Privacy Policy

1. Overview and Agreement

1.1. This Privacy Notice outlines how we handle personal data collected (Section 3) through the AI Remodel - Interior Design application and its associated services (collectively, the "Service"), the details of our data processing practices (Section 4), and your statutory rights regarding your personal information (Section 10).

1.2. We utilize Google services to enhance application performance, present tailored advertisements, and analyze usage patterns. Further information on Google's data handling practices is available via their privacy documentation.

1.3. By accessing or using the Service, you confirm that (i) you have reviewed, understood, and accepted the terms of this Privacy Policy and the data practices described herein, and (ii) you are at least 18 years old. If you cannot make these confirmations or do not consent to these terms, you must refrain from using the Service, terminate your user account, request data deletion, cancel active subscriptions, and uninstall the app from your devices.

1.4. The Service is strictly intended for individuals aged 18 and older. We do not intentionally gather or process data from minors. If you discover that a person under 18 has submitted personal data to us, please notify us immediately at general@pulseappsolutions.com.

1.5. For inquiries, concerns, or requests to exercise privacy rights, contact our support team at general@pulseappsolutions.com.

2. Data Controller Identification

The entity responsible for processing your personal data ("we", "us", or "our") is PulseApps Solutions OÜ, registered at Harju maakond, Tallinn, Kesklinna linnaosa, Maakri tn 19, 10145.

3. Types and Sources of Collected Data

3.1. We gather personal information from three main channels: direct submission by users, automatic logging during Service interaction, and transfers from third-party partners (such as purchase details from Apple App Store).

3.2. Direct Submissions:
- Contact & Identifiers: Full name and email address provided when contacting support or registering.
- App Content: Room photos, interior/exterior images, and custom text prompts entered for AI processing.
- Support Communications: Any information shared during customer service interactions.

3.3. Automated Data Collection:
- Device & Network Details: IP address, locale/language settings, time zone, device model/hardware specifications, OS version, ISP, mobile carrier, and persistent identifiers (e.g., IDFA/GAID).
- Interaction Logs: Feature usage patterns, page views, session duration, and usage frequency.
- Tracking Technologies: Cookies, Software Development Kits (SDKs), and similar mechanisms used for feature functionality, ad personalization, and traffic analytics. Disabling these tools may impact app functionality.

3.4. Third-Party Data Sources:
- Payment & Purchase Details: While financial account information is processed directly by payment gateways (we do not store full payment card details), we receive transaction summaries including purchase timestamps, amounts, payment method types, tokenized identifiers, and partial card numbers.

3.5. Sensitive Personal Data Exclusions: We do not intentionally request or process sensitive categories of data (e.g., racial/ethnic origin, political affiliations, religious beliefs, trade union membership, genetic/biometric data, health information, sex life, or criminal history).

3.6. Minimization & Accuracy: Data collection is strictly limited to what is essential for the purposes listed in Section 4. We implement reasonable measures to ensure stored information remains complete, accurate, and up-to-date.

4. Purposes and Legal Bases for Data Processing

4.1. Processing activities are anchored on four lawful grounds:
- Contractual Necessity: Execution and fulfillment of our agreement (Terms of Use) with you.
- Legitimate Interests: Enhancing, securing, and promoting our Service while balancing user rights.
- Statutory Obligations: Compliance with regulatory, tax, or law enforcement mandates.
- Consent: Explicit authorization granted for specific features or processing functions.

4.2. Overview of Processing Purposes:

Purpose / Activity

Data Categories

Lawful Grounds

Handling support inquiries and user communications.

Identifiers (Name, Email)

Contract Performance; User Consent

App development, optimization, performance tracking, and marketing.

Device & Geolocation Data (IP, Device ID, OS, etc.)

Contract Performance; Legitimate Interests

Website performance analysis and user journey tracking.

Log & Usage Data

Contract Performance; Legitimate Interests

Managing subscription statuses, validity periods, and renewals.

Subscription & Transaction Data

Contract Performance; User Consent

Enabling camera and photo library access for core app features.

Device Permissions (Camera, Gallery Access)

Contract Performance; User Consent

Generating interior design renders and AI suggestions.

Uploaded photos/images, text prompts

Contract Performance; User Consent; Legitimate Interests

4.3. Specific Legitimate Interests:
- Communicating updates and running targeted marketing campaigns.
- Analyzing platform analytics to refine user experience.
- Defending against legal claims and protecting system integrity.
- Enforcing our Terms of Use and preventing fraudulent activity.

5. Integrated Artificial Intelligence Features

5.1. The Service integrates generative artificial intelligence capabilities (including technologies like OpenAI's GPT-Image and Google's Gemini Nano Banana) to synthesize redesign options, property evaluations, and architectural concepts.

5.2. By utilizing these features, you authorize the processing of submitted media and text prompts by our integrated AI modules. We enforce strict data minimization: no personally identifiable metadata is linked or transferred to external AI processors. Users are advised not to submit files containing personal data or visible facial features. If inadvertently uploaded, such content is processed programmatically without personal identification or storage.

