Privacy Policy
Last updated: September 21, 2026
This policy explains what personal data the TrickerAI web app handles, why, who we share it with, how long we keep it and the rights you have. In short: your photos and pranks are kept in private storage that only you can open through the app, you can delete them at any time, we never sell your data or use it for advertising, and nobody trains AI models on your photos. You can try the app without an account; subscribing requires signing in with Apple or Google, and your subscription is linked to that account.
1. Who is responsible
The controller of your personal data is Sigsten Gustavii, who runs TrickerAI as a private individual in Sweden. Email: sigsten.gustavii@gmail.com. You can also use Settings → Contact support in the app. There is no data protection officer (none is required for a service of this size); questions go to the same address.
2. What we collect
We only handle what is needed to run the service:
- Photos and prompts. The photo you choose to edit and the text prompt (or template) describing the edit, sent when you generate a prank, plus an optional title.
- Generated images. The AI-edited results, saved in your browser and in private storage on our servers (Section 6).
- Sign-in details (required to subscribe). When you sign in with Apple or Google we receive an account identifier from that provider and, if you allow it, your name and email address (with Apple you can hide your email). We never receive or store a password. We keep an account record on our servers: the account identifier, whether you used Apple or Google, your name and email (if shared), when you signed up and when you last used the app (updated at most once a day), the country of your IP address when you sign in, and the app language. We use it to run your account, give support and manage your subscription.
- Subscription information. Stripe, our payment provider, collects your payment details and billing email. We receive your Stripe customer ID and your subscription status (plan, status and renewal date) — never your card number. To enforce the weekly limit we keep the times of your recent generations with your subscription record at Stripe, and your account identifier (and name and email, if shared) is stored there too so the subscription follows your account.
- Usage records. For each prank we record when it was made and whether it was a free preview, a generation or an unlock. Template usage is also counted in aggregate (for example "1.2k pranks made" on a template); those counts contain no personal data.
- Support messages and withdrawals. If you contact support or use Withdraw from contract here, we receive your email address, the topic, your message (for withdrawals: your name and contract details) and, unless you turn it off, technical details: app version, browser and device type, screen size, language, subscription status, number of pranks, your account ID, account email and Stripe customer ID, and a one-way hash of this browser's device ID.
- Template suggestions and votes. If you use Settings → Suggest a template, we receive the idea you write and/or your "top 10" favourite templates, with the app language, the time, and whether you were signed in (Google, Apple or not signed in). They are linked to your account, or if you're not signed in to a pseudonymous ID derived from this browser's device ID, so a new top 10 replaces your old one; the account ID and device ID themselves are not stored with them. Please don't write personal details in an idea.
- Technical data. Our hosting provider receives standard request information such as your IP address, browser type and the time of each request. Vercel also tells us the country your IP address is in; we use it to show and charge prices in the right currency and, when you're signed in, save it in your account record (above); otherwise it isn't stored. To prevent abuse of free previews and the contact form, our servers briefly count requests per IP address using a one-way keyed hash of the address, kept only in memory; the address itself is not stored.
- Visitor statistics (only if you allow them, no cookies). The landing page asks whether we may count your visit. Only if you tap Allow do the landing page and the app send a small, cookieless page-view signal: the page or app screen (for example "/app/home", never IDs, prompts or query strings), whether it starts a visit, the website that referred you (host name only, e.g. "tiktok.com") and whether you opened the app from the landing page. From the request our server derives your country (from the IP address), device type (mobile, tablet or desktop), browser and operating system family. Only aggregate counts are stored (for example "Sweden: 120 visits on 21 September"). To count unique visitors, your IP address and browser identifier are combined with a secret that changes every day and turned into a one-way hash, which is immediately reduced to an anonymous statistical sketch; the IP address, the browser identifier and the hash itself are never stored, and visitors can't be recognised from one day to the next. With your permission we also use Vercel Web Analytics, which works the same way (no cookies, a daily-changing anonymous hash, aggregate reports of pages, referrers, country, browser and device type). If you tap No thanks or ignore the question, nothing is sent; nothing is ever sent if your browser sends a Do Not Track or Global Privacy Control signal. Your choice is remembered in this browser (
tk_analytics) and you can change it here at any time:
Is providing data required? You don't have to give us anything to look around. To create a prank you must provide a photo and a prompt (that is the service). To subscribe you must sign in with Apple or Google and pay through Stripe; without that we can't sell you a subscription. Support messages need an email address so we can reply.
