Privacy policy
Last updated 16 August 2026.
redo that. is made by innovx Management AB (company registered in Sweden), Masthamnsgatan 21, 413 29 Göteborg, Sweden. We are the data controller for everything described here. Write to [email protected] with any question about this policy, or to exercise any of the rights below.
The short version: your photos are stored privately, one folder per account, on servers in the EU. We send them to an AI provider so it can produce the redesign you asked for. We do not sell your data, we do not show ads, and there are no third-party advertising or tracking tools in the app. You can delete everything from inside the app.
What we collect
Photos and the things you make
- The photos you take or upload — the room or facade you want redesigned, plus any product photos or inspiration images you add.
- The images the app generates from them.
- What you asked for — the vibe, colours and materials you picked, any note you typed, the points you tapped on the photo and the notes attached to them, and the full prompt we composed from all of it.
- Your moodboards and projects — their names, the styles, palettes and materials in them, and any notes you wrote.
- Your style profile — the taste preferences you set during onboarding.
Before a photo leaves your device it is re-encoded and resized (long edge 2048 px). That re-encoding removes the EXIF metadata that cameras attach, including GPS coordinates, so location data from your photos is not uploaded.
Account
- When you first open the app you get an anonymous session — a random identifier, no name, no email.
- When you create a real account you do it with Sign in with Apple or Google. We receive and store the email address and, where the provider supplies it, the name attached to that sign-in. We never see or handle your Apple or Google password.
Credits and purchases
We keep a ledger of every credit granted and spent on your account — the amount, the reason (sign-up grant, a render, a refund, a subscription top-up, a referral or feedback reward) and when it happened. If you subscribe, we store the App Store transaction identifier and the resulting credit grants. Payment card details never reach us; the store handles the whole payment.
Notifications
If you allow notifications, we store a push token for your device together with the platform (iOS or Android). We use it only to tell you that a render finished or failed. You can turn notifications off in your device settings at any time.
Usage analytics
The app records product events — screens opened, a photo taken, a render started, completed or failed, a paywall viewed, a share, and similar. These are stored in our own database; there is no third-party analytics SDK in the app. Events are stamped with your account identifier, so they are personal data. The event properties are deliberately kept to counts, durations and fixed option names — never the text you type. Custom colour or material terms you write are recorded as the literal word custom, not as your words.
Feedback and referrals
If you send feedback, we store your message together with which screen you were on and the app version and build. If you use a referral code, we store which account redeemed which code and when. Neither person ever sees the other's identity in the app.
Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Producing the redesign you asked for; storing your photos and designs so you can come back to them | Performance of a contract |
| Running your account, credits, subscription and referrals | Performance of a contract |
| Push notifications about your renders | Your consent (the permission you grant on the device) |
| Product analytics, abuse prevention and rate limiting, debugging | Our legitimate interest in a working, non-abused product |
| Answering the feedback and messages you send us | Our legitimate interest in supporting our users |
| Meeting accounting and consumer-law obligations | Legal obligation |
Where it is stored
Our database and file storage run on Supabase, in the eu-north-1 region (AWS, Stockholm, Sweden). Photo storage is private: every bucket is closed to the public internet, and access rules tie each file to the account that uploaded it. The app itself reaches your images through short-lived signed links that expire after an hour.
Who else processes it
We keep the list short on purpose. These are the only third parties that handle your data on our behalf.
| Who | What they do | What they receive |
|---|---|---|
| Supabase | Database, file storage, authentication, server functions (EU region) | Everything described above |
| OpenAI | Generates the redesigned image (model gpt-image-2) |
The photo you submitted, any reference photos, and the composed prompt |
| Expo | Delivers push notifications to your device | Your push token and the short message text |
| Apple / Google | Sign-in, app distribution, and payments where you subscribe | Sign-in identity and purchase data, handled under their own policies |
| Cloudflare | Serves this website | Standard web request data for redothat.app |
About the AI step. When you start a render, the server downloads your photo from private storage and sends it, with your prompt, to OpenAI's image API. OpenAI produces the new image and returns it; we write it back to your private storage. OpenAI handles that request under its own API data policies as our processor. We do not send them your email address, your name or your account identifier.
Transfers outside the EU/EEA. OpenAI, Expo, Apple, Google and Cloudflare are US companies and may process data outside the EEA. Where that happens we rely on the European Commission's standard contractual clauses, which those providers include in their data processing terms.
What we never do
- We do not sell your data, or share it with data brokers.
- There are no ads in the app and no advertising or attribution SDKs.
- We do not use your photos to train our own or anyone else's models.
- We do not build profiles about you for anyone other than you.
How long we keep it
- Photos, designs, moodboards and projects stay until you delete them, or until you delete your account.
- Account data, the credit ledger and referral records stay for as long as the account exists.
- Purchase records may be kept longer where Swedish accounting law requires it.
- Analytics events are kept as a long-term product record. See the note in the next section about what happens to them when you delete your account.
Deleting your account
Open the credit badge on the camera screen to reach your profile, then choose Delete account. It is immediate and permanent, and it removes:
- every photo and generated image in your storage folders,
- your profile, style profile, projects, moodboards and saved designs,
- your generation history, credit ledger, push tokens, feedback and referral records,
- your sign-in identity with us.
One exception, stated plainly: your analytics event rows are not deleted. The account identifier on them is erased, which detaches them from you and from any other record we hold, and what remains is a set of anonymous counters. We keep them so our historical product numbers stay intact. If you would rather we deleted those rows too, email [email protected] and we will.
Deleting the app from your phone does not delete your account — use the in-app option, or write to us.
Your rights
Under the GDPR you can ask us for a copy of your data, correct it, have it erased, restrict or object to how we use it, and receive it in a portable format. Where we rely on your consent you can withdraw it at any time. Email [email protected] and we will answer within one month.
If you think we have got it wrong, you can complain to the Swedish authority, Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy.se — or to the supervisory authority where you live.
Children
redo that. is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, write to us and we will remove it.
Security
Traffic is encrypted in transit. Storage buckets are private and enforced per account at the database level, so one account cannot read another's files even with a valid session. Sign-in is handled by Apple and Google; we never hold your password. No system is perfect — if we ever discover a breach that puts your rights at risk we will tell you and the regulator, as the law requires.
Changes
If we change this policy we will update the date at the top and, for anything material, tell you in the app before it takes effect.
Contact
innovx Management AB
Masthamnsgatan 21, 413 29 Göteborg, Sweden
[email protected]