple | Payments, sign-in, attribution, diagnostics | Per Apple's own privacy policy (apple.com/legal/privacy) | Apple is an independent controller for your Apple account and payments; Apple's terms govern refunds and billing |
| [FILL/OWNER] Sentry (Functional Software, Inc.) | Crash reports: stack traces, device model, OS, app version, a random installation id. Not photos | Crash reporting (planned in T-056) | [FILL] US or EU data residency — choose EU | [unverified] Add only if T-056 ships before launch; otherwise delete this row |
| Netlify, Inc. | The launch-list email address and selected plan from the website form | Hosting the website and storing form submissions | United States | Netlify Privacy Policy and DPA [unverified — not read yet] |
| [FILL/OWNER] Email provider for support@ | Your support emails | Support | [FILL] | [FILL] |
We do not use any advertising SDK, social-media SDK or data broker.
Authorities: we may disclose data if a law, court order or lawful request obliges us to, or to protect the safety of a person or the integrity of the service. We will tell you when the law lets us.
Business transfer: if Photoreal3d LLC is sold or merges, your data may move to the new owner under this same policy; we will notify you in the app before that happens.
5. AI processing and your consent
Before your first upload, the app shows a consent sheet that names Google, lists exactly what is sent (photo, room type, notes), states the purpose and links to this policy. Nothing leaves your device until you tap Allow. If you tap Not now, you can still browse the app but cannot generate images.
Withdrawing consent. Settings → AI processing → Off. Generation stops until you turn it back on; nothing already generated is affected. [OWNER/spec] This toggle is proposed in spec 001 §8 Q12 and item A4 of the review checklist; if it does not ship in T-043, change this paragraph to "email us to withdraw consent" before publishing.
What the AI does with your photo. Google's model reads your photo and our instructions and returns a new image. Google's paid API does not use your content to train its models (§4). Google keeps a short-term log for abuse detection. Our server keeps the result and the technical scores described in §2.
Provenance marks. Every image Google generates carries an invisible SynthID watermark (Google Gemini API documentation, read 2026-09-05). We never remove it. Free-tier results also carry a small visible "Made with Unempty AI" mark; listing exports carry a visible "Virtually staged" label by default. Together these are how we mark AI-generated images as required by the EU AI Act (Regulation (EU) 2024/1689) Art. 50(2), applicable from 2 August 2026: machine-readable in the pixels, and visible on anything meant for a listing. Marking is not personal data about you and is never used to identify you; it says of the image itself that it was generated by AI. Our Terms §6 explain what it means for you when you publish a result.
Automated decisions. The app makes two automated calls that affect what you see: it proposes a room type and mode (you can change both), and it runs a structure check that may reject a result (you are not charged and can retry). Neither produces legal or similarly significant effects on you (GDPR Art. 22). [LAWYER] confirm.
6. International transfers
Your data is stored in Ireland (Supabase). It is transferred outside the EU/UK/UAE/KSA/Turkey when:
- Google processes your photo (Google may use facilities in any country, including the US);
- RevenueCat processes purchase data (US);
- Supabase support staff or sub-processors access data from outside the EU;
- [FILL] Sentry / support email provider, if outside the EU.
