Privacy Policy
This Privacy Policy explains how ZEITARC ("we", "us", "our") collects, uses, stores, and protects your personal data when you use the LINEORA mobile application ("App"). This Policy is designed to comply with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data-protection laws.
LINEORA converts photos to line drawings using AI image generation. To produce a drawing, the App uploads your photo over a TLS-encrypted connection directly to ZEITARC's cloud storage (Hetzner Object Storage in the European Union), using a short-lived signed URL issued by our API. A background service then sends a copy of the stored photo to third-party AI image-generation providers for stylization and writes the generated drawing back to your cloud library, where the App fetches it for display. We have designed the App so that the information we hold about you is pseudonymous: your account is identified only by a random UUID, never by a name or email, unless you choose to provide one (for example, when contacting support).
Important: By using LINEORA, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the App.
1. Data Controller
The data controller responsible for your personal data is:
ZEITARC Islamabad, Pakistan Website: zeitarc.com
As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring compliance with applicable data-protection laws.
1.1 EU Representative (Article 27 GDPR)
ZEITARC is based outside the European Union. Under GDPR Article 27(2)(a), a representative in the EU is not required where processing is occasional, does not include large-scale processing of special categories of data, and is unlikely to result in a risk to the rights and freedoms of data subjects.
We believe this exemption applies to LINEORA because:
- We do maintain a server-side record of your account — a randomly generated UUID, your remaining credit balance, your uploaded photos and generated drawings, sketch metadata, push-notification tokens, support correspondence, and legal acceptances — but this record is pseudonymous: it is not linked to your name, email, government ID, or any other real-world identifier unless you choose to share one with us. Storage of your photos and drawings is hosted within the European Union (Hetzner Object Storage), is encrypted in transit and at rest, and is accessible only via short-lived signed URLs issued to your authenticated session.
- We do not process special categories of personal data (such as health data) within the App.
- The nature, context, and scope of our processing is unlikely to result in a risk to the rights and freedoms of data subjects, given the technical and organisational safeguards we have in place.
We keep this assessment under regular review. Should our processing activities change in nature or scale, we will appoint an EU representative and update this Policy accordingly. In the meantime, you may contact us directly at privacy.line@zeitarc.com for any data-protection matters.
2. Personal Data We Process
We process the categories of personal data described below.
2.1 Photos and Generated Drawings
When you select a photo and tap a style, the App reads the photo from your camera or photo library, downscales it to a maximum dimension of 1500 pixels to limit upload size, and uploads the resulting image over a TLS-encrypted connection directly to ZEITARC's cloud storage (Hetzner Object Storage in the European Union) using a short-lived signed URL issued by our API. A background service then sends a copy of the stored photo to third-party AI image-generation providers for stylization, receives a generated drawing, and writes it back to your cloud library, where the App fetches it for display. Both your uploaded photo and the generated drawing are retained in our cloud library, hosted in Hetzner Object Storage in the European Union, so your gallery follows you across devices and the App's compare-with-original view can re-fetch the source photo. Stored images are encrypted in transit and at rest, are accessible only via short-lived signed URLs issued to your authenticated session, and are deleted from our storage when you delete the corresponding sketch from the in-app gallery.
2.1a Device Identifier
On first launch the App calls our API to mint a brand-new anonymous account. Our API generates a random UUID for the account and returns it along with a bearer token; the App stores both in the operating system's secure storage. Every subsequent API call authenticates with the bearer token, and our server resolves your account from the token. Server-side enforcement covers your credit balance only — the small free-render allotment is tracked locally on your device, which is why uninstalling the App or clearing its data resets the allotment. The UUID is not derived from any hardware or OS-level identifier; if you want to keep your account and credits across reinstalls, save the recovery code we offer in Settings.
2.2 Purchase and Entitlement Data
When you buy a credit pack, the transaction is processed by Apple Inc. (App Store) on iOS or by Google LLC (Google Play Store) on Android, and validated through RevenueCat, Inc. We receive confirmation that you own the entitlement, plus an anonymous app-user identifier assigned by RevenueCat so that we can restore your purchases on reinstall and across devices signed in to the same Apple ID or Google Account. We do not receive your payment-method details, billing address, or full account identifiers.
