Back to HomeDeep Stencil

Privacy Policy

Last updated: 09/07/2026

Introduction

This policy describes how Deep Stencil collects, uses, retains, and protects your personal data, in compliance with EU Regulation 2016/679 (GDPR). The service is reserved exclusively for adult users (18 years of age or older). By using Deep Stencil you accept the practices described in this policy.

Data Controller

The data controller is Deep Stencil, based in Italy. For privacy-related contacts: info@deepstencil.com

Data Collected

Registration data: email address, name (optional), OAuth authentication data (Google).

Usage data: generation prompts, created designs, style preferences, uploaded images.

Technical data: IP address, browser type, operating system, pages visited, session duration.

Payment data: handled entirely by Stripe. We do not store credit card numbers on our servers.

Personal photos for Try-On: if you use the virtual try-on feature, the photos of your body or face that you upload are processed to apply a tattoo preview. These images are stored in a private storage space, accessible only through temporary signed links, and are removed upon account deletion.

Purpose of Processing

Your data is processed for: providing and delivering the service, generating designs and virtual try-on, managing your account and subscriptions, improving the user experience, aggregate statistical analysis, service-related communications, legal and tax compliance, and preventing abuse and fraud.

Legal Basis

We process your data on the following legal bases (Art. 6 GDPR): performance of a contract (providing the service, generation, try-on, subscription management); consent (analytics cookies and any marketing communications, revocable at any time); legitimate interest (platform security, abuse prevention, technical operational analysis with minimized data); legal obligation (tax and accounting compliance).

AI Processing

The images and text (prompts) you submit are processed by a third-party artificial intelligence provider based in the United States, to generate designs and the virtual try-on. The data is transmitted in encrypted form and, under the provider's terms, is not used to train the AI models. This entails a transfer of data outside the European Economic Area (see the International Transfers section).

Data Retention

We retain data for the time strictly necessary: account data, photos, and generated designs are retained until account deletion, which you can request at any time from the dashboard; technical analytics events are automatically anonymized after 90 days, removing any reference to the user; administrative access logs are deleted after 90 days. Upon account deletion, all of your personal data, photos, and designs are permanently removed.

International Transfers

Some providers we use process data outside the European Economic Area, in particular in the United States (for artificial intelligence processing and traffic analysis). These transfers are protected by the Standard Contractual Clauses (SCC) approved by the European Commission and/or by equivalent adequacy mechanisms provided for by the GDPR.

Your Rights (GDPR)

You have the right to: access your data, rectify it, erase it (right to be forgotten, available directly from the dashboard), restrict its processing, object to processing, and withdraw consent. You also have the right to data portability: you can download a copy of your data in a readable format through the "Download my data" feature in the dashboard. You can exercise these rights by writing to info@deepstencil.com. Finally, you have the right to lodge a complaint with the competent supervisory authority (in Italy, the Garante per la protezione dei dati personali (Italy)).

Third-Party Services

We rely on the following data processors (sub-processors), each with its own privacy policy: Supabase (database, authentication, and storage); Vercel (application hosting); Stripe (payment processing); a third-party generative artificial intelligence provider (design generation and try-on, USA); Google Analytics 4 (traffic analysis, USA); Resend (transactional email delivery); Upstash (request rate limiting and anti-abuse protection); Sentry (technical error monitoring).

Security

We adopt appropriate technical and organizational measures to protect your data: encryption in transit (HTTPS/TLS), secure authentication via OAuth, storage of sensitive photos in a private space accessible only through temporary signed links, restriction of data access to authorized personnel only, and monitoring of administrative access.

Minimum Age

Deep Stencil is reserved exclusively for adults (18 years of age or older). Confirmation of legal age is required upon first access. We do not knowingly collect data from minors; should we become aware of an account created by a minor, we will proceed with its deletion.

Changes to Privacy Policy

We reserve the right to update this policy. Significant changes will be communicated via email or through a notice on the platform.

DPO Contact

For any request regarding privacy and the processing of your personal data: info@deepstencil.com