Privacy Policy

Last updated: October 11, 2026

This policy explains what personal data Idetta collects, why, how long we keep it, who we share it with, and the choices you have. Idetta is operated by the Idetta team ("Idetta", "we"). For the purposes of data protection law (such as the GDPR), we are the controller of your personal data.

Photos used for identity documents show your face, and in many places face images can be treated as sensitive data. We therefore keep what we collect to a minimum and delete it on a schedule.

1. The Short Version

  • We use your photos only to make your document photo.
  • To do that, your photos are processed by third-party AI providers (see section 5).
  • We do not sell your personal data.
  • Your uploaded and processed photos are automatically deleted after 30 days, or sooner if you delete them yourself.
  • You can ask us to access, correct or delete your data at any time: support@idetta.com.

2. Data We Collect

a) Photos you give us

The images you upload and the versions we produce from them, plus the document type and country you select.

b) Account data

Your email address, and a password (stored in hashed form) if you register with email. If you sign in with a third-party provider such as Google or Apple, we receive the basic details they share with us, normally your name and email address. We do not receive your password from them.

c) Payment data

Purchases are handled by third-party payment providers and app stores. We receive confirmation of payment, the plan, amount and a transaction reference. We do not see or store your full card number.

d) Technical data

Device type, operating system, browser, language, IP address, approximate location derived from IP, and how you use the Service. We also keep short-term security logs (such as login times and IP) to detect abuse.

e) Communications

Messages you send to support and your email preferences.

We do not use your photos to identify you or to compare you with other people. Automated analysis of your photo is limited to checking and adjusting it against the photo requirements you selected.

3. Why We Use Your Data And On What Legal Basis

  • To create your document photo and deliver the Service: performance of our contract with you (GDPR Art. 6(1)(b)). Where face images are treated as special-category data, we rely on your explicit consent when you upload the photo (Art. 9(2)(a)), which you can withdraw by deleting the photo or your account.
  • To manage your account and subscription and give support: contract performance.
  • To secure the Service and prevent fraud and abuse: our legitimate interests (Art. 6(1)(f)).
  • To meet legal obligations such as tax and accounting records: legal obligation (Art. 6(1)(c)).
  • To measure and improve the Service using analytics: legitimate interests, or your consent where the law requires it.
  • To send you product news and offers: your consent, which you can withdraw at any time using the unsubscribe link. Service emails (receipts, security alerts) are not marketing.

4. How Long We Keep It

  • Uploaded and processed photos: deleted automatically 30 days after upload, or immediately when you delete them or your account.
  • Account data: until you delete your account, then removed within a reasonable period, except where we must keep some data.
  • Payment and invoice records: kept for as long as tax and accounting law requires.
  • Security logs: a limited period, not longer than necessary.

5. Who We Share Data With

We do not sell your personal data. We share it only with the following:

  • AI service providers. To analyse and edit your photo, we send it to third-party AI model providers (for example, large AI providers such as OpenAI or Google). Which provider handles a given request may vary. We send only what is needed to process your request, and we do not use Your Photos to train our own models. Each provider handles data under its own terms and privacy policy.
  • Infrastructure providers. We use Supabase for hosting, database and file storage, and other providers for email delivery, analytics and error monitoring.
  • Payment providers and app stores, to process your purchases.
  • Authorities or advisers, where the law requires it or to protect legal rights.
  • A buyer or successor if Idetta is part of a merger or sale, who must honour this policy.

We do not send your photos to passport, visa or other authorities. You submit the photo to them yourself.

6. International Transfers

Our providers may process data in countries other than yours, including outside the EEA and the UK. Where required, we rely on safeguards such as the EU Standard Contractual Clauses or an adequacy decision.

7. Security

We use encryption in transit (HTTPS/TLS), access controls limited to people who need access, and regular reviews of our systems. No online service is completely risk-free, so please use a strong, unique password. If a breach affects your data, we will notify you and the authorities as the law requires.

8. Cookies And Similar Technologies

We use essential cookies and local storage to keep you signed in and remember settings. With your consent where required, we also use analytics and marketing cookies. You can change your choices through the cookie settings or your browser. Blocking essential cookies may stop parts of the Service working.

9. Your Rights

Depending on where you live, you may have the right to: access your data; correct it; delete it; restrict or object to certain processing; receive a copy in a portable format; withdraw consent; and complain to your local data protection authority. To use any of these, write to support@idetta.com from the email linked to your account. We may need to verify your identity, and we will respond within the period required by applicable law (normally one month).

Account deletion: you can delete your account in the app settings, or request it by email. Deletion removes your photos and profile data, subject to section 4.

US residents: we do not sell personal information or share it for cross-context behavioural advertising. Residents of certain US states have additional rights, including to access, delete and correct their data, which you can exercise as described above.

10. Children

Idetta accounts are for adults. A parent or guardian may upload a child's photo to prepare a document photo for that child. We do not knowingly create accounts for or collect data directly from children. If you believe a child has used the Service on their own, contact us and we will delete the data.

11. Third-Party Links And Logins

Sign-in providers and other external sites have their own privacy policies, which we do not control.

12. Changes To This Policy

If we make material changes, we will tell you by email or in the app before they take effect. The date at the top shows when the policy was last updated.

13. Contact

Idetta team Email: support@idetta.com