Legal
Privacy Policy
Last updated: August 17, 2026
1. Who we are
MimicAI is an AI photo editor. We are the data controller for your personal data — we decide how and why it is processed.
Questions: support@mimicai.app with the subject line “Data Protection Request.”
2. What we collect
We collect the minimum needed to run the service.
Account data
- Email address (Google sign-in or email code)
- User ID (generated automatically)
- Authentication method
- Your language preference
Photos you upload
- Images you choose to upload for generation, stored in Cloudflare R2
AI-generated outputs
- Images created from your uploads, stored in R2 next to your originals
Generation metadata
- Template used, model, prompt, timestamps, status, and credits charged
- Used to deliver results, refund failed jobs, and operate the product
Payment data
- Handled by Creem (our merchant of record / payment processor)
- We store customer and subscription references, status, and credit balance
- We never see or store your full card number
Transactional email
- If email is configured, we may send sign-in codes and essential account notices
- We do not send marketing emails
3. Why we process your data (legal basis)
Contract performance (GDPR Art. 6(1)(b))
- Creating and managing your account
- Processing subscriptions, payments, and credits
- Delivering AI-generated images
Explicit consent (GDPR Art. 6(1)(a) / Art. 9 where applicable)
When you upload a photo that includes a face, you consent to us sending it to our AI provider solely to generate the output you requested. We do not perform biometric identification or facial recognition.
Legitimate interest (GDPR Art. 6(1)(f))
- Security, abuse prevention, and rate limiting
- Diagnosing failures in generation
Legal obligation (GDPR Art. 6(1)(c))
- Keeping payment records required for tax and accounting
4. Who we share data with
These processors help us run the service. We do not sell your data.
| Service | Purpose | Location |
|---|---|---|
| Cloudflare | Hosting (Workers), database (D1), object storage (R2) | Global |
| Replicate | AI image generation | United States |
| Creem | Checkout, subscriptions, billing portal | International |
| OAuth sign-in (if you choose Google) | United States | |
| Google Analytics | Product usage analytics | United States |
| Resend | Transactional email (if configured) | United States |
5. AI-specific disclosure
When you generate an image:
- You upload a photo and pick a template (or write a prompt)
- We send the photo and prompt to Replicate
- Replicate returns an image
- We store the output in our own R2 bucket
6. How long we keep data
- Uploads and outputs: until you delete the generation in Gallery, or we delete them after an account-deletion request
- Account data: until you ask us to delete your account
- Payment records: retained as required for tax and legal compliance
7. International transfers
Our processors may be located outside your country (including the United States). Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses or the EU-US Data Privacy Framework where a processor is certified.
8. Your rights
Under GDPR / UK GDPR you may request access, correction, erasure, portability, restriction, objection, and withdrawal of consent for facial-image processing.
- Delete individual results in Gallery
- For account deletion or other requests: email support@mimicai.app
- We aim to respond within 30 days
You can also complain to your local data protection authority (for example the ICO in the UK or your EU DPA).
9. Cookies
We use strictly necessary session cookies or tokens to keep you signed in. We also load Google Analytics 4, which sets `_ga` and `_ga_*` cookies to measure page views and in-product usage. We do not load advertising pixels.
10. Children
MimicAI is for users 13 and older. If you are 13–18, review this policy with a parent or guardian. Some countries require 16+ or parental consent. We will delete data if we learn it belongs to a child under 13.
11. Security
- TLS/HTTPS in transit
- Object access via our API and configured public media URLs
- Rate limiting on API endpoints
No system is perfectly secure. Report issues to support@mimicai.app.
12. Data breach notification
If a breach is likely to affect your personal data, we will notify the relevant authority where required, tell you if the risk to you is high, and keep a record of what happened and what we did.
13. Changes
We may update this policy. Material changes will be announced in the product or by email where we have it. Continued use after changes means you accept the update. If you disagree, stop using the service and request deletion.
14. Contact
MimicAI