Privacy Policy
Last updated: 15 August 2026
1. Data controller
The controller of your personal data is FastTip Sp. z o.o. with its registered office in Kraków (os. 2 Pułku Lotniczego 13 lok. 2, 31-868 Kraków, Poland), NIP: 6751808533, KRS: 0001148920, registry court: District Court for Kraków-Śródmieście in Kraków, 11th Commercial Division of the KRS, share capital: PLN 5,000.00 (the “Controller”). For all data-related matters contact: [email protected].
2. Legal bases and purposes
Personal data are processed on the following legal bases:
- Art. 6(1)(b) GDPR - performance of a contract (providing the Service, managing your Subscription).
- Art. 6(1)(c) GDPR - legal obligation (e.g. invoicing, tax and accounting rules).
- Art. 6(1)(f) GDPR - legitimate interests (security, fraud prevention, product development).
- Art. 6(1)(a) GDPR - your consent (for purely marketing activities, where consent was given).
Providing data is voluntary but necessary to create an Account and use paid features of the Service.
3. Categories of data
- Cryptographic hashes of the device identifier and of the IP address, used solely to grant the single free image generation (section 8).
- Email address and Google identifier (when signing in with OAuth).
- Company name, address, VAT ID (for billing).
- Payment data - processed directly by Stripe, Inc.; the Controller does not store full card numbers.
- Uploaded source materials and AI-generated outputs.
- Server logs: IP address, browser type, request timestamps.
4. Processors
To operate the Service, data may be shared with trusted processors:
- PostHog (product analytics), only after consent; data processed on servers in the European Union.
- Meta Platforms Ireland Limited - advertising measurement, only after consent; only an irreversible hash of the email address is transmitted, never the address in the clear.
- TikTok Technology Limited - advertising measurement, only after consent; only irreversible hashes of the email address and of the account number are transmitted, never either value in the clear.
- Stripe, Inc. - payments and subscriptions.
- Google LLC - OAuth sign-in, cloud infrastructure.
- Specialised AI model providers - solely to generate content at the User's request.
- Object storage infrastructure provider - storing uploaded materials and generated content.
- Mobile subscription billing provider - processing in-app purchases (App Store / Google Play).
- Hosting and accounting service providers supporting FastTip Sp. z o.o.
5. Retention
- Account data is kept for the lifetime of the Account and up to 30 days after deletion (for potential claims).
- AI-generated content is kept while the Account is active and is permanently deleted when the Account is removed.
- Billing documents (invoices) are kept for 5 years from the end of the calendar year in which the tax payment deadline expired (legal requirement).
6. Your rights
Under the GDPR you have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Erasure (“right to be forgotten”).
- Restrict processing and data portability.
- Object to certain processing.
- Lodge a complaint with a supervisory authority (in Poland: the President of the Personal Data Protection Office, UODO).
To exercise your rights, email [email protected].
8. Product analytics and device identifier
This section describes two separate operations. They rest on different legal bases and are therefore described separately.
Product analytics. The Controller uses PostHog to establish which parts of the Service and the app are used and which cause difficulty. Events recorded include page views, the start and completion of an image generation, viewing the pricing and starting a payment, together with the account identifier once signed in. Data is processed on PostHog servers located in the European Union. The legal basis is Article 6(1)(a) GDPR, that is consent. Until consent is given the tool is not started at all and sends no data. Consent can be withdrawn at any time: on the website by clearing site data in the browser, in the mobile app by writing to [email protected]. Session recording is disabled. The content of uploaded photos is never sent to the analytics tool.
Advertising measurement. If the User consents to analytics, the Controller also uses the Meta Pixel and the Conversions API, as well as the TikTok Pixel and the Events API, to establish which advertising campaigns lead to a paid plan. What is transmitted is a page view, the completion of sign-up, and the fact that a subscription was paid for together with its amount. To attribute a purchase to an ad click, an irreversible cryptographic hash of the email address (SHA-256) is transmitted, and in TikTok's case the same kind of hash of the account number held by the Controller; neither value ever leaves the Controller's systems in the clear. The content of uploaded photos is not transmitted. The legal basis is Article 6(1)(a) GDPR, consent, the same consent that covers product analytics. Until it is given the tool does not start at all. Consent may be withdrawn at any time in the manner described above.
Device identifier and the one free image. Every newly created Account receives one free image generation, once. To establish whether a given device has already used it, the application sends a device identifier which is immediately converted into an irreversible cryptographic hash (HMAC) and stored only in that form. The IP address is treated the same way, its hash serving only as a safeguard against bulk account creation. Neither the raw device identifier nor the raw IP address is stored in this record. The legal basis is Article 6(1)(f) GDPR, the legitimate interest in preventing abuse: without this mechanism the same person could open account after account and take unlimited free generations. The operation serves neither profiling nor marketing and does not depend on consent to analytics. The hashes are kept for the lifetime of the Account. A right to object applies to this processing (Article 21 GDPR).