TattooMaker

Privacy Policy

What TattooMaker collects, why, who processes it (hosting, AI models, payments), how long we keep it and your privacy rights.

Last updated: 2026-10-05

This Privacy Policy explains how TattooMaker (“TattooMaker”, “we”, “us”) collects and uses personal data when you use tattoomaker.org (the “Service”).

Who is responsible

TattooMaker is operated by Chen Zhe, an individual based in the People’s Republic of China, who is the controller of your personal data. Privacy questions and requests: support@tattoomaker.org.

What we collect

  • Account data — when you sign in with Google we receive your name, email address and profile picture. We don’t receive your Google password.
  • What you create — the prompts and settings you submit, the designs generated for you and the designs you choose to share.
  • Photos you upload — photos for photo to tattoo, cover-ups and AI try-on. They are stored privately, used only for your request and deleted automatically within 24 hours. Photos you use in the stencil maker and browser try-on never leave your device.
  • Purchases — your credit balance, the products you bought and order references. Payments are processed by Waffo (see below); we never see or store your full card details.
  • Safety records — prompts, photos or designs that our safety checks block, the safety model’s verdict, and reports you send or receive.
  • Technical data — IP address, browser type and request logs, used for security, abuse prevention and keeping the Service running.

Why we use it

  • To provide the Service: generate, save and show your designs, and keep your credits and purchases in order (performance of our contract with you).
  • To keep the Service safe and lawful: moderate content, prevent abuse and fraud, and meet legal obligations (legitimate interests and legal obligation).
  • To support you and tell you about important changes to the Service or your account.

We don’t sell your personal data, we don’t use it for advertising, and we don’t use your prompts, photos or designs to train AI models.

Who processes it

We share data only with service providers that help us run TattooMaker, under contracts that limit their use of it:

  • Cloudflare — hosting, database and file storage.
  • Google — sign-in, and the Gemini Flash model that safety-checks prompts, photos and designs.
  • Kie.ai — the API gateway we use to reach the image models. Your prompt, and the photo or design being edited, are sent through it to ByteDance (Seedream) or OpenAI (GPT Image), depending on the model you choose, to generate your images.
  • Waffo Pancake — our payment processor and Merchant of Record, which processes payments, handles tax and issues receipts. Waffo receives your email address and payment details directly and acts as an independent controller for that data under its own privacy policy. Card data is processed by Waffo Pancake and never stored on our servers.

We may also disclose data if the law requires it, to protect people’s safety (for example, reporting child sexual abuse material to the authorities), or as part of a sale or reorganisation of the business.

Cookies and analytics

We use only essential cookies: one that keeps you signed in and one that identifies your browser to our design tools before you sign in. We don’t use advertising or cross-site tracking cookies, and we don’t run third-party analytics that track you across sites.

Emails

We only send service emails (sign-in, receipts from Waffo, account and policy notices). We don’t send marketing emails; if we ever do, they will need your consent and include an unsubscribe link.

How long we keep it

  • Uploaded photos — deleted within 24 hours.
  • Designs — until you delete them or your account.
  • Account data — until you delete your account, then removed within 90 days.
  • Safety records — at least 12 months, and longer where a serious violation must be kept for legal reasons.
  • Purchase records — as long as tax and accounting laws require.

Your rights

Depending on where you live (for example under the GDPR, UK GDPR or California law), you can ask to access, correct, delete or export your personal data, object to or restrict how we use it, and withdraw consent where we rely on it. Email support@tattoomaker.org from your account email and we’ll respond within 30 days. You can also complain to your local data protection authority.

International transfers

Our providers may process data outside your country, including in the United States. Where required, transfers are protected by safeguards such as the European Commission’s Standard Contractual Clauses.

Security

Data is encrypted in transit, access is limited to what is needed to run the Service, and uploaded photos are short-lived by design. No system is perfectly secure: if a breach affects your personal data, we will notify you and, where required, the relevant authority within 72 hours of becoming aware of it. Please contact us at once if you suspect a problem with your account.

Third-party links

Our pages may link to other websites, such as Waffo’s checkout or a model provider’s site. Their privacy practices are governed by their own policies.

Children

You must be 18 or older to create an account. We don’t knowingly collect personal data from children; if you believe a child has given us personal data, contact us and we’ll delete it.

Changes

We’ll post any update here with a new date and announce material changes on the site before they take effect.