Your information
Privacy Policy
This policy explains what Tatz collects, why we use it, when it leaves our systems, and the controls available to you. It covers the Tatz mobile application, website, and related services.
Effective and last updated: September 21, 2026
We use your information to operate Tatz, generate and store tattoo designs, secure accounts, and manage subscriptions. We do not sell personal information or use it for cross-context behavioural advertising. Designs marked public can be viewed and saved by other Tatz users. New designs are public by default, so choose private before generating if you do not want a design in Explore.
01
Scope and our role
This Privacy Policy applies when you use the Tatz mobile application, tatz.ai, api.tatz.ai, or any service that links to this policy (together, the “Service”). “Tatz,” “we,” “us,” and “our” refer to Reev Tech Inc., a corporation incorporated under the laws of Canada and doing business as Tatz. Reev Tech Inc. is the controller of personal information described in this policy unless a different role is stated. Our registered office is 3080 Yonge Street, Suite 6060, Toronto, Ontario M4N 3N1, Canada.
This policy does not govern a tattoo artist, app store, identity provider, device platform, or third-party site acting under its own terms. Their privacy notices apply to their separate processing.
02
Information we collect
Information you provide or create
- Account and identity information. Tatz creates an anonymous Firebase account when you first use the app. If you link Apple or Google sign-in, we receive a provider identifier and associated account information made available by that provider, which may include your email address, name, or profile details. Our application database stores your Firebase user identifier and a Tatz user identifier.
- Creative content. We collect prompts, design names, tattoo style, colour, placement, size, detail level, edit instructions, visibility choice, generated images, and generated discovery tags. If you choose to submit them, we also process reference photos, source artwork, and edit masks.
- Preferences and activity. We collect onboarding responses, such as tattoo experience, preferred styles, and reasons for using Tatz; designs you create, save, edit, share, make private, or delete; and your virtual “ink” balance and ledger.
- Purchase information. RevenueCat and the applicable app store provide us with subscription product identifiers, purchase and renewal status, entitlement status, transaction references, and related technical information. We do not receive or store your full payment-card number.
- Communications. If you contact us, we collect the content of your message, contact details, and information needed to respond and keep an appropriate record.
Information collected automatically
- Identifiers and security data. We process an app-scoped random device identifier, Firebase identifiers and tokens, App Check attestation material, IP address, request time, route, response status, and similar authentication, fraud-prevention, and server-log data.
- Device and network data. Our providers may receive device type, operating system, app version, language, country or approximate location inferred from IP or store, user agent, network information, and diagnostics generated when a request fails.
- Service activity. We process feature requests, generation status, content visibility, timestamps, and subscription access necessary to provide and troubleshoot the Service.
Device permissions and on-device processing
Tatz may request camera, photo-library, microphone, speech-recognition, and photo-save permissions. Camera and library photos used only for tattoo try-on, placement, stencil, or similar local tools are processed on your device unless you choose to submit an image for cloud generation, editing, saving, or sharing. Speech recognition is performed by your device’s operating-system speech service and the resulting text is placed into your prompt. Your platform provider may process audio under its own privacy terms. You can change app permissions in device settings.
Website data
The public website does not currently use advertising trackers or analytics cookies. Our hosting provider may still process ordinary request and security logs, including IP address, browser type, requested URL, and timestamp. If we add non-essential tracking, we will update this policy and provide any consent controls required by law.
03
How we use information
We use personal information to:
- create and authenticate guest or linked accounts and sync content across devices;
- turn prompts and optional images into tattoo concepts, edits, titles, and tags;
- store your library, display public designs in Explore, and manage saved designs;
- provide subscriptions, entitlements, virtual ink, purchase restoration, and support;
- operate local and cloud features you request and remember app preferences;
- protect the Service, verify genuine app instances, prevent abuse, and enforce our terms;
- debug failures, maintain reliability, and improve features and user experience;
- respond to requests, disputes, safety reports, and legal obligations; and
- create aggregated or de-identified statistics that do not reasonably identify you.
We do not use user content to make decisions that produce legal or similarly significant effects about you. Tattoo-style preferences and images are not used to infer health status, ethnicity, religion, biometric identity, or other sensitive traits.
04
Legal bases for processing
Where applicable law requires a legal basis for processing, our legal bases depend on the activity:
- Contract. We process account, content, activity, and purchase information to provide the features you request and administer our Terms of Service.
- Legitimate interests. We secure, maintain, troubleshoot, and improve the Service; prevent fraud and abuse; understand basic service performance; and establish or defend legal claims. We balance these interests against your rights.
- Consent. We rely on your permission for device access, submission of optional photos, public sharing, and any processing for which consent is legally required. You may withdraw consent, but this does not affect earlier lawful processing.
- Legal obligation. We process information where required for tax, accounting, consumer protection, safety, sanctions, court orders, or other law.
05
Public designs and artificial intelligence
Public and private designs
New designs are public by default. A public design’s generated image, name, style and other public-facing design details may appear in Explore and can be viewed, saved, and shared by other users. Your underlying prompt and account identifier are not included in the public Explore response. You can choose private before generation or change a design’s visibility later. Making a design private stops future access through Explore, but cannot retract copies another person already saved outside Tatz or shared elsewhere.
AI processing
To provide generation and editing, Tatz sends your prompt, design options, and any submitted reference or edit image to OpenAI’s API. OpenAI returns structured design details and a generated image. OpenAI states that API inputs and outputs are not used to train its models by default unless the customer opts in. OpenAI may retain API content and related metadata for limited safety and abuse-monitoring purposes under its then-current business terms. Do not submit content you lack permission to use or information you do not want processed by an AI service provider.
