Privacy Policy
Effective date: July 27, 2026
This Privacy Policy explains how Lukas Vaičiulis, operating Mend ("Mend", "we", "us"), collects, uses, shares, and protects personal data when you use the mobile application Mend: AI Photo & Video Editor (the "App") and the website usemend.app (together, the "Services"). It is written to be accurate against how the App actually works — not aspirational.
At a glance
- We never sell your personal data and we do not use it for advertising or cross-app tracking. The App uses no advertising identifiers.
- Your photos and videos are processed only to create the AI edits you request, by the named providers listed in Section 5 — nothing else.
- Uploaded photos and videos are automatically and permanently deleted from our storage 24 hours after upload (your generated results stay in your gallery until you delete them).
- We do not train AI models on your content, and under our AI providers' published API terms your content is not used to train their models.
- Product analytics (PostHog) is off by default: full analytics only runs if you opt in. Before opt-in, only a small set of anonymous app-lifecycle events (app opened, backgrounded, installed, updated) and purchase-funnel events is counted, never linked to a user profile. Crash reporting (Sentry) is always on but aggressively stripped of personal content.
- You can delete individual creations, export your data, and delete your whole account directly in the App.
- We aim to answer privacy requests within 30 days, consistent with the GDPR.
1. Who is responsible for your data
The data controller for the Services is:
- Controller: Lukas Vaičiulis, operating Mend
- Location: Vilnius, Lithuania, European Union
- Email for privacy, data requests, and legal notices: support@usemend.app
- Website: https://usemend.app
Because Mend distributes a paid service in the EU, trader contact details are also displayed on the App's Apple App Store and Google Play listings as required by the EU Digital Services Act. Support and data-request responses are handled within the response windows stated in Section 12.
2. What data we collect
2.1 Data you provide
| Data | Details | Purpose |
|---|---|---|
| Photos and videos you upload | Images/videos you pick or capture for AI editing; they routinely contain faces. Automatically deleted from our storage 24 hours after upload | Creating the AI transformation you request; automated content-safety checks |
| Generated results and thumbnails | The AI outputs created for you, stored in your private gallery | Showing, saving, and letting you share your creations |
| Prompts and personalization details | Text you type for custom effects, and optional fields some templates offer (e.g. a name, age, or place to appear in the result). Custom prompts are checked for safety and may be automatically rewritten; both your original prompt and the version used for generation are stored with your generation history (and deleted with it), and a one-way hash of your prompt may additionally be kept for safety auditing | Generating your requested result; content safety; abuse prevention |
| Account information | Email address and name — only if you choose to sign in with Apple or Google. Guest use requires no email or name | Sign-in, syncing your gallery and purchases across devices |
| Consent records | Your AI-processing consent choice with its version and timestamp; the record may include the IP address and device user-agent at the time of consent | Legal compliance (proof of consent) |
| Support messages | Emails you send to support (the in-app "Report a Problem" email pre-fills your app version, platform, user ID, and subscription tier so we can help you) | Support and troubleshooting |
2.2 Data collected automatically
| Data | Details | Purpose |
|---|---|---|
| Account identifier | A random user ID (UUID) created for every user, including guests | Operating your account, gallery, credits, and purchases |
| Install identifier | A random per-installation ID generated on your device. It is not derived from your device's hardware or settings and identifies only the app installation; it is regenerated if you delete your account | Abuse prevention and rate limiting |
| Generation history and usage records | Job records (effect used, status, timestamps), credit ledger, moderation decisions (pass/fail and category codes — not the flagged content itself), rate-limit counters | Running the service, refunding failed generations, abuse prevention |
| Push notification token | Your device push token and platform (iOS/Android), only if you allow notifications | Notifying you when a generation finishes, plus occasional subscription reminders and offers |
| Crash and performance diagnostics (Sentry) | Crash reports, error traces, and performance data linked to your random user ID, with device/OS/app-version context. Automatically scrubbed before leaving your device: no photos, prompts, URLs, file paths, tokens, emails, or names; no screenshots | Fixing crashes and bugs (legitimate interest) |
| Product analytics (PostHog) — only if you opt in | Off by default. If you enable "Analytics & Performance" in Settings, we receive scrubbed usage events (screens viewed, feature usage, coarse buckets like prompt length ranges) linked to your random user ID. Before you opt in, only a limited set of app-lifecycle events (app opened, backgrounded, installed, updated) plus onboarding and purchase-funnel events is sent anonymously — no user profile is created and they are not linked to your account (legitimate interest in measuring that the App starts correctly and that the signup flow works). The same automatic scrubbing applies to everything: never your photos, prompts, emails, URLs, or tokens; session replay is disabled | Understanding which features are used, improving the App |
| Transport metadata | Standard connection data (such as your IP address) is visible to each server endpoint you connect to, as with any internet service | Delivering the service; security |
No tracking: the App declares no tracking in its Apple Privacy Manifest (NSPrivacyTracking: false). We use no advertising SDKs, no IDFA/advertising IDs, and no cross-app or cross-site tracking.
