Google Play · Required disclosure

Privacy Policy

What Aishkin sends, what it keeps, and who else touches it on the way — written against what the app actually does.

Effective
7 September 2026
Last updated
27 September 2026
Application
Aishkin
Package ID
com.aiopenpocket.mobile
Developer
Ivan Golovachev
Contact
kwoutt1@gmail.com

01Who this policy covers

This policy explains what Ivan Golovachev (“we”, “us”) does with information when you use Aishkin (com.aiopenpocket.mobile), distributed through Google Play.

It covers the app and the backend service it talks to at aiopenpocket.fly.dev. It does not cover anything you reach by leaving the app — an advertiser’s page, or a third-party service you sign in to separately. Those are governed by their own policies.

On Android the app asks you for no access to your photos, camera, contacts or location. The one prompt you may see is on Android 9 and older: saving a result to your gallery there needs the old storage permission, asked when you press Save. A picture you attach comes through the Android system photo picker, which hands over only the image you chose, and a photo you take goes through your camera app, which hands back just that file. Without asking, the app uses the network (INTERNET, ACCESS_NETWORK_STATE), in-app purchases through Google Play (BILLING) and, for advertising, the advertising ID (AD_ID, see section 6); Google’s own libraries add a few more for background work. On iPhone the app asks only when you use the feature: photo access to show your recent photos in the attachment sheet, camera access to take a photo there, permission to save results to your library, and the system tracking prompt for ads. Nothing from your photos leaves the phone until you pick one and start a job with it.

The app is intended for users aged 13 and over. See section 14.

02Summary

The table uses the same categories as Google Play’s Data safety section, so you can compare it directly against our store listing.

Data Collected Shared Why
Prompts and images you submit Not stored Yes Sent to the AI provider that fulfils your request; not kept once it is done
Generated results No No Downloaded to your device; you choose whether to save them to your gallery
Results you report Only if you report No When you report a result as offensive, the picture, its prompt, the model and your note come to us so we can review it; see section 3
Email address Yes Processor It is your account — sign-in, support and receipts
Purchase and subscription history Yes Processor Entitlements, billing and refunds
Spark balance and job history Yes No Charging and refunding what you spend; which model ran and when, never the content
Advertising ID Yes Yes Serving and measuring ads
Crash logs and diagnostics Yes Yes Stability only: when the app crashes, the stack trace, device model, OS and app version go to Firebase Crashlytics and are kept for 90 days
App events Yes Yes Product only: a short list of moments — you signed in, a run started, a run finished or failed, you ran out of sparks — goes to Firebase Analytics, together with the model slug and the kind of media. We use it to see where people get stuck before their first result. Your prompts, your images, your e-mail and your account id are never part of it, and analytics data is not used to personalise ads
Location, contacts, camera, files No No No permission is requested for any of these; photo access on iPhone is optional, see section 1

“Processor” means the data goes to a provider that handles it on our instructions and may not use it for its own purposes. On the advertising row Google acts as an independent controller.

03Your prompts, images and results

We do not keep your prompts, the pictures you attach, or what the model produces — unless you report a result to us. But they do leave your device, and you should know exactly where they go.

A generation request travels from the app to our server at aiopenpocket.fly.dev, which forwards it to the AI provider that runs the model you selected. Today that provider is Replicate; some models Replicate offers run in turn on OpenAI or Google Cloud Vertex AI. The same path is used when the app picks a model for you or rewrites your prompt on request: the prompt goes to a text model run through Replicate. When you ask for style advice (“What suits me”), the photo you chose goes the same way to an OpenAI model run through Replicate, which looks at it and answers in words. The result comes back the same way and is written to the app’s own folder on your device.

On our side the request exists only while the job runs. We do not write your prompts or images to a database, do not attach them to your account, do not review them, and do not use them to train any model. We never sell them and never disclose them to advertisers.

What we cannot do is speak for the providers. Once a request reaches Replicate, OpenAI or Google, that provider handles it under its own terms, which may include holding it for a period to detect abuse. Their policies are linked in section 8. Do not send anything through the app that you would not be willing to hand to a third-party processor.

We do keep a plain record that a job ran: which model, and when. That line is what your spark balance is charged against, and it carries none of the content — no prompt, no image, no result. It is described with the rest of your account record in section 4.

The one exception is a report. If you use Report on a result, the app sends us that result’s picture (when it is an image), its prompt, the model that made it and the note you typed, so that we can review it. Nothing is sent until you press Send. We keep a report until we have reviewed it and closed it, and never longer than your account: deleting the account deletes your reports with it. Reports are read only by us and are not shared with advertisers or used to train any model.

