Privacy Policy
Last updated 2 September 2026
The short version. Imagik sends the photos you choose to edit to model providers so they can be edited, and keeps the result for seven days so you can get it back. It signs in with your Apple ID and nothing else. It carries no analytics, advertising or tracking SDKs. It does not sell your data, and it does not use your photos to train models. You can delete your account, and everything attached to it, from inside the app.
This policy explains what Imagik (“we”, “us”) collects when you use the Imagik iPhone app and the imagik.io website, why we collect it, who else sees it, and what you can do about it.
What we collect
Your account
Imagik uses Sign in with Apple, handled for us by Clerk. We receive a stable account identifier, and the name and email address Apple passes along. If you use Apple’s Hide My Email, we only ever see the relay address. There is no password, because we never create one.
Photos and prompts you submit
When you run an edit or a creation, the image you selected, any reference images attached to it, and the text of your prompt are uploaded to our servers and forwarded to the model provider that runs the job. Photos you only open in the app and never submit stay on your iPhone.
Job and billing records
We store the state of each job (which engine ran, at which quality, its status, and what it cost in credits), your credit balance, your plan, and the identifiers of the App Store transactions that granted your credits. We do not receive or store your payment card — Apple handles the payment and tells us only that a transaction is valid.
Device attestation
Every edit request is signed by your iPhone using Apple’s App Attest. We store the resulting public key and a counter so we can verify that later requests come from the same genuine app on the same device. This is a hardware-backed key, not an advertising identifier, and it cannot be used to track you across other apps.
Operational logs
Our hosting provider records ordinary server logs — timestamps, request paths, status codes, IP addresses — which are used to run and secure the service. Our own application logs record job outcomes and error classes; they are written not to contain prompt text, image contents or credentials.
What we do not collect
- No analytics, advertising, attribution or crash-reporting SDKs are bundled in the app.
- No advertising identifier (IDFA), and no App Tracking Transparency prompt, because there is nothing to track.
- No access to your photo library for reading. Imagik requests only add permission, to save images you export.
- No contacts, no location, no health data, no microphone.
Who else sees your photos
To edit an image, we have to send it to the engine that does the editing. Those providers are:
| Provider | What it receives | Why |
|---|---|---|
| OpenAI | Images, reference images and prompt text | Runs the Forge edit and creation engine, and the Quill prompt writer |
| Images, reference images and prompt text | Runs the Spark creation engine | |
| Our retouch model provider | Images and prompt text | Runs the Prism filter and look engine |
| Clerk | Your Apple sign-in identity | Authentication and account records |
| Vercel | Requests, images in private storage, server logs | Hosting, functions and file storage |
| Upstash | Job state, credit balances, attestation keys | Database |
| Apple | Purchases and subscription events | In-app purchase and billing |
We use these providers under commercial API terms, which means the content we send is processed to fulfil the request and is not used to train their models. We do not authorise any of them to use your photos for training, and we never do so ourselves. Each provider keeps its own limited copies for abuse monitoring under its own policy and retention schedule.
These providers process data in the United States and other countries. If you are using Imagik from the EU, the UK or elsewhere, your data will be transferred there.
How long we keep things
| Data | Retention |
|---|---|
| Result download links | Expire five minutes after they are issued |
| Submitted images and results | Seven days, then deleted |
| Job records | Seven days, then deleted |
| Credit balance and plan | For as long as your account exists |
| App Store transaction identifiers | Retained as long as needed to prevent a purchase being granted twice, and to meet tax and accounting obligations |
| Attestation keys | Until your account is deleted |
| Server logs | Per our hosting provider’s standard retention |
Images you save to your own device or Photos library are yours and are not covered by our retention — deleting your account does not reach into your phone.
Why we are allowed to do this
Where the UK GDPR or EU GDPR applies, our lawful bases are: contract, for everything needed to actually run the edits you asked for, hold your credits and deliver your results; legitimate interests, for security, abuse prevention, attestation and keeping the service running; and legal obligation, for tax and accounting records. We do not rely on consent for advertising, because we do not advertise to you.
Your choices and rights
- Delete your account. Profile → Delete Account, inside the app. This removes your job records, credit ledger, attestation keys and stored images on a best-effort basis, and then deletes your account itself. It cannot be undone, and unused credits are not refundable.
- Get a copy of your data, or ask us to correct it. Email us and we will respond within 30 days.
- Object or restrict. If GDPR applies to you, you can object to processing based on legitimate interests, and you can complain to your local supervisory authority.
- Manage your subscription. Subscriptions are handled by Apple: Settings → your name → Subscriptions.
- Hide images behind Face ID. Images and references you hide are gated on device.
Children
Imagik is not directed at children and is not intended for anyone under 13, or under the minimum age of digital consent in your country if that is higher. We do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.
Security
Connections use HTTPS. Every state-changing request is signed by your device with App Attest over the exact bytes of the request, and the server refuses requests it cannot verify. Uploaded images and results are held in private storage and reachable only through short-lived, owner-scoped links. No system is perfect, and we will notify you and the relevant authorities as required by law if a breach affects your data.
What is generated is not a photograph
Imagik’s output is produced by generative models. It is a plausible picture, not evidence of anything that happened. Do not present it as a factual record, and do not use Imagik to depict a real person in a way they have not agreed to.
Changes to this policy
If we change this policy in a way that materially affects you, we will update the date at the top and, where the change is significant, tell you in the app before it takes effect.
Contact
Questions, requests, or anything else about this policy: nathaniel@witit.com.