Paint Color Visualizer — Privacy Policy

Effective Date: August 24, 2026

Paint Color Visualizer ("the App") is developed by Mobile Card Games & Travel Apps LLC. This Privacy Policy explains what data the App collects, how it is used, and how your privacy is protected.

It covers both the iOS app on the App Store and the Android app on Google Play. The two versions behave identically from your point of view, but they reach our AI provider by different routes and store slightly different data. Where that matters, this policy says which platform it is describing.

1. Data We Collect

The app handles the following data:

The app does not collect your name, email address, location, or device advertising identifiers, and contains no analytics or advertising SDKs.

2. How We Use Your Data

When you tap to visualize a paint color, your room photo (resized and compressed) and a text description of the surfaces to repaint and the target color are sent to OpenAI's image-generation API (openai.com), which returns an edited image showing your room with the new paint color.

The route differs by platform. On iOS, the request travels over an encrypted HTTPS connection through AIProxy (aiproxy.com), a secure API relay service. On Android, it travels over an encrypted HTTPS connection through our own backend, hosted on Google Cloud (Firebase Cloud Functions), which forwards it to OpenAI and returns the result. In both cases the photo is handled only for the duration of that request; neither AIProxy nor our backend keeps a copy.

Room photos may incidentally include people. Any such photo is treated exactly the same way: sent to OpenAI only to generate the repainted image, never analyzed for identity, and never stored on any server we operate. Per OpenAI's API data-usage policy, data sent through the API is not used to train their models.

3. Third-Party Data Sharing

We do not sell, rent, or share your data with any other third parties.

Abuse prevention: every AI request the App sends carries a device-attestation token — Apple DeviceCheck together with your device's Apple identifier-for-vendor on iOS, and Google Play Integrity on Android. The Android app additionally sends a one-way hash of an app-specific device identifier once, on first launch, so that the single free visualization cannot be claimed repeatedly; we store only a further keyed hash of that value, which cannot be reversed to identify your device. All of this is used solely to prevent abuse and rate-limit AI requests. None of it is linked to your name or identity, and none of it is used for advertising or tracking.

4. Data Storage and Retention

5. Data Security

All data transmitted to third-party services is sent over encrypted HTTPS connections. No AI provider key is ever embedded in the App: on iOS the key is protected by the AIProxy relay service, and on Android it is held in Google Secret Manager and used only by our backend. Requests to our backend are accepted only from a verified, unmodified copy of the App (Firebase App Check with Google Play Integrity), and the anonymous credit balance can be read only by the account it belongs to and written only by our backend.

6. Your Rights

You have the right to:

Depending on where you live, privacy laws such as the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) give you rights over your personal data, including the rights to know, access, correct, and delete it. On iOS we hold nothing on our own servers, so there is typically nothing for us to access or delete — deleting the App deletes your data. On Android we hold the anonymous account described in section 4; you may contact us at the email below to have it and its records deleted. In either case, where the App processes data in transit or a third-party service described above collects data, you may contact us to exercise your rights and we will respond as required by applicable law.

7. Children's Privacy

The App is not directed at children under 13, and we do not knowingly collect data from children under 13. In some regions, including the European Union, a higher minimum age applies to consent for data processing; the same statement applies there — we do not knowingly collect data from anyone under the applicable age.

8. Data Breach Notification

In the unlikely event of a data breach affecting user data on any system we operate, we will notify affected users as required by applicable law.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Effective Date" at the top of this page.

10. Contact Us

If you have questions about this Privacy Policy or your data, please contact us at:

v5cqpsj4e3u4@opayq.com