2.3 Anonymous Usage Events
We use PostHog, Inc. to record how features of the App are used (for example: which drawing styles are tapped, whether the paywall was opened, whether a render succeeded). Events do not contain photo content, file names, or text you have entered. PostHog assigns an anonymous installation identifier scoped to the device.
2.4 Crash and Error Reports
We use Sentry, Inc. to record uncaught errors and crashes so we can investigate and fix them. A typical report contains the error message, a stack trace, and basic device information (model, operating-system version, App version). It does not contain photo content.
2.5 Advertising Attribution Data
We advertise the App on Facebook and Instagram. So that we can tell which of those ads actually lead to installs and purchases — and stop paying for the ones that do not — the Android version of the App includes Meta Platforms' App Events SDK. It reports a small set of milestone events to Meta Platforms Ireland Limited: that the App was installed and opened, that you finished your first drawing, that you opened the purchase screen, and that you completed a purchase, including its amount and currency. Alongside those events it sends the anonymous account UUID described in Section 2.1a and your device's Google Advertising ID. No photo, no generated drawing, no recovery code, and no support correspondence is ever sent to Meta.
The iOS version of the App does not contain Meta's SDK, asks for no App Tracking Transparency permission, and sends nothing to Meta. Everything in this Section 2.5, and every later reference to it, describes the Android App only.
The Google Advertising ID is issued and controlled by your operating system, not by us, and you can revoke it without our involvement: open Settings > Privacy > Ads and choose Delete advertising ID. From that moment Meta receives no usable identifier from the App and can no longer match your device against its own records. The milestone events themselves can be stopped by writing to privacy.line@zeitarc.com, and you may object to this processing at any time under Section 9.6.
Meta uses this data to attribute installs and purchases to its ads and to measure and optimize campaign performance. For that data Meta acts as an independent controller under its own privacy policy, not as our processor, which means it may also use what it receives for its own purposes — including deciding which ads you are shown. This and the optional rewarded advertisements described in Section 2.6 are the only places in the App where data is shared for an advertising purpose.
2.6 Rewarded Advertisements
When you have no drawing credits, the App may offer a rewarded video after you choose to watch an advertisement. Depending on the feature, completing it earns one drawing credit, unlocks sharing or printing of an ad-funded drawing, or pays for one PDF build. The App does not show advertisements automatically at launch or between drawings. Offers depend on the feature being enabled, your daily allowance and an advertisement being available. A positive purchased-credit balance bypasses the advertisement offers and gates; buying a pack does not promise that advertisements will remain unavailable after its credits have been used.
To verify a reward, we give Google's advertising service an opaque reward reference and your anonymous Lineora account UUID. Google's servers send our API a signed completion notice containing those references and its transaction reference. We store the reward purpose, completion status, timestamps and references with your account; a share or print reward also identifies the relevant drawing in our own database. A drawing credit is granted only after server verification. We use these records to deliver rewards, enforce daily allowances and prevent duplicate claims, rather than to select personalised advertisements.
On iOS, advertisements are non-personalised: they are not selected using a profile of your activity across other companies' apps or websites. We do not request App Tracking Transparency (ATT) permission or access to the Identifier for Advertisers (IDFA). Publisher first-party ID and ad personalisation are disabled in our advertising SDK configuration, and our product analytics are not enabled for advertising personalisation.
Google LLC supplies the advertisements through AdMob. Even a non-personalised advertisement involves data processing: Google may collect your IP address, from which it may estimate your general location, device and App information (such as device model, operating-system version, App version and language), advertising interactions (such as video views, taps and dismissals), and crash and performance information. Google may share advertising delivery and measurement data with partners that provide an advertisement. Google describes its handling of this data at https://policies.google.com/privacy and https://policies.google.com/technologies/partner-sites. We do not send your photos, generated drawings, recovery codes or support correspondence to the advertising service.
