Bizzibis Privacy Policy

Effective date: 16 June 2026
Version: 1.0

1. Introduction

Bizzibis is an iOS mobile app that uses artificial intelligence (AI) to generate professional profile photos (e.g. for LinkedIn or a CV) from a face photo provided by the user.

This Privacy Policy explains what personal data we process, for what purposes, on what legal basis, with whom we share it, and what rights data subjects have, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Polish data protection law.

2. Data Controller

The controller of your personal data is:

No Data Protection Officer has been appointed (not required for this business). For data-protection matters contact: kontakt@gmac.pl.

3. What data we process

3.1. Face photos (biometric / special-category data)

To generate a profile photo, you upload or take a photo of your face. A photo containing your likeness may, in the context of being used to recreate your likeness, constitute special-category personal data (biometric / likeness data) within the meaning of Article 9 GDPR. For this reason we process such photos solely on the basis of your explicit consent (see section 5) and only to the extent necessary to provide the service. The app does not create a biometric template or faceprint and does not perform facial recognition, identification, or matching — your photo is used only as an image input to generate your portrait, and no identifier is derived from your facial features.

Sharing your photo with a third-party service. To create your portrait, your selected photo is sent to third-party image-generation providers (in particular Google / Gemini; see section 6). The photo is transmitted only after you give explicit consent in the app, which we display before any data is sent, and is used solely to prepare your portrait — for no other purpose and not to train models.

3.2. Account and authentication data

Sign-in is handled via Sign in with Apple. Depending on your settings, we receive:

3.3. Purchase data (credits / IAP)

Purchases are made exclusively through Apple In-App Purchase. We do not process or store your payment card data — Apple does. We receive the information needed to attribute purchased "credits" to your account and to verify the transaction (e.g. a transaction/receipt identifier).

3.4. Technical data and logs

To ensure operation, security, and diagnostics, we process limited technical data such as: request timestamps, generation job identifiers, error codes, and basic device/app-version information.

3.5. What we do NOT do

4. Purposes of processing

Purpose Data categories
AI generation of profile photos face photos (input and output)
Account creation and management, authentication e-mail, Apple identifier
Processing and verifying purchases (credits) IAP transaction data
Security, abuse prevention technical data / logs
Handling complaints and contact e-mail, request data
Compliance with legal obligations transaction / accounting data

5. Legal bases (Articles 6 and 9 GDPR)

6. Recipients / processors (sub-processors)

To provide the service we use trusted providers acting as processors on our behalf:

Provider Role Data processed
Supabase Database hosting (Postgres), file storage (Storage), Edge Functions account, photos (private bucket), logs
Google (Gemini 2.5 Flash Image — "Nano Banana") AI image generation photo + prompt
KIE.ai AI image generation photo + prompt
OpenRouter AI model access intermediary photo + prompt
Apple Sign in with Apple, In-App Purchase e-mail / identifier, transaction data

Position on model training: User photos are sent solely to generate a one-time output. Our intention and position is that user photos are not used to train AI models, and that processing follows each provider's terms of service. Per the providers' terms (Google, KIE.ai, OpenRouter) photos are processed solely to generate the result and, to our best knowledge, are not used to train models.

7. International data transfers (outside the EEA)

Some providers (e.g. AI model providers and Apple) may process data on servers located outside the European Economic Area (EEA), including in the United States. In such cases, transfers are based on appropriate safeguards, in particular Standard Contractual Clauses (SCCs) approved by the European Commission, or on an adequacy decision (e.g. the EU-U.S. Data Privacy Framework, where a given provider participates in it).

Some AI providers may process data outside the EEA (incl. the USA) under Standard Contractual Clauses (SCC) and/or the Data Privacy Framework, per each provider's terms.

8. Data retention

9. Your rights

In connection with the processing of your personal data, you have the right to:

To exercise your rights, contact us at kontakt@gmac.pl.

10. In-app account deletion

The app provides a permanent account deletion feature. Using it deletes your account server-side together with all associated photos and any remaining credits. Some data may be retained only to the extent and for the period required by applicable law (e.g. accounting data — see section 8).

11. Security

We apply technical and organizational measures appropriate to the risk, including: storing photos in a private, access-controlled bucket, encrypting connections in transit (TLS), restricting access to data, and automatically deleting photos after 14 days. However, no method of transmission or storage is 100% secure.

12. Children

The app is not directed at children. It may be used by adults or by persons who are at least 16 years old; for persons under 16, processing based on consent requires the consent of a legal guardian (in line with Art. 8 GDPR and national law). The minimum user age may also be set by the App Store age rating (17+).

13. Changes to this Privacy Policy

We may update this Privacy Policy. We will notify you of material changes in the app or by other appropriate means. The updated version applies from the stated effective date.

14. Contact

For privacy and data protection matters, contact us: