Privacy Policy

Effective date: September 6, 2026

About This Policy

EyeSay is operated by Mingliang Liang, an individual developer and the controller responsible for the processing described here. This policy covers the iOS app, its connected service, accounts, support and the eyesay.app website. Contact [email protected] for privacy questions or data requests. Postal address: Vossendijk 53, 6534 TC Nijmegen, Netherlands. If the English and Chinese versions differ, the English version applies.

Photos and Search

With your upload permission, EyeSay sends a reduced-size photo when you analyze it or ask a question. Questions, search descriptions and search words are sent when needed. Original photo files are not uploaded. Photo-library access and permission to upload are separate choices. Duplicate comparisons and searches over existing indexes run on your device; iCloud originals may need downloading to your device.

Local Results and Photo Changes

Tags, search indexes, manual edits, processing progress and album history are saved on your device. Creating or undoing albums does not delete original photos. Deleting duplicates is a separate action requiring confirmation, affects iCloud Photos when enabled, and may remove Live Photo motion. Review the selection before confirming.

Accounts and Purchases

Email sign-in sends your email, password and any required verification code. The service stores your email, account identifiers and a password hash for email accounts; Apple and Google sign-in use authorization information and linked identifiers. Google authorization opens a system browser; EyeSay receives your verified email and Google account identifier, without receiving your Google password. When enabled, membership services store session hashes, usage and purchase records. Apple processes payments; EyeSay verifies signed purchase information without collecting payment-card details.

Usage, Security and Support

Every request carries a random install identifier created by the app; the service keeps only a truncated hash of it for quotas and abuse prevention. Signed-in usage is linked to your account. To avoid charging retries twice, the service stores request identifiers and content hashes, not the submitted content. When enabled, usage logs record time, key identifier, operation, image count, byte count and status; error diagnostics omit request content. The server’s access log records the connecting IP address, country, request path, timing, status and the install identifier. Cloudflare, in front of the server, also processes IP addresses and connection metadata. Support emails contain your address and what you send. Photos and questions are not sold or used for advertising.

Purposes and Legal Grounds

Photos, questions and search text are used only to produce the result you requested; they are not used to train models and are not reviewed by people. Where GDPR applies, photo and text uploads rely on your consent; necessary account, membership and requested support processing serves the service contract. Service-security and abuse-prevention records serve legitimate interests, subject to your rights. Records legally required for transactions or legal requests are processed to meet those obligations. Declining optional uploads does not authorize any alternative use of your photos.

Service Providers and Transfers

Photos, questions and search text are analysed by EyeSay’s own AI model on EyeSay’s own servers; they are not sent to any third-party AI service or API. Mingliang Liang manages the service and the website on an OVHcloud VPS in London, United Kingdom. Requests pass through Cloudflare. Google provides Google sign-in; Apple provides Apple sign-in and purchase services; email delivery and support involve email providers. Cloudflare, Google, Apple and email providers may process data in the United States and other countries outside the EEA. Where GDPR applies, such transfers rely on the EU-US Data Privacy Framework for certified providers and otherwise on Standard Contractual Clauses; contact us for details of the applicable safeguards.

Retention and Deletion

Photos, questions and generated results are processed in memory without being saved by the inference service. Local results remain until you clear the app’s data. Account and purchase records remain until account deletion. Verified offer transactions awaiting account linkage are removed after expiry. Email codes expire after 10 minutes and sessions after 30 days. Completed-request records are deleted after 30 days, the server access log after 7 days, and monthly usage counters, usage logs, deleted-account identifiers and hashes of deleted subscription identifiers after 13 months; the one-time free trial counter linked to an installation is deleted 13 months after that installation's last analysis. Expired records are removed during subsequent service activity. Contact us for access or deletion requests, including retained records.

Your Privacy Rights

Depending on applicable law, you may request access, correction, deletion, a portable copy, restricted processing or object to processing. Contact the privacy email above; we may verify your identity and will respond within applicable legal deadlines. You may complain to your local data-protection authority. Withdrawing consent does not affect earlier lawful processing. EyeSay’s photo suggestions are not intended to make decisions with legal or similarly significant effects about you.

Controls and Account Deletion

Stop processing, manage photo access or withdraw upload permission in Settings; sent requests may finish. Storage controls clear local results or caches. Delete Account under Account & Membership removes account details and associated sessions, request and purchase records. Installation-linked usage (including the one-time trial counter), a deleted-account identifier and subscription-identifier hashes without an account association remain for up to 13 months after last activity to prevent quota resets, repeated offer claims and reactivation by delayed purchase notifications; deletion receipts remain until their session expiry. Local photos and results stay on your device. Account deletion does not cancel Apple subscriptions.

Keychain and Security

Sign-in tokens and the install identifier are kept in the iOS Keychain and may survive app deletion. Signing out clears the current account session on this device. The built-in service uses HTTPS. These measures reduce risk but cannot guarantee absolute security; avoid sending sensitive material you do not need analyzed.

Children and Policy Updates

EyeSay is not designed specifically for children. If a child uses the service without guardian authorization required by local law, contact us about the relevant account or data. This policy is bundled with the app. Changes to upload purposes require updated notice and, where necessary, fresh consent; reading a revised policy alone does not provide that consent.