Before requesting advertisements, Google's User Messaging Platform checks whether a regional privacy message or consent is required, including in the European Economic Area, the United Kingdom and Switzerland. We request consent where required for advertising-related storage and processing even though iOS advertisements are non-personalised. Where available, Settings > Ad privacy options lets you review or withdraw your choices. This consent is separate from ATT and does not enable cross-app tracking or personalised advertisements. If your choices or the available inventory prevent an advertisement from loading, no reward is earned and purchasing credits remains available.
In the Android version, Google also collects the Google Advertising ID and app set ID for rewarded advertisements, and advertisements may be personalised according to your choices. Android's Settings > Privacy > Ads lets you manage the Advertising ID, and the App's Ad privacy options entry point lets you review regional consent where available. Meta attribution remains exclusive to Android as described in Section 2.5; the iOS App contains no Meta SDK.
3. Permissions
The App may request the following operating-system permissions, each only when the corresponding feature is invoked. You may grant or deny each permission from your device settings; denying a permission disables the feature it covers, and the rest of the App continues to function.
- Camera. Used solely when you tap the camera button to capture a photo. The App does not access the camera at any other time.
- Photo Library. Used solely when you pick a photo from the library or save a generated drawing back to it.
- Push Notifications. Requested the first time you tap Generate so we can ping you when a render finishes (renders are processed in the background and can take a couple of minutes). The push payload contains only a brief notice that your sketch is ready — no photo content.
Rewarded advertisements need no camera, photo-library, microphone, location or tracking permission. Existing camera and photo-library permissions are used only for the photo and export features described above. Advertising-related regional consent is handled separately as described in Section 2.6; the iOS App never asks for ATT permission. You may decline an advertisement and use purchased credits instead.
4. Purposes and Legal Basis for Processing
Under GDPR Article 6, we process your personal data based on the following legal grounds:
- Performance of a contract with you (Art. 6(1)(b) GDPR) — to deliver the App, fulfil purchases, and validate entitlements.
- Our legitimate interests (Art. 6(1)(f) GDPR) — to keep the App stable (crash reporting), to understand how features are used (anonymous analytics), to measure whether the ads we pay for actually bring people to the App (advertising attribution, Section 2.5), to fund the free drawings you earn by choosing to watch a rewarded advertisement (Section 2.6), and to detect or prevent fraud or abuse. We have weighed these interests against your rights and freedoms and concluded that the processing is proportionate. For advertising attribution and rewarded advertisements specifically you have an unconditional right to object under Section 9.6, and immediate device-level opt-outs described in Sections 2.5 and 2.6.
- Your consent (Art. 6(1)(a) GDPR) — where required by law, for example for any optional permission you grant. For rewarded advertisements, consent is requested where required for advertising-related storage and processing. iOS advertisements remain non-personalised regardless of your choices; Android personalisation depends on your consent and settings. Section 2.6 explains how to change your choices.
- Compliance with a legal obligation (Art. 6(1)(c) GDPR) — to retain transaction records as required by tax or consumer-protection law.
Where we rely on legitimate interests, you have the right to object to processing on grounds relating to your particular situation (see Section 9). Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
5. How We Use the Information
- To run the conversions you request.
- To honor your purchases across reinstalls and devices.
- To diagnose and fix crashes and other defects.
- To understand which features are used so we can prioritize improvements.
- To prevent, investigate, and respond to fraud, abuse, or violations of the Terms of Service or applicable law.
- To measure whether the ads we run for the App result in installs and purchases, so we can stop paying for the ones that do not.
- To show you, only when you ask for one, a rewarded advertisement in exchange for a free drawing or a free share, as described in Section 2.6.
