Privacy Policy
Effective date: to be set once legal review is complete
1. Who operates EPVision
EPVision is operated by [FULL LEGAL NAME], a sole proprietor established in Iceland. Because the controller is established in the European Economic Area, no representative has been appointed under Article 27 of the GDPR.
EPVision is initially distributed and marketed only in Iceland. The United Kingdom is excluded from distribution and targeting. Availability in the United Kingdom will require a separate legal and regulatory review before launch.
Contact (privacy inquiries): privacy@eternalplates.com
Public business postal address: [PUBLIC BUSINESS POSTAL ADDRESS — REQUIRED BEFORE PRODUCTION]
2. Data we process, and how
EPVision is designed to keep most of your content on your own device. Here is exactly what happens to different kinds of data:
2.1 Your account identifier
When you first open EPVision, we automatically create an anonymous account for you using Firebase Authentication. This does not involve a name, email address, or password. This anonymous identifier is used only to:
- let your device talk to our backend servers securely,
- apply fair-use limits (so one device can't overload the service), and
- let you request deletion of your data.
2.2 Content you create — stored on your device only
Your recipes, sketchbook items, camera photos, generated images, and related content are stored only on your device. We do not upload this content to our servers or store a copy of it anywhere else, except for the temporary processing described in section 2.3 below, and only when you actively use an AI feature.
2.3 AI features — temporary processing by third-party AI providers
AI features are intended to be part of EPVision at public launch — they are core to what the app does, not an optional add-on. As of this policy, they remain turned off in production behind a server-side control while final testing, safeguards, and security checks are completed. This section describes what happens when an AI feature processes your content, whether that is today (in testing) or after public launch.
EPVision currently uses more than one third-party AI provider, all called only from our own backend server — never directly from your device. We do not promise to use any single AI provider permanently. EPVision may use one or multiple AI providers at a time, and may add, remove, or change providers or the specific AI models used, based on factors such as output quality and capability, privacy and safety terms, contractual terms, reliability, and availability. If a change in provider or model would materially change how your content is handled, we will reflect that in an updated version of this Privacy Policy before the change takes effect for your data. As of this policy, the providers used are:
- Text and image requests for our chat, recipe-recognition, and recipe-generation features are sent to OpenAI.
- Image-generation requests for certain culinary-image and plating features are sent to Google's Gemini API.
When you use an AI-powered feature, the relevant text and/or image you provide is sent to our backend server, which forwards it to whichever third-party AI provider that specific feature currently uses, solely to generate the response shown back to you for that one request. This immediate, per-request processing is separate from any possible future use of your content to train an EPVision-owned AI model — see below.
We do not store a copy of your prompts, images, or the AI's responses on our servers. The content is used only to generate the response shown back to you, and then it is not written to any database we control.
These providers may briefly retain this data on their own systems, under their own policies, independent of EPVision:
- OpenAI's published policy states that data sent through its API is not used to train OpenAI's models by default, and that abuse-monitoring logs are retained on OpenAI's own systems for up to 30 days by default. We use this standard default and have not requested Zero Data Retention or Modified Abuse Monitoring as of this policy, though we may do so in the future.
- Google's Gemini API terms distinguish paid and unpaid service tiers with different data-use rules: under the paid tier, prompts/responses are not used to improve Google's products; under the unpaid/free tier, they may be, including human review after being disconnected from account identifiers. We have verified that the Google Cloud project holding our Gemini API key has active Cloud Billing, but this does not by itself confirm the key's own billing tier — until that is directly confirmed, assume the less protective (unpaid-tier) terms may apply.
Possible future AI training on your content: EPVision does not currently use your stored recipes, photos, or other content to train, fine-tune, or evaluate any EPVision-owned AI model. We may, in the future, offer an optional feature letting you choose to contribute specific content to help improve EPVision's own AI. If built, this would be a separate, clearly-labeled, opt-in feature — off by default, never required to use the app's core features, and not implied simply by having an account. This Privacy Policy would be updated with full details before that feature launches.
2.4 Operational data (fair-use limits)
To prevent abuse, our backend temporarily records how many requests your anonymous account has made in short time windows. This record contains only a count and an expiration time — never the content of your requests.
2.5 Server logs
Our backend keeps limited technical logs of each request for reliability and debugging: which feature was used, whether it succeeded or failed (using a small set of fixed error categories), how long it took, and a device-integrity signal classification. For AI-feature requests, these logs include your anonymous account identifier. They never include your actual prompt text, images, or the AI's response, and never include your authentication token. Deletion-request logs additionally never include your account identifier at all.
