Elanorya
AppsToolsGuidesBlogSupportPrivacyTerms
ENEnglish▾
  • ✓English
  • Türkçe

Privacy Policy

Last updated August 8, 2026 · Version 1.0

This policy explains how Jewelry AI actually handles your data, described from the systems running in production today. Where something is not settled yet — such as how long technical logs are kept, or how long deleted data survives in backups — this policy says so plainly instead of stating a period we cannot keep.

This document is also shown inside the Jewelry AI app.

Contents

  1. Controller and contact details
  2. Scope and age approach
  3. Account, authentication, and session data
  4. Uploaded content and generation data
  5. Library, support, and technical records
  6. Credits, purchases, and subscriptions
  7. Why we use data and applicable grounds
  8. AI-provider processing notice
  9. Other processors and recipients
  10. International transfers
  11. Retention, deletion, and restricted records
  12. Device permissions and local storage
  13. Security and incident handling
  14. Your rights and choices
  15. Changes and contact

Controller and contact details

Jewelry AI is operated under the Elanorya brand. Privacy and data-rights requests are received at privacy@elanorya.com; general support at support@elanorya.com; and security reports at security@elanorya.com. Each mailbox is in service and has been tested for two-way delivery and response. We answer data-rights requests through these channels; a postal address is available on request where a law requires one.

Scope and age approach

This policy covers the mobile app, related APIs, account emails, and published Elanorya web pages. The service is intended for people aged 18 or over and is not directed to children. We do not intend to knowingly create child accounts or collect children’s data for behavioural advertising. If you believe a child’s data is being processed, contact privacy@elanorya.com.

Account, authentication, and session data

We may process your email address, a one-way password hash, email-verification status, account lifecycle status, session-family identifiers, readable device labels, platform type, and security tokens stored only in hashed form. Google or Apple sign-in may provide a provider account identifier and verified email address. Social-login passwords are never provided to us. For Apple sign-in, a refresh token is encrypted on the application server and used only to revoke the Apple authorisation when the account is deleted; it is erased after successful revocation. Your preferred app locale may be stored on your account; choosing automatic language stores no locale and lets each device follow its own settings.

Uploaded content and generation data

We may process product or model images, selected tool and model, category, placement and other settings, editing instructions, input and output files, generation state, provider/model/version data, and technical request identifiers. Images may contain personal data, faces, bodies, or sensitive context. Upload only content for which you have all necessary copyright, privacy, personality, and model-release permissions.

Library, support, and technical records

Collections, favourites, deletion state, and library organisation are linked to your account. If you contact support, we process the message, attachments, and correspondence history. For reliability and security we may retain request ID, method, safe route, response status, duration, app version, and limited platform information. Logs are designed not to contain passwords, one-time codes, access or refresh tokens, API keys, email addresses, or image contents.

Credits, purchases, and subscriptions

We process wallet balance, append-only credit entries and lots, product identifiers, store transaction identifiers, purchase and subscription state, entitlements, refunds, chargebacks, and credit reversals. Jewelry AI does not process full payment-card details; payment is handled by Apple App Store or Google Play. RevenueCat links store lifecycle events to a server-generated user identifier. We do not send email as an unnecessary RevenueCat customer attribute.

Why we use data and applicable grounds

Data is used to create and secure accounts, perform the AI operation you request, store and display results, manage libraries and collections, verify purchases and subscription rights, administer credits, prevent duplicate or abusive transactions, provide support, comply with law, and establish or defend legal claims. Depending on your location, the legal ground may be performance of a contract, compliance with law, legitimate interests that do not override your rights, or a separate consent for an optional activity. We do not sell personal data for third-party behavioural advertising.

AI-provider processing notice

Depending on the tool, required input images, editing instructions, and generation settings may be sent to Google Gemini API or Replicate to produce the result you requested. A concise notice is shown again on the final review screen before submission. This transfer is necessary for that feature and is not described as optional marketing consent. Each request carries only what the feature needs. On the model try-on request we set the provider option that prevents the request from being retained on the provider side; that option is not available on the other provider calls, which follow the provider’s own default retention. We have not completed a contractual review of every provider’s data locations, retention behaviour, training settings, subprocessors, and deletion controls, and we do not claim one here. Temporary provider output is copied into controlled object storage before it is treated as delivered.

Other processors and recipients

Apple and Google may process store, payment, subscription, and social-login data; RevenueCat may verify purchases and entitlements; Resend may deliver verification and password-reset email; application data is held on server infrastructure we operate, in a PostgreSQL database; and uploaded and generated files are stored in Cloudflare object storage hosted in the European Union. Our published web pages are delivered through the Cloudflare edge network, which may process IP addresses, HTTP request metadata, and security telemetry for delivery, security, and abuse prevention, and whose security challenges may set strictly necessary cookies. Neither the app nor the website places analytics or marketing cookies. Authorised advisers or public authorities may receive limited data where legally required. The processors named above are the ones actually in use; if one is added, removed, or replaced, this section is updated.

