Privacy Policy
Effective date: March 28, 2026 · Last updated: March 28, 2026
This Privacy Policy describes how Hint: Soulmate Sketch ("Hint," "we," "us," or "our") collects, uses, and protects your information. This policy applies to the Hint mobile application (the "App").
Also see our Terms of Service.
Who We Are
Data Controller: Anton, individual developer
Location: Batumi, Georgia
Contact: support@byanton.dev
Website: byanton.dev
As a small-scale individual developer, we are not required to appoint a Data Protection Officer under GDPR Article 37. For all privacy inquiries, contact us at the email above.
Summary: Hint generates AI portraits and provides an AI chat companion. We collect minimal data (name, date of birth, gender, photos) stored locally on your device. Photos sent to AI providers are processed and immediately discarded. We do not sell your data. We do not track you.
1. AI System Disclosure (EU AI Act Article 50)
You are interacting with artificial intelligence systems. Specifically:
- Soulmate portraits are generated by AI image models provided by OpenAI. They do not depict real people.
- The chat companion is powered by Google Vertex AI, a large language model. It is not a real person.
- Personality descriptions, compatibility analyses, and daily secrets are generated by Google Vertex AI.
- AI-generated images may be marked with provenance metadata (C2PA) where supported.
2. Information We Collect
2.1 Information You Provide
| Data | Purpose | Storage | Retention |
| First name | Personalizing your experience | On your device only | Until you delete the app or account |
| Date of birth | Age verification, zodiac compatibility | On your device only | Until you delete the app or account |
| Gender | Generating appropriate portraits | On your device only | Until you delete the app or account |
| Quiz answers | Customizing AI generation | On your device only | Until you delete the app or account |
| Selfie photo | "You Together" / "Future Baby" scenarios | Temporarily uploaded to Cloudflare R2 | Automatically deleted within 24 hours |
| Chat messages | AI companion conversation | On your device only | Until you delete the app or account |
2.2 Information Collected Automatically
- Device locale/language — to customize content language
- Device country code — provided by Cloudflare at request time for regional appearance diversity (not stored)
2.3 Information We Do NOT Collect
- Email address, phone number, or physical address
- Location (GPS)
- Contacts or calendar
- Advertising identifiers (IDFA)
- Browsing history or cookies
- We do not create user accounts or require registration
3. Legal Basis for Processing (GDPR Article 6)
| Processing Activity | Legal Basis |
| Generating AI portraits from quiz answers | Consent (you initiate the quiz and generation) |
| Processing selfie photos via AI | Explicit consent (you choose to upload) |
| AI chat companion | Consent (you initiate conversation) |
| Age verification | Legal obligation (COPPA, GDPR Art. 8) |
| Device locale for content language | Legitimate interest (localization) |
| Subscription processing | Contract performance (via Apple StoreKit) |
4. Third-Party AI Services
Apple Guideline 5.1.2(i) Disclosure: Your data is processed by the following named third-party AI providers. By using Hint, you consent to this processing.
| Provider | Service | Data Sent | Retention by Provider |
| Google LLC (Vertex AI) | Text profile generation, AI chat | Name, DOB, quiz answers, chat messages | Not retained per Vertex AI data processing terms |
| OpenAI, Inc. | AI image generation | Text prompt, selfie URL (if applicable) | Not used for training per OpenAI API data usage policy |
| Cloudflare, Inc. | API routing (Workers), temporary image storage (R2) | Request data, uploaded selfie | Selfie deleted within 24 hours; logs max 30 days |
5. Biometric Data Disclosure
When you upload a selfie for "You Together" or "Future Baby" scenarios, the AI image generation service may process facial features (geometry, proportions) to generate the combined portrait. This constitutes biometric data processing under Illinois BIPA, GDPR, and LGPD.
