Legal

Privacy policy

Last updated: 17 September 2026 · Pursuant to GDPR (EU) 2016/679

1. Who is responsible

Florin-Elis Buju, Bauernstraße 6, 2514 Traiskirchen, Austria, is the controller for everything described here: for this website and for the Designey app. For access, rectification, erasure, or any other request under the GDPR, write to office@designey.ai. There is no form to fill in. An informal email is enough, and a person answers it.

2. This website

The page you are reading informs you about Designey and processes very little itself. Our host keeps short-lived server logs (IP address, timestamp, requested page) to keep the site up and to stop abuse; the legal basis is Art. 6(1)(f) GDPR, and they are deleted after 14 days at the latest. Two strictly necessary cookies come with it: one stores your language choice (German/English), the other your answer to the cookie banner, so we do not ask you again on every page. Neither needs consent (§ 165(3) TKG 2021). Fonts are self-hosted.

Google Analytics. To measure how this website is used, we use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA). Google Analytics sets cookies and processes your truncated IP address, the pages you visit, how long you stay and technical device data, so we can see how the site is used. Data may be transferred to Google LLC servers in the United States; Google LLC is certified under the EU-US Data Privacy Framework. Google Analytics runs only if you consent via the cookie banner (Art. 6(1)(a) GDPR, § 165(3) TKG 2021); without consent it is not loaded at all. You can withdraw your consent at any time in the cookie settings, with effect for the future. Analytics data is deleted after 14 months at the latest.

3. The app: what we process, and why

Your room photo and your room size. Uploaded without an account, and with your agreement to the US transfer (section 4): the upload form asks for it, and without it no room is created and no photo is kept. The photo is re-encoded the moment it arrives, which removes the metadata your camera attached to it, meaning location, device and timestamp. It is stored in a private bucket in Frankfurt that is not reachable from the public internet. The room size is one you type in yourself or confirm after we estimate it from the photo. When you replace a single piece of furniture you upload a photo of that piece where it stands; it is treated like a room photo. Legal basis: Art. 6(1)(b) GDPR, because it is the service you asked for. The agreement to send it onward is recorded against the room, with the exact wording you agreed to and the date.

Your account. When you render for the first time you sign in: with a code we email you, with your Google account, or in the iOS app with your Apple account. With Google and Apple our sign-in service (section 5) checks the token Google or Apple issues and stores what it contains: with Google, your name and profile picture beside the email address. We ourselves take only your verified email address from it, and the record at the sign-in service goes with your account. Google or Apple learns that you are signing in to Designey; what they do with that is governed by their own privacy policies. From then we keep your email address, the moment you verified it, the country the app shows products and prices for, the products you save, a copy of the transfer agreement your room carries (section 4) with any withdrawal of it, and a render ledger: one dated row per successful picture, so your 3 free pictures, and any credits you bought after them, can be counted down. The ledger records that you rendered, never what. The country is set first from the country of your connection, which our host reads from the IP address, and after that from your choice on the account page. In our database there is no name, no profile, no advertising identifier, and no record of what you looked at; only what you mark yourself is saved.

The mobile app. The app for iOS and Android talks to the same server as the web app and processes the same things. Two things are added. First, notifications: if you allow them, the app fetches a push token from your device and we store it with your account, to tell you when a picture is ready. The message goes from our server to Expo's push service (650 Industries, Inc., USA) and from there to Apple or Google, who deliver it to your device. It contains the note that your picture is ready, the name of the style and the identifier of the room, never the picture itself. Legal basis is Art. 6(1)(a) GDPR: the permission your device asks you for, which you can take back in its settings at any time. A token that can no longer be reached we delete on our own, and all of them go with the account. Second, purchases: in the mobile app you buy credits through the App Store or Google Play, not through Stripe (section 5).

The beta waitlist. If you ask to hear when custom design, the door that measures your room from a video, opens, we store your email address and the moment you asked, and nothing else. That moment is the record of your agreement. Legal basis: Art. 6(1)(a) GDPR, your consent, given by typing the address into a field whose one stated purpose sits beside it; § 174 TKG 2021 covers sending the message. We will write to you exactly once, when the beta opens. There is no newsletter, nothing else is sent, and the address is not joined to anything else we hold. A waitlist entry is not an account, and signing up does not create one.

Server logs. Our host keeps short-lived request logs (IP address, time, requested path) to keep the service up and to stop abuse. Legal basis: Art. 6(1)(f), our legitimate interest in operating a working, un-abused service.

Crash reports. When something fails, on our server or in your browser, we record the error, the technical trace of where it happened, the page you were on, and, if you are signed in, your internal account number. Not your email address, not your photo, and no link to it. Legal basis: Art. 6(1)(f), our legitimate interest in a service that works, and in hearing about it when it doesn't rather than waiting to be told. We do not ask you for this one: an error report puts nothing on your device.

The masked replay a crash in your browser can bring with it is separate, and runs only with your consent. It puts a short-lived entry in your browser's session storage to hold the recording together, and that is access to your own device. So the legal basis is Art. 6(1)(a) GDPR together with § 165(3) TKG 2021, taken through the cookie banner under "error diagnostics". Decline and nothing is recorded at all, and errors are still reported. What such a replay does and does not contain is in section 7.

4. Your room photo goes to the United States

Two things are done with your room photo by an AI model operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA: the visualization of a concept in your own room is produced from it, and the room is read (its colours, its materials, how bright it is, and which pieces of furniture it already has) to match products to it, so what we suggest suits the room you actually have.

The reading is done from the photo alone. The picture needs more, so with your re-encoded room photo we send a floor plan of the room, which we draw from the room size you gave us and which shows where each product is to stand, the product images, and one line of text per product. The room size is written into the instructions as well, so the picture keeps the proportions of the room you measured. Your budget is not sent: it decides which pieces of our own catalogue you are offered, and that happens here. We do not send your email address, your account identifier, or anything else that names you.

The model we use is a preview model, and preview models do not come with the usual EU safeguards. There are no standard contractual clauses under Art. 46 GDPR covering this transfer and no processor guarantees of the kind that cover our other providers. US authorities can, under US law, demand access to data held there, and enforcing your rights against a US company is harder than against an Austrian one. Google may handle preview traffic differently from its generally available services.

Because of that, the transfer runs on your explicit consent under Art. 49(1)(a) GDPR. We ask for it on the upload form, before your photo is sent anywhere at all, on a box you have to tick yourself, covering both of the things above. It is asked once per room, because it is the room's photo that gets sent, and we record the exact wording you agreed to alongside it. If the wording ever changes, we ask again rather than treating an old agreement as covering something new.

If you do not agree, we cannot take your room any further. Nothing is sent, nothing is stored, and no room is created. There is also no concept, no plan and no shopping list, because all of them start from the photo. We would rather say that plainly here than let you find it out at the end.

You can withdraw at any time, from your account page in one tap, or by emailing office@designey.ai. After that we send nothing further about the rooms you already have. Withdrawal does not undo renders already made (Art. 7(3)); deleting your account does, and takes the photos with it. A new room asks the question again, and a fresh agreement stands on its own.

Every render is labelled as an AI visualization in the app, and the images carry Google's invisible SynthID watermark.

A room video goes to the United States too, but not to Google. If you have a 3D preview made from a finished picture, we send that picture, and only that, to fal (Features and Labels, Inc., 2261 Market Street, San Francisco, USA), where a video model turns it into a short camera move. Your photo does not go with it, but a picture that shows your room does. Unlike the preview model above, the usual safeguards apply here: fal processes on our behalf under Art. 28 GDPR, under EU standard contractual clauses under Art. 46 GDPR, and we collect the finished video and store it in our Frankfurt storage, next to the picture it came from. So we do not ask separately for this; the legal basis is Art. 6(1)(b) GDPR, because you request the video, and what it costs in credits is on the button before you press it.

5. Who else touches your data

These companies touch your data in the running of the service. They process it on our behalf under Art. 28 GDPR, on our instructions only, and never for their own purposes. The payment provider carries one duty of its own beside that, and it is named here as what it is: as a regulated payment institution it must check payments for fraud and money laundering, and it decides that part for itself under its own privacy notice. It does not sell anything. We do: the seller of the credit packs and the plans is the person named in section 1.