Safeguards we rely on [LAWYER — confirm each]:
| Destination | Mechanism |
|---|---|
| EU/UK → Google (US) | Google's data-processing terms with EU Standard Contractual Clauses; Google LLC's certification under the EU-U.S. Data Privacy Framework and UK Extension [unverified — could not read Google's DPF page on 2026-09-05; check dataprivacyframework.gov list] |
| EU/UK → Supabase | Supabase DPA: EU SCCs Module Two (controller-to-processor), UK Addendum, Swiss Addendum (DPA dated 2026-08-01) |
| EU/UK → RevenueCat (US) | RevenueCat DPA / SCCs [unverified — DPA not read] |
| EU/UK → PostHog | EU hosting in Germany if chosen; otherwise SCCs via PostHog DPA [unverified] |
| UAE → outside UAE | UAE PDPL Arts. 22–23: transfer to countries with adequate protection, or with appropriate safeguards / contract, or with the individual's consent. The Data Office's adequacy list and executive regulations status [unverified as of 2026-09-05] |
| KSA residents' data → outside KSA | KSA PDPL Art. 29 and the Transfer Regulations (2024): adequacy or "appropriate safeguards" (standard contractual clauses, binding rules), plus a transfer-risk assessment where required [LAWYER] |
| Turkey → abroad | KVKK Art. 9 (as amended 2024-03-02): adequacy decision, or a standard contract notified to the Personal Data Protection Board within 5 business days of signature, or explicit consent in limited cases. [LAWYER] We are a foreign controller receiving data from Turkey; determine whether Art. 9 applies to the user's own upload to us and, if so, which mechanism |
| US (California) users | No transfer restriction; disclosure in §11 |
Because Photoreal3d LLC is itself in the UAE, the transfer from the EU to us (the controller) also needs a mechanism. [LAWYER] Options: Art. 49(1)(b) (necessary for the contract with the user) for the core service, or SCCs are not available controller-to-self; confirm the position and the wording. Note that the data itself sits in Ireland and we access it from the UAE.
7. How long we keep data
| Data | Retention | Notes |
|---|---|---|
| Original photo not in a project | 30 days after upload, then deleted automatically: a server function runs every 15 minutes and removes the expired files | assets.expires_at set on upload; the retention function deletes the files, the daily job (03:17 UTC) only sweeps records whose file is already gone |
| Original photo and results in a project | Until you delete the project (Delete room in the app calls our delete-project function) or your account |
|
| Generated results, exports | Results in a project: same as the project. Results not in a project: 30 days after generation, like originals. Exports: until you delete the project or your account | assets.expires_at is set for results without a project too |
| Job records (mode, style, notes, model, scores, cost) | Kept while your account exists; deleted with the account | Notes text is inside the job record |
| Credit ledger, entitlements | Kept while your account exists; purchase totals needed for accounting are kept in aggregated or transaction-id form for [FILL: 5 / 7 / 10] years [LAWYER — UAE Commercial Companies Law / tax record-keeping period; VAT records; EU member-state rules] | |
| Sign-in bonus hash | Kept indefinitely, also after account deletion — it is the only way to keep the one-time bonus honest | Cannot be reversed to your Apple identifier by us |
| Reports | Kept while your account exists, then deleted with it | The reports row references your account with on delete cascade, so deleting the account removes the report as well (verified in the database schema on 2026-09-10). Nothing about a report survives except the fact that the reported job is excluded from our quality tests |
| Usage analytics | [FILL: PostHog retention, proposed 12 months] then deleted or aggregated. On account deletion your PostHog person and its events are deleted (see below) | |
| Crash data | [FILL: 90 days proposed] | |
| Server logs (IP) | [FILL: Supabase default log retention — Pro plan 7 days [unverified]] | |
| Support emails | [FILL: 24 months proposed] | |
| Launch-list emails | Until the launch email is sent, then deleted; earlier if you ask | Stored in Netlify Forms |
| Google's abuse log | "Limited period" per Google's terms; length not published [unverified] | Outside our control |
| RevenueCat transaction records | RevenueCat retains for the life of our account; on account deletion we delete your RevenueCat customer record through the RevenueCat API | Apple keeps its own purchase history (next row) |
| Apple purchase history | Held by Apple under Apple's policy | Outside our control |
Account deletion. Settings → Delete account & data calls our delete-account function, which removes your account rows, projects, jobs, credit ledger, reports and every stored file (originals, results, exports) within 24 hours, deletes your RevenueCat customer record and your PostHog person together with its events, and deletes your authentication user. If a generation is still running when you ask, the deletion completes automatically as soon as it has finished. It works for anonymous accounts too. Deleting the app alone does not delete server data; an anonymous account you never delete keeps its data until you delete it [LAWYER/OWNER] — consider an inactivity rule (e.g. purge anonymous accounts with no activity for 12 months) and state it here. Unused credits and active subscriptions are forfeited on deletion; cancel the subscription with Apple first, or it will keep renewing (Terms §8).