We do not sell, rent, or trade your photos, your generated drawings, your recovery code, or the contents of your account, for any purpose. We do not build advertising profiles ourselves. There are two exceptions to an otherwise advertising-free data flow, and we would rather state them plainly than bury them: the milestone events and advertising identifier described in Section 2.5 go to Meta, which uses them to measure our ads and, under its own policies, to inform the ads you are shown; and the platform-specific data and advertisement interactions described in Section 2.6 go to Google when you choose to watch a rewarded advertisement. Some laws — including the California Consumer Privacy Act as amended by the CPRA — classify those transfers as a "sale" or as "sharing" for cross-context behavioral advertising. Section 10 explains how to opt out. No photo or drawing content is involved in either.
6. Data Sharing and International Transfers
6.1 Categories of Recipients
We may share limited data with the following categories of recipient, each governed by its own privacy policy:
- App Store (Apple Inc.) on iOS and Google Play Store (Google LLC) on Android — purchase processing.
- RevenueCat, Inc. — purchase validation and entitlements: https://www.revenuecat.com/privacy
- PostHog, Inc. — anonymous product analytics: https://posthog.com/privacy
- Sentry, Inc. — crash and error reporting: https://sentry.io/privacy/
- Third-party AI image-generation providers — your stored photo is forwarded to these providers' image-generation APIs to produce the requested drawing. We contract only with providers whose API terms commit to not using inputs to train their models.
- Hetzner Online GmbH — object storage in the European Union for your uploaded photos and generated drawings, used to power the cross-device gallery and the in-app compare-with-original view: https://www.hetzner.com/legal/privacy-policy
- Google LLC (Firebase Cloud Messaging) — delivery of push notifications to your device. We register your device's push token against your account so we can notify you when a background render finishes; the payload itself contains no photo content: https://firebase.google.com/support/privacy
- Meta Platforms Ireland Limited — advertising attribution and measurement, Android App only. Receives the milestone events, account UUID, and Google Advertising ID described in Section 2.5. Meta is an independent controller for this data rather than our processor: https://www.facebook.com/privacy/policy
- Google LLC (AdMob and User Messaging Platform) — rewarded advertisements and regional consent on Android and iOS. Receives the platform-specific advertising and reward-verification data described in Section 2.6: https://policies.google.com/privacy
6.2 International Transfers
The third parties listed above may process data in the United States or other regions outside your country of residence. Where required by GDPR or UK GDPR, we and our providers rely on European Commission Standard Contractual Clauses (or the UK International Data Transfer Addendum), and on the EU–U.S. Data Privacy Framework where applicable, to provide an adequate level of protection.
6.3 Access from Pakistan
ZEITARC is headquartered in Islamabad, Pakistan, which does not currently have an EU adequacy decision. Our team in Pakistan may access aggregate analytics and crash data, and may handle support enquiries you send us, for the operational purposes described in this Policy. Where this involves any transfer of personal data, we rely on the safeguards described in Section 6.2 and the technical and organisational measures described in Section 8. You may request a copy of the safeguards in place by contacting us at privacy.line@zeitarc.com.
6.4 Legal Disclosures
We may disclose your data if required by law, to comply with legal process or government requests, to protect our rights or safety, to enforce our Terms of Service, or in connection with a merger, acquisition, or sale of assets (with notice to you where required).
7. Data Retention
- Uploaded photos and generated drawings are stored in Hetzner Object Storage (European Union) until you delete the corresponding sketch from the in-app gallery, at which point the underlying objects are removed from our storage. Photos that are uploaded but never successfully processed are cleaned up automatically within a short retention window. You can request server-side deletion of all of your stored images by contacting privacy.line@zeitarc.com.
- Anonymous usage events and crash reports are retained by PostHog and Sentry under their default retention windows (typically up to 12 months for events and 90 days for full error context), then aggregated or deleted.
- Advertising attribution events are retained by Meta on Meta's own schedule, which we neither set nor control; Meta describes it in its Privacy Policy. We keep no copy of your advertising identifier on our own servers. Withdrawing the identifier as described in Section 2.5 stops any further events being tied to your device, though it does not by itself erase what Meta already holds — for that, contact us or use Meta's own off-Facebook activity controls.
