caricly

Legal

Privacy Policy

What happens to your photo, in plain sentences, and below that the same thing again in full.

Last updated: 23 August 2026 Required page for the App Review

This English text is a courtesy translation. In case of doubt the German version is the binding one.

The essentials in four sentences

Your photo is processed and discarded, not permanently stored. GPS and capture time are removed beforehand. The result deletes itself after 24 hours. You need no account, and we set no trackers.

Controller

The controller for data processing within the meaning of the GDPR is:

Ivo Schmidt
Nachtweideweg 27
13589 Berlin
Germany

For information requests and deletion: support [at] caricly [dot] de
Replace “ [at] ” with @ and “ [dot] ” with a full stop.

What data is processed

As little as possible. Specifically:

  • The photo you upload: solely in order to draw the caricature from it.
  • A random device identifier: so that your credits and your history can be assigned to your device. It contains no name and no email address.
  • A checksum of your photo: a string your image cannot be reconstructed from. It prevents the same photo from being billed twice after a dropped connection.
  • Events about your use of the app: app opened, photo picked, style tapped, caricature started, result received, saved, shared, and around purchases. Each event carries the device identifier, platform, app version and the time. We evaluate them to see where people get stuck. Free text is technically impossible: every value comes from a fixed list.
  • Proof of your consent to the photo transfer: device identifier, whether consent was given or withdrawn, timestamp, version of the consent text, and where the consent was given from. This proves that and when you consented, as required by Art. 7(1) GDPR.
  • For each caricature: the style chosen, the model used, success or failure, duration and cost. We need this for operation and billing.
  • Technical server logs: for operation and security. The IP address is truncated immediately, and neither user agent nor referrer is written down at all.

No name, no email address, no password, no advertising identifiers, no third-party analytics services. What we measure, we measure ourselves and on our own server.

This data is pseudonymous, not anonymous. Every row carries your device identifier, and whoever holds it sees a usage history. We therefore treat it as personal data, even though no name is attached to it.

What happens to your photos

The original is processed to generate the caricature and discarded afterwards. It is not permanently stored on our side. Before processing we remove the EXIF metadata, in particular GPS coordinates and capture time. The generated image is deleted automatically after 24 hours.

Finding faces in the image: this stays on your device

So that the caricature turns out well, the app suggests a tighter crop. To do so it looks for the areas of the photo where faces appear. Your iPhone computes this itself, using a function of the operating system (Apple Vision). The result is one rectangle per face, that is, a position in the image, and nothing else.

These rectangles exist only in your device's memory while the photo is open in the app, and are gone afterwards. We do not store them, we do not transmit them, and nobody else receives them: no server of ours, no third party. Nothing is derived from them that could be used to recognise a person: no measurement of the face, no faceprint or feature template, no comparison with other images, no link to you or to an earlier photo. The app cannot determine who is in the picture, and does not try.

The photo itself is the other half, and we will be plain about it: it almost always shows a face, and it does leave your device. That is exactly what we ask your consent for before the first photo can be picked, and you can switch it off again at any time in the app's settings (“Allow photo transfer”). What is transmitted is the image, not facial features computed from it, and only for one purpose: drawing the caricature you asked for. What happens to it is described directly below.

Transfer to the United States

The drawing does not happen on our server. Your photo is sent to Google (Google Cloud, the "Vertex AI" service), whose model generates the caricature. Google is the only recipient. What is transmitted is the downscaled photo without metadata, together with the fixed text describing the style. Nothing else: no device identifier, no name, no IP address.

The endpoint used is explicitly not bound to any region. We can therefore neither determine nor tell in which country your photo is processed; the United States are included. Google does not offer a European endpoint for this model.

Under its own terms, Google does not use the transmitted data to train its models. Google may, however, log the requests for a limited time in order to detect abuse. We have no influence over that.

This is a transfer to a third country within the meaning of Art. 44 et seq. GDPR. The legal basis for the processing is Art. 6(1)(b) GDPR: you requested the caricature, and without this transfer there is none.

Contractual basis: a data processing agreement under Art. 28 GDPR is in place with Google: Google's "Cloud Data Processing Addendum", accepted on 13 August 2026. It bases transfers to third countries on the European Commission’s standard contractual clauses.

How long we keep what

  • Your uploaded photo: not at all. There is no place to store it, neither in the database nor on disk. During the request it briefly exists as a temporary file on the server and disappears when the request ends.
  • The finished caricature: 24 hours, then it is deleted automatically.
  • IP addresses: 7 days.
  • Device identifier and checksum on the generated images: 90 days. After that only style, model, status, duration and cost remain, and none of it can be traced back to anyone.
  • Usage events: 90 days.
  • Consent record: 3 years. Longer than the other periods, because the record must cover the period it is needed for.
  • Server logs: 14 days.

On our side, deleting mostly means emptying the personal fields, not removing whole rows. What remains is pure operational statistics with no link to you. The one exception is the consent record: after three years we delete the whole row, because a record with no person left to attest for loses its purpose.

Deletion: how it actually works

Because there is no account, everything hangs on your device identifier. To have everything belonging to your device deleted:

  1. Open Settings in the app and tap Copy device identifier.
  2. Send it to the contact address named above, subject “Deletion”.
  3. We delete everything assigned to that identifier and confirm it to you.

You can delete your local history yourself at any time, in the app via “Edit” in the history, or by removing the app.

Your rights

You have the right to information, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with a supervisory authority. Just write to us. No justification needed.