8. Your rights
You can exercise any right below from Settings (delete, withdraw AI consent, analytics toggle) or by emailing [FILL: privacy email]. We answer within one month (GDPR/UK GDPR; extendable by two months for complex requests), 45 days (CCPA, extendable once), 30 days (Turkey KVKK Art. 13), or the shorter period local law sets. We may ask you to prove you control the account (for anonymous accounts, this means making the request from inside the app). We do not charge for requests unless they are manifestly unfounded or excessive.
Everyone: access a copy of your data; correct it; delete it; object to or restrict processing based on legitimate interest; withdraw consent at any time (without affecting earlier processing); receive your photos and results in a portable format (they are already saved to your Photos when you tap Save); complain to a supervisory authority; not be discriminated against for exercising these rights.
EU/EEA (GDPR) — rights under Arts. 15–22. Supervisory authority: the authority in your member state (list: edpb.europa.eu), or the Irish Data Protection Commission where data is hosted [LAWYER — lead authority does not apply to a non-EU controller; users complain to their local authority]. Our EU representative: [FILL / LAWYER, §12].
United Kingdom (UK GDPR / Data Protection Act 2018) — same rights; complaints to the Information Commissioner's Office (ico.org.uk). Our UK representative: [FILL / LAWYER].
California (CCPA/CPRA) — see §11.
United Arab Emirates (Federal Decree-Law No. 45 of 2021, PDPL) — rights to access, correction, erasure, restriction, objection to automated decisions, data portability and to withdraw consent; complaints to the UAE Data Office. [LAWYER] confirm the PDPL applies to Photoreal3d LLC as a RAKEZ (non-financial free zone) entity — the law excludes only DIFC and ADGM regimes — and whether its executive regulations are in force (not confirmed as of 2026-09-05 [unverified]).
Saudi Arabia (PDPL, Royal Decree M/19 as amended by M/148; in force 2023-09-14, grace period ended 2024-09-14) — the law applies to "processing of personal data related to individuals residing in KSA by any means by any entity outside KSA" (DLA Piper summary, updated 2026-02-11). Rights to be informed, access, obtain a copy, correction, destruction; complaints to SDAIA. [LAWYER] confirm whether registration on SDAIA's National Data Governance Platform or a local representative is required for a foreign controller, and the consent wording needed for our processing.
Turkey (Law No. 6698, KVKK) — rights under Art. 11: learn whether your data is processed, request information, learn the purpose, know the recipients in Turkey and abroad, request correction or erasure, object to results produced by automated analysis, claim compensation for unlawful processing. Requests per the Communiqué on Application Procedures (in writing or via a method the Board accepts). [LAWYER/OWNER] (a) A Turkish-language information notice ("aydınlatma metni") meeting Art. 10 must be shown to Turkish users — the TR localisation of this policy should be reviewed for that; (b) determine whether we must register in VERBIS via a Turkish representative (Art. 16) or fall under an exemption.
Canada (PIPEDA) — rights of access and correction; complaints to the Office of the Privacy Commissioner. [LAWYER] Quebec Law 25 additional requirements (privacy officer named, privacy impact assessment for transfers outside Quebec) [unverified].
GCC other (Qatar, Kuwait, Bahrain, Oman) — Qatar Law No. 13 of 2016, Bahrain PDPL Law No. 30 of 2018, Oman Royal Decree 6/2022, Kuwait CITRA regulations [unverified, not researched]. [LAWYER] decide whether the general rights section suffices at launch.
9. Security
- All traffic uses HTTPS/TLS. Photos are uploaded to a private bucket through a short-lived signed URL tied to your session.
- The app never contains AI-provider or database service keys; every generation goes through our server with your authenticated session.
- Row-level security in our database means each account can read only its own rows.
