Privacy Policy

1. Who is responsible

The controller of your personal data is Sigsten Gustavii, who runs TrickerAI as a private individual in Sweden. Email: sigsten.gustavii@gmail.com. You can also use Settings → Contact support in the app. There is no data protection officer (none is required for a service of this size); questions go to the same address.

2. What we collect

We only handle what is needed to run the service:

Is providing data required? You don't have to give us anything to look around. To create a prank you must provide a photo and a prompt (that is the service). To subscribe you must sign in with Apple or Google and pay through Stripe; without that we can't sell you a subscription. Support messages need an email address so we can reply.

3. How your photo is processed

When you generate a prank, your photo and prompt go over an encrypted connection to our server, which sends them to xAI's Grok image API (SpaceXAI LLC, USA) to create the edited image. xAI processes them on our behalf under a data processing agreement. Under its API terms xAI does not use API inputs or outputs to train its models; it keeps requests and results for up to 30 days to detect abuse and then deletes them. The result comes back to your browser, and our server saves your photo, prompt and the result in private storage (Section 6) so you can find your pranks again. The create screen tells you this next to the Generate button.

Every generated image is marked as AI-generated: the file carries machine-readable metadata (IPTC "trained algorithmic media", EXIF/XMP) and the app labels results "AI-generated", as the EU AI Act requires. We don't recognise or identify faces, and we don't create face templates or other biometric data: the photo is only edited as you describe.

4. People in your photos

If you upload a photo of someone else, we also process that person's image. You may only do that with their agreement (see the Terms), and photos of minors are not allowed. We process these images to provide the edit you asked for, based on our and your legitimate interest in providing and using the service (GDPR Art. 6(1)(f)), with the safeguards in this policy: private storage, deletion at any time, automatic prompt filters and AI-generated marking. Because we can't contact people shown in photos, this policy is how we inform them. If you appear in a prank and want it removed, or object to the processing, email sigsten.gustavii@gmail.com with what you can tell us about the image; we will delete matching pranks we can find.

6. Where your data is stored

On your device: your pranks (photo and result) are kept in your browser's storage (IndexedDB), and app preferences in local storage (Section 7).

On our servers: your photos and results are stored in private file storage on Vercel Blob (United States), never publicly accessible; the app shows them to you through links that expire after about an hour. Your prompts, prank details, usage records, account details (account identifier, name and email if shared) and subscription status are stored in a Postgres database hosted by Neon (United States). Where that database isn't used, your account record (Section 2) is kept as a small private file in the same Vercel Blob store. Support messages are stored as private files in the same Vercel Blob store. Data is linked to your Apple or Google account if you are signed in, otherwise to this browser through a random identifier in a cookie. When you sign in, pranks made in this browser before signing in are moved to your account.

Deleting: deleting a prank removes its images from our servers right away (a stub row without text or images is purged after 30 days). Settings → Delete all data removes your pranks, usage records, account details and template suggestions from our servers (for your account and for this browser), clears this browser and signs you out. It doesn't cancel your subscription and doesn't delete support messages or billing records that we or Stripe must keep (Section 11); ask us if you want support messages deleted too.

Admin access: the operator can see account, subscription and support data through a protected admin panel (two-factor login, every action logged) and only uses it to provide support, handle payments and withdrawals, keep the service secure and meet legal obligations.

7. Cookies and similar storage

We only use first-party cookies that are strictly necessary for the service you asked for, so they need no consent (the only thing we ask about is visitor statistics, Section 2). They can't be read by scripts on the page, and the ones that hold data are signed so they can't be tampered with:

The app also keeps a few things in your browser's local and session storage that never leave your device unless described above: your pranks (IndexedDB), app state and settings such as whether you finished onboarding and your language (tk_state, tk_lang, tk_country), your visitor-statistics choice (tk_analytics), your template "top 10" (tk_top10), which of your pranks are also saved on our servers (tk_cloud_links), a pending checkout so the app can finish it when you return from Stripe (tk_checkout_pending, up to 2 hours), a draft photo and prompt while you check out or write to support, whether you came from the landing page (for this visit only), and cached template counts.

Apple and Google sign-in: Google's sign-in code is only loaded from Google when you tap "Continue with Google". Apple's sign-in script is loaded from Apple's servers when the "Continue with Apple" button is shown (so the sign-in window can open when you tap it); this shares your IP address with Apple. Apple, Google and Stripe use their own cookies on their sign-in and payment pages, under their own policies. We don't use advertising, analytics or tracking cookies: our visitor statistics (Section 2) work without cookies and only run if you allow them.

8. Using TrickerAI on another device

Your subscription is linked to the Apple or Google account you subscribed with. To use it on another device, sign in there with the same account. Access links, which earlier versions of the app offered, are no longer used or accepted.

9. Who receives your data

10. Transfers outside the EU/EEA

Several of these providers are in the United States. Transfers are protected by the EU–US Data Privacy Framework (Vercel, Stripe, Neon, Resend, Google and Apple are certified) and/or the European Commission's Standard Contractual Clauses included in the providers' data processing agreements (xAI, Vercel, Stripe). You can ask us for more information about these safeguards.

11. How long we keep data

12. Your rights and choices

You can delete pranks, or everything with Settings → Delete all data, log out with Settings → Log Out, and cancel your subscription at any time in Settings → Subscription. Visitor statistics only run if you allow them; you can change your choice in Section 2 (Global Privacy Control or Do Not Track also switch them off).

Under the GDPR you also have the right to:

To use these rights, email sigsten.gustavii@gmail.com or use Settings → Contact support (topic "Account & privacy"). We reply within one month (at most two more months for complex requests, and we'll tell you if so), free of charge. To protect your data we may ask you to confirm your identity, for example by writing from your account's email address or from the app on your device. For data Stripe holds as a controller, we'll help you with requests to Stripe.

13. No automated decisions

We don't make decisions about you based solely on automated processing that have legal or similarly significant effects. Automatic filters may refuse a prompt or an edit, which only means that image isn't generated; contact us if you think a refusal was wrong.

14. Security

We use encrypted connections, private storage with short-lived links, signed HttpOnly cookies, same-origin checks, two-factor protection and an audit log for admin access, and providers with recognised security certifications. If a personal data breach is likely to put you at risk, we will tell you and report it to IMY as the law requires.

15. Children

TrickerAI is only for people aged 18 and over. It is not directed at children, photos of minors must not be uploaded, and we don't knowingly collect children's data. If you believe a child has used the service or appears in a prank, contact us and we will remove the related data.

16. Changes to this policy

If this policy changes, we will update the "Last updated" date above and, for material changes, let you know in the app before they take effect.

17. Contact

Questions about this policy or your data: sigsten.gustavii@gmail.com (Sigsten Gustavii, TrickerAI, Sweden). You can also complain to the Swedish Authority for Privacy Protection (IMY) or your local data protection authority.