Privacy Policy
Last updated: May 14, 2026
This Privacy Policy explains how QUICKAPPNINJA SIA("we", "us") collects, uses and protects personal data when you use RetroPulse (the "Service"). We are the data controller within the meaning of the EU General Data Protection Regulation (GDPR).
1. Controller and contact
QUICKAPPNINJA SIA
14 Detlava Brantkalna iela, Riga, LV-1082, Latvia
Reg. No. 40003673459
Privacy contact: support@retropulse.app
2. Categories of personal data we process
- Account data: name, email address, hashed password, account preferences, language.
- User Content (photographs): the digital images you upload for restoration. These may incidentally include images of other identifiable individuals.
- Payment data: billing name, billing address, last four digits of card and transaction identifiers received from our payment processors. Full card numbers are processed by Stripe and are not stored by us.
- Usage data: log data, device and browser information, IP address, timestamps and interactions with the Service.
- Support data: messages and attachments you send to our support team.
3. Purposes and legal bases
- To provide the Service (process your photos, manage your account, deliver subscriptions and tokens) — Art. 6(1)(b) GDPR (performance of a contract).
- To process payments and prevent fraud — Art. 6(1)(b) and (f) GDPR.
- To comply with legal obligations (accounting, tax, consumer law) — Art. 6(1)(c) GDPR.
- To improve the Service and ensure security(aggregated analytics, abuse prevention) — Art. 6(1)(f) GDPR (legitimate interests).
- To send service emails (receipts, security and policy updates) — Art. 6(1)(b) and (c) GDPR. Marketing emails are sent only with your consent — Art. 6(1)(a) GDPR.
We do not use your photographs to train AI models, and we do not sell personal data.
4. Retention
- Photographs: uploaded photographs and their restored outputs are automatically deleted from our systems within 30 days after processing. You may delete any photo immediately from your account.
- Account data: retained while your account is active. After account closure, we delete or anonymise account data within 90 days, except where longer retention is required by law.
- Billing records: retained for the period required by applicable accounting and tax law (typically up to 10 years in Latvia).
- Logs: typically retained for up to 12 months.
5. Sub-processors and recipients
We share personal data only with vetted service providers acting on our behalf as processors, under written agreements that include the safeguards required by Art. 28 GDPR.
- Stripe Payments Europe, Ltd. — payment processing.
- Yuno S.A.S. — payment orchestration.
- Lovable Cloud (Supabase) — hosting, database and authentication.
- Third-party AI image-processing providers — running the restoration and colorization models.
- Email delivery providers — sending transactional and (if you consent) marketing emails.
6. International transfers
Some sub-processors may process data outside the European Economic Area. Where this is the case we rely on appropriate safeguards under Chapter V GDPR, including the European Commission's Standard Contractual Clauses, supplementary measures where applicable, and adequacy decisions where they apply.
7. Your rights
Subject to the conditions of the GDPR, you have the right to:
- access your personal data and request a copy;
- request correction of inaccurate data;
- request erasure ("right to be forgotten");
- request restriction of processing;
- object to processing based on legitimate interests;
- request data portability;
- withdraw consent at any time, where processing is based on consent.
To exercise these rights, write to support@retropulse.app. You also have the right to lodge a complaint with the Latvian Data State Inspectorate (Datu valsts inspekcija, www.dvi.gov.lv) or your local supervisory authority.
8. Security
We use industry-standard technical and organisational measures to protect personal data, including encryption in transit, encryption at rest for stored photographs, access controls and audit logging. No system can be guaranteed 100% secure; please notify us promptly if you suspect a security incident.
9. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top reflects the latest revision. Material changes will be notified by email or in-app.