06
How we disclose information
We disclose information only as described below:
- Service providers. Cloudflare provides hosting, database, object storage, request security, queues, and infrastructure; Google Firebase provides authentication and app attestation; OpenAI processes generation and edit requests; RevenueCat manages subscription entitlements; and Apple or Google process sign-in, device services, distribution, and in-app purchases. These providers process information under their contracts and applicable privacy terms.
- Other users and the public. We disclose content you mark public as described above. If you use your device’s share sheet, the recipient and selected app receive the file and text you choose to share.
- Legal, safety, and rights protection. We may disclose information when we reasonably believe it is required by law or legal process; necessary to protect users, Tatz, or others; or appropriate to investigate fraud, security incidents, or violations.
- Business transfers. Information may be reviewed or transferred as part of financing, due diligence, merger, acquisition, reorganisation, insolvency, or sale of all or part of the business, subject to appropriate confidentiality and legal safeguards.
- At your direction. We disclose information when you direct us or give valid consent.
We do not sell personal information for money. We do not share personal information for cross-context behavioural advertising and do not knowingly sell or share the personal information of anyone under 18.
07
International data transfers
Tatz is operated from Canada and uses providers with infrastructure in Canada, the United States, and other countries. Firebase Authentication is operated from the United States, and other providers may process information wherever they or their subprocessors maintain facilities. Those countries may have privacy laws different from yours, and information may be accessible to courts, law enforcement, or national-security authorities under local law.
Where required, we use contractual, organisational, and technical safeguards or another lawful transfer mechanism. Contact us to ask about the safeguards relevant to your information.
08
Retention and deletion
We keep information only as long as reasonably necessary for the purposes described here:
- Account records, prompts, design settings, generated images, bookmarks, onboarding answers, and virtual-ink records are generally kept while your account or guest profile is active, unless you delete a design or account sooner.
- Reference photos and edit masks staged for generation are designed to be deleted from Tatz storage after the generation reaches a final success or failure state. Temporary provider copies may remain for the provider’s limited security or legal retention period.
- When you use in-app account deletion, Tatz deletes saved designs, generated images, staged images, bookmarks, onboarding answers, and virtual-ink records from active Tatz systems and requests deletion of the Firebase account. Firebase states that deleted authentication data may take up to 180 days to leave backup systems.
- We retain a minimal identifier tombstone after deletion to prevent already-issued tokens from recreating the deleted account. We may also retain limited records where reasonably necessary for fraud prevention, security, legal compliance, disputes, or enforcement.
- Server and security logs are kept for limited operational periods. OpenAI states that default API abuse-monitoring logs may be retained for up to 30 days, unless longer retention is legally required.
Deleting Tatz does not cancel an app-store subscription. Cancel it in the applicable store settings to stop future renewals.
09
Your choices and privacy rights
You can take many actions directly in the app:
- choose private before generating and change an existing design’s visibility;
- delete individual designs or bookmarks;
- deny or revoke camera, photo, microphone, and speech permissions in device settings;
- manage or cancel subscriptions through the applicable app store; and
- delete your guest data or registered account from Account settings.
Depending on where you live, you may have rights to know or access personal information; obtain a portable copy; correct inaccurate information; delete information; restrict or object to processing; withdraw consent; opt out of sale, targeted advertising, or certain profiling; and appeal a denied request. You may also complain to your local privacy or data protection authority. We will not discriminate against you for exercising a privacy right.
Submit a request to privacy@tatz.ai. Describe your request and the account or device involved. We may need to verify your identity or authority before acting. An authorised agent may submit a request where local law allows, but we may request proof of authority and direct verification with you. Some rights are subject to legal exceptions.
10
Regional privacy disclosures
Canada
You may request access to and correction of personal information under applicable Canadian law and challenge our compliance with the person responsible for privacy. You may withdraw consent, subject to legal or contractual restrictions and reasonable notice; withdrawal may prevent us from providing features that require the information. You may complain to the Office of the Privacy Commissioner of Canada or the applicable provincial regulator.
United States state privacy laws
In the preceding 12 months, we may have collected the categories described in Section 2: identifiers; customer and commercial records; internet or electronic activity; approximate geolocation derived from IP or store; audio or visual information you choose to submit; account credentials and content that may be considered sensitive under some laws; and inferences reflected in your stated tattoo preferences. We collect these categories from you, your device, identity providers, app stores, and service providers; use them for the purposes in Section 3; and disclose them to the recipient categories in Section 6. We retain them as described in Section 8.
We have not sold these categories or shared them for cross-context behavioural advertising. Because we do not engage in those practices, there is no sale or advertising share to opt out of. If that changes, we will update this policy and honour applicable opt-out signals, including Global Privacy Control. California residents may also request the categories of sources, business purposes, recipient categories, and specific pieces of personal information collected, subject to law.
11
Security
We use administrative, technical, and organisational measures intended to protect personal information, including authenticated API access, app-attestation checks, private object storage, access controls, encrypted network transport, and deletion workflows. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. You are responsible for protecting your device and linked identity-provider account.
12
Children
The Service is intended only for people who are at least 18 years old and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information, contact us so we can investigate and delete it as appropriate.
13
Changes to this policy
We may update this policy as the Service, providers, or law changes. We will post the updated policy here and change the effective date. If a change materially affects how we use information already collected, we will provide additional notice or request consent where required. Your continued use after the effective date is subject to the updated policy.
14
Contact us
Questions, complaints, and privacy requests can be sent to the Privacy Officer of Reev Tech Inc. at privacy@tatz.ai. For other legal questions, email legal@tatz.ai.
Reev Tech Inc.3080 Yonge Street, Suite 6060
Toronto, Ontario M4N 3N1
Canada
Telephone: +1 647 957 8182
You can also review our Terms of Service.