Privacy Policy

Last updated: April 17, 2026

1. Data Controller

This privacy policy applies to the Not Me! ("we", "us", "our") mobile application. As data controller under the Turkish Personal Data Protection Law (KVKK No. 6698) and the EU General Data Protection Regulation (GDPR), we process your personal data for the purposes described below.


2. Data We Collect

The following data is processed during your use of the application:

Email address

For account creation and authentication

Uploaded photos

Used solely for AI image generation; automatically deleted from our servers after generation is complete

Generated images

Stored linked to your account, or (when used without sign-in) to a randomly generated device identifier (UUID), for the history and favorites features

Favorite templates

Stored in the database to personalize your experience

Credit and transaction history

For billing and support purposes

Push notification token

For in-app notifications only; never shared with third parties

Analytics data

In-app interactions, device information, and user ID — processed by Amplitude Inc.


3. Purpose of Processing

  • Account creation and authentication
  • AI-powered personalized image generation
  • Providing generation history and favorites features
  • Credit system and subscription management
  • Technical support and customer service
  • Compliance with legal obligations

4. Third-Party Service Providers

We work with the following third-party providers to deliver our services. Each provider processes data only for the stated purpose:

OVHcloud

Policy ↗

Application server and database hosting (France, within the EU)

Hetzner

Policy ↗

Photo and image file storage (Finland, within the EU)

AI image generation service — uploaded photos are transmitted solely for image generation

RevenueCat

Policy ↗

Subscription and in-app purchase management

Apple App Store / Google Play

App distribution and payment processing

Amplitude

Policy ↗

Analytics — in-app interactions, device information, and user ID; used to improve the app experience


5. Face and Photo Data

Input photos (selfies): Temporarily stored in encrypted form on secure cloud storage within the EU for the purpose of AI image generation. Automatically deleted from our servers after generation is complete. No facial recognition, biometric analysis, or face mapping is performed; no biometric identifiers are extracted from your photos.

Generated images: Retained on our servers for the history feature, linked to your account if signed in, or to a randomly generated device identifier (UUID) if used anonymously. This identifier is not personal data; it contains no name, email, or biometric information. You can delete individual images from your History screen, delete your entire account from Profile settings, or uninstall the app (when used anonymously) to permanently remove all data.

Third-party sharing: Your photos are shared only with kie.ai for AI image generation purposes. They are not shared with advertisers, analytics providers, or any other third parties.


6. Data Security

Your personal data is encrypted in transit (HTTPS), protected with authenticated access, and stored with industry-standard security measures. Authorization controls ensure users can only access their own data. In the event of a data breach, affected individuals and relevant authorities will be notified in accordance with applicable law.


7. Your Rights (KVKK / GDPR)

You have the following rights regarding your personal data:

  • Right to know whether your data is being processed
  • Right to request information about processing
  • Right to know the purpose of processing and whether data is used accordingly
  • Right to know third parties to whom data is transferred
  • Right to request correction of incomplete or inaccurate data
  • Right to request deletion or destruction of your data
  • Right to request notification of corrections/deletions to third parties
  • Right to object to automated decision-making that adversely affects you
  • Right to claim compensation for damages arising from unlawful processing

To exercise your rights, contact us at [email protected] Requests are responded to within 30 days.


8. Children's Privacy

Not Me! is not directed to individuals under the age of 13. If we become aware that we have collected data from a user under 13, that data will be deleted immediately.


9. Policy Changes

This policy may be updated from time to time. Significant changes will be communicated through the application. You can always access the current policy on this page.

© 2026 Not Me!. All rights reserved.