Privacy Policy
Last updated: 6 September 2026
This notice explains what personal data Pion AI collects, why, who sees it, how long we keep it and what you can demand of us. The controller is Individual Entrepreneur Sergei Zolotikh, registered in Georgia, registered address: Georgia, Tbilisi, Gldani district, Niko Ketskhoveli street N 16, entrance 1, floor 10, apartment N 58. Contact: sergeyzolotykhh@gmail.com.
Summary of key points
- What we collect: your email and profile basics, the photographs you upload and generate, and technical usage data.
- Sensitive personal information: we do not process it. We do not scan face geometry, build faceprints or run facial recognition.
- Training: we never train AI models on your photographs, and neither does our provider.
- Selling: we do not sell or share personal data for advertising.
- This website: no cookies, no analytics, no third-party requests of any kind.
- No faceprints: we do not scan face geometry, build face templates, or run facial recognition. See section 3.
- Control: you can delete any image, or your whole account, yourself at any time.
- Questions: sergeyzolotykhh@gmail.com, answered within 30 days.
1. What data we collect
1.1 Data you give us
- Account data: email address, display name, profile picture.
- Photographs: selfies, reference images and other pictures you upload, plus the images generated for you.
- Correspondence: what you write to support, and any attachments.
- Purchase confirmations: when you buy something, Apple tells us that a purchase happened and what it was. Apple keeps the card details; we never receive your card number, security code or billing address.
Sensitive personal information. We do not process sensitive personal information, and we do not collect biometric information. Those are legal terms, so here is what they mean in practice for an app that works with faces: sensitive personal information and biometric data cover the processing of a person's characteristics for the purpose of uniquely identifying them. We do not do that. We do not scan face geometry, do not create or store a faceprint or face template, and run no facial recognition, matching or search. What we hold is photographs, used to generate new photographs at your request. This is set out in full in section 3.
1.2 Data collected automatically
- Technical data: IP address, device model, operating system version, language, app version, and a device identifier used to keep your session and your purchases attached to the right account.
- Permissions you grant on the device: camera and photo library, used only when you open the overlay or pick a picture. We do not request location, contacts, microphone or health data, and the app does not read your photo library in the background. If you enable push notifications, we store the token needed to deliver them.
- Usage data: features used, number of generations, timestamps, errors.
- Cookies: see section 8.
1.3 Data from others
- Sign-in providers. If you sign in through a third-party account, that provider sends us your account identifier and, where available, your email address, name and avatar. We receive no password. What the provider collects on its own side is governed by its own privacy policy, and you can disconnect the link at any time in the app's account settings, or in the provider's own settings.
- Payment provider: payment status, last four digits of the card, card brand, billing country. Never the full number or security code.
2. Why we use it, and on what legal basis
- To run the Service — account, gallery, generations, watermarking, downloads. Basis: performance of our contract with you.
- To process photographs, including images of faces. Basis: performance of our contract with you, since generating the picture is the thing you asked for, together with your consent, which we take as an additional safeguard. You can withdraw consent at any time by deleting the images or the account; withdrawal does not undo processing already done.
- To take payment and administer subscriptions. Basis: contract, plus legal obligation for accounting records.
- To keep the Service safe — abuse, fraud and attack prevention. Basis: our legitimate interest.
- To improve the Service — aggregated statistics that do not identify anyone. Basis: our legitimate interest.
- To contact you about your account, security or material changes to these documents. Basis: contract and legal obligation. Marketing email only with consent, always with an unsubscribe link.
We do not use your data for automated decision-making that produces legal effects for you.
3. AI features, and what happens to your face
This is the section most people actually want, so it is not buried.
The app generates images using Google's Gemini image model, reached through the API provider kie.ai acting for us under contract. To produce a result, the reference image and the selfies you chose are transmitted to that provider, processed, and the output returned. Nothing else is sent: not your gallery, not your account history, not photographs from other sessions.
- We never train AI models on your photographs. Not our own models, and not anyone else's: our provider is contractually barred from using them for training too. Your pictures are used to produce the image you asked for, and for nothing else.
