Privacy Policy
This app redesigns a photo of your own kitchen with generative AI. We built it to need as little of your data as possible: your photo is stripped of location data on your device, sent securely for the redesign, and never stored on our servers. This policy explains, in plain language, what we process, why, on what legal basis, who we work with, and the rights you have.
1. Who we are (the data controller)
The controller responsible for the processing described here is:
Toob (sole proprietorship / eenmanszaak), operated by Tobias Hesselink
Address: Koppelsbrink 38, 7622 CW Borne, Netherlands
Chamber of Commerce (KvK): 88227677
VAT ID (btw-identificatienummer): NL004565523B51
Email: [email protected]
We have not appointed a Data Protection Officer (DPO). We are not legally required to, given the nature and scale of our processing. For any privacy question or request, email [email protected].
2. What this policy covers
This policy covers the Kitchen Designer AI iOS app and the backend service behind it (our API at api.keukenvisualizer.nl). It does not cover Apple's App Store or the third parties listed in section 7, who each have their own privacy terms.
3. What we process, why, and on what legal basis
The table below is the complete picture. "Legal basis" refers to Article 6 of the GDPR.
| What | Why | Legal basis |
|---|---|---|
| Your kitchen photo and any reference photo you add | To generate your redesigned kitchen (the core service you asked for) | Performance of a contract (Art. 6(1)(b)) |
| Design choices (mode, style, materials, colours, intensity, reference selection) | To drive the redesign you requested | Performance of a contract (Art. 6(1)(b)) |
| Generated result images | To show and let you save your redesign | Performance of a contract (Art. 6(1)(b)) |
| Device security signals: a device identifier, plus Apple App Attest and DeviceCheck data | To prevent fraud and abuse and to meter the free tier fairly so it cannot be reset endlessly by reinstalling | Legitimate interest (Art. 6(1)(f)): protecting the service against abuse |
| Subscription status (derived from your App Store purchase via RevenueCat: is-pro, product, renewal/expiry) | To unlock Kitchen AI Pro and to meet our bookkeeping and tax duties | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Privacy-friendly product analytics (a small set of usage events, see section 8) | To understand how the app is used and improve it | Legitimate interest (Art. 6(1)(f)); you can opt out at any time |
| Error and diagnostics data (server exceptions, no personal content) | To detect and fix failures (for example a failed refund) | Legitimate interest (Art. 6(1)(f)): a reliable, secure service |
| Server logs (technical request data). We do not store your IP address; it is discarded. | Operations, security and abuse prevention | Legitimate interest (Art. 6(1)(f)) |
| Support correspondence | To answer your questions and handle your requests | Contract and legitimate interest (Art. 6(1)(b) and (f)) |
4. How your photo is handled (the important part)
- Location data is removed on your device. Before your photo is uploaded, the app re-renders it, which drops GPS and camera metadata. Your location does not leave your phone.
- It is sent securely. The photo travels over an encrypted (TLS) connection to our server, and from there to Google's Gemini AI, which produces the redesign. When our direct connection to Google is unavailable, the request may instead be routed through OpenRouter, which forwards it to the same Google Gemini models. In every case, only Google's Gemini models process your photo to generate the image; no other AI model receives it.
- It is not stored on our servers. Your photo and the generated result exist only briefly, in memory and in a short-lived processing slot that is automatically deleted after about five minutes. They are never written to disk and never kept afterwards.
- Your results live on your device. The redesigned images are saved on your device only. You can delete them there at any time.
- People in photos. The app is meant for photos of rooms, not people. Please do not upload photos of other identifiable people without their permission. If a person is incidentally visible, that image is processed the same way as any other (removed from our servers after about five minutes) and is never used to identify anyone.
- Your results are made by AI. See section 9.
5. How long we keep data
- Your photo and the result (on our servers)
- Not retained. Held only transiently and deleted automatically after about five minutes.
- Your results (on your device)
- Kept on your device until you delete them or remove the app.
- Free-tier and anti-abuse data (device identifier, App Attest, DeviceCheck)
- Kept for as long as needed to prevent abuse of the free tier. This data is tied to your device, not to your name or Apple ID.
- Subscription status
- Kept while the subscription relationship exists. Transaction records that we are required to keep for tax and bookkeeping are retained for 7 years (Dutch fiscal law).
- Product analytics
- Kept for up to 12 months, then deleted.
- Server logs
- We do not store your IP address; it is discarded and never written to our logs. Technical operational logs contain no data that identifies you and are kept only briefly (up to 14 days, with our EU-hosted log provider) for security and operations.
- Support correspondence
- Kept for up to 24 months after your request is resolved.
6. Automated decision-making
We run an automated safety check on uploaded images to block unsafe content before processing. This does not produce legal or similarly significant effects on you within the meaning of Article 22 of the GDPR. We do not profile you and we make no automated decisions about you beyond this safety filter and ordinary fraud prevention.