- GPS metadata is stripped on your device before upload.
- Access to production data is limited to [FILL: number] named people at Photoreal3d LLC with two-factor authentication.
- If a breach affecting you occurs, we will notify the competent authority within 72 hours (GDPR/UK GDPR Art. 33), the UAE Data Office and SDAIA within the periods they set [LAWYER] (KSA: 72 hours [unverified]), and you without undue delay where the risk to you is high.
10. Children
Unempty is not directed at children. You must be at least 13, and at least 16 if you live in an EU/EEA country that has kept the GDPR default (GDPR Art. 8(1): lawful from 16; member states may lower it to no less than 13). The UK sets 13 (Data Protection Act 2018 s. 9 [unverified today — ICO page not reachable]). [LAWYER] provide the per-country table for the EU launch storefronts (DE 16, FR 15, ES 14, IT 14, PT 13 — from memory [unverified]) and confirm the ages for UAE, KSA and Turkey (KVKK has no specific digital consent age; Turkish Civil Code majority is 18 [unverified]). If we learn we hold data of a child below the applicable age without a parent's consent, we delete it; email [FILL] to tell us.
We do not knowingly sell or share the personal information of anyone under 16 (CCPA).
11. California privacy notice (CCPA/CPRA)
[LAWYER] The CCPA applies to for-profit businesses that "have a gross annual revenue of over $25 million", "buy, sell, or share the personal information of 100,000 or more California residents or households", or "derive 50% or more of their annual revenue from selling California residents' personal information" (California AG, page updated 2026-08-28). We expect to be below all three thresholds at launch; we provide this notice anyway and follow its rules voluntarily. Confirm and revisit when revenue or user counts approach the thresholds.
Categories of personal information collected in the last 12 months (Cal. Civ. Code §1798.140(v)): identifiers (account id, Apple user id, hashed Apple id, email if you share it, analytics id, IP address); commercial information (purchases, credits); internet or electronic activity (app usage events, server logs); audio/electronic/visual information (your room photos and the images we generate); inferences (detected room type — an inference about the photo, not about you). Sensitive personal information: none intended; a photo could incidentally show something sensitive — we use it only to generate your image.
Sources: you, your device, Apple, RevenueCat. Business purposes: those in §3. Disclosed to service providers: those in §4. Sold or shared for cross-context behavioural advertising: none, never. We do not use or disclose sensitive personal information for anything other than providing the service. Because we do not sell or share, no "Do Not Sell or Share My Personal Information" link is required [LAWYER] confirm; we honour Global Privacy Control signals to the extent they reach an app [LAWYER].
Your rights: know, delete, correct, opt out of sale/sharing (not applicable), limit use of sensitive PI (not applicable), non-discrimination. How to exercise: in-app (Settings) or [FILL: email]; an authorised agent may act for you with written permission. We respond within 45 days. Retention: §7.
Other US states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others): equivalent rights where those laws apply to us; thresholds not assessed [LAWYER].
12. Representatives and authorities
| Region | Our representative | Authority |
|---|---|---|
| EU/EEA | [FILL / LAWYER: name, address, email of the Art. 27 representative — or state the exemption relied on] | Your national data protection authority |
| UK | [FILL / LAWYER: UK Art. 27 representative] | Information Commissioner's Office |
| Turkey | [FILL / LAWYER: representative if VERBIS registration is required] | Kişisel Verileri Koruma Kurumu |
| UAE | Not required (we are established in the UAE) | UAE Data Office |
| KSA | [FILL / LAWYER] | SDAIA |
13. Changes to this policy
We will post changes here with a new effective date. For material changes (new processor, new purpose, new retention), the app shows a notice on next launch and, where the law requires it, asks for your consent again. Previous versions: [FILL: link to /privacy/archive on unempty.app].
14. Contact
Photoreal3d LLC, [FILL: address], RAKEZ, Ras Al Khaimah, United Arab Emirates. Email: [FILL: privacy email]. Support: [FILL: support email] / unempty.app/support.