Planned, not yet active: we intend to add Firebase Crashlytics (crash reporting only, without Firebase Analytics) before public launch, to help us fix app crashes. Crash reports will never include your prompts, images, recipes, authentication tokens, or other secret values.
2.6 Infrastructure-level data
Our backend runs on Google Cloud / Firebase infrastructure. As with any online service, the underlying infrastructure necessarily processes standard technical information such as your device's IP address as part of normal network communication. We do not read or store this ourselves; it is processed by Google Cloud as our infrastructure provider.
2.7 What we do not collect
We do not currently collect: your name, email address, phone number, precise location, contacts, health data, or browsing history. We do not use advertising SDKs, tracking technology, or general usage analytics, and have no plans to at launch.
EPVision is intended to launch with in-app token/credit purchases. EPVision contains purchase and credit user-interface and backend components that are still being prepared. Production purchases are currently unavailable and cannot complete because the required Google Play products and production purchase-verification path have not been enabled. EPVision does not process or store any payment card or bank information itself — a completed purchase, once enabled, would be handled by Google's own payment systems. This policy will be updated before purchases are made available.
Your on-device recipes, photos, and sketchbook content are not currently backed up or synced to EPVision's servers, and cannot currently be recovered from our systems if lost from your device — see section 2.2. Cloud backup is a possible future feature, not part of the initial release; this policy will be updated before it ships.
2.8 Optional account security — linking a Google account
EPVision's anonymous account (section 2.1) can optionally be upgraded by linking a Google account, from Help & Support → Account. This is entirely optional, is never required for any free or local feature, and does not create a second account — it adds a Google sign-in credential to your existing anonymous identifier so that your account can be recognized across a reinstall or a new device.
EPVision's own app code does not read, log, store, or display your Google email address, name, or photo — it only records whether the linking attempt succeeded, and shows a fixed label ("Google") to confirm your account is secured. However, linking does cause your Google account's email address (and typically your name and profile photo) to be stored as part of your account record with our authentication provider, Firebase Authentication (operated by Google), independent of EPVision's own code. This is a standard part of how account linking works on this platform, and this section exists so that fact is not hidden by the fact that our own code never touches it directly. If you delete your account (section 7), this record is deleted along with everything else tied to your account identifier.
This feature is active today for anyone who chooses to use it.
3. Purposes of processing
We process the data described above only to:
- provide and operate the app's features (including AI features, when enabled),
- maintain the security and integrity of the service (fair-use limits, device-integrity checks),
- diagnose and fix technical problems, and
- honor your data-deletion requests.
We do not use your data for advertising, and we do not sell your data.
4. Legal bases for processing
EPVision is initially distributed and marketed only in Iceland (see section 1). We use GDPR/EEA privacy standards as our baseline, since Iceland is part of the European Economic Area. If distribution later expands to other regions, this section will be reviewed and updated before that expansion.
We process personal data only when a lawful basis applies. Depending on the processing activity, we rely on:
- Contract (GDPR Article 6(1)(b)): providing requested core app functionality and account services where processing is necessary to perform the service.
- Legitimate interests (GDPR Article 6(1)(f)): security, fraud and abuse prevention, service integrity, and proportionate diagnostics, subject to appropriate safeguards.
- Legal obligation (GDPR Article 6(1)(c)): tax, accounting, purchase, refund, and other records that applicable law requires us to retain.
- Consent (GDPR Article 6(1)(a)): optional marketing or non-essential analytics/cookies — only if those activities are actually introduced and valid consent is obtained. We do not rely on consent for ordinary core processing.
Mapping each specific processing activity described in section 2 to exactly one of the bases above, and confirming any activity that cannot yet be verified against a basis, is pending legal review.
5. Data retention
- On-device content (recipes, images, sketchbook data): retained until you delete it individually or use "Delete all my data."
- Anonymous account identifier: retained until you delete your account.
- Fair-use/rate-limit records and active-request locks: these records carry an expiration time, and an automatic deletion policy (Firestore TTL) for this expiration is active. Automatic deletion of this kind is a background process and is not instantaneous — it may normally take up to approximately 24 hours after expiration to complete. Deleting your account (section 7) removes these records immediately regardless of this automatic process.
- Server logs: retained for a limited period on our cloud logging infrastructure — 30 days for ordinary logs and 400 days for required audit logs (Google Cloud's own default retention periods; not customized by us). We do not export these logs to any additional storage or analytics destination.