2.3 Data from third parties
| Source | Data received | Purpose |
|---|---|---|
| Apple / Google sign-in | Email address, name, and a sign-in identifier (only when you choose to sign in) | Account creation and login |
| RevenueCat / app stores | Purchase and subscription status, product identifiers, transaction dates, price/currency/store country. We never receive your payment card details — Apple and Google process all payments | Unlocking your subscription and credits; restore purchases |
3. Why we process your data (legal bases)
For users in the EEA/UK/Switzerland, our legal bases under the GDPR are:
| Processing | Legal basis |
|---|---|
| Providing the AI editing service you request (uploading, generating, storing your creations, account management) | Contract (Art. 6(1)(b)) |
| Sending your photos/prompts to third-party AI providers — done only after you give the explicit in-app AI-processing consent | Consent (Art. 6(1)(a)); performance of contract (Art. 6(1)(b)) |
| Subscriptions, credits, purchase restore | Contract (Art. 6(1)(b)) |
| Product analytics (PostHog) | Consent (Art. 6(1)(a)) — opt-in toggle, withdrawable anytime in Settings |
| Push notifications | Consent — the operating-system notification permission, revocable in system settings |
| Crash/error diagnostics (Sentry), content moderation, fraud and abuse prevention, rate limiting | Legitimate interests (Art. 6(1)(f)) — keeping the service working, safe, and lawful |
| Retaining purchase and consent records | Legal obligation (Art. 6(1)(c)) and legitimate interests (defense of legal claims) |
Mend does not process photos to identify anyone, so GDPR Article 9 "special category" biometric processing does not apply — see Section 6 and our Face & Biometric Data Notice.
4. How AI processing works
Before your first use of AI features, the App asks for your explicit consent to AI processing (Apple and Google require this, and so do we). When you then run a generation:
- Your photo/video uploads over an encrypted connection into a private storage bucket only your account can access.
- The uploaded image is automatically checked by OpenAI's moderation service against prohibited content, via a time-limited private link. If you typed a custom prompt, the prompt text is also checked and may be automatically rewritten into a safer, provider-neutral instruction.
- The image link and the final effect instructions go to fal.ai, whose infrastructure runs the generative model. For video models, a pseudonymous account identifier is included for the provider's abuse prevention. No name or email is ever sent to fal.ai or OpenAI.
- Before the result reaches you, it is automatically checked by OpenAI's moderation service: for an image, the generated image itself; for a video, three still frames (first, middle and last) extracted from the generated video. If that check rejects the result, the result is deleted and never shown to you; if the check cannot be completed at all, the generation is failed rather than delivered unchecked — in both cases your credits are refunded.
- The result and a thumbnail are stored in your private gallery, and (if you allowed notifications) we send a push notification that contains no personal content — just "your creation is ready".
- If generation fails, is rejected by moderation, or times out, the credits for that job are automatically refunded.
- 24 hours after upload, your original photo or video is automatically and permanently deleted from our storage by a scheduled process that runs every minute (so deletion happens within about a minute of the 24-hour mark). It is deleted sooner if you delete the generation or your account first. After this, in-app features that need the original (such as the before/after comparison) are no longer available for that creation.
