Aphilly
Terms of ServicePrivacy PolicyCookie PolicyImprint / Contact

Privacy Policy

Last updated: 2026-07-26

1. Controller & contact

Data controller: Riddle OÜ (registry code 17254064), Estonia. Privacy contact: info@riddle.ee.

2. What we collect and why

DataPurposeLawful basisRetention
Email, name, avatar, Google account idAccount & authenticationContract (Art. 6(1)(b))Until account deletion
Stripe customer id, purchase & credit-ledger historyBilling, fraud prevention, accountingContract + Legal obligationLedger retained for accounting (tax law) even after account close
Uploaded images, generated images, promptsProviding the core generation serviceContractUntil you delete them / account deletion
Discovered ASINs, blacklist, preferencesAmazon product discovery & personalizationContractUntil account deletion
Amazon Associates tracking ID (affiliate tag)Building your affiliate links on generated pinsContractUntil you change/remove it or delete your account
Referral code & attributed purchasesRunning the referral programLegitimate interest (Art. 6(1)(f))Up to 24 months after the referral, for reconciliation
IP address, request countersRate limiting, abuse prevention, securityLegitimate interestShort-lived (≈24h cache TTL)
Terms acceptance record (version accepted & timestamp)Proving which version of these terms you agreed toLegal obligation + Legitimate interestUntil account deletion, then retained with billing records where needed as evidence
Cookie choice (accepted/rejected + timestamp)Honouring and evidencing your cookie decisionLegal obligation (Art. 7(1))Stored in your browser until you change it or clear storage
Analytics usage data (pages viewed, approximate region, device/browser, anonymised IP) — only if you accept analytics cookiesAggregate statistics to improve the ServiceConsent (Art. 6(1)(a))Up to 14 months in Google Analytics; cookies up to 2 years
Checkout consent record (immediate performance & withdrawal waiver)Evidence of consent required by EU consumer lawLegal obligation (Art. 6(1)(c))Held by Stripe with the payment record for the statutory accounting period

3. Sub-processors

We share data with the following processors, each under a data-processing agreement:

  • Hosting/CDN: Vercel Inc.
  • Database: Neon (PostgreSQL)
  • Cache/queue: a managed Redis hosting provider (used for short-lived caching and the generation job queue). We will name the current provider on request — email us.
  • Object storage: Amazon Web Services (S3), currently in the AWS us-east-1 region (see §4 on our planned move to an EU region)
  • Payments: Stripe
  • AI image/text generation: OpenAI
  • Amazon product data (bestseller discovery): Rainforest API (TrajectData)
  • Authentication: Google
  • Analytics: Google Analytics 4 (Google Ireland Limited) — only after you accept analytics cookies; see our Cookie Policy

3a. Amazon product discovery

When you discover products, we query a third-party Amazon data provider (Rainforest API) to retrieve publicly available Amazon catalog data — product titles, images, ASINs, and ranking. This is Amazon's product data, not your personal data, and we store the products you keep against your account so you can generate pins from them. The affiliate links on your generated pins are built from the Amazon Associates tracking ID you provide; we do not track clicks, sales, or commissions on your links — that happens in your own Amazon Associates account.

3b. AI generation & what we send to OpenAI

To generate an image or its title and description, we send the product image and the product description/style choices for that generation to OpenAI, which processes them on our behalf under its API terms. We do not send your name, email, or payment details. OpenAI states that data submitted through its API is not used to train its models, and may be retained by OpenAI for a limited period for abuse monitoring before deletion. Because the generated result is returned to us and stored in our own storage, deleting an image in Aphilly deletes our copy; it does not control any transient copy held by OpenAI under its own retention policy.

3c. Deleting your data & backups

When you delete an image, or delete your account, we remove your images from our active object storage and your rows from our active database. Copies may persist for a short period in our hosting providers' encrypted backups and point-in-time recovery snapshots before those expire on their normal schedule, because such backups exist to recover from failure and cannot be edited selectively. We do not restore deleted accounts from backup. As noted in the table above, billing and credit-ledger records are kept after account deletion where accounting and tax law requires it — these are financial records, not your images or prompts.

4. International transfers

Several of our processors are based in the United States (OpenAI, Stripe, Google), and our object storage and database are currently hosted in a US AWS region (us-east-1). Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses and/or the processor's EU–US Data Privacy Framework certification as the transfer safeguard. We are working to migrate our database and object storage to an EU region to minimise such transfers; this policy will be updated when that migration completes. You can request details of the safeguards for a specific processor by emailing info@riddle.ee.

5. Your rights

Under the GDPR you can access, rectify, erase, restrict, port, and object to processing of your data, and lodge a complaint with your supervisory authority. Use Account → Privacy & data to export or delete your data, or email info@riddle.ee. We respond within 30 days.

6. Cookies & analytics

We use strictly necessary cookies (sign-in and CSRF protection) and a functional first-party referral store, neither of which requires your consent. In addition, if and only if you accept on our cookie banner, we use Google Analytics 4 to measure aggregate site usage so we can improve the product — legal basis: your consent (Art. 6(1)(a)), withdrawable at any time via Cookie settings in the site footer. If you reject, or do not answer, the analytics script is never loaded and no analytics cookie is set; withdrawing also deletes any analytics cookies already present. We do not use advertising, ad-targeting, or cross-site tracking cookies. The full inventory, retention periods and transfer details are in our Cookie Policy.

7. Security & breaches

We take appropriate technical and organisational measures to protect your data. In particular: data is transmitted over encrypted (HTTPS/TLS) connections; your uploaded and generated images are stored in a private object-storage bucket with public access blocked, and are served only through short-lived, ownership-checked links; every request for your data is scoped to your own account, so one user cannot access another user's products, images, or billing records; we never see or store your full payment-card details (card data is handled entirely by Stripe); and access keys and secrets are held server-side only and are never shipped to the browser.

If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours where required, and will inform affected users without undue delay when the breach is likely to result in a high risk to them.

8. Children

The Service is not directed to children under 16.

9. Changes

We will post updates here and, for material changes, notify you in-app.

← Back to app© 2026 Aphilly. All rights reserved.