Effective date: 16 June 2026
Version: 1.0
Bizzibis is an iOS mobile app that uses artificial intelligence (AI) to generate professional profile photos (e.g. for LinkedIn or a CV) from a face photo provided by the user.
This Privacy Policy explains what personal data we process, for what purposes, on what legal basis, with whom we share it, and what rights data subjects have, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Polish data protection law.
The controller of your personal data is:
ul. Makowa 7, 66-431 JanczewoNIP: PL5992961187kontakt@gmac.plNo Data Protection Officer has been appointed (not required for this business). For data-protection matters contact: kontakt@gmac.pl.
To generate a profile photo, you upload or take a photo of your face. A photo containing your likeness may, in the context of being used to recreate your likeness, constitute special-category personal data (biometric / likeness data) within the meaning of Article 9 GDPR. For this reason we process such photos solely on the basis of your explicit consent (see section 5) and only to the extent necessary to provide the service. The app does not create a biometric template or faceprint and does not perform facial recognition, identification, or matching — your photo is used only as an image input to generate your portrait, and no identifier is derived from your facial features.
Sharing your photo with a third-party service. To create your portrait, your selected photo is sent to third-party image-generation providers (in particular Google / Gemini; see section 6). The photo is transmitted only after you give explicit consent in the app, which we display before any data is sent, and is used solely to prepare your portrait — for no other purpose and not to train models.
Sign-in is handled via Sign in with Apple. Depending on your settings, we receive:
Purchases are made exclusively through Apple In-App Purchase. We do not process or store your payment card data — Apple does. We receive the information needed to attribute purchased "credits" to your account and to verify the transaction (e.g. a transaction/receipt identifier).
To ensure operation, security, and diagnostics, we process limited technical data such as: request timestamps, generation job identifiers, error codes, and basic device/app-version information.
| Purpose | Data categories |
|---|---|
| AI generation of profile photos | face photos (input and output) |
| Account creation and management, authentication | e-mail, Apple identifier |
| Processing and verifying purchases (credits) | IAP transaction data |
| Security, abuse prevention | technical data / logs |
| Handling complaints and contact | e-mail, request data |
| Compliance with legal obligations | transaction / accounting data |
To provide the service we use trusted providers acting as processors on our behalf:
| Provider | Role | Data processed |
|---|---|---|
| Supabase | Database hosting (Postgres), file storage (Storage), Edge Functions | account, photos (private bucket), logs |
| Google (Gemini 2.5 Flash Image — "Nano Banana") | AI image generation | photo + prompt |
| KIE.ai | AI image generation | photo + prompt |
| OpenRouter | AI model access intermediary | photo + prompt |
| Apple | Sign in with Apple, In-App Purchase | e-mail / identifier, transaction data |
Position on model training: User photos are sent solely to generate a one-time output. Our intention and position is that user photos are not used to train AI models, and that processing follows each provider's terms of service. Per the providers' terms (Google, KIE.ai, OpenRouter) photos are processed solely to generate the result and, to our best knowledge, are not used to train models.
Some providers (e.g. AI model providers and Apple) may process data on servers located outside the European Economic Area (EEA), including in the United States. In such cases, transfers are based on appropriate safeguards, in particular Standard Contractual Clauses (SCCs) approved by the European Commission, or on an adequacy decision (e.g. the EU-U.S. Data Privacy Framework, where a given provider participates in it).
Some AI providers may process data outside the EEA (incl. the USA) under Standard Contractual Clauses (SCC) and/or the Data Privacy Framework, per each provider's terms.
The input photo is stored in a private bucket only for as long as needed to generate the results and is deleted with the session (max. 14 days) or when the account is deleted.do czasu usunięcia konta przez użytkownika / until the user deletes their account.In connection with the processing of your personal data, you have the right to:
To exercise your rights, contact us at kontakt@gmac.pl.
The app provides a permanent account deletion feature. Using it deletes your account server-side together with all associated photos and any remaining credits. Some data may be retained only to the extent and for the period required by applicable law (e.g. accounting data — see section 8).
We apply technical and organizational measures appropriate to the risk, including: storing photos in a private, access-controlled bucket, encrypting connections in transit (TLS), restricting access to data, and automatically deleting photos after 14 days. However, no method of transmission or storage is 100% secure.
The app is not directed at children. It may be used by adults or by persons who are at least 16 years old; for persons under 16, processing based on consent requires the consent of a legal guardian (in line with Art. 8 GDPR and national law). The minimum user age may also be set by the App Store age rating (17+).
We may update this Privacy Policy. We will notify you of material changes in the app or by other appropriate means. The updated version applies from the stated effective date.
For privacy and data protection matters, contact us:
kontakt@gmac.plul. Makowa 7, 66-431 Janczewo