Legal
Privacy Policy
Last updated: June 3, 2026
Veyoro is an AI-powered visual generation platform for jewelry brands, operated by Kerem Alemdar ("Veyoro", "we", "us"). This Privacy Policy explains what personal data we collect when you use the Veyoro website, iOS app, or APIs (the "Service"), why we collect it, who we share it with, and the choices you have. By using the Service you agree to the practices described here.
If you are in the European Economic Area, the United Kingdom, or Switzerland, we act as the data controller for your personal data. If you have questions or want to exercise your rights, contact us at info@veyoro.com.
1. Information we collect
Account data. When you sign up we collect your email address, an encrypted hash of your password (if you sign up that way), and a record of which third-party providers (Apple, Google) you have linked. We do not see your password in plain text at any point.
Content you provide. When you generate a campaign, we receive the product reference image you upload and the wizard selections you make (product category, platform, style, model attributes, count, etc.). These together form what we internally call your "canonical payload".
Generated output. We store the images our AI providers return to you, plus the internal brief our prompt-transformation step produced from your selections.
Usage data. We log basic technical information about each request: timestamps, the type of action (sign-in, generation, deletion), credit transactions, and (for abuse-prevention) the IP address the request came from. We do not run analytics SDKs that track behavior across other sites.
Device data. The iOS app may log non-personal diagnostic information (iOS version, app version, error stack traces) to help us debug crashes.
2. How we use your information
We use the data described above to:
• Run the Service — authenticate you, generate the campaigns you request, deliver results, and track your credit balance.
• Communicate with you about your account (verification emails, password resets, important service announcements). We do not send marketing emails unless you opt in.
• Keep the Service secure — detect abuse, prevent fraud, enforce our Terms of Service.
• Improve the Service — analyze aggregate, de-identified usage patterns to understand which features are useful. We do not train AI models on your uploaded content.
• Comply with legal obligations (tax, accounting, legal requests we are required to respond to).
3. Third-party processors
We rely on the following service providers, each of whom processes your data strictly on our behalf and under contract:
• Supabase — authentication, database, and file storage. Hosted in the EU (Frankfurt) for accounts created from Europe.
• OpenAI — used to transform your wizard selections into a creative brief that drives image generation. Your reference image is not sent to OpenAI; only the structured selections are.
• Fal.ai — runs the image generation model that produces your campaign visuals. Both your reference image and the brief are sent.
• Apple and Google — used only when you choose Sign in with Apple / Google. They share a minimal identity token with us; we never see your Apple / Google password.
• Hetzner / Coolify — infrastructure provider that hosts our backend.
We do not sell your personal data. We do not share it with advertising networks.
4. International data transfers
Some of our processors (OpenAI, Fal.ai) operate in the United States. When your data is transferred outside the European Economic Area, we rely on European Commission-approved Standard Contractual Clauses with the receiving party and apply additional safeguards where appropriate.
5. How long we keep your data
We keep your account data for as long as your account is active. When you delete your account from inside the app (Settings → Delete account), we permanently remove your account record, your generated campaigns, your reference images, and your credit history within 30 days. Some data may be retained longer where required by law (for example, tax records).
Logs containing IP addresses for security purposes are kept for up to 90 days, then automatically purged.
6. Your rights
If you are in the EEA, UK, or Switzerland, the GDPR (or equivalent local law) gives you the right to:
• Access the personal data we hold about you.
• Correct inaccurate data.
• Delete your account and associated data (you can do this directly inside the app).
• Object to, or restrict, certain processing.
• Receive your data in a portable format.
• Lodge a complaint with your local data protection authority.
To exercise any of these rights, email info@veyoro.com. We will respond within 30 days.
7. How we protect your data
We encrypt data in transit (HTTPS for all endpoints) and at rest (Supabase's encrypted storage). Passwords are salted and hashed with industry-standard algorithms before being persisted. Access to production systems is limited and audited.
No system is perfectly secure. If we ever discover a breach that puts your data at risk, we will notify affected users without undue delay.
8. Children
Veyoro is intended for users aged 16 and older. We do not knowingly collect data from children under 16. If you believe a child has signed up, contact us and we will delete the account.
9. Changes to this policy
We may update this policy from time to time. When we make material changes we will notify you by email or in-app banner before the changes take effect. The "Last updated" date at the top of this page always reflects the most recent revision.