Decoria.Studio Privacy Policy
1. Who we are
The controller of your personal data is JS Technology Jakub Szczybiełkiewicz, ul. Bukowa 24A, 55-093 Kiełczów, Poland, Tax ID (NIP): 8272162838, REGON: 100300408 ("we", "us"). Our privacy officer (including for Canada and Québec) is Jakub Szczybiełkiewicz. Contact for all privacy matters: hi@decoria.studio.
2. How the app works and where data comes from
Using the app requires signing in — with your Apple account (Sign in with Apple, iOS) or your Google account (Sign in with Google, Android). From Apple or Google we receive only a stable account identifier and your e-mail address (on iOS you may use Apple's "Hide My Email" alias). We never receive your password. Projects, scans and purchased packs are tied to your account and are available on every device where you sign in. The app also keeps a random technical device identifier for free-tier limits and diagnostics.
3. What data we process
| Category | Examples | Purpose |
|---|---|---|
| Account data | Apple or Google account identifier, e-mail address (may be an Apple alias) | sign-in, linking projects and packs, cross-device sync, support |
| Device identifier | random UUID stored on the device | free-tier limits, diagnostics |
| Project content | style-and-budget conversation (brief), room scans (geometry and dimensions), room photos, generated visualisations, furniture layouts, shopping lists | providing the service — designing your interior |
| Purchase data | App Store or Google Play transaction ID, product, quantity | crediting packs, fraud prevention, complaints |
| Usage and device data | screens visited and actions in the app, device model, OS and app version, market/region, last-activity time | diagnostics, support, product statistics |
| Advertising identifiers | IDFA (iOS, only after you allow tracking in the App Tracking Transparency prompt) or Android Advertising ID; consent choices | serving ads in the free tier (Google AdMob) |
| Device integrity tokens | Apple DeviceCheck, Google Play Integrity | enforcing free-tier limits, abuse prevention |
We never process payment-card data — payments are handled entirely by Apple or Google. We do not collect precise location, contacts, health data or biometric data. Room scans describe the geometry of a room, not people.
4. Shop links and affiliate programmes
Shopping lists may contain links to products in external shops and marketplaces (for example eBay). Some of these links are affiliate links: if you buy after tapping one, we may earn a commission at no extra cost to you. When you tap a link, we record an anonymous click event (partner network, product category, price and market) — without your account or device identifier — to understand which offers are useful. After you leave the app, the shop's or marketplace's own privacy policy applies. We do not share your personal data with affiliate networks.
5. Legal bases (EU/EEA/UK users)
- performance of a contract (Art. 6(1)(b) GDPR) — providing the app's services and crediting purchases;
- legitimate interest (Art. 6(1)(f) GDPR) — security, abuse prevention, statistics, non-personalised ads;
- consent (Art. 6(1)(a) GDPR) — personalised ads; you can change or withdraw consent at any time in the app (Account → Privacy choices) or in your device settings;
- legal obligation (Art. 6(1)(c) GDPR) — accounting and complaints.
6. Service providers and recipients
- Google Cloud (Google Ireland Ltd.) — backend and file hosting; data stored in the europe-central2 region (Warsaw, EU);
- Anthropic PBC (USA) — AI processing of the brief, shopping lists and render prompts, and an automatic quality check of generated visualisations (the generated image is analysed to confirm it matches your layout);
- Replicate Inc. (USA) — generating visualisations (a 3D sketch of your layout or your room photo and a style description are transmitted);
- Google AdMob — ads in the free tier, consent management (Google User Messaging Platform);
- Apple Inc. and Google LLC — sign-in, payments, DeviceCheck / Play Integrity;
- Cloudflare, Inc. — hosting of decoria.studio and cookieless, anonymous website statistics.
Transfers outside the EEA rely on the EU–US Data Privacy Framework or Standard Contractual Clauses. Our providers may process data only on our instructions.
7. Retention
Project content — until you delete it or delete your account. Purchase data — for the period required by accounting and limitation rules. Usage and device data — up to 24 months after last activity. Anonymous click events — up to 24 months.
8. Your rights and how to exercise them
You can access, correct, delete or export your data, restrict or object to processing, and withdraw consent. Delete your account in the app (Account → Delete account) — your account and all its data (projects, scans, photos, visualisations, shopping lists) are deleted; purchase records are kept only as long as the law requires. You can also write to hi@decoria.studio from the e-mail linked to your account — we reply within 30 days (45 days where US state law allows). We will not discriminate against you for exercising your rights. You may lodge a complaint with a data-protection authority (in Poland: uodo.gov.pl).
9. Additional information for United States residents
This section applies to residents of California (CCPA as amended by the CPRA) and other US states with comprehensive privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, Texas, Oregon).
- Categories collected in the last 12 months: identifiers (account ID, e-mail, device and advertising IDs), commercial information (in-app purchases), internet or other electronic network activity (app usage), and user-generated content (brief, scans, photos, designs). Sources and purposes are described in sections 2–4; retention in section 7.
- Sale and sharing: we do not sell personal information for money. When personalised ads are enabled, advertising identifiers and app activity are shared with Google AdMob for cross-context behavioural advertising, which may be a "sale" or "sharing" under some state laws.
- Your choice — Do Not Sell or Share My Personal Information / opt out of targeted advertising: open the app → Account → Privacy choices, or e-mail hi@decoria.studio with the subject "Do Not Sell or Share". We honour Global Privacy Control signals on our website where applicable. On iOS you can also deny tracking in Settings → Privacy & Security → Tracking; on Android, delete or reset your advertising ID in device settings.
- Sensitive personal information: we do not collect or use sensitive personal information to infer characteristics about you.
- Your rights: to know/access, delete, correct, obtain a portable copy, and opt out of sale, sharing and targeted advertising. You may use an authorised agent; we may verify your request through the e-mail linked to your account. If we deny a request, you may appeal by replying to our decision e-mail with the subject "Appeal"; if the appeal is denied, you may contact your state Attorney General.
- Minors: we do not knowingly sell or share personal information of consumers under 16.
10. Additional information for Canadian residents
We process personal information in accordance with PIPEDA and, for Québec residents, the Act respecting the protection of personal information in the private sector (Law 25). We collect personal information only for the purposes described in this policy and with your consent, which you can withdraw at any time (subject to legal or contractual restrictions) — for personalised ads via Account → Privacy choices. You have the right to access and correct your personal information and to ask about its use and disclosure; write to our privacy officer at hi@decoria.studio. Your personal information is stored in the European Union and processed by the providers listed in section 6, including in the United States, where it may be accessible to local authorities under local law. We do not use personal information to make decisions based exclusively on automated processing. You may file a complaint with the Office of the Privacy Commissioner of Canada or, in Québec, the Commission d'accès à l'information.
11. Children
The app is not directed at children under 13 and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.
12. Security
Data is transmitted over encrypted connections (HTTPS) and stored with access controls at our hosting provider. No system is perfectly secure, but we take reasonable measures appropriate to the data we process.
13. Changes
We will announce material changes in the app. The current version is always available at this address.