Privacy

Privacy Policy

Effective: 24 August 2026 · Version 3.1

1. Controller

The controller of the Coloryx application (coloryx.app) is Peter Valašik, place of business Obrancov mieru 2005/10, 953 01 Zlaté Moravce, Slovenská republika. Company ID: 50 058 045, Tax ID: 1121257951, Not a VAT payer under Section 4 of Slovak Act No. 222/2004 Coll.; registered under Section 7a, VAT ID SK1121257951. The price shown at checkout is final and no VAT is added on top.. Registered in Trade Licence Register of the Slovak Republic, District Office Nitra, reg. no. 430-48062. For data-protection matters contact us at drakderos@gmail.com, phone +421 948 616 012. We have not appointed a Data Protection Officer (DPO) because the law does not require us to.

2. Categories of data subjects

  • Registered users of the app (parents, adults).
  • Children using the app under the supervision of a parent or legal guardian.
  • People depicted in photos uploaded by users.
  • People who submit reports through our violation-reporting form.

3. What we process, why, and on what legal basis

3.1 Account and profile

Data: e-mail address, display name (optional), avatar (optionally from your Google account when signing in with Google), internal user ID.
Purpose: account creation and management, sign-in, service communication.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Recipients: Supabase (database hosting and authentication — Supabase Inc., USA); for Google sign-in also Google LLC.
Retention: for the lifetime of the account. You can request account closure and deletion by e-mailing drakderos@gmail.com; statutory transaction records follow Section 3.5.

3.2 Uploaded photograph (photo-to-coloring-page generator)

Data: the image file you voluntarily upload. Before upload, the photo is downscaled and re-encoded in your browser via the canvas API, which removes EXIF metadata (camera model, GPS, timestamps). Only the image pixels reach Coloryx servers.
Purpose: generating a coloring page from your photo using artificial intelligence, at your explicit request.
Legal basis: performance of a contract (delivering the feature you requested).
Recipients: Supabase (Supabase Inc., USA) — private storage without a public URL. Lovable AI Gateway (Lovable AB, Sweden) routes the request to the Google Gemini 2.5 Flash Image model (Google LLC, USA), which processes the photo to create the requested result.
Retention: after each completed attempt, the system requests deletion of the original. If deletion fails or the session is interrupted, the file may remain temporarily in private storage; no public link is created. If you continue through sign-up before generating, the pending photo is stored locally in this browser's IndexedDB for up to 30 minutes and an expired draft is removed the next time the generator is opened.

3.3 Generated coloring page

Data: the generated coloring-page image.
Purpose: storing the result in your account.
Legal basis: performance of a contract.
Recipients: Supabase (private storage). The result is private and delivered to you through a signed URL valid for 1 hour. It is not shared until you choose to publish it to the community gallery.
Retention: for the lifetime of your account. You can request earlier deletion by e-mailing drakderos@gmail.com.

3.4 Community gallery

Data: the colored image (never the original photograph), title, optional category/topic, author nickname, publication time and a record of your consent.
Purpose: displaying your work in the community gallery.
Legal basis: consent (Art. 6(1)(a) GDPR), given by ticking a confirmation box before publishing. You can withdraw consent at any time by requesting removal at drakderos@gmail.com.
Recipients: Supabase; the community image is publicly readable inside the gallery. The original photograph is never published.
Retention: until consent is withdrawn or the post is removed at your request.

3.5 Payments (credits, subscription)

Data: transaction ID at the payment provider, subscription and customer ID at the payment provider, product/price, amount, currency, subscription status, billing period, environment (test/live), internal user ID.
We do not process or store payment-card data. Payment happens directly with the payment processor, which handles PCI-DSS compliance.
Purpose: order processing, subscription management, statutory obligations (accounting, VAT — where applicable).
Legal basis: contract and legal obligation (Art. 6(1)(b) and (c) GDPR).
Recipients: Stripe (Stripe, Inc., USA / Stripe Payments Europe Ltd., Ireland) via the Lovable Connector Gateway.
Retention: transaction records — 10 years (Slovak accounting and tax law).

3.6 Reviews

Data: rating (1–5), review text, display name shown next to the review, internal user ID.
Purpose: displaying ratings to other users.
Legal basis: consent (by submitting the review).
Retention: until you delete the review or your account.