- Advertising data collected by Google when you watch a rewarded advertisement is retained by Google on its own schedule, described in Google's Privacy Policy. We keep only the reward record described in Section 2.6 — the reward reference, your account UUID and Google's transaction reference — as part of your account record below.
- Purchase and entitlement records are retained by Apple (for App Store purchases), Google (for Google Play Store purchases), and RevenueCat for as long as your purchase remains valid and for any further period required by tax or accounting law.
- Your account record (the random UUID, current credit balance, hashed recovery code, sketch metadata, rewarded-advertisement records, push-notification tokens, support correspondence, and your legal-acceptance history) is retained for as long as your account is active. When you request account deletion under Section 9.3 we erase your stored images, your account record, and your push tokens; support correspondence is retained with the user link severed so we can keep an internal audit trail without continuing to associate it with you.
8. Data Security
8.1 Technical Measures
- Encryption in transit — all data exchanged with our service providers, including our cloud storage and our AI image-generation providers, is encrypted using TLS 1.2 or higher.
- Pre-upload downscale — photos are resized to a maximum dimension of 1500 pixels on your device before any network upload, limiting the data exposed.
- Encryption at rest — uploaded photos and generated drawings are stored in Hetzner Object Storage with server-side encryption applied by the provider, and are accessed only via short-lived presigned URLs scoped to your authenticated session.
- No passwords or direct identifiers collected — your account is identified by a random UUID issued by our API and the bearer token paired with it. We do not ask for, or store, a password, name, email, or phone number; the only way to access your account from another device is the recovery code you can mint in Settings. In the Android App, the device-level identifiers used for advertising are the Google Advertising ID described in Sections 2.5 and 2.6 and, for rewarded advertisements only, the app set ID described in Section 2.6; your operating system issues both, and you can reset or delete the Advertising ID there at any time.
- Hardened service-provider configurations — we have reviewed each provider's settings to minimise the data they receive.
8.2 Organisational Measures
- Limited employee access to provider dashboards on a need-to-know basis.
- Confidentiality obligations for all team members with access to any personal data.
- Documented incident-response procedures.
- Regular review of third-party providers and their practices.
8.3 Data-Breach Notification
In the event of a personal-data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours where required by GDPR Article 33.
- Notify affected users without undue delay if there is a high risk to their rights and freedoms (GDPR Article 34).
- Document the breach and all remedial actions taken.
9. Your Rights Under GDPR
As a data subject, you have the following rights. We will respond to valid requests within one month, extendable by two further months for complex requests (with notification to you within the first month).
9.1 Right of Access (Article 15)
You may obtain confirmation of whether we process your personal data and request a copy of that data. Email privacy.line@zeitarc.com to request your data.
9.2 Right to Rectification (Article 16)
You may correct inaccurate personal data or complete incomplete data we hold about you.
9.3 Right to Erasure (Article 17)
You may request deletion of personal data we hold about you. You can delete individual sketches and their stored original photos from the in-app gallery, which removes the underlying objects from our cloud storage. For a full account-level erasure (including any remaining stored images, anonymous identifiers, and feedback or support history we have attached to your account), email privacy.line@zeitarc.com and we will action your request within the timeframes set out in this Section 9.
9.4 Right to Restriction of Processing (Article 18)
You may request that we limit how we use your data — for example while we verify the accuracy of the data or consider an objection you have raised.
9.5 Right to Data Portability (Article 20)
Where applicable, you have the right to receive personal data you provided to us in a structured, commonly used, machine-readable format. Email privacy.line@zeitarc.com to request a portable export.
9.6 Right to Object (Article 21)
You may object to processing based on legitimate interests on grounds relating to your particular situation. We will stop processing unless we demonstrate compelling legitimate grounds that override your interests, or unless we need to process the data to establish, exercise, or defend legal claims. We do not use your data for direct marketing or profiling.
9.7 Automated Decision-Making (Article 22)
We do not make any decisions based solely on automated processing that produce legal or similarly significant effects on you. The image-conversion model runs on a third-party AI service in response to your direct tap, and the resulting drawing is returned to you for review.