3. How your photo is processed
When you generate a prank, your photo and prompt go over an encrypted connection to our server, which sends them to xAI's Grok image API (SpaceXAI LLC, USA) to create the edited image. xAI processes them on our behalf under a data processing agreement. Under its API terms xAI does not use API inputs or outputs to train its models; it keeps requests and results for up to 30 days to detect abuse and then deletes them. The result comes back to your browser, and our server saves your photo, prompt and the result in private storage (Section 6) so you can find your pranks again. The create screen tells you this next to the Generate button.
Every generated image is marked as AI-generated: the file carries machine-readable metadata (IPTC "trained algorithmic media", EXIF/XMP) and the app labels results "AI-generated", as the EU AI Act requires. We don't recognise or identify faces, and we don't create face templates or other biometric data: the photo is only edited as you describe.
4. People in your photos
If you upload a photo of someone else, we also process that person's image. You may only do that with their agreement (see the Terms), and photos of minors are not allowed. We process these images to provide the edit you asked for, based on our and your legitimate interest in providing and using the service (GDPR Art. 6(1)(f)), with the safeguards in this policy: private storage, deletion at any time, automatic prompt filters and AI-generated marking. Because we can't contact people shown in photos, this policy is how we inform them. If you appear in a prank and want it removed, or object to the processing, email sigsten.gustavii@gmail.com with what you can tell us about the image; we will delete matching pranks we can find.
5. Why we use your data and our legal bases
- Creating and storing your pranks, running your account and subscription, the free preview and the withdrawal function — to perform our contract with you (GDPR Art. 6(1)(b)).
- Processing images of other people in your photos — legitimate interests (Art. 6(1)(f)), see Section 4.
- Bookkeeping, tax and consumer-law records (payments, refunds, withdrawals) — legal obligation (Art. 6(1)(c)).
- Security and abuse prevention (hosting logs, rate limits, the one-preview-per-browser limit, prompt filters, admin audit log) — legitimate interest in keeping the service safe and working (Art. 6(1)(f)).
- Answering support messages — contract where it concerns your purchase or pranks, otherwise legitimate interest in helping you (Art. 6(1)(b)/(f)).
- Template suggestions and votes (Section 2) — legitimate interest in improving the app and choosing which templates to make next (Art. 6(1)(f)). Only the operator sees them, in the admin panel; they're not published or emailed.
- Choosing your currency from your country — legitimate interest in showing the correct price (Art. 6(1)(f)).
- Cookieless, aggregate visitor statistics (Section 2) — your consent (Art. 6(1)(a) GDPR and, for the page-view signal sent from your browser, the Swedish Electronic Communications Act, LEK 9 kap. 28 §). You can withdraw it at any time in Section 2; that doesn't affect counts already made.
We don't use your data for advertising, profiling or marketing emails, and we don't sell it.
6. Where your data is stored
On your device: your pranks (photo and result) are kept in your browser's storage (IndexedDB), and app preferences in local storage (Section 7).
On our servers: your photos and results are stored in private file storage on Vercel Blob (United States), never publicly accessible; the app shows them to you through links that expire after about an hour. Your prompts, prank details, usage records, account details (account identifier, name and email if shared) and subscription status are stored in a Postgres database hosted by Neon (United States). Where that database isn't used, your account record (Section 2) is kept as a small private file in the same Vercel Blob store. Support messages are stored as private files in the same Vercel Blob store. Data is linked to your Apple or Google account if you are signed in, otherwise to this browser through a random identifier in a cookie. When you sign in, pranks made in this browser before signing in are moved to your account.
Deleting: deleting a prank removes its images from our servers right away (a stub row without text or images is purged after 30 days). Settings → Delete all data removes your pranks, usage records, account details and template suggestions from our servers (for your account and for this browser), clears this browser and signs you out. It doesn't cancel your subscription and doesn't delete support messages or billing records that we or Stripe must keep (Section 11); ask us if you want support messages deleted too.
Admin access: the operator can see account, subscription and support data through a protected admin panel (two-factor login, every action logged) and only uses it to provide support, handle payments and withdrawals, keep the service secure and meet legal obligations.
8. Using TrickerAI on another device
Your subscription is linked to the Apple or Google account you subscribed with. To use it on another device, sign in there with the same account. Access links, which earlier versions of the app offered, are no longer used or accepted.
9. Who receives your data
- xAI (SpaceXAI LLC, USA) — processor: creates the edited images from your photo and prompt (Section 3). x.ai/legal/privacy-policy
- Vercel Inc. (USA) — processor: hosts the website and server functions, stores photos, results and support messages in private Vercel Blob storage, keeps request logs for operations and security, and provides cookieless visitor statistics (Vercel Web Analytics, only if you allow them). vercel.com/legal/privacy-policy
- Neon (Databricks, USA) — processor: hosts our Postgres database. neon.com/privacy-policy
- Stripe (Stripe Payments Europe Ltd, Ireland, and Stripe, Inc., USA) — processes payments on our behalf, stores billing details and runs the billing portal; for fraud prevention and its own legal duties Stripe acts as an independent controller. stripe.com/privacy
- Apple and Google — independent controllers for "Sign in with Apple" and "Sign in with Google"; they confirm your identity and share the details in Section 2. We send them nothing beyond the standard sign-in.
