Privacy Policy

Last updated: 24 July 2026

1. Scope and Data Controller

This policy explains how EditMyPet handles personal data when you use our website, accounts, AI pet-image tools, purchases, support, galleries, contests, referrals, and related features. It is intended to meet the transparency requirements of the UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, and the EU GDPR where it applies.

Data controller
EditMyPet
Email
support@editmypet.com

Our privacy contact can be reached at support@editmypet.com or through our contact form. If a data protection officer or representative is appointed or legally required, we will publish their contact details here.

2. Key Points

  • Private account images are not placed in the public gallery unless you choose a public feature.
  • We send the photo, prompt, and generation settings needed to our AI provider to create your result.
  • Temporary generation uploads are removed after processing and operational recovery; saved outputs remain until deleted or no longer needed.
  • We do not receive your full payment-card number and do not sell personal data for money.
  • Non-essential analytics technologies are disabled unless you consent through our cookie controls.
  • You can exercise data-protection rights or make a privacy complaint using the contact details above.
3. Personal Data We Collect
  • Account and profile: email, user ID, sign-in provider, display name, avatar, preferences, privacy choices, and saved-pet settings.
  • Content: uploaded photos, prompts, selected styles and accessories, generated images, favourites, public/private choice, and file metadata.
  • Generation records: job IDs, model and style configuration, token cost, timestamps, errors, logs, flags, review notes, and outcomes.
  • Purchases: products, prices, currency, billing country, payment-provider customer, session and transaction references, invoices, token grants and allocations, subscription status, refunds, and disputes. Our payment provider receives payment credentials directly.
  • Community and rewards: contest entries, public submissions, votes, ranks, referral codes and relationships, reward eligibility, and anti-abuse records.
  • Support: name, email, subject, message, attachments or details you provide, and our response and internal review record.
  • Technical and security: IP address, coarse IP-derived location, browser, device, pages and features used, timestamps, diagnostic events, security logs, rate-limit and CAPTCHA signals.
  • Consent and communications: cookie choices, marketing preference, email delivery status, suppression events, and service-message history.

Photos may incidentally contain a person, home interior, location clue, or embedded metadata. Please crop or remove information that is not needed and do not upload special-category data or another person's image unless you have a lawful reason and their permission.

4. Where Data Comes From

We collect data from you, your browser or device, and your use of EditMyPet. We also receive limited data from sign-in, payment, email and security providers, referral links, other users who vote or interact with a public submission, and administrators who review support or moderation requests.

5. Why We Use Data and Our Lawful Bases
PurposeData involvedUK/EU GDPR basis
Create and secure your accountEmail, user ID, sign-in provider, profile, settings, authentication and security eventsContract; legitimate interests in account security and preventing misuse
Generate and store imagesUploaded pet photo, prompt, styles, controls, generated outputs, job and file metadataContract; legitimate interests in reliable delivery, troubleshooting, and service security
Process purchases and token useOrder and payment-provider references, billing country, product, price, token grants, allocations, refunds and disputesContract; legal obligations for tax and accounting; legitimate interests in fraud prevention and claims
Operate galleries, contests, referrals and rewardsChosen public image, display name, entry, votes, rank, referral code, eligibility and reward recordsContract and your request to participate; legitimate interests in fair operation and abuse prevention
Support and manual reviewsMessages, account and order details, flagged content, generation logs, review notes and outcomeContract; legitimate interests in support, quality, safety, and resolving disputes
Protect and maintain the serviceIP address, device/browser data, logs, rate-limit signals, CAPTCHA outcome and audit recordsLegitimate interests in security, availability, fraud prevention, and legal claims; legal obligations
Measure and improve product usePage views, interactions, device data, coarse location, performance and diagnostic eventsConsent where non-essential cookies or similar technologies are used
Send communicationsEmail address, service messages, support replies and marketing preferencesContract for service messages; consent or another basis permitted by direct-marketing law for marketing

Our legitimate interests include delivering a reliable product, understanding and fixing failures, securing accounts and infrastructure, preventing fraud and reward manipulation, handling complaints, and establishing or defending legal claims. We balance those interests against your rights and reasonable expectations. Where we rely on consent, you may withdraw it without affecting earlier lawful processing.

Account, generation, and purchase information marked as required is necessary to enter into or perform our contract with you. Without it, we may be unable to create an account, generate an image, fulfil a purchase, or provide the requested feature. Public sharing, optional profile information, marketing, and non-essential analytics are optional.

6. Uploaded Photos and AI Processing

To generate an image, we create a protected temporary working copy of your source photo and make it available to the generation workflow for a limited time. The source image, prompt, chosen styles, and necessary instructions are sent to our AI generation provider. Temporary working files are queued for deletion after a job completes or fails and the short operational-recovery period ends. A failed cleanup may be retried.

Generated results and their metadata are stored in your account so you can view, download, flag, or delete them. Owner-only media is kept in private storage and accessed using time-limited links. If you opt into a gallery, contest, or other public feature, a public derivative and the associated public profile information may be displayed until removed under that feature's rules.

