Privacy Policy
Last updated: August 2026
1. Data Controller
Deni Dedic
Germany
Contact: privacy@reviewr.studio
2. What Data We Collect
We collect the following information when you use Reviewr:
- Account data: Email address, display name, profile information you provide
- Photos: Images you upload for critique. Photos are scaled to a maximum of 2000px on the longest edge and converted to WebP format for storage. Your original files are not retained after processing
- EXIF metadata: Camera settings (aperture, shutter speed, ISO, focal length, camera model) are extracted from your original image before compression and displayed alongside your critique. EXIF data is stored in your critique record
- Usage data: Critique history, XP, achievements, preferences
- Progress & gamification data: XP, levels, streaks, achievements, quest entries and results, and leaderboard standings
- Community data: Gallery posts, comments, direct messages, notifications, reports, and public profile fields you choose to fill in
- Technical data: IP address, browser type, device information (for security and analytics)
- Anonymous preview data: If you use the free critique without an account, we store a one-way hashed version of your IP address and a browser fingerprint value. We use this only to limit how many free previews a single visitor can request
- Payment data: If and when paid credits are offered, payments are processed by Stripe; we never store card details
3. How We Use Your Data
- To provide AI-powered photo critiques
- To maintain your profile, progress, and achievements
- To operate community features: the gallery, comments, messages, notifications, quests, and leaderboards
- To prevent abuse of the free critique allowance
- To process payments, where paid credits are offered
- To improve our service and develop new features
- To communicate important updates
4. AI Processing & Image Handling
When you upload a photo for critique, the following processing takes place:
- EXIF extraction: Camera metadata (aperture, shutter speed, ISO, focal length, camera model) is read from your original file before any compression. This data is stored with your critique to provide technical context
- Image compression: Your photo is scaled to a maximum of 2000px on the longest edge and converted to WebP format (quality 0.82) for efficient storage. HEIC/HEIF files are converted to JPEG client-side before upload. The complete image is always preserved — no cropping is applied
- AI analysis: The processed image is securely transmitted through OpenRouter, our AI gateway, to Google Gemini models for critique generation. These providers process images according to their data processing agreements
Your photos are not used to train AI models. Images are processed in real-time and are not retained by AI providers beyond the critique session.
5. Data Sharing
We share data only with:
- OpenRouter: As the AI gateway that routes critique requests to the model provider
- Google (Gemini models): For generating critiques, follow-up answers, and portfolio analyses
- Google Analytics: For anonymised usage statistics, only after you accept analytics cookies
- Email delivery provider: For account verification, sign-in links, and service announcements
- Sign-in providers: If you use Google or Apple sign-in, that provider confirms your identity and shares your email address with us
- Stripe: For payment processing, where paid credits are offered
- Hosting providers: For infrastructure (secured servers)
We do not sell your personal data to third parties.
6. Community Features & Visibility
Some parts of Reviewr are public by design. Photos and critiques you share to the gallery, your username, avatar, badges, and leaderboard position can be seen by other users and by visitors who are not signed in. Comments you write are shown publicly next to the post. Direct messages are visible to you and the recipient, and may be reviewed by us if reported for abuse.
Shared critique links are unlisted URLs: anyone holding the link can open that single critique. Treat a share link as public. You can make a critique private, delete a gallery post, remove a comment, or revoke sharing at any time from your account.
7. Your Rights (GDPR)
As a user, you have the right to:
- Access: Request a copy of your data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your account and data
- Portability: Export your data in a machine-readable format
- Object: Object to certain processing activities
- Withdraw consent: At any time for consent-based processing
To exercise these rights, contact us at privacy@reviewr.studio
8. Data Retention
- Account data: Retained while your account is active
- Critiques & photos: Retained until you delete them or your account
- Anonymous preview records: Hashed IP and fingerprint values are kept only as long as needed for abuse prevention
- After deletion: Data is permanently removed within 30 days
9. Cookies & Analytics
We use essential cookies and local storage for authentication, session management, your language choice, and interface preferences. These are required for the service to work and are set without consent.
We also use Google Analytics 4 to understand how the site is used. Analytics runs under Google Consent Mode v2, with all consent categories defaulting to denied until you accept analytics cookies in the cookie banner. IP handling is restricted and no advertising or remarketing data is collected. You can withdraw or change your choice at any time by reopening the cookie settings from the banner or clearing site data in your browser.
10. Security
We implement industry-standard security measures including encryption in transit (HTTPS), secure authentication, and regular security audits. While we strive to protect your data, no system is 100% secure.
11. Changes to This Policy
We may update this policy periodically. Significant changes will be communicated via email or in-app notification.
12. Contact
For privacy inquiries or to exercise your rights:
Email: privacy@reviewr.studio
13. Export Your Data
You can download a copy of all your data at any time, in accordance with GDPR Article 20 (Right to Data Portability).