Apart from reports we keep no copy of the content, so we cannot restore your history and cannot produce your prompts in response to a data request — from you or from anyone else. Results live on your device; saving one to your gallery is your choice, and deleting it is entirely in your hands.

04Your account and how you sign in

Sign-in is handled by Firebase Authentication. You can sign in with Google, with an email address and password, or — on iPhone — with Apple. We never see or hold a password: when you use one, Firebase checks it, and in every case it hands us a signed token carrying your verified email address. If you choose Apple’s “Hide My Email”, the address we receive is the private relay address Apple creates for you.

That email address is your account. Our server stores it, together with the record we need to run the service and to bill you correctly:

What our server holds against your account
email · account id · created date · billing ids · status
spark balance · job history · promo codes · reward progress · ledger

No name, no phone number, no contacts, no location and no photographs. Job history records which model you ran and when — never the prompt, the image or the result. The ledger is the record of sparks bought and spent, which is what lets us settle a refund. Billing ids are the references our payment providers use, described in section 5.

Your email is used to identify your account across devices, to answer you when you write to support, and to attach purchases to the right person. It is not used for marketing, and we do not send newsletters.

The activity records exist for billing, not for profiling. Sparks are the app’s internal credit: we have to know what you bought, what you spent and on which job, or we could neither charge you correctly nor refund you. We do not use these records to build a picture of you, and we do not share them with advertisers.

05Purchases and subscriptions

Paid features are handled by RevenueCat, which sits on top of Google Play Billing and the App Store and keeps track of what you are entitled to. Every purchase is made through the store; we take no payments outside it.

These providers receive an account identifier, the purchase or subscription in question, and the technical details their fraud and billing systems require. We store their references against your account so we know your purchase is yours.

We never see or store your card number. Card details are entered in Google’s or Apple’s own interface and never pass through the app or our server.

06Advertising and the choices you have

The app displays advertising through Google AdMob. To do that, AdMob accesses your device’s Advertising ID — a resettable identifier Android provides for this purpose — along with your IP address, device type, and information about which ads you were shown and interacted with. This lets Google select ads, limit how often you see the same one, and measure whether an ad worked.

Google may use this information as an independent controller under its policy for partner sites and apps. We do not receive your identity from Google, and we never pass your prompts, your images, your results or your email address to any advertising network.

Turning off personalised ads

  • On your device: Settings → Google → Ads, where you can reset the Advertising ID or delete it entirely. Deleting it stops personalised ads; you will still see non-personalised ones.
  • Across Google services: My Ad Centre.
  • In the European Economic Area, the United Kingdom and Switzerland we ask for your consent through Google’s consent interface the first time you open the app, and you can change that choice at any time from the app’s settings.

07What we use information for

We process the limited data described above only for the purposes listed here. Where the GDPR applies, the legal basis for each purpose is given in brackets.

  • Signing you in and recognising your account across devices [performance of a contract].
  • Delivering the core function of the app — passing your request to an AI provider and returning the result [performance of a contract].
  • Charging and refunding sparks, taking payment and tracking entitlements [performance of a contract].
  • Keeping the service available and preventing abuse of credits and welcome bonuses [legitimate interests].
  • Reviewing results you report as offensive or illegal and keeping the service safe [legitimate interests; legal obligation].
  • Showing advertising that funds the app [consent for personalised advertising; legitimate interests for non-personalised advertising and fraud prevention].
  • Meeting legal obligations, including tax records for purchases, and responding to lawful requests [legal obligation].

We do not sell personal information, and we do not share it for cross-context behavioural advertising beyond the AdMob processing described in section 6.

08Service providers

These are the third parties that can receive data from the app or our server:

  • Google — Firebase Authentication, Sign in with Google, Firebase Crashlytics and Firebase Analytics, which verify who you are, hold the account on Google’s side, receive crash reports (stack trace, device model, OS and app version) so we can fix what crashed, and receive the short list of app events described above. Firebase privacy and security.
  • Google AdMob — advertising delivery and measurement. Google Privacy Policy.
  • Replicate — runs the models that fulfil your requests, and receives your prompt and any image you attach. Replicate privacy policy.
  • OpenAI — runs some of the models reached through Replicate, including the text model that picks a model for you and rewrites prompts on request, and the model that gives style advice on a photo you choose. It receives the prompt sent to them and, for style advice, that photo. OpenAI privacy policy.
  • Apple — Sign in with Apple on iPhone, and App Store purchases. Apple Privacy Policy.
  • Google Cloud Vertex AI — hosts some of the image models reached through Replicate. Google Cloud privacy notice.
  • RevenueCat — subscription and entitlement management. RevenueCat privacy policy.
  • Stripe — payment processing outside the store. Stripe privacy policy.
  • Fly.io — hosts our server at aiopenpocket.fly.dev. Fly.io privacy policy.

