Draft. This page has not yet been reviewed by a lawyer and still contains placeholders. Do not publish it in this state.
MB Makery ("we", "us") is the controller of the personal data described in this policy.
| Legal name | MB Makery |
|---|---|
| Company code | 307770736 |
| VAT number | not VAT registered |
| Registered address | V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania |
| Privacy contact | support@developers911.com |
| Support contact | support@developers911.com |
| Website | https://www.developers911.com/eraframe/ |
We have not appointed a data protection officer. Our assessment is that Article 37 GDPR does not require one, because we do not carry out large-scale processing of special category data and we do not carry out regular and systematic monitoring of data subjects. We are established in Lithuania, so no Article 27 representative is required.
You choose one photo. It is sent to our server over an encrypted connection, re-encoded, and passed to OpenAI's GPT Image model with a text prompt so the model can render black-and-white portraits of the same person. Your original photo is deleted as soon as the roll finishes or is cancelled. The generated portraits are deleted after 24 hours. There is no account, no name and no e-mail address, and the app contains no general analytics, no advertising and no crash reporting. A random identifier created on your device tells our server which portraits are yours and how many free rolls are left. The one thing we measure is the subscription screen: our paywall provider records, under that random identifier, which version of the screen was shown and whether it led to a purchase.
Eraframe takes one photo of a person, together with your choice of one to eight photographic styles, and returns stylised monochrome portraits generated by an artificial intelligence model. The portraits are synthetic images. They are not photographs of a real moment, and they are labelled as AI-generated in the app, when shared, and in the image file metadata.
| Data | Where it comes from | Why we process it | Lawful basis |
|---|---|---|---|
| The photo you submit, and the re-encoded working copy our server makes from it | You, through the Android photo picker or the camera | To generate the portraits you asked for | Art. 6(1)(b) — performance of a contract with you |
| The generated portraits | Produced by the model from your photo | To deliver the result to your device and let you view, save, share and retry | Art. 6(1)(b) |
| Install id — a random UUID created once when you install the app | Generated on your device | To link a roll to the device that created it, so that only your device can retrieve your images; to count free and daily rolls; to apply rate limits | Art. 6(1)(b) for delivery and quota; Art. 6(1)(f) for rate limiting and abuse prevention |
| Usage counters — install id, calendar day (UTC), number of rolls | Our server | To enforce the free roll and the daily Pro allowance, and to detect abusive volume | Art. 6(1)(b) and Art. 6(1)(f) |
| Job records — job id, install id, chosen style ids, shot type, status, timestamps | Our server | To run the roll, show progress, and support retries | Art. 6(1)(b) |
| Report contents — reason code, optional free text you write (up to 1,000 characters), and the reported image | You, through the in-app report sheet | To review the report, remove content that breaks our rules, improve filtering, and act against repeat abuse | Art. 6(1)(f) — our legitimate interest in a safe service |
| Purchase and subscription status — Superwall app user id, entitlement name, expiry date | Superwall, which receives Google Play purchase tokens from Google Play | To unlock Eraframe Pro features for the device that paid | Art. 6(1)(b) |
| Paywall events — the same anonymous app user id, device and app metadata (device model, operating system version, app version, country, language), and events such as "paywall shown", "plan selected", "purchase completed", "screen dismissed" | Superwall's software inside the app, when a subscription screen is shown | To present the subscription screen, to see which wording, layout and prices work, and to run A/B experiments between paywall variants | Art. 6(1)(f) — our legitimate interest in understanding and improving how we present the subscription |
| Technical logs — IP address, timestamp, endpoint, HTTP status, error code, install id | Automatically, as part of every HTTPS request | Security, rate limiting, fraud and abuse prevention, diagnosing faults | Art. 6(1)(f) |
| Correspondence — the e-mail address and message you send us | You, if you write to us | To answer you and to handle rights requests | Art. 6(1)(b) or Art. 6(1)(f); Art. 6(1)(c) where we must answer a rights request |
Where we rely on legitimate interests, we have weighed our interest against your rights. The data involved is limited, is not used to build a profile of you, is not combined with data from other sources, and is deleted on the schedule in section 9. You may object at any time (section 10).