- Third-party AI provider logs: governed by each provider's own retention policy, described in section 2.3, and outside our direct control.
- Planned diagnostic data (Crashlytics, once implemented): retained per Firebase Crashlytics' own default retention; will be documented here once the feature actually ships.
6. Security
We use industry-standard transport encryption (HTTPS/TLS) for all communication between the app and our servers. Our backend infrastructure runs on Google Cloud/Firebase, which encrypts data at rest by default as part of its platform. We do not claim any additional security certification (such as SOC 2 or ISO 27001).
Content stored locally on your device is not separately encrypted by the app; it relies on your device's own operating-system-level protections.
7. Your rights and how to exercise them
You can request deletion of your EPVision account and data at any time from Help & Support → Delete all my data inside the app, or using the external method described on our Account & Data Deletion page (emailing privacy@eternalplates.com if you no longer have the app installed — we may ask for details that help us identify your account, since EPVision does not use an email or username). This deletes your on-device content, your active account profile, and the fair-use/operational records tied to your account on our servers, and this deletion is permanent and cannot be undone. Where in-app purchases are enabled, purchase, credit-ledger, accounting, taxation, refund, chargeback, security, and fraud-prevention records may be retained beyond account deletion only where legally required or legitimately necessary — pseudonymized or disassociated from your active profile where reasonably possible, with restricted access and a defined retention period.
Please note: deleting your account does not retroactively erase records that AI providers may have briefly retained on their own systems under their own policies (see section 2.3), and cannot instantly purge every backup or infrastructure log our cloud provider may transiently retain before its own retention period elapses.
For as long as EPVision is distributed only in Iceland and the European Economic Area (see section 1), and subject to applicable legal conditions, limitations, and record-retention obligations, you have the right to:
- access your personal data;
- rectification of inaccurate personal data;
- erasure of your personal data;
- restriction of processing;
- data portability;
- object to processing; and
- withdraw consent at any time, where processing relies on consent, without affecting the lawfulness of processing carried out before that withdrawal.
You may also lodge a complaint with Persónuvernd, the Icelandic Data Protection Authority. If EPVision later distributes to California or another jurisdiction outside the EEA, that jurisdiction's own regional privacy requirements (which may differ from the rights listed above) will be reviewed before distribution there.
8. Children's privacy
EPVision is intended for users 18 years of age and older, for as long as any user-facing feature uses an AI provider (currently Google's Gemini API) whose own terms prohibit serving clients under 18. This is a current provider-contract restriction, not a permanent statement of EPVision's intended audience: our future goal is to lower this to approximately 15 and older, but only once every AI provider actively used by the app, and all applicable legal requirements, permit it, and only after a full review confirms this. EPVision currently has no age-verification mechanism; by using the App, you represent that you are at least 18.
We do not knowingly collect data from anyone under 18. If you believe a child under 18 has provided us data, contact privacy@eternalplates.com and we will delete it.
9. International data processing
Our backend runs on Google Cloud/Firebase infrastructure. Based on our code, our Cloud Functions currently run in the us-central1 region (United States). Since EPVision is currently distributed from Iceland, within the European Economic Area, this means user data described in section 2 is processed outside Iceland and the EEA, in the United States.
Some service providers may process personal data outside Iceland or the European Economic Area. Where required by applicable law, international transfers are based on an adequacy decision or appropriate safeguards, such as approved standard contractual clauses, together with supplementary protections where appropriate. Users may contact us for information about the safeguards applicable to their data.
We have not yet verified the specific data-processing agreements, standard contractual clauses, or processing-region configurations actually in place with Firebase/Google Cloud and with each AI provider (OpenAI, Google Gemini API). Until each is individually verified, this should be treated as a legal-production blocker, not a completed compliance statement.
10. Third-party service providers
We use the following third-party services to operate EPVision:
- Firebase / Google Cloud (Google LLC) — authentication, backend hosting, database, logging, and app-integrity verification.
- OpenAI — processes text and image content you submit to AI features that use OpenAI, solely to generate the response shown to you.
- Google Gemini API (Google LLC) — processes text and image content you submit to AI features that use Gemini, solely to generate the response shown to you.
Links to each provider's own current privacy policy will be added at publication time.
11. Changes to this policy
We may update this Privacy Policy from time to time. Our specific update/notification process has not yet been finalized.
12. Contact us
Privacy questions or data requests: privacy@eternalplates.com
General support: support@eternalplates.com (see also our support page)