  • Supabase, Inc. (USA): Database, private file storage and the sign-in service, which also checks sign-ins through Google and Apple. The project runs in the EU region eu-central-1 (Frankfurt, Germany); room photos, pictures and videos are stored there and nowhere else. Standard data protection agreement including EU standard contractual clauses.
  • Vercel, Inc. (USA): Hosting for the app, and the page-view analytics that comes with it: first-party, cookieless, and counting visits rather than visitors. Server functions are pinned to the fra1 region (Frankfurt, Germany). Vercel keeps short-lived request logs for operational security. Standard data protection agreement including EU standard contractual clauses.
  • Resend, Inc. (USA): Delivers the emails this service sends: the sign-in emails that carry your 6-digit code, and the single message to the beta waitlist when custom design opens. Receives your email address and nothing else.
  • Functional Software, Inc. d/b/a Sentry (USA): Error tracking. When something in the app fails, Sentry receives the error, its stack trace, the page it happened on and, if you were signed in, your internal account number, which is a random identifier and not your email address. The masked replay is added only if you have consented to error diagnostics (sections 3 and 7). Reports are stored in Sentry's EU region (Frankfurt, Germany). Standard data protection agreement including EU standard contractual clauses.
  • Stripe Payments Europe, Limited (Ireland): Takes the payment for the render credit packs and the plans. We sell them ourselves, so the receipt and the invoice are ours; Stripe is the payment processor behind them, which is why your card statement shows DESIGNEY and not a payment company's name. Buying sends you to Stripe's own checkout page, where you enter your email address and your card or bank details: Stripe receives those, along with your country and your IP address, and we never see the card. What comes back to us is the address you bought under, Stripe's own customer, payment and invoice identifiers, and how many pictures the purchase granted. Stripe acts on our instructions for the payment, and on its own account for the fraud, anti-money-laundering and card-network duties a regulated payment institution carries. Standard data protection agreement including EU standard contractual clauses for what reaches its US parent, which is additionally certified under the EU-US Data Privacy Framework.
  • Google: receives your room photo for reading and rendering only with your explicit consent (section 4), checks your account when you sign in with Google (section 3), and runs the audience measurement on this website (section 2, Google Analytics, consent only).
  • fal (Features and Labels, Inc., USA): makes the room video from a finished picture (section 4). Receives that one picture and nothing else that names you. Standard data protection agreement including EU standard contractual clauses.
  • Expo (650 Industries, Inc., USA): delivers the mobile app's notifications (section 3). Receives your device's push token and the text of the message, and passes both on to Apple or Google. Certified under the EU-US Data Privacy Framework.
  • Apple Inc. and Google LLC (USA): bring the notification to your device and handle the purchases in the mobile app, Apple through the App Store, Google through Google Play. What they store in doing so is governed by their own privacy policies; we receive no payment details from them. Both are certified under the EU-US Data Privacy Framework.
  • RevenueCat, Inc. (USA): matches the purchases in the mobile app to your account. Receives your email address as the customer identifier and the store's purchase receipts, so the credits land with you. Standard data protection agreement including EU standard contractual clauses.

Partner links. We do not sell data, and we pass nothing to advertisers. The products in the app come from our partner retailer's range, and a product link leads through the retailer's partner programme into its shop. For XXXLutz that is pvn.xxxlutz.at, run by XXXLutz KG, Römerstraße 39, 4600 Wels, Austria, with EASY Marketing GmbH, Dortmund, Germany, as its technical provider. When you click, the programme sets two cookies in the retailer's shop (TRS and TRSCJ) that attribute a later purchase to Designey. They mark the partnership, not you, and nothing about you travels from us with them. All we learn from them is that a purchase happened, its value and our commission, never who bought. The retailer is responsible for this tracking; you can object to it at pvn.xxxlutz.at/privacy-optout.do, and what you do in its shop is covered by its privacy policy, not this one.

6. How long we keep things

Room photos, pictures and videos: 12 months of inactivity. They are kept while you are using the service, and deleted after 12 months in which you have neither uploaded a room nor made a render. Because we keep no record of your visits, simply signing in or reopening an old render does not count. If you want to keep a photo, make something with it. A photo uploaded without ever signing in is deleted 12 months after upload. This runs automatically, every night. A video hangs on its picture and goes with it.

Account data (email, verification date, country, saved products, in the mobile app the push tokens of your devices, your copy of the transfer agreement and any withdrawal of it, and the render ledger) is kept while your account exists. Each room's own consent record is part of that room, so it is deleted whenever the room is, either by the purge above or by deleting your account.

What a purchase leaves behind (that a pack or a plan was bought under your address, Stripe's own customer, payment and invoice identifiers or, for a purchase in the mobile app, the store's identifier, how many pictures it granted and when) is kept while your account exists too. It is not on the twelve-month clock above: it is what your balance is counted from, so deleting it would delete the credits with it. A purchase made under an address that never signs in has no account to delete, so that record simply stays until someone asks us to erase it. Email office@designey.ai and we will.

The invoice is the one thing we cannot delete. We are the seller, so Austrian tax law makes us keep the accounting record of a sale for seven years (§ 132 BAO), and Art. 17(3)(b) GDPR is the reason an erasure request does not reach it. It is held at our payment provider, it names your address and what you paid, and it stays for those seven years whatever else you delete. Nothing about your rooms, your photos or your pictures is in it.