International transfers

Technology providers are located outside Türkiye, and running the service transfers personal data to them today. Input images, editing instructions, and generation settings are sent to the Google Gemini API and to Replicate through their global endpoints, which offer no region selection. Uploaded and generated files are stored in Cloudflare object storage hosted in the European Union. Your email address is sent to Resend for verification and password-reset messages. Store, payment, and subscription data is processed by Apple and Google, and purchase verification by RevenueCat. Published web pages are delivered through the Cloudflare edge network. The transfer mechanism applicable to each of these activities has not been finalised; we do not state a completion date and do not claim a safeguard we cannot evidence. No processing currently relies on your separate explicit consent. If an activity comes to require it, consent will be requested independently from this notice and will explain the recipient, destination, purpose, and consequences of refusal.

Retention, deletion, and restricted records

Active accounts and creations are retained until you delete them or start account deletion, subject to stated retention limits. Normal deletion may first move a creation to a recoverable deleted area. Permanent deletion attempts to remove your unshared input and output assets. Account deletion removes direct identifiers such as email, password hash, social-login ID, and device ID; revokes sessions; hides content; and queues user files for purge. Restricted records linked to an internal user ID may remain for legally required financial records, fraud prevention, provider-cost reconciliation, and transaction integrity. Those records are not described as anonymous merely because direct identifiers were removed. A creation you delete in the normal way stays in the recoverable area for 30 days and is then removed permanently and automatically; an upload that is never linked to a creation is removed after 24 hours. A deletion request is completed within 30 days at the latest and removal normally begins immediately, but instantaneous or absolute erasure is not guaranteed: a storage-provider outage can delay it, and the queue keeps retrying until it succeeds. We have not fixed a log-retention period or a backup-deletion period, and this policy therefore does not state one rather than promising a period we could not keep.

Device permissions and local storage

Photo or file permissions are requested only when you select an image, save a result, or share a file. Refusal limits only the related feature. Authentication secrets are stored in supported Keychain or Keystore-backed storage. Non-critical settings such as language and appearance may be stored locally. AI-provider secret keys are never included in the mobile bundle.

Security and incident handling

Controls include encrypted transport, strong password hashing, short-lived access tokens, revocable refresh sessions, per-user and per-app isolation, request throttling, verified store webhooks, server-side cost authority, and data-minimised logging. No system can guarantee absolute security. Security reports should be sent to security@elanorya.com without passwords, one-time codes, or payment-card data. We keep a documented incident-response procedure covering the escalation path and, where a regulatory notification duty applies, the 72-hour assessment that duty requires.

Your rights and choices

You can permanently delete creations, close sessions, change supported preferences, and begin account deletion in the app. Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; obtain information about transfers; receive a portable copy of your data; withdraw a consent prospectively; and complain to your local supervisory authority. Users in Türkiye hold the rights set out in Article 11 of Law No. 6698, including learning whether their data is processed, requesting correction or erasure, and applying to the Personal Data Protection Board. We do not sell personal data and do not share it for cross-context behavioural advertising. To exercise a right, write to privacy@elanorya.com from your account email, stating which right you are exercising; a portable copy is prepared manually and sent to that address. Requests may require proportionate identity verification, and we ask only for what is reasonably needed to confirm authority — never send your password, a one-time code, an access token, or a full payment-card number. Where the law allows an authorised agent to act for you, we may ask for proof of authority and direct confirmation from the account holder. Requests are answered within the period set by the applicable law; our two-business-day support target is an initial-response goal and does not shorten or replace that period. If a request is refused, the reply explains why and, where required, the appeal or regulator route open to you. No data-protection officer or representative has been appointed at this time; if one is appointed, the name and contact address will be published here.

Changes and contact

A new date and appropriate in-app notice will accompany material policy changes. A new acceptance is requested only when legally required; presentation of a notice, contract acceptance, and optional consent are recorded separately. Privacy requests go to privacy@elanorya.com, security reports to security@elanorya.com, and general support to support@elanorya.com. The target for an initial human support response is two business days; statutory data-rights deadlines remain unchanged.

Apps

  • Jewelry AI

Legal

  • Privacy
  • Terms
  • Delete your data
  • About
  • Editorial policy
  • Brand

Contact

  • support@elanorya.com
  • privacy@elanorya.com

Elanorya