✳ PhotoToTattoo.
PricingContact
Plainly, before you begin

Privacy Policy

Your photograph is personal. Here is what we collect, why we need it, and what private means here.

Last updated: October 9, 2026
The detailsPrivacy PolicyTerms of ServiceRefund PolicyContact

Who is responsible

The operator responsible for this service and the personal information it holds is LING SEN, based in Chengdu, Sichuan, China. Contact contact@photototattoo.com for privacy questions or requests. PhotoToTattoo Team is our support name.

The service is intended for adults aged 18 and over. We do not knowingly accept accounts or uploads from children. If you believe a child has provided information, contact us so we can review and remove it where appropriate.

What we collect

When you sign in, we use your account identifier and, when provided by Google, your name, email address, and profile image URL. We use these to keep your account, generation balance, and private designs together.

When you generate a concept, we store the cropped photo, selected style, written requirements, output image, processing status, and related version records. Payment order and generation ledger records are kept so that purchases, reservations, failures, and refunds can be reconciled.

Operational logs may include request identifiers, error information, and timestamps needed to resolve problems. Please do not put sensitive personal information into your generation instructions or PDF notes.

Before you click Generate

Photo selection and cropping happen in your browser. The prepared photo is uploaded only when you are signed in and submit a generation. A single browser draft may be stored on your device to preserve your photo and choices across sign-in or a visit to checkout. The same signed-in account can restore it for up to 15 minutes. Restoring it in one returning tab does not consume it for another returning tab. Signing out clears the browser draft.

Who processes your data

Google handles Google sign-in. Cloudflare hosts the application, processes image files for the service, and stores private images in R2. Neon stores account, design, balance, payment, and moderation records; the application connects to it through Cloudflare Hyperdrive.

Kie processes the photo and instructions submitted for a real generation, using Nano Banana 2.1 (provider model identifier: nano-banana-2-1). Kie receives a temporary signed input link to read the photo. Replicate may still process or return results for historical requests submitted before the provider change; new requests use Kie.

For generation requests, Sightengine receives the prepared input image and generated output image for automated content checks. Waffo’s content-safety service receives your written requirements, when provided, and the final prompt prepared for the image model. These checks must allow the content before generation can start or an output can be delivered.

Waffo Pancake also handles checkout when payments are enabled. Payment details are entered in its checkout; PhotoToTattoo does not store full card numbers or card security codes.

These providers have their own privacy and retention practices and may process data outside your country. We do not promise that providers will never use submitted data for training or that their copies are deleted on a particular schedule. Deleting a design here does not guarantee immediate removal from a provider’s systems. We do not sell your personal information or use your photos for public advertising without your permission.

Content-check records

We keep moderation decisions, machine categories and scores, policy versions, request identifiers, timestamps, and a fingerprint of the checked content. Moderation audit records do not contain the original image, full prompt text, private image links, or the provider’s complete response. Your photo and written requirements are stored separately as part of your private design request.

Automated checks can make mistakes. A blocked or unconfirmed image is not made available for viewing or download. Contact contact@photototattoo.com with the design reference if you think a decision is mistaken; do not send illegal images or private access links.

Why we use the information

We use account, photo and order data to perform our agreement with you: providing the requested service, reconciling payments and handling support. Our legitimate interests in protecting the service support security checks, abuse prevention and investigating failures. We retain or disclose records when required to meet a legal obligation. Where a processing activity requires your consent, you can withdraw that consent by contacting us; this does not undo processing already carried out.

Private access

Your library is private by default. Access to your design history and our image, download, and deletion endpoints requires an authenticated account that owns the design.

Images also pass through temporary provider URLs and signed storage URLs. These links are not protected by your PhotoToTattoo login: anyone who obtains an active link may be able to view its image. Do not share those links if you do not want another person to see the image. Downloaded copies remain on the device where you save them.

Retention and deletion

Each stored image expires 30 days after it is saved. The application stops allowing access at expiry, including new viewing, download, and generation requests that need that image. Scheduled cleanup removes expired files in batches. A backlog or failed storage operation can delay physical deletion; failed operations can be retried. Download images you want to keep before they expire.

You can delete a design from My designs to hide that version sooner. Images still needed by another version are kept until they are no longer referenced or expire. Uploads or outputs that have not passed content checks remain private and are also subject to expiry and cleanup.

Deleting a design or image does not erase the generation, moderation, or payment records needed to settle a processing request, investigate abuse, reconcile a balance, or handle a refund. Account-data deletion requests are handled separately through support. Existing temporary links, backups, and provider copies may take additional time to expire or be removed. We do not promise instantaneous deletion everywhere.

Security

HTTPS protects information in transit. Our application requires account ownership for private design endpoints, uses private image storage, and limits provider access through temporary signed links. These measures reduce risk but cannot guarantee absolute security. If a personal data breach requires notification, we will notify affected people or authorities as required by applicable law.

Cookies and your choices

Essential session cookies support sign-in and private access. Your browser also keeps temporary local draft and request recovery information. You can clear site storage through your browser settings; doing so may remove a prepared photo or a local shortcut to a saved request.

You may ask about access, correction, or deletion of account information through our configured support channel. We may need to verify account ownership before completing a request.

Your rights and contact

Depending on the laws that apply to you, you may request access, correction, deletion or a portable copy of your information, or object to or restrict processing. Contact contact@photototattoo.com from your account email. We verify ownership, explain any records we must retain and respond within the period required by applicable law. You may also contact your relevant data protection authority.

We will update this page when our data practices change and provide an appropriate notice of material changes. The date above identifies the current version.

PhotoToTattoo.

A starting point for a conversation with your tattoo artist.

PrivacyTermsRefundsContact

© 2026 PhotoToTattoo