We may also disclose information where the law requires it, to enforce our terms, or as part of a merger or acquisition — in which case this policy continues to apply to the data transferred, or you will be told before anything changes.

09How long we keep things

What Kept for
Prompts and attached imagesNot retained by us — discarded once the job finishes. Provider retention is set by the provider
Generated resultsStored on your device only, until you delete them
Reports you send (the reported picture, its prompt, the model and your note)Until we review and close the report, and never longer than your account
Account record, including emailUntil you delete your account, then erased after the grace period below
Spark balance, job history, promo codes and rewardsUntil you delete your account, then erased with it
Money-movement recordsAnonymised when the account is erased, then kept as long as accounting and refund handling require
Deletion markerKept indefinitely as an irreversible fingerprint of your email — see section 10
Purchase recordsAs long as tax and accounting law requires
Server request logsMethod, path, status and timing only — no prompts, no images, no results. Held by our hosting platform for its standard period

10Deleting your account and your data

You can delete your account and everything attached to it in two ways:

  • Inside the app: Profile → Delete account. The account stops working straight away.
  • Without installing the app: aiopenpocket.fly.dev/delete-account explains both routes, and you can write to kwoutt1@gmail.com from the address you signed up with. Requests by email are handled by hand, within 30 days.

Erasure is not instant, on purpose. The account is marked and held for a grace period of 30 days, during which you can sign in the same way as before — the same Google or Apple account, or the same email and password — and restore it. After that it is erased permanently: your email address, your access keys, your job history, your promo codes and reward progress, any reports you sent, and any unspent sparks, which are forfeited and not refunded in money.

Two things outlive the account, and neither identifies you. The first is a deletion marker: a keyed, one-way fingerprint of your email address — not the address itself, and not reversible back to it. It exists for one purpose, so that someone who deletes an account and signs up again does not collect the welcome sparks a second time. The second is the money-movement records, which are not deleted but anonymised — stripped of your address and of any link to you — so that a refund arriving after erasure can still be reconciled.

Prompts and results need no deletion request, because we never held them — except the ones inside a report you sent, and those go with the account. Pictures you saved to your phone are your own files, which the app does not touch. Deleting your account here does not cancel a subscription bought through Google Play — cancel that in the Play Store, otherwise billing continues.

11Your rights

Depending on where you live, you may have the right to access the data we hold about you, correct it, delete it, restrict or object to how we use it, receive it in a portable format, and withdraw a consent you previously gave. Exercising a right costs nothing and does not degrade the service.

Write to kwoutt1@gmail.com and we will respond within 30 days. In practice the answer to an access request is short: your email address, when the account was created, what you have bought, your spark balance and the list of jobs you ran.

If you are in the EEA or the UK and you are not satisfied with our response, you may complain to your national data protection authority.

12Security

Traffic between the app, our server and every provider is encrypted in transit with TLS. Sessions are held by a bearer token sent in the Authorization header rather than a cookie, so nothing rides along with unrelated requests. Access to the server is limited to the people who need it.

Keeping little is itself a control here: we hold no passwords, no card numbers, and no record of what you generated, so none of those can leak from us.

No system is perfectly secure. If a breach affects your data and creates a risk to you, we will notify you and the relevant authority as the law requires.

13International transfers

Our providers operate globally, so information may be processed in countries other than your own, including the United States. Where data leaves the EEA or the UK, transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision, together with the safeguards our providers publish.

14Children

The app is not directed to children. It is intended for users aged 13 and over, and in the EEA for users old enough to consent to data processing in their country — between 13 and 16, depending on the member state.

We do not knowingly collect personal information from children below that age. If you believe a child has provided information to us, write to kwoutt1@gmail.com and we will delete the account.

15Changes to this policy

If we change what we collect, why, or which providers we use, we will update this page and move the “last updated” date at the top. For changes that materially affect you we will give notice in the app before they take effect, and where the law requires it we will ask for your consent again.

16Contact

For anything in this policy, including privacy requests:

Developer Ivan Golovachev
Application Aishkin · com.aiopenpocket.mobile
Aishkin — Privacy Policy Version 1.0 · Effective 7 September 2026