Content moderation, honestly described: uploaded images and custom prompts are checked automatically before generation, and every generated result is checked automatically after generation — the generated image, or for video three still frames extracted from the generated video, is sent to OpenAI's moderation service over a time-limited private link. If a moderation check cannot be completed, the generation is failed and refunded rather than delivered unchecked. We may additionally review and remove content that is reported to us or flagged by our systems, and we keep moderation decisions (pass/fail status and category codes) — not the flagged content itself — for abuse prevention.
5. Who processes your data (recipients)
We share personal data only with the processors below, only for the purposes shown. We never sell personal data and never share it for third-party marketing.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Authentication, database, private file storage, server functions | Account data, uploads, results, thumbnails, generation history, credits, consent records | EU (Ireland) |
| fal.ai | Runs the generative AI models (images and video) | Time-limited links to your uploads, effect instructions/prompts, model settings, pseudonymous account identifier (video models). For video results, fal.ai also extracts the still frames used for the post-generation safety check from the video it already holds | US |
| OpenAI | Automated content moderation of uploads and of generated results; prompt safety-check and rewrite | Time-limited links to your uploads and to your generated results (for video results, to still frames extracted from them); prompt text. No account identifier attached | US |
| RevenueCat | Subscription and purchase management | Random user ID, purchase history, product IDs, subscription status, price/currency/store country | US |
| Apple / Google | App distribution, payments (merchants of record), optional sign-in, push delivery (APNs/FCM) | Purchase processing on their side; sign-in identity if used; push routing | US / global |
| Sentry (Functional Software, Inc.) | Crash and performance monitoring | Scrubbed crash/error/performance events linked to your random user ID; device/OS context. No photos, prompts, URLs, tokens, emails, or screenshots | EU data region (Germany) |
| PostHog | Product analytics — only if you opt in | Scrubbed usage events linked to your random user ID | EU Cloud |
| Expo | Push-notification delivery service (relays to APNs/FCM) | Push token, platform, notification payloads (which contain no personal content) | US |
5.1 AI training
Your content is not used to train AI models
Mend does not train any AI models on your photos, videos, prompts, or results. Under their published API terms, fal.ai and OpenAI state that content submitted through their APIs is not used to train their models. Providers may retain API data for a limited period for abuse monitoring under their published policies: see the fal.ai Privacy Policy, fal.ai media-retention documentation, and OpenAI Privacy Policy.
5.2 Other disclosures
Beyond the processors above, we disclose personal data only: when required by law or valid legal process; to protect the rights, safety, or property of users, the public, or Mend (including reporting child sexual abuse material to authorities); or in connection with a transfer of the Mend service to a successor operator, with notice to you.
6. Photos that contain faces
Mend performs no facial recognition and creates no faceprints, face templates, face embeddings, or face databases. Faces in your photos are processed solely to render the edit you requested. Because no data capable of identifying a person is ever created, this processing is not "biometric identification" under laws such as GDPR Article 9 or the Illinois BIPA. Full details, including our voluntary safeguards, are in the Face & Biometric Data Notice — the document the App calls the "Biometric Policy".
7. Analytics and diagnostics in detail
- PostHog (product analytics) is disabled until you opt in — either via the optional checkbox on the consent screen during onboarding or via Settings > "Analytics & Performance" — and you can opt out again at any time in Settings. Events are filtered on-device before sending: photo content, prompt text, emails, names, URLs, file paths, and tokens are stripped or redacted by construction. Session replay is disabled. Events are linked to your random user ID so we can count users — not to your name or email.
- Sentry (crash reporting) runs by default under our legitimate interest in keeping the App working. It is configured to send no personal content: screenshots and view-hierarchy capture are off, request data is dropped, the user record is reduced to your random user ID, and all messages pass the same redaction rules as analytics. It is independent of the analytics toggle.
8. Storage and security
- All uploads, results, and thumbnails live in private storage buckets — never publicly accessible — under a per-user path, protected by row-level security so each account can only reach its own files.
- Files are accessed through short-lived signed URLs (typically 15 minutes for media, up to 1 hour for thumbnails and provider processing links).
- All data is encrypted in transit (TLS), and our storage providers encrypt data at rest.