5.3. Usage Disclaimer: Submitted prompts and synthesized image outputs may be used internally for system training or externally in promotional materials demonstrating application features. Continuing to use the platform signifies consent to such operational and promotional uses.

5.4. Evolving AI Integrations: We reserve the right to incorporate additional AI service providers over time. All future third-party AI integrations will comply with the anonymization and security standards defined in this section.

6. Third-Party Sharing and Disclosures

6.1. We share necessary data elements with vetted third-party service providers, contractors, and corporate affiliates to operate, analyze, and market the Service. All partners are bound by legal obligations to preserve confidentiality and process data solely according to our directives.

6.2. Key Third-Party Service Providers:

Provider

Service / Feature

Operational Role

Privacy Documentation

Google LLC

Google Play / Google Ads / Firebase / Gemini

App distribution, marketing, cloud development, AI generation

https://policies.google.com/

OpenAI OpCo, LLC

GPT-Image

Generative image creation

https://openai.com/policies/privacy-policy/

Amplitude Inc

Amplitude

Product analytics and feature tracking

https://amplitude.com/trust

Appfigures, Inc

Appfigures

App store optimization & intelligence

https://appfigures.com/privacy

Appsflyer, Inc.

AppsFlyer

Mobile marketing attribution

https://www.appsflyer.com/legal/services-privacy-policy/

Fly.io, Inc

Tigris

Object storage infrastructure

https://fly.io/legal/privacy-policy/

Functional Software, Inc.

Sentry.io

Error monitoring and application performance

https://sentry.io/privacy/

Applovin Corporation

AppLovin

User interaction analytics & ad efficiency

https://www.applovin.com/privacy/

ClickHouse, Inc.

Langfuse

AI observability and data encryption

https://langfuse.com/privacy/privacy

Vercel Inc.

Vercel AI

API orchestration for AI platforms

https://vercel.com/legal/privacy-notice

6.3. Legal Disclosures: Information may be disclosed to law enforcement bodies, regulatory authorities, or courts to comply with statutory obligations, defend legal claims, or safeguard user safety.

6.4. Corporate Transfers: In the event of a merger, acquisition, asset sale, or organizational restructuring, user data may be transferred to successor entities as part of business assets.

7. International Data Transfers

7.1. Collected information may be transferred to and processed in countries outside your jurisdiction. When transferring data across borders, we implement appropriate protective frameworks.

7.2. European Economic Area Transfers: Transfers from the EEA to non-adequate jurisdictions rely on European Commission Standard Contractual Clauses (SCCs) or applicable adequacy decisions.

8. Security Measures and Data Retention

8.1. Safeguards: We employ physical, technical (e.g., SSL/TLS encryption), and administrative safeguards to prevent unauthorized access, loss, or disclosure. Data access is strictly restricted on a need-to-know basis.

8.2. Breach Protocols: Standardized incident management procedures are maintained to investigate suspected breaches and fulfill statutory notification duties.

8.3. Retention Periods: Personal data is retained for as long as required to provide the Service, resolve disputes, enforce agreements, or satisfy statutory record-keeping obligations. Storage periods are determined based on data sensitivity, potential exposure risks, and statutory requirements.

9. Revisions to this Notice

We reserve the right to modify this Privacy Policy periodically. Substantial modifications will be communicated through in-app alerts, email notifications, or revised consent prompts. Continued platform usage after updates indicates acceptance of the amended terms.

10. Jurisdiction-Specific Privacy Rights

10.1. General Rights Execution: Users may submit privacy inquiries or exercise statutory rights by emailing general@pulseappsolutions.com. Identity verification (such as account details or purchase timestamps) may be required to prevent unauthorized access.

10.2. Rights of EEA & UK Residents:
- Access, Rectification, and Erasure: Request confirmation of processing, correction of details, or account deletion.
- Restriction & Objection: Limit specific processing activities or object to legitimate interest processing.
- Data Portability & Consent Withdrawal: Receive a structured copy of submitted data or revoke previously given consent.
- Supervisory Complaints: EEA residents may lodge complaints with their local DPA; UK residents may contact the Information Commissioner's Office (ICO) via www.ico.org.uk or 0303 123 1113.

10.3. United States Resident Rights:
Residents of states including California, Colorado, Connecticut, Indiana, Iowa, Montana, Tennessee, Texas, Utah, and Virginia enjoy specific rights (Access, Correction, Deletion, Portability, Opt-Out of targeted advertising/sales, and protection against sole automated decision-making). Requests are handled within statutory timelines (typically 30–60 days).

10.4. CCPA / CPRA Notice: We do not sell personal information for monetary value. California residents may exercise formal opt-out preferences or request annual disclosures under California's "Shine the Light" law by contacting general@pulseappsolutions.com with subject "Request for California Shine the Light Privacy Information".

10.5. Do Not Track (DNT): The Service does not currently respond to automated browser DNT signals.

10.6. Canadian Residents: Rights under PIPEDA and provincial laws may be exercised via direct support contact, with recourse to the Office of the Privacy Commissioner of Canada.

11. Contact Details

For any inquiries concerning this Privacy Policy or data protection practices, please contact: general@pulseappsolutions.com.