7. Who we share data with, and international transfers
We use a small number of carefully chosen processors and partners. We do not sell your data and we do not share it for advertising.
| Party | What they do | What they receive | Where | Transfer basis |
|---|---|---|---|---|
| Google (Gemini API) | Generates the redesign and runs a vision pre-check of the image | Your photo (location removed) and the design prompt | United States / global | EU-US Data Privacy Framework (Google is certified) and EU Standard Contractual Clauses |
| OpenRouter | A routing fallback that forwards requests to Google's Gemini models only | Your photo (location removed) and the design prompt, only on fallback | United States | EU Standard Contractual Clauses |
| Apple | App distribution, In-App Purchase (Apple is the seller), App Attest and DeviceCheck | Payment and device attestation | Apple entities (EU seller: Apple Distribution International Ltd., Ireland) | Apple acts as an independent controller under its own terms |
| RevenueCat | Validates purchases and provides subscription/entitlement status | An anonymous app-user identifier and purchase/receipt data. No photos. | United States | EU Standard Contractual Clauses |
| PostHog (EU Cloud) | Privacy-friendly product analytics and server error tracking | Pseudonymised usage events and error reports (no photos, no name, no email, no IP) | European Union (Frankfurt, Germany) | Stays in the EU; no third-country transfer |
| Hetzner | Hosts our server | Everything that passes through the server, within its short retention | Germany / Finland (EU) | Stays in the EU; no third-country transfer |
| Ploi | Manages our server (infrastructure only) | Server management data; it does not process your personal data in normal use | Netherlands (EU) | Stays in the EU; no third-country transfer |
| Grafana Labs (Grafana Cloud Loki) | Stores and lets us search our backend and infrastructure logs | Technical server and system logs (no photos, no IP address, no data that identifies you) | European Union (logs hosted in the EU); US parent company | Logs are stored in the EU; for the US parent company we also rely on the EU-US Data Privacy Framework and SCCs |
| Cloudflare (Email Routing) | Forwards our support mailbox to the operator | Support correspondence you send us | United States / global edge | EU-US Data Privacy Framework (Cloudflare certified) and SCCs |
Transfers outside the EEA. Google, OpenRouter, RevenueCat and Cloudflare (our email routing) process data in the United States. Where a partner is certified under the EU-US Data Privacy Framework, we rely on that; in all cases we also rely on the European Commission's Standard Contractual Clauses as a safeguard. Our log provider (Grafana Labs) stores logs in the EU, but because it is a US-headquartered company we also rely on the Data Privacy Framework and SCCs for any parent-company access. You can ask us for more detail on any of these safeguards.
Note on OpenRouter and Google. Our accounts are configured so that prompts and images are not used to train any AI model and are not retained for logging beyond what is needed to deliver the result. Google's paid Gemini API does not use inputs or outputs to train its models, and OpenRouter is set to route only to Google's Gemini models with logging and training routing disabled.
RevenueCat's own sub-processors. RevenueCat uses its own service providers (which include cloud and AI vendors such as OpenAI and Anthropic) to run its platform. They receive only the limited purchase data described above, never your photos.
Refunds. If you ask Apple for a refund, RevenueCat may share anonymous subscription-usage information with Apple so Apple can assess the request. This is device-anonymous, contains no name or email, and is not linked to your identity.
8. Analytics and your choices
To understand how the app is used, we collect a small set of privacy-friendly usage events (for example: app opened, onboarding completed, a design started, a generation completed, the paywall shown, a purchase completed). This analytics is pseudonymised and not linked to your identity:
- events are tagged with a random per-install identifier that resets if you reinstall the app, and is never linked to your name or identity;
- no name, email, photo or other directly identifying data;
- no advertising identifiers and no tracking across other apps or websites;
- your IP address is not collected for analytics;
- no session recording, no screen recording, no heatmaps;
- data is hosted in the EU (PostHog EU Cloud) and is never used to train third-party AI models.
Your choice. You can turn analytics off at any time in the app under Settings. Development builds send no analytics at all.
We also collect server-side error reports (exceptions) to keep the service reliable. These carry no personal content and no user identity, only a technical environment tag.
9. AI-generated content
Your results are made by AI and are meant for inspiration and visualisation. They are not a construction plan, a quote, or professional design advice, and they may contain inaccuracies. Images generated by Google's Gemini models carry Google's invisible SynthID watermark, which marks them as AI-generated in a machine-readable way. The app also tells you, before you start and on your results, that the content is created by AI. See our short AI transparency notice for more.
10. Your rights
Under the GDPR you have the right to:
- Access
- ask what personal data we hold about you and get a copy;
- Rectification
- have inaccurate data corrected;
- Erasure
- have your data deleted ("right to be forgotten");
- Restriction
- ask us to limit how we use your data;
- Objection
- object to processing based on our legitimate interests;
- Portability
- receive data you gave us in a portable format.
How to exercise them. Email [email protected]. You do not register with us; to request deletion of the limited data tied to you, include the support ID shown in the app under Settings, and we delete your entitlement record and RevenueCat customer. Because most of what we process is either transient (your photo) or tied to your device rather than your identity, we may ask you to verify your request so we act on the right data. We respond within one month.
Complaints. If you believe we handle your data incorrectly, please contact us first so we can help. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
11. Children
The app is intended for people aged 16 and older and is not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has used the app, contact us and we will delete any related data.
12. Security
We use encryption in transit (TLS), on-device removal of location data, device attestation against abuse, and processors that meet recognised security standards. No service can be perfectly secure, but we keep the amount of data we hold to a minimum, which is the strongest protection of all.
13. Changes to this policy
If we change this policy we will update the version and date above and, for significant changes, tell you in the app. This is version 2.1.
14. Contact
Questions about your privacy? Email [email protected]. Our full company details are in the imprint.