The beta waitlist: until we write to you, and no longer. Your address is kept until we send the one email it exists for, and deleted once that email has gone. You do not have to do anything to be forgotten, and the message itself will say so, naming the day you signed up and telling you the address has already been removed. If you would rather it went sooner, write to office@designey.ai and it goes the same day.

You can delete your account at any time from your account page. That erases your photos, your pictures and videos, your saved products, the push tokens of your devices, your ledger, the record of any purchase made under your address and our copy of the customer record it created at Stripe, and the address itself, including at the sign-in provider, immediately and without asking why. The invoice stays, for the seven years described above. Any unspent credits are lost with it and are not refunded, which is why the page that asks you to confirm says how many they are; if you want a refund instead, ask us at office@designey.ai before you delete. If you would rather we did the deletion, write to the same address.

This website: server logs are deleted after 14 days at the latest, Google Analytics data after 14 months at the latest (section 2).

7. Cookies

One decision, and it covers both sites. designey.ai and app.designey.ai are the same domain, so we store your answer to the cookie banner in a cookie both of them read: you decide once, and the other one does not ask again. The answer stands for six months; after that we ask again, and sooner if something arrives that you have not answered for yet. You can change or withdraw it at any time: on this website through “Cookie settings” in the footer of every page, in the app on your account page. The full list of every single entry, with its purpose, its duration and its provider, is in the cookie policy.

On this website, two strictly necessary cookies store your language choice and that decision. Google Analytics sets cookies of its own, but only after you consent via the banner (section 2). If you decline, nothing is loaded and nothing is set.

The app adds two cookies of its own. __Host-designey_session arrives only after you sign in: it holds a signed reference to your account so the server knows the pictures are yours, lasts 30 days, cannot be read by scripts, and is not sent when another site links to us. country remembers for a year which country the app shows products and prices for. Strictly necessary cookies need no consent under § 165(3) TKG 2021. There is no advertising in the app, no ad network and no tracking pixel, and nothing of ours follows you to another site; what a retailer's partner programme sets in its own shop is in section 5.

Two things run alongside the app itself, on every page. One is the error tracker in section 5, which waits for something to break. The other is a page-view count served from our own domain: it records that a page was opened and which step of the flow it was: a photo uploaded, concepts seen, a sign-in begun, a sign-in finished, the section 4 transfer agreed to or refused, the render balance run out, and a link followed to a shop, with the kind of furniture it was and the shop it led to. That is the whole list, and none of it says who did any of it. Before anything is counted, the web address is stripped of the identifiers the app puts in it, so the count knows a room page was opened and never which room. Neither of the two sets a cookie, and neither tries to recognize you from one visit to the next.

Buying loads nothing into the app at all. The shop shows the prices we set, and the Buy button sends you away from the app to Stripe's own checkout page, which is where you enter your email address and your card or bank details. Until you press it, no payment company has seen anything: there is no payment script on our pages and no cookie of theirs in your browser from visiting us. What Stripe stores while you are on its page is on its page, under its privacy notice rather than this one, and paying brings you back here with your credits and nothing else. None of it is advertising.

If you consented to error diagnostics, a crash report carries a replay of the moments before it. If you did not, nothing is recorded and nothing is put anywhere; the error is still reported (section 3). And even with your consent, nothing is stored for a visit that works: the recording is held in your browser and thrown away unless an error actually fires. All text is masked and all images and video are blocked, so your room photo and your render are black rectangles. What we get is where you clicked and how the page was laid out, never what your home looks like. While the app is open, the error tracker keeps one short-lived entry in your browser's session storage for this; your browser discards it when you close the tab, and a withdrawal stops the recording at once.

8. Your rights

You have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict or object to processing (Art. 18, 21), to receive it in a portable form (Art. 20), and to withdraw any consent you gave (Art. 7(3)) without affecting what was lawful before: the audience-measurement and error-diagnostics consents through the cookie settings, reachable from the footer of every page on this website and from your account page in the app, the transfer agreement as described in section 4, the permission for notifications in your device's settings. Write to office@designey.ai, and we answer within a month.

You can also complain to the Austrian data protection authority: Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at.

9. Changes

Designey is early, and the way it works still moves. If the processing changes we update this page and its date; if the change affects the US transfer we ask for your consent again rather than reusing the old one.

The necessary parts keep the service running. Beyond that we would like to measure how this site is used, and to trace errors in the app; both only with your consent.