We do not sell personal data. We do not use it for advertising. We do not use your photos or the generated portraits to train any model of our own, and our production setup requires Google's Paid Services, whose terms say prompts and responses are not used to improve Google's products.
Once, after your first roll has been saved or shared, the app may ask Google Play to show its own in-app review dialog. The dialog, and any rating or review you write in it, belong to Google Play and are handled under Google's terms. We are not told whether you were shown the dialog, whether you wrote anything, or what you said. The app records only a local flag on your device so that it does not ask again.
We do not collect your name, e-mail address (unless you write to us), postal address, phone number, precise or approximate location, contacts, calendar, browsing history, or any advertising identifier. Version 1 of the app contains no general analytics, no advertising and no crash-reporting software. The paywall events described in the table above are the only measurement we collect; they describe the subscription screen, not your photos, your portraits or anything else you do in the app. The app requests no photo, storage or camera permissions; it uses the Android system photo picker and the camera intent, which give it only the one image you choose. Fonts are bundled inside the app, so it makes no requests to third-party font services. Apart from Google Play and Superwall, which handle purchases and the subscription screen, the app communicates only with our own server.
The photo you submit usually shows a face. We process it so that the model can render a portrait that resembles the same person. We do not extract a faceprint or biometric template, we do not compare the photo against any database of people, and we do not attempt to establish or verify who anyone is. Neither our server nor the model we use is configured to identify people.
Our assessment is therefore that we do not process biometric data "for the purpose of uniquely identifying a natural person" within the meaning of Article 9(1) GDPR, and that no Article 9 condition is required. The photo is still personal data, and everything else in this policy applies to it.
Before you can continue, the app asks you to confirm: "This is me, or I have permission to use this photo."
If the photo shows someone other than you, you are responsible for having that person's permission for their photo to be submitted to Eraframe and turned into AI-generated portraits. In that situation the lawful basis for processing their photo is their consent under Art. 6(1)(a), and you are the person who obtained it. Do not submit photos of children, of people who have not agreed, or of public figures. If you have submitted someone's photo without permission, or if you are that person, write to support@developers911.com and we will delete what we hold.
| Recipient | Role | What it receives | Where |
|---|---|---|---|
| Hostinger VPS, Paris, France (EU) | Processor — hosting and storage of our server and database | Everything in section 4 that our server holds | European Union |
| OpenAI | Processor — image generation | The re-encoded photo (EXIF removed, at most 1536 px on the long edge) and the text prompt. It does not receive your install id, your report text or your purchase data | Global by default; confirm the contracting entity, region and controls for the production project |
| Superwall Inc. | Processor — purchases/subscriptions, the subscription screen, paywall analytics and experiments | The anonymous app user id, Google Play purchase token, subscription status, device and app metadata, and paywall events. It does not receive your photo, your portraits, your report text or your payment details | United States |
| Google (Google Play and Google Play Billing) | Independent controller for the purchase itself | Your Google account and payment details, which you give directly to Google. We never see them. Google is the seller of record for Google Play purchases and handles EU VAT | Global, under Google's own privacy policy |
We may also disclose data to professional advisers, or to a public authority or court, where the law requires it.
OpenAI may process image API data outside the EEA unless an eligible regional project is configured. Superwall processes data in the United States.
/v1/images/edits has up to 30 days of abuse-monitoring retention and no application-state retention; eligible projects can use Zero Data Retention. Confirm the production project's actual controls, contracting entity, DPA and transfer safeguards before publication. See OpenAI data controls.You can ask us for a copy of the safeguards in place by writing to support@developers911.com. Our own server and database are hosted in the European Union.