3.7 Violation reports

Data: name, e-mail, optional phone number, relationship to the affected person, link to the disputed content, description of the report, optional attachment (photo, PDF). We do not require an ID document by default — we may ask for one only when strictly necessary (e.g., a dispute over eligibility).
Purpose: assessing and handling the report, removing infringing content.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in protecting third-party rights and complying with legal obligations.
Retention: 3 years after the report is closed.

3.8 Complaints and withdrawal requests

Data: e-mail address, full name, internal user ID, order or contract reference, complaint description, requested resolution, withdrawal notice, submission date and time, and confirmation-delivery status.
Purpose: receiving, acknowledging, recording and handling a complaint or withdrawal request, and demonstrating compliance with legal obligations.
Legal basis: contract and legal obligation (Art. 6(1)(b) and (c) GDPR); where necessary, legitimate interest in establishing, exercising or defending legal claims.
Recipients: Supabase (database), Lovable (managed transactional e-mail), the operator's e-mail mailbox, and legal or accounting advisers where necessary.
Retention: as long as needed to handle and evidence the request; records connected with a transaction or legal claim may be retained for up to 10 years where required by law or to defend a claim.

3.9 Technical logs

Data: error messages (message, path in the app, timestamp, optionally user ID). We do not store IP addresses or User-Agent in our own application logs. Supabase's hosting logs may include an IP address for security purposes; those are processed by Supabase as a processor.
Purpose: diagnostics, security, abuse prevention.
Legal basis: legitimate interest.
Retention: only as long as needed for diagnostics and security under the provider settings.

3.10 Analytics and cookies

With your consent, we use PostHog through an EU endpoint, Google Analytics 4 and internal analytics events. We process a pseudonymous identifier, the visited path and product events. We do not send e-mail addresses, photo or result content, or URL query parameters to analytics. The list of browser storage currently used is in our Cookie Policy. Without consent, no analytics or marketing cookies are set.

4. Categories of recipients (processors)

  • Supabase, Inc. (USA) — database hosting, authentication, private object storage.
  • Lovable AB (Sweden) — application hosting, AI request routing and managed transactional e-mail delivery.
  • Google LLC (USA) — Gemini 2.5 Flash Image, Google Analytics 4 (consent-based only), Google Sign-In and the operator's mailbox for notifications or replies.
  • Stripe, Inc. / Stripe Payments Europe Ltd. (Ireland) — payment processing.
  • PostHog (EU endpoint) — pseudonymous product analytics, only with consent.
  • External legal, accounting and IT advisors, only as strictly necessary.

We do not sell personal data and do not use it for profiling or targeted advertising.

5. Transfers outside the EU/EEA

Some processors are located in the USA (Supabase, Google, Stripe). Transfers are secured by:

  • Certification under the EU–U.S. Data Privacy Framework, where the provider is listed, and/or
  • European Commission Standard Contractual Clauses (SCCs) in the processor agreement.

6. Mandatory data

An e-mail address is required to create an account — without it we cannot create one for you. Uploading a photo is optional and needed only for the photo-to-coloring feature. Name and contact in a violation report are required for us to be able to handle it. Everything else (avatar, nickname, review) is voluntary.

7. Automated decision-making and profiling

We do not carry out automated individual decision-making with legal effects within the meaning of Art. 22 GDPR. On the "Unlimited" plan the app may cap the daily number of generations (an operational limit), but this is not profiling of the person.

8. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and the right to object (Art. 21). Where processing is based on consent, you can withdraw it at any time — withdrawal does not affect the lawfulness of processing before withdrawal. Exercise your rights by e-mailing drakderos@gmail.com. We reply within 30 days.

You also have the right to lodge a complaint with the supervisory authority: Office for Personal Data Protection of the Slovak Republic, Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, dataprotection.gov.sk.

9. Children

The app is designed for families. Accounts are created by adults; children use the app under the supervision of a parent or legal guardian. If we discover that an account was created for a child without parental consent, we will delete that account.

10. Changes to this policy

We may update this policy. Material changes will be announced in the app or by e-mail. The version number and effective date are shown in the header of this page.

11. Related documents

Cookie Policy · Terms of Use · Contact / Imprint