Aphilly
Terms of ServicePrivacy PolicyCookie PolicyImprint / Contact

Privacy Policy

Last updated: 2026-07-19

1. Controller & contact

Data controller: Riddle OÜ (registry code 17254064), Estonia. Privacy contact: info@riddle.ee.

2. What we collect and why

DataPurposeLawful basisRetention
Email, name, avatar, Google account idAccount & authenticationContract (Art. 6(1)(b))Until account deletion
Stripe customer id, purchase & credit-ledger historyBilling, fraud prevention, accountingContract + Legal obligationLedger retained for accounting (tax law) even after account close
Uploaded images, generated images, promptsProviding the core generation serviceContractUntil you delete them / account deletion
Discovered ASINs, blacklist, preferencesAmazon product discovery & personalizationContractUntil account deletion
Amazon Associates tracking ID (affiliate tag)Building your affiliate links on generated pinsContractUntil you change/remove it or delete your account
Referral code & attributed purchasesRunning the referral programLegitimate interest (Art. 6(1)(f))Up to 24 months after the referral, for reconciliation
IP address, request countersRate limiting, abuse prevention, securityLegitimate interestShort-lived (≈24h cache TTL)

3. Sub-processors

We share data with the following processors, each under a data-processing agreement:

  • Hosting/CDN: Vercel Inc.
  • Database: Neon (PostgreSQL)
  • Cache/queue: Redis (managed Redis provider)
  • Object storage: Amazon Web Services (S3), currently in the AWS us-east-1 region (see §4 on our planned move to an EU region)
  • Payments: Stripe
  • AI image/text generation: OpenAI
  • Amazon product data (bestseller discovery): Rainforest API (TrajectData)
  • Authentication: Google

3a. Amazon product discovery

When you discover products, we query a third-party Amazon data provider (Rainforest API) to retrieve publicly available Amazon catalog data — product titles, images, ASINs, and ranking. This is Amazon's product data, not your personal data, and we store the products you keep against your account so you can generate pins from them. The affiliate links on your generated pins are built from the Amazon Associates tracking ID you provide; we do not track clicks, sales, or commissions on your links — that happens in your own Amazon Associates account.

4. International transfers

Several of our processors are based in the United States (OpenAI, Stripe, Google), and our object storage and database are currently hosted in a US AWS region (us-east-1). Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses and/or the processor's EU–US Data Privacy Framework certification as the transfer safeguard. We are working to migrate our database and object storage to an EU region to minimise such transfers; this policy will be updated when that migration completes. You can request details of the safeguards for a specific processor by emailing info@riddle.ee.

5. Your rights

Under the GDPR you can access, rectify, erase, restrict, port, and object to processing of your data, and lodge a complaint with your supervisory authority. Use Account → Privacy & data to export or delete your data, or email info@riddle.ee. We respond within 30 days.

6. Cookies

See our Cookie Policy. We use only essential cookies plus a functional first-party referral store; we do not use advertising cookies.

7. Security & breaches

We take appropriate technical and organisational measures to protect your data. In particular: data is transmitted over encrypted (HTTPS/TLS) connections; your uploaded and generated images are stored in a private object-storage bucket with public access blocked, and are served only through short-lived, ownership-checked links; every request for your data is scoped to your own account, so one user cannot access another user's products, images, or billing records; we never see or store your full payment-card details (card data is handled entirely by Stripe); and access keys and secrets are held server-side only and are never shipped to the browser.

If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours where required, and will inform affected users without undue delay when the breach is likely to result in a high risk to them.

8. Children

The Service is not directed to children under 16.

9. Changes

We will post updates here and, for material changes, notify you in-app.

← Back to app© 2026 Aphilly. All rights reserved.