7. Who Receives Personal Data

We use carefully selected service providers acting for us or providing an integrated service. Depending on the features you use, the relevant categories include:

  • Cloud infrastructure providers for hosting, databases, account authentication, media storage, content delivery, queues, caching, and operational reliability;
  • AI processing providers that receive the source image, prompt, selected options, and necessary instructions to generate your requested result;
  • Payment and billing providers for checkout, payment credentials, subscriptions, fraud prevention, refunds, and disputes;
  • Security providers for CAPTCHA, rate limiting, abuse prevention, and service protection;
  • Communications providers for transactional and service email delivery, delivery status, and suppression handling;
  • Consent and analytics providers for recording privacy choices and, only with the required consent, understanding product use and performance; and
  • Content-management providers for publishing public editorial and help content.

We may also disclose data to professional advisers, insurers, courts, regulators, law enforcement, or a buyer or successor where reasonably necessary and lawful. Public content is shared with visitors by your choice. We do not sell personal data for money. You may contact us for more information about a relevant provider or the safeguards applying to your data.

8. International Transfers

Some providers process data outside the UK or European Economic Area. Where transfer rules apply, we use an adequacy regulation or decision, the UK International Data Transfer Agreement or UK Addendum, EU Standard Contractual Clauses, or another permitted safeguard, together with supplementary measures where appropriate. Contact us to request more information about the safeguard relevant to your data.

9. How Long We Keep Data

We keep data only for as long as needed for the purpose collected, taking account of account status, feature operation, user choices, legal duties, security, disputes, and limitation periods. Our current retention approach is:

  • Temporary generation uploads: until the generation and short recovery window finish, then queued for deletion; failed cleanups are retried.
  • Account and private generated content: while your account or saved content remains active, then deleted or anonymised when no longer needed, subject to backups and legal holds.
  • Public submissions: while public or needed to administer the feature, plus a reasonable period for cached copies, moderation, disputes, and integrity records.
  • Payment, refund, and token-ledger records: generally for up to seven years after the relevant transaction or relationship, where needed for tax, accounting, fraud, disputes, and legal claims.
  • Support, moderation, and complaint records: for the time needed to resolve the matter and normally up to three years afterwards, longer if a claim or legal duty requires it.
  • Security and technical logs: for a shorter operational period unless an event must be investigated, preserved as evidence, or retained by a provider's documented schedule.
  • Consent records: for as long as needed to demonstrate and honour your choice and resolve related complaints.

Deletion from live systems may not immediately remove encrypted backup copies. Backups are protected, rotate on a limited schedule, and are not used for ordinary product activity.

10. Security

We use access controls, owner-scoped media paths, private storage, time-limited media links, encryption in transit, service-role separation, rate limits, audit records, webhook verification, and security monitoring designed to protect personal data. No online system is risk-free. Please use a secure sign-in method and tell us if you suspect compromise.

11. Your Data-Protection Rights

Depending on the law and processing, you may ask us to access, correct, erase, restrict, or provide a portable copy of your personal data. You may withdraw consent and may object to processing based on legitimate interests or to direct marketing. Some rights have exceptions, for example where records must be retained by law or are needed for legal claims.

Your right to object: you may object at any time to direct marketing. You may also object to processing based on legitimate interests by explaining your circumstances. We will stop unless we can demonstrate compelling lawful grounds or the processing is needed for legal claims.

Send a request using our contact form or email, preferably from your account address. We may ask for proportionate proof of identity. We normally respond without undue delay and within one month; the law allows an extension for a complex or numerous request, in which case we will explain it. Rights requests are normally free.

12. Automated Checks

We use automated rate limits, CAPTCHA, payment-provider fraud signals, queue controls, and abuse checks. They may block or delay an action, but EditMyPet does not currently use solely automated processing to make a decision that has a legal or similarly significant effect on you. Contact support if you believe an automated control made a mistake; we can review the relevant account or transaction information.

13. Privacy Complaints

To complain about our use of personal data, use the contact form with the subject "Data protection complaint" or email us. Explain what happened, the relevant account or feature, and the outcome you seek. We will acknowledge a data-protection complaint within 30 days, investigate it appropriately, keep you informed where needed, and communicate an outcome without undue delay.

You may also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. If the EU GDPR applies, you may complain to the supervisory authority where you live, work, or believe an infringement occurred. We ask that you contact us first, but you do not have to.

14. Children

EditMyPet is not for children under 13. Users under 18 should involve a parent or guardian, especially before a purchase or public submission. We aim to use privacy-protective defaults, make public sharing a choice, avoid behavioural advertising to known children, and collect no more data than the feature needs. Parents, guardians, and children can contact us about an account or privacy concern. If we learn that an under-13 has provided data without appropriate authority, we will investigate and delete it where required.

15. Cookies and Similar Technologies

We use essential storage for requested features and consented technologies for analytics. Read the Cookie Policy for categories, providers, and controls.

16. Changes to This Policy

We review this policy when our service, providers, or legal duties change. We will update the date and bring a material new use of personal data to your attention before it starts where required.