- Facial feature extraction is performed by the third-party AI provider (OpenAI), not by Hint
- We do not store, retain, or have access to extracted biometric data
- Biometric data is used solely for generating the requested portrait and is immediately discarded
- By uploading your selfie, you provide informed, explicit consent to this processing
- You may withdraw consent at any time by not using selfie-based features
6. Data Storage and Retention
| Data | Where Stored | Retention Period |
| Name, DOB, gender, quiz answers | Your device (SwiftData) | Until you delete the app or tap "Delete account" |
| Generated portraits | Your device (SwiftData) | Until you delete the app or tap "Delete account" |
| Chat messages | Your device (SwiftData) | Until you delete the app or tap "Delete account" |
| Uploaded selfies | Cloudflare R2 (temporary) | Automatically deleted within 24 hours |
| Server request logs | Cloudflare Workers | Maximum 30 days, then automatically purged |
| Subscription data | Apple servers | Managed by Apple per their privacy policy |
We do not indefinitely retain any personal data. All primary storage is local to your device and under your control.
7. Children's Privacy
Hint is rated 13+ on the App Store.
- Age gate: Users must enter their date of birth during onboarding. Users under 13 are blocked from using the App and their entered data is not stored
- COPPA: We do not knowingly collect personal information from children under 13. If we discover such data was collected, we will delete it immediately
- GDPR Article 8: For users aged 13-15 in EU member states where the digital age of consent is 16 (Germany, Ireland, Netherlands, France), parental or guardian consent may be required
- Chat safety: The AI chat companion enforces age-appropriate content. Romantic language is restricted for users who indicate they are under 16
- We do not sell, share, or use minors' data for advertising or AI model training
8. Your Rights
All Users
- Access: View all your data within the App (Profile tab)
- Deletion: Delete all data using "Delete account" in Profile. This permanently removes all local data
- Portability: Save portraits to your photo library at any time
EU/EEA Residents (GDPR)
- Right to access, rectification, erasure, restriction of processing, portability, and objection
- Right to withdraw consent at any time without affecting prior processing
- Right to lodge a complaint with your local data protection authority (e.g., CNIL in France, BfDI in Germany, DPC in Ireland)
- Right not to be subject to solely automated decisions with legal effects (our AI processing is for entertainment only and has no legal effects)
California Residents (CCPA/CPRA)
- Right to know, delete, correct, and opt-out of sale/sharing
- We do not sell or share your personal information
- We do not use your data for cross-context behavioral advertising
- Automated decision-making: Hint uses AI to generate portraits and chat responses. This is entertainment-only processing with no legal or similarly significant effects. You may request human review of any concern
Brazil Residents (LGPD)
- Right to confirmation, access, correction, anonymization, deletion, portability, and consent withdrawal
- We will respond to data subject requests within 15 days
Turkey Residents (KVKK)
- Right to access, correction, deletion, objection, and compensation for damages
- Cross-border transfers to the US are conducted under appropriate safeguards
- We will respond to requests within 30 days
Japan Residents (APPI)
- Right to disclosure, correction, cessation of use, and deletion
- Photos that may reveal physical characteristics are processed only with your explicit consent
9. International Data Transfers
Your data may be transferred to and processed in the United States (Cloudflare, Google, OpenAI). These transfers are protected by:
- EU-US Data Privacy Framework (where applicable)
- EU Standard Contractual Clauses (SCCs) per GDPR Article 46
- Cloudflare's and Google's data processing agreements
- Our commitment to applying equivalent protections regardless of where data is processed
10. Data Security
- All data in transit encrypted using TLS 1.3 (HTTPS)
- Primary data storage on your device, protected by iOS encryption and Secure Enclave
- Temporary server storage (Cloudflare R2) uses encryption at rest
- No user accounts or passwords to compromise — minimal attack surface
11. No Tracking, No Advertising
- Hint does not track you across apps or websites
- We do not use advertising identifiers (IDFA) or App Tracking Transparency
- We do not display advertisements
- We do not share data with data brokers, ad networks, or analytics providers
- We do not sell or share your personal information under any circumstances
12. Data Breach Notification
In the unlikely event of a data breach affecting your personal information:
- We will notify affected users within 72 hours of discovery (GDPR, LGPD, KVKK)
- We will notify relevant supervisory authorities as required
- We will take immediate steps to contain and remediate the breach
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through an updated "Last updated" date and, where practicable, through an in-app notification. Continued use after changes constitutes acceptance.
14. Contact Us
For privacy inquiries, data subject requests, or complaints:
© 2026 Anton. All rights reserved.