- Resend (USA) — processor, only when email sending is switched on: delivers support notifications to us and withdrawal confirmations to you. resend.com/legal/privacy-policy
- Google (Gmail) — our support mailbox, where support emails and replies are kept.
- Authorities — only if the law requires it (for example a court order), and advisers such as an accountant where needed for bookkeeping.
10. Transfers outside the EU/EEA
Several of these providers are in the United States. Transfers are protected by the EU–US Data Privacy Framework (Vercel, Stripe, Neon, Resend, Google and Apple are certified) and/or the European Commission's Standard Contractual Clauses included in the providers' data processing agreements (xAI, Vercel, Stripe). You can ask us for more information about these safeguards.
11. How long we keep data
- Photos, prompts and generated images on our servers: until you delete them (a single prank, or everything with Delete all data) or ask us to. If you're not signed in, they're deleted automatically after 90 days without activity from your browser.
- At xAI: up to 30 days after each generation, for abuse monitoring.
- Account details (including your account record) and usage records on our servers: until you use Delete all data or ask us to delete them; for browsers without a signed-in account, 90 days after the last activity.
- Pranks and settings on your device: until you delete them, clear this site's data, or use Delete all data.
- Session cookie: up to a year after your last visit, or until you log out.
- Generation times at Stripe: only the last 7 days are kept, to enforce the weekly limit.
- Payment, refund and withdrawal records: as long as bookkeeping and consumer law require (in Sweden generally 7 years); Stripe keeps its own records under its policy.
- Support messages: up to 24 months after the conversation ends, unless we need them longer for a legal claim; delete earlier on request.
- Template suggestions and votes: up to 24 months; a new top 10 replaces the previous one right away, and Delete all data removes them.
- Visitor statistics: only aggregate counts are kept, for up to 13 months; the daily secret used to count unique visitors is never stored. Vercel Web Analytics keeps its aggregate reports under Vercel's policy.
- Hosting logs and the admin audit log: hosting logs for a short period set by Vercel (days); the admin audit log for up to 12 months.
12. Your rights and choices
You can delete pranks, or everything with Settings → Delete all data, log out with Settings → Log Out, and cancel your subscription at any time in Settings → Subscription. Visitor statistics only run if you allow them; you can change your choice in Section 2 (Global Privacy Control or Do Not Track also switch them off).
Under the GDPR you also have the right to:
- access your data and get a copy, and data portability — we send your pranks (images) and the related records in a common format (a ZIP with images and a JSON file);
- rectification of inaccurate data and erasure;
- restriction of processing;
- object at any time to processing based on legitimate interests (Section 5), including as a person shown in someone else's photo;
- complain to a supervisory authority: in Sweden the Swedish Authority for Privacy Protection (IMY), or the authority where you live or work.
To use these rights, email sigsten.gustavii@gmail.com or use Settings → Contact support (topic "Account & privacy"). We reply within one month (at most two more months for complex requests, and we'll tell you if so), free of charge. To protect your data we may ask you to confirm your identity, for example by writing from your account's email address or from the app on your device. For data Stripe holds as a controller, we'll help you with requests to Stripe.
13. No automated decisions
We don't make decisions about you based solely on automated processing that have legal or similarly significant effects. Automatic filters may refuse a prompt or an edit, which only means that image isn't generated; contact us if you think a refusal was wrong.
14. Security
We use encrypted connections, private storage with short-lived links, signed HttpOnly cookies, same-origin checks, two-factor protection and an audit log for admin access, and providers with recognised security certifications. If a personal data breach is likely to put you at risk, we will tell you and report it to IMY as the law requires.
15. Children
TrickerAI is only for people aged 18 and over. It is not directed at children, photos of minors must not be uploaded, and we don't knowingly collect children's data. If you believe a child has used the service or appears in a prank, contact us and we will remove the related data.
16. Changes to this policy
If this policy changes, we will update the "Last updated" date above and, for material changes, let you know in the app before they take effect.
17. Contact
Questions about this policy or your data: sigsten.gustavii@gmail.com (Sigsten Gustavii, TrickerAI, Sweden). You can also complain to the Swedish Authority for Privacy Protection (IMY) or your local data protection authority.