Photo MakerAI image generator and photo editor

PRIVACY POLICY

Privacy Policy

This Privacy Policy explains how Photo Maker gathers, uses, shares, and protects your personal data. It covers the AI image generator, the AI photo editor, and any related services run by Photo-Maker.org.

Last updated: 2026-08-30. We will flag any significant change with a clear notice on photo-maker.org, or by reaching out to you directly when the law requires it.

1. Data Controller & contact

The Data Controller in charge of processing your personal data is Photo-Maker.org, reachable at info@photo-maker.org.

The Data Protection Officer (DPO), appointed under Article 37 of EU Regulation 2016/679 (GDPR), is represented by Photo Maker and can be reached at the same email address.

2. Personal data we collect

We only collect personal data when it is needed to deliver the studio or to honor a legal duty. The categories include:

  • Technical data — truncated IP address, browser type and version, operating system, device identifiers, screen resolution, language preferences, and referrer URL.
  • Usage data — pages visited, time spent on each page, click patterns, and how you interact with our AI image generator.
  • Prompt data — the text prompts and source images you submit to the AI image generator. They are processed to fulfill your request and cached briefly to speed up repeat operations.
  • Consent data — records of the choices you make in the cookie banner (advertising, analytics, personalization, security, functionality).
  • Communication data — if you email us, we keep the message body and the metadata needed to reply.

3. How we use your personal data

We use the data we collect for the following purposes:

  • To operate, maintain, and improve Photo Maker, including AI image generation, photo editing, and gallery features.
  • To remember your preferences and consent choices.
  • To measure aggregated, anonymized traffic and usage patterns.
  • To detect and prevent abuse, fraud, or other security incidents.
  • To comply with our legal obligations and respond to lawful requests from public authorities.

5. How we share personal data

Personal data is never sold. We share it only with the following categories of recipients:

  • Service providers — hosting, content delivery, traffic optimization, image generation, analytics, and conversion-tracking vendors operating under data processing agreements.
  • Public authorities — when required by law or to protect our legal rights.
  • Corporate transactions — in the event of a merger, acquisition, or asset sale, your data may be transferred under continued protection.

6. Retention of data

We keep personal data only as long as needed to deliver our services, comply with legal duties, resolve disputes, and enforce agreements. Specific windows:

  • Server logs: up to 30 days.
  • Aggregated analytics: up to 14 months.
  • Generated image cache: up to 90 days; you can always ask for earlier deletion.
  • Consent records: up to 12 months from the date of withdrawal.
  • Email communications: up to 24 months.

Once the retention window closes, we will delete, de-identify, or anonymize the personal data. If that is not immediately possible (for example, because the data sits in a backup archive), we will stop processing it until deletion becomes feasible.

7. International data transfers

Some of our service providers sit outside the European Economic Area, including in the United States. Whenever we move personal data internationally, we rely on the Standard Contractual Clauses (SCC) approved by the European Commission, or other lawful transfer mechanisms, combined with technical and organizational safeguards such as encryption in transit and strict access controls.

8. Your rights as a data subject

Subject to applicable law, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your personal data ("right to be forgotten").
  • Restriction — ask us to limit how we process your data while a complaint is investigated.
  • Portability — receive your data in a structured, commonly used, machine-readable format.
  • Objection — object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent — at any time, without affecting the lawfulness of processing prior to withdrawal.
  • Lodge a complaint — with your local data protection authority.

To exercise any of these rights, write to us at info@photo-maker.org. We will reply within thirty (30) days.

9. Data deletion requests

You can request at any time that we erase the personal data and user-generated content we hold about you. Where applicable, this covers:

  • text prompts you submitted to the AI image generator,
  • source photos you uploaded for editing,
  • generated images cached against your session,
  • communication records (emails you sent us), and
  • consent and usage logs tied to your identifiers.

How to submit a request: send an email to info@photo-maker.org from the email address you originally reached us with (or any address you can prove belongs to you). Use the subject line "Data deletion request" and include:

  1. your full name,
  2. the email address you used on the site,
  3. the approximate date(s) you used the studio (if known), and
  4. a clear statement that you want your data deleted.

We may need to verify your identity before acting on the request, to prevent unauthorized deletion of another person's data. We will acknowledge receipt within seven (7) days and complete the deletion within thirty (30) days, unless we are legally required to keep certain records (for example, for tax or accounting purposes).

If part of your data cannot be deleted for legal reasons, we will tell you in writing which categories are retained, on what legal basis, and for how long.

10. How we protect personal information

We maintain administrative, technical, and physical safeguards designed to protect personal information against accidental, unlawful, or unauthorized destruction, loss, alteration, access, disclosure, or use. These include encryption in transit (HTTPS), access controls, regular backups, and ongoing staff training.

No electronic transmission of information is ever entirely secure. We cannot guarantee that the safeguards protecting personal information will never be defeated or fail, or that those measures will always be sufficient on their own.

11. "Do Not Track" disclosure

We do not track our users over time and across third-party websites to deliver targeted advertising on this studio. Some third-party websites may still track your browsing activity when they deliver content, so they can tailor what they show you. If you visit such websites, you can switch on a "Do Not Track" signal in your browser to tell those third parties you do not want to be tracked. We honor both "Do Not Track" and global privacy control signals sent from end-user browsers.

12. Children's privacy

Photo Maker is not directed at children under the age of sixteen (16), and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at info@photo-maker.org and we will take steps to delete the data.

13. Updates to this Privacy Policy

This Privacy Policy may be updated periodically. We will post a clear notice on photo-maker.org whenever a significant change happens and update the "Last updated" date at the bottom. We will also reach out directly when the law requires us to.

14. Get in touch

If you have any questions about this Privacy Policy or our data practices, drop us a line at info@photo-maker.org.

Last updated: 2026-08-30. This page is informational only and does not constitute legal advice.