- Server-side checks enforce ownership on every media request, webhook calls are authenticated (cryptographic signature verification for the AI provider; a secret header for the payments provider), and generation endpoints are rate-limited.
No system is perfectly secure; we cannot guarantee absolute security, and we hold no formal security certifications.
9. How long we keep data (retention)
| Data | Kept until |
|---|---|
| Uploaded photos/videos (inputs) | Automatically and permanently deleted 24 hours after upload — or sooner, if you delete the generation they belong to or delete your account. Deleting a creation in the App removes its uploaded photo, result, and thumbnail together |
| Generated results and thumbnails | You delete them or your account |
| Account data, generation history, credit ledger, favorites | Account deletion |
| Moderation and abuse-prevention records (decisions and counters — no content) | Moderation decisions and usage records are automatically deleted after 90 days — or on account deletion, if that comes sooner. Rate-limit counters are kept until account deletion |
| Content and illegal-content reports (fixed reason and pseudonymous references — no copied media or report text) | Up to 3 years for safety review, dispute handling, and legal compliance |
| Push tokens | Account deletion, or automatically deactivated when your device unregisters |
| Data-export files | Cached briefly server-side (about 7 days) to enforce the export cooldown; export media links expire after 1 hour |
| Purchase records | After account deletion, a pseudonymous purchase record is retained (see Section 10) for restore-purchases integrity and financial/tax record-keeping required of a Lithuanian sole trader. The associated pseudonymous credit wallet is purged within about 90 days once empty, and at most 3 years after your last purchase activity |
| Consent records | After account deletion, kept in pseudonymized form (network address and device details removed; the identifier no longer links to any account data) for as long as reasonably necessary to demonstrate that valid consent existed, generally no longer than applicable limitation periods for legal claims |
| Crash diagnostics (Sentry) | Rolling window under the provider's standard retention (approximately 90 days) |
| Analytics events (PostHog, opt-in only) | Kept while needed for product analytics; you can opt out at any time, which stops all further collection. When you delete your account, your analytics profile and its events are deleted as part of the deletion process |
10. Deleting your data and exporting it
10.1 In the App
- Delete one creation: open it and delete — this removes the uploaded photo, the result, the thumbnail, and the job record.
- Delete your account: Settings > Delete Account (double confirmation). This permanently deletes your uploads, results, thumbnails, database records, and login. If any step is interrupted, an automatic process retries until deletion completes.
- Export your data: Settings > Export My Data produces a machine-readable file with your account data, generation history, purchase and credit records, consent record, and one-hour download links for your media (GDPR Art. 20 portability). Exports have a cooldown of about 24 hours between requests.
10.2 On the web
You can also request deletion or export without the App: email support@usemend.app with the subject "Account Deletion Request" (or use the links on our Support page).
10.3 What remains after account deletion — full honesty
- A pseudonymous purchase record is retained. Our payments processor (RevenueCat) keeps the customer record keyed by a random identifier, with no name, email, photo, or other personal content. We keep it because deleting it would permanently break "Restore Purchases" — if you ever repurchase or restore on the same Apple/Google account, this record is what returns any unspent purchased credits to you. It also serves as a financial record.
- A minimal pseudonymous credit wallet is retained in our own database. It contains only your remaining purchased-credit balance, any remaining subscription credits and their current credit-period metadata, keyed by the payment processor's stable purchase identifier — no name, email address, photos, or prompts. We keep it so unspent purchased credits can be returned if you restore purchases later, so subscription credits can be restored only while their original paid credit period remains current, and to prevent abuse through repeated account deletion and restoration. Subscription credits still reset or expire on their normal schedule and deletion never creates a fresh allowance (legal bases: legitimate interest in fraud prevention and statutory accounting obligations — GDPR Art. 6(1)(f), 6(1)(c) and 17(3)(b)). Once empty it is purged within about 90 days, and in any case the wallet is permanently deleted no later than 3 years after your last purchase activity.
- Pseudonymized consent and purchase-event records are retained as described in Section 9, de-linked from your identity.
- Active subscriptions are not cancelled by account deletion. Subscriptions live with Apple/Google — cancel them in your device's subscription settings (see Section 12 of the Terms of Service).