- We do not build a face template or faceprint. The model reads your selfies to produce a picture; it does not extract, store or index a mathematical representation of your face for identification, and we run no face recognition, no face matching and no face search of any kind.
- We ask for your explicit consent anyway. Although photographs processed this way are not biometric data in the legal sense, we take your consent before anything is uploaded, and you can withdraw it at any time by deleting the images or the account. This is a safeguard we chose, not one imposed on us.
- Destruction schedule. Photographs are destroyed when the purpose for collecting them has been satisfied, or within three years of your last interaction with us, whichever comes first, and immediately when you delete them or close your account.
- AI output varies and can be wrong. We make no decision about you on the basis of these images, and nothing in the app produces a legal or similarly significant effect from automated processing.
4. Who we share it with
We do not sell personal data. We may share it with third-party vendors and service providers who perform services for us or on our behalf and need access to do that work. We have contracts in place with them: they cannot do anything with your personal information unless we have instructed them to, they will not share it with any organisation apart from us, and they retain it only for the period we instruct.
The third parties we may share personal information with are as follows:
- AI Service Providers — kie.ai, Google Gemini
- Invoice and Billing — Apple
- User Account Registration and Authentication — Apple Sign-In
- Cloud Computing Services and Data Storage — our hosting and object storage provider
- Performance Monitoring — Sentry
- Website Hosting — Cloudflare Pages
We may also need to share your personal information where the law requires it, where it is necessary to establish, exercise or defend legal claims, or in connection with a merger, sale of assets, financing or acquisition of all or part of our business.
We may also disclose data where the law requires it, or where it is necessary to establish, exercise or defend legal claims. If the business is ever sold or reorganised, data may transfer to the successor, and you will be told before that happens.
5. International transfers
Our servers are located in the United States. Wherever you are, your information may be transferred to, stored in and processed in the United States and in the facilities of the processors listed in section 4, which may themselves operate in the United States or the European Union. Where data leaves your country we rely on appropriate safeguards, such as standard contractual clauses or an adequacy decision covering the recipient country, and you may ask us for a copy of the safeguards in place.
6. How long we keep it
We keep your personal information only for as long as it is necessary for the purposes set out in this notice, unless a longer retention period is required or permitted by law, such as for tax or accounting reasons. No purpose in this notice will require us to keep your personal information for longer than one (1) month past the termination of your account.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it, or, where that is not possible because it sits in a backup archive, securely store it and isolate it from any further processing until deletion is possible.
7. Your rights
Subject to the law that applies to you, you may: get access to your data; have it corrected; have it erased; restrict or object to certain processing; receive it in a portable format; and withdraw consent at any time. Much of this you can do yourself — delete a single image, or the whole account, from your settings. For anything else write to sergeyzolotykhh@gmail.com; we reply within 30 days and do not charge for it. If you think we have mishandled your data, you may complain to your local data protection authority.
8. Reviewing, updating or deleting your data
Open the app and go to account settings. There you can edit your profile, delete individual images from your gallery, and delete the account together with everything in it, as Apple requires every app that offers accounts to allow. If you cannot sign in, email sergeyzolotykhh@gmail.com from the address on the account and we will verify you another way before acting.
9. Cookies and tracking
This website
pion-app.com sets no cookies, runs no analytics, carries no advertising tags and makes no request to any third party. Fonts, stylesheets and images are all served from this domain, so opening these pages tells nobody anything, us included. That is also why there is no cookie banner here: there is nothing to consent to.
The application
The app stores on your device only what it needs to function: a session token that keeps you signed in, a guest identifier so images taken before you register are not lost, and a flag remembering you have seen the introduction. Deleting the app clears all of it and simply signs you out.
We also measure how the application is used, which features get opened, how many generations run, which errors occur, so that we can keep it working and decide what to build next. Where a third-party analytics or error-monitoring service is involved in that, those services are listed in section 4.
10. Do Not Track
Some browsers and devices send a "Do Not Track" signal, and iOS offers App Tracking Transparency. There is still no agreed standard for responding to Do Not Track, so we do not respond to it differently, and we do not ask for tracking permission through App Tracking Transparency because we do not track you across other companies' apps or websites in the first place.