9.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority — for EEA users, your national data-protection authority; for UK users, the Information Commissioner's Office (ico.org.uk). We encourage you to contact us first so we can address your concerns.
9.9 How to Exercise Your Rights
To exercise any of these rights, email privacy.line@zeitarc.com with the right(s) you wish to exercise. Because the App does not link the data we hold to your real-world identity, we may ask for additional information needed to verify your request. There is no fee for exercising your rights unless requests are manifestly unfounded or excessive.
10. California Privacy Rights
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to (i) know what personal information we collect, use, disclose, and (where applicable) sell or share; (ii) request deletion of your personal information; (iii) correct inaccurate personal information; (iv) opt out of any sale or sharing of personal information for cross-context behavioral advertising; and (v) limit use of sensitive personal information.
We do not knowingly collect "sensitive personal information" as defined by the CPRA, and we do not discriminate against you for exercising any of these rights.
In the Android App, we do share personal information for advertising purposes in two cases: the advertising identifier, account UUID, and milestone events described in Section 2.5, which go to Meta Platforms; and the advertising identifier, app set ID, IP address, device information and advertisement interactions described in Section 2.6, which go to Google when you choose to watch a rewarded advertisement. The CPRA may treat these as a "sale" or as "sharing" for cross-context behavioral advertising, so we treat them as such. You have two ways to opt out, and neither costs you any App functionality beyond the optional advertisement itself:
- Remove the advertising identifier in your device settings, as described in Sections 2.5 and 2.6. This is immediate and requires nothing from us. Rewarded advertisements are additionally never shown unless you tap "Watch an ad", so declining the offer keeps that data from being collected at all.
- Email privacy.line@zeitarc.com with the subject "Do Not Sell or Share" and we will suppress the sharing for your account and confirm when it is done.
We honor opt-out preference signals where the platform transmits one to us.
11. Children's Privacy
The App is intended for use by adults aged 16 and older, and is not directed to children. We do not knowingly collect personal data from children under 16 (or the equivalent age in your country). If you become aware that a child has used the App in a way that caused us to receive their personal information, contact privacy.line@zeitarc.com and we will delete it promptly.
12. Cookies and Local Storage
The App is a native mobile application. Its advertising and consent software may use local storage or similar technologies for consent preferences, advertisement frequency limits, delivery and fraud prevention, including for non-personalised advertisements. The App also uses the following local-storage mechanisms on your device:
- Local preferences — App settings, the random UUID and bearer token issued by our API for your account (stored in the operating system's secure storage), the free-tier counter, and your purchase entitlements.
- Cache — temporary in-memory storage for previously rendered drawings so that re-tapping a style returns instantly without a new request.
We honor Do Not Track and opt-out preference signals where applicable. We do not follow what you do on third-party websites or in other apps, and we receive no information about your activity outside this App. The advertising identifier described in Sections 2.5 and 2.6 is the one piece of data we send that Meta and Google are able to match against records they hold from elsewhere; removing it in your device settings ends that ability.
- Advertising and consent preferences — stored by Google's advertising and consent software to remember your choices and manage advertisements. Where available, Settings > Ad privacy options lets you review or withdraw consent. Declining an advertisement avoids its delivery and reward-verification processing.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
13.1 Notification of Changes
We will notify you of material changes by updating the "Last updated" date at the top of this Policy and displaying a notice in the App before the change takes effect.
13.2 Your Continued Use
Continued use of the App after the effective date constitutes acceptance of the updated Policy. If you do not agree with the updated Policy, you should stop using the App and uninstall it.
14. Contact Information and Complaints
For privacy questions or to exercise your rights, please contact us using the addresses below. We aim to respond to standard requests within one month, complex requests within three months (with notification within the first month), and urgent security matters within 72 hours.
Contact
Data Protection: privacy.line@zeitarc.com Support: support.line@zeitarc.com Legal: legal.line@zeitarc.com