11. International transfers
Your stored content lives in the EU: our Supabase project is hosted in the EU (Ireland), and Sentry and PostHog are configured to use their EU regions. Some processors (fal.ai, OpenAI, RevenueCat, Expo, Apple, Google) process data in the United States. Where personal data is transferred outside the EEA, we rely on the safeguards in each provider's data-processing terms — principally the EU Standard Contractual Clauses (SCCs), supplemented by the EU–US Data Privacy Framework where the provider is certified. Media shared with AI providers is additionally protected by time-limited access links and deleted from our storage 24 hours after upload. You can request more information about these safeguards at support@usemend.app.
12. Your rights
You can exercise these rights in-app (deletion, export) or by emailing support@usemend.app:
- Access your data (Art. 15) and portability (Art. 20) — the in-app export covers both;
- Rectification of inaccurate data (Art. 16);
- Erasure (Art. 17) — in-app account deletion, or by email;
- Restriction of processing (Art. 18) and objection to legitimate-interest processing (Art. 21);
- Withdraw consent at any time (Art. 7(3)) — analytics via the Settings toggle; AI-processing consent by ceasing to use AI features or emailing us — without affecting past processing;
- Complain to a supervisory authority. Our authority is the Lithuanian State Data Protection Inspectorate — Valstybinė duomenų apsaugos inspekcija (VDAI), https://vdai.lrv.lt. You may also complain to the authority in your own EU country.
We may need to verify your identity before acting on a request. We aim to respond within 30 days; the GDPR permits an extension of up to two further months for complex requests, and we will tell you if we need it.
13. California and other US state privacy rights
If you live in California (CCPA/CPRA) or a state with a similar law, you have rights to know, access, correct, and delete personal information, and to opt out of "sale" or "sharing" of personal information.
We do not sell or share your personal information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We also do not use or disclose sensitive personal information (such as photos that contain faces) for any purpose other than providing the service you request, security, and legal compliance — the purposes permitted without a "limit use" right under the CPRA.
Categories collected in the last 12 months: identifiers (random user ID, install ID, email if you sign in); commercial information (purchases, credits); audio/visual information (photos/videos you upload and results); internet activity (app usage/diagnostics as described in Section 2); inferences are not drawn. Categories disclosed for a business purpose: to the processors in Section 5 only. Mend is a 13+ service and we do not knowingly collect data from children under 13. To exercise rights, use the in-app tools or email support@usemend.app; you may use an authorized agent. We will not discriminate against you for exercising your rights. Residents of Brazil (LGPD) and other regions with similar laws may exercise the equivalent rights the same way.
14. Children
Mend is intended for users aged 13 and older, and the App's store listings carry a corresponding age rating. We do not knowingly collect personal data from children under 13. Users under 18 may use Mend only with permission from a parent or legal guardian. In EEA countries where the age for independently consenting to online data processing is above 13, a parent or legal guardian must authorize that processing. If you believe a child under 13 has used Mend, or that a minor used it without required authorization, contact support@usemend.app and we will investigate and delete the account and its data where required.
15. Automated decision-making
We use automated systems for content moderation (images and prompts), credit accounting, and abuse prevention (rate limits, concurrency caps, cooldowns). These may automatically reject a generation or temporarily restrict requests; rejected generations have their credits automatically refunded. These systems do not produce legal or similarly significant effects on you; if you believe a moderation or restriction decision was wrong, email support@usemend.app and a human will review it.
16. Data breaches
If a personal-data breach occurs, we will notify the VDAI within 72 hours where the GDPR requires it, inform affected users without undue delay when the breach is likely to result in a high risk to them, and document the incident.
17. Changes to this policy
We may update this policy as the App or the law changes. We will update the effective date above and, for material changes, notify you in the App or by email and refresh consent where the law requires it. Earlier versions are superseded by this one.
18. Contact
- Data controller: Lukas Vaičiulis, operating Mend
- Location: Vilnius, Lithuania, European Union
- Email: support@usemend.app
- Support page: https://usemend.app/support
- Supervisory authority: VDAI — https://vdai.lrv.lt
Related documents: Terms of Service · Face & Biometric Data Notice