| Data | Retention |
|---|---|
| The photo you submit | The original bytes are discarded as soon as the server re-encodes the image. The re-encoded working copy is deleted the moment the roll finishes, fails or is cancelled — normally under two minutes |
| Generated portraits | 24 hours from creation, then deleted automatically |
| Job records | 24 hours, deleted with the job |
| A portrait you report | 30 days from the report, so that we can review it, then deleted |
| Reports (reason code, optional free text, timestamps) | 24 months, so that we can recognise repeat abuse |
| Usage counters (install id, day, roll count) | 13 months |
| Technical and security logs | 30 days |
| Purchase and subscription records | For as long as the subscription is active, and afterwards for the period Lithuanian accounting and tax law requires: 10 years where Lithuanian accounting or tax law requires it |
| Data held by Superwall (subscription records and paywall events) in their own systems | For the periods set by those providers' own retention policies, which we do not control |
| Correspondence with us | 24 months from the last message |
Copies you save to your device's gallery, or send to other people, are under your control. We cannot delete those.
Using Settings → Delete my data in the app deletes everything we hold for your install id immediately, before these periods expire. Reports are kept, but the install id is removed from them, so they can no longer be linked to your device. The app also resets the anonymous app user id used by Superwall, for future app events; restoring an existing subscription can associate it with the new identifier. An active subscription is not cancelled by this: a subscription lives in Google Play, and you cancel it there. See the data deletion page.
Under the GDPR you have the right to access the personal data we hold about you and receive a copy; to rectify data that is inaccurate or incomplete; to erase your data; to restrict processing while a dispute about it is resolved; to portability of data you gave us, where processing is based on contract or consent and is carried out by automated means; to object to processing based on our legitimate interests, on grounds relating to your particular situation; and to withdraw consent where processing is based on consent, without affecting processing carried out before the withdrawal.
How to use them. The fastest route to erasure is Settings → Delete my data, which purges everything held for your install id immediately and needs no correspondence with us. For any other right, write to support@developers911.com. We answer within one month, and may extend by two further months for complex requests, in which case we will tell you within the first month.
One practical limit. Eraframe has no accounts. The only identifier we hold is the random install id generated on your device, and we hold nothing that connects it to your name or e-mail address. If you write to us, we usually cannot tell which data is yours unless you give us the install id, and Article 11 GDPR does not require us to collect extra data purely to identify you. Please include the install id in your message where you can. If you cannot supply it, the in-app deletion function still works, because the app knows its own install id.
Exercising these rights is free. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive.
We do not carry out automated decision-making that produces legal effects concerning you, or similarly significantly affects you, within the meaning of Article 22 GDPR. We do not profile you.
Three automated steps are worth explaining. Content moderation: the image model may refuse to generate a particular style, and the app shows "Skipped — this still didn't pass the safety check" and offers a retry. This affects one image in one roll. Abuse handling: where reports show repeated serious abuse we may block an install id, but that decision is taken by a person. You can contest it by writing to support@developers911.com. Paywall experiments: which version of the subscription screen you see may be assigned at random, so that we can compare wording and layout. The assignment is not based on a profile of you, and whatever plan is offered is always shown with its Google Play price before you buy anything.
The app stores an adult self-attestation on your device before access is granted. It does not request a date of birth, an identity document or an age-verification service. This flag is not uploaded and is cleared by Delete my data. Purchase and paywall SDK startup is deferred until you confirm you are at least 18.
Eraframe is for people aged 18 or over. It is not directed at children, it is not listed in Google Play's family programmes, and we do not knowingly process the personal data of anyone under 18. If we learn that we hold data about someone under 18, we delete it. If you believe a child has used the app, write to support@developers911.com.
Do not submit photographs of children to Eraframe under any circumstances, including your own children.
No service can promise perfect security, but we keep the amount of data we hold, and the time we hold it, as small as the service allows.
If you think we have handled your personal data unlawfully, please tell us first at support@developers911.com, so that we can put it right.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live or work. Our supervisory authority is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), Vilnius, Lithuania — https://vdai.lrv.lt. You may also seek a judicial remedy.
If we change this policy we will publish the new version at https://www.developers911.com/eraframe/ and update the effective date above. Where a change materially affects you, we will tell you in the app before it takes effect.
Privacy questions and rights requests: support@developers911.com
Everything else: support@developers911.com