Privacy Policy
Last updated: 18 July 2026
This policy explains what personal data RevealMe AI collects, why, how long we keep it, and the rights you have. It applies to everyone who uses the service, wherever you are located.
Who is responsible for your data
The data controller is Zijlstra.tech, Archipelweg 111 D, Leeuwarden, the Netherlands (KvK 82728143). You can reach us about privacy at info@zijlstra.tech.
What we collect and why
- Photos you upload and the images we generate. Your uploaded photo is processed to create an AI-generated result. Because your photo shows your face, in some regions the analysis of facial imagery may be treated as biometric or special-category data. See “Biometric data” below.
- Consent records. When you start a generation we record which consent statements you accepted, the consent version, and a one-way hashed value of your IP address and browser user-agent (we do not store these in raw form).
- Account and payment data. If you register or buy credits, we process your email and, through our payment provider, the information needed to complete the purchase. We never receive or store your full card number.
- Optional analytics. Only if you accept analytics cookies. Analytics events never include your uploaded photos, generated images, or any biometric data.
Legal bases (EU/EEA and UK users)
- Consent for processing your photo/facial imagery, for any biometric processing, and for optional analytics. You may withdraw consent at any time.
- Performance of a contract to deliver the results you request and the credits you purchase.
- Legal obligation for tax, accounting, and responding to lawful requests.
- Legitimate interests in keeping the service secure and preventing abuse, balanced against your rights.
Biometric data
RevealMe AI analyses facial features in your uploaded photo solely to generate the transformation you request. We do not use face data to identify you, we do not build face-recognition templates for identification, we do not sell face images, and we do not use your images to train AI models without your separate, explicit consent. Uploaded originals are deleted on the schedule below, which also destroys any associated facial analysis.
How long we keep it
- Uploaded original photos: scheduled for deletion about 24 hours after upload.
- Generated images: scheduled for deletion about 30 days after creation, unless saved by a paying user.
- Consent records and transaction records: retained as needed for legal, accounting, and dispute-handling purposes.
Who we share it with (subprocessors)
We use a small number of vetted service providers to run RevealMe AI:
- OpenAI — AI image transformation. Images are sent for processing on a no-training basis.
- Stripe — payment processing.
- PostHog — product analytics, loaded only after you accept analytics cookies.
- Vercel — frontend application hosting.
- Laravel Cloud — backend application hosting.
- Cloudflare R2 — encrypted image storage, hosted in the Western Europe (WEUR) region.
We do not sell your personal data and do not “share” it for cross-context behavioural advertising as defined under California law.
International transfers
Our application hosting and image storage are located in the EU. Some of the other providers above — such as OpenAI, Stripe, and our analytics provider — may process data outside the EU/EEA, including in the United States. Where required, such transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your data, to object to processing, and to withdraw consent. Every result page includes deletion controls, and originals auto-delete within about 24 hours. To make any other request, contact info@zijlstra.tech. EU/EEA and UK users also have the right to lodge a complaint with their local supervisory authority; California residents may exercise CCPA/CPRA rights without discrimination.
Children
RevealMe AI is intended for adults. You must be at least 18 years old to create an account or generate images. We do not knowingly collect personal data from children. If you believe a minor has used the service, contact info@zijlstra.tech and we will delete the data.
Security
Storage uses signed URLs where supported, encryption in transit, and encryption at rest through the configured storage provider. Consent records store hashed IP and user-agent values rather than raw identifiers.
Changes
We will update this policy as the service evolves and will revise the “Last updated” date above.