11. If you live in the United States
You have rights under certain US state data protection laws. These rights are not absolute, and in some cases we may decline a request as the law permits. They include:
- Right to know whether or not we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to request the deletion of your personal data
- Right to obtain a copy of the personal data you previously shared with us
- Right to non-discrimination for exercising your rights
- Right to opt out of the processing of your personal data if it is used for targeted advertising, for the sale of personal data, or for profiling in furtherance of decisions that produce legal or similarly significant effects. We do none of these three, so there is nothing to opt out of.
Depending on the state where you live, you may also have:
- Right to access the categories of personal data being processed (including under the privacy law in Minnesota)
- Right to obtain a list of the categories of third parties to which we have disclosed personal data (including under the privacy law in California, Delaware and Maryland)
- Right to obtain a list of specific third parties to which we have disclosed personal data (including under the privacy law in Minnesota and Oregon)
- Right to obtain a list of third parties to which we have sold personal data (including under the privacy law in Connecticut). We sell no personal data, so this list is empty.
- Right to review, understand, question and, depending on where you live, correct how personal data has been profiled (including under the privacy law in Minnesota)
- Right to opt out of the collection of sensitive data and of personal data collected through the operation of a voice or facial recognition feature (including under the privacy law in Florida). We operate no voice or facial recognition feature.
- Right to limit the use or disclosure of sensitive personal data (including under the privacy law in California). We process no sensitive personal data.
Exercise any of these through section 7, or by writing to sergeyzolotykhh@gmail.com. We answer within the period the applicable law sets, and never charge for it. Under California's "Shine the Light" law you may request the categories of personal information we disclosed to third parties for their direct marketing purposes: the answer is none. If we decline a request you may appeal, by replying to our decision; if the appeal is refused you may complain to your state Attorney General.
Biometric privacy laws
Some states regulate biometric identifiers specifically, and because this app works with photographs of faces we address them directly rather than leaving it to a checkbox in a table.
- Illinois (BIPA). We do not collect, capture, purchase, receive through trade, or otherwise obtain a "biometric identifier" or "biometric information" as the Biometric Information Privacy Act defines those terms: we do not scan face geometry, do not create or store faceprints or face templates, and run no facial recognition or identification. What we hold is photographs, processed to generate new photographs at your request. We do not sell, lease or trade photographs or anything derived from them. Our written retention and destruction schedule is in section 3: photographs are destroyed when the purpose for collecting them is satisfied, or within three years of your last interaction with us, whichever comes first, and immediately on deletion.
- Texas (CUBI) and Washington (My Health My Data). The same holds. We capture no biometric identifier for a commercial purpose in Texas, and we neither collect nor share consumer health data as Washington defines it.
- These commitments — consent before upload, no sale, and a published destruction schedule — stand regardless of how any particular statute is read.
12. Children
The Service is not for children. We do not knowingly collect, solicit data from, or market to anyone under 18 years of age, or the equivalent age of majority where you live, and we do not knowingly sell such personal information. By using the Service you represent that you are at least 18, or the equivalent age where you live. Pion AI carries an age rating of 18+ in the App Store, and Apple applies that rating together with any Screen Time or Ask to Buy restrictions a parent has set on the device, which is the gate we rely on. If we learn that we hold personal information from someone under that age, we deactivate the account and delete the data. If you believe a child has given us personal data, write to sergeyzolotykhh@gmail.com and it will be removed.
13. Third-party websites
Pages we link to are not covered by this notice, and we are not responsible for what they collect. Check their policies before giving them anything.
14. Security
We use HTTPS in transit, encrypted storage, access limited to what is needed, short-lived signed links for image downloads, and regular backups. No system is perfect; if a breach affects your personal data we will notify you and the relevant authority within the deadlines the law sets.
15. Changes to this notice
The current version always sits on this page with the date of the last update. Material changes are announced by email or inside the application before they take effect.
16. Contact
Individual Entrepreneur Sergei Zolotikh
Identification number: 300481128
Georgia, Tbilisi, Gldani district, Niko Ketskhoveli street N 16, entrance 1, floor 10, apartment N 58
Email: sergeyzolotykhh@gmail.com
Telephone: +995 575 757 367