Skip to content
Painted In.
How it worksThe collectionSupport
Made for iPhone · In beta
Menu +
How it worksThe collectionSupportPrivacyTerms

Clear by design

Privacy, plainly.

Your photos are personal. Here’s what Painted In handles, where it goes, and the choices available in the current beta.

Private betaUpdated October 5, 2026Version 2026-10-05

On this page

About this policyWhat we handleHow creation uses your photosServices involvedHow long information staysYour choices and deletionUsing this websitePhotos of other peopleChanges and contact

The short version: selected photos and creation instructions go to OpenAI when you create a painting. Saved work also lives on your device. The beta has limits around automatic expiry and account deletion, explained below.

About this policy

This policy describes the Painted In website and the current private beta of our iPhone app. Painted In helps you create personal adaptations of public-domain paintings using photos you select. Some services, including purchases, private iCloud sync, and notifications, depend on the configuration of your beta build.

Our public release is still being prepared. This page describes current handling of data; it does not mean that a feature or privacy control described as unavailable has been released.

What we handle

InformationWhy it is used
Selected photos and subject namesTo create and identify your people and pet profiles and generate the paintings you request. Subject type, selected painting, placement choice, and correction notes also form part of a request.
Paintings and creation historyTo run generation jobs, recover interrupted sessions, return results, and support included redos.
Installation and account identifiersTo recognize your installation, protect access to your work, record the free trial, and connect an Apple sign-in to your app account.
Purchase and credit recordsWhen purchases are available, to verify Apple transactions and maintain your balance. Apple processes payments; our service does not receive your full payment-card details.
Support reportsTo review the problem you describe and any images you choose to attach, and record decisions or credit remedies.
Notification device tokenIf ready notifications are enabled and allowed, to deliver a notification to your device.
Technical and abuse-prevention informationTo operate the service, diagnose failures, and limit abuse. Our rate-limiting system processes IP addresses and stores keyed, salted counter identifiers.

Creating a profile does not give Painted In access to your entire photo library. The app uses the photos you select. When you sign in with Apple, we use an app-specific identifier rather than storing your Apple name or email.

How creation uses your photos

When you create a painting, selected reference photos are uploaded to our generation service. We send them to OpenAI with the source painting and instructions, including selected subject names, whether each subject is a person or pet, placement choices, and any correction text. A redo also uses the previous generated painting.

Only share photos you have the right and permission to use. Avoid including private information in subject names or correction notes that is not needed to make your painting.

OpenAI’s API documentation says API content is not used to train its models unless the API customer opts in. Its default abuse-monitoring logs may retain content for up to 30 days, with exceptions for legal or safety reasons. We do not promise zero provider retention. See OpenAI’s API data controls for the provider’s practices.

Services involved

  • OpenAI: processes image-generation requests.
  • Cloudflare: hosts this website and processes connection information to deliver its pages.
  • Fly.io: hosts the configured generation service and its private storage.
  • Apple: provides platform services such as Sign in with Apple, App Store purchases, optional push notifications, and private iCloud sync when configured.
  • Museum image hosts: supply the original artwork. Our source-image requests do not send your reference photos to the museums.

Saved profiles and paintings are held locally on your device. When private iCloud sync is configured and enabled, supported library content is also stored in your private iCloud database. Sending a saved painting to a Frame TV transfers that image over your local network. Pairing and automation setup remain device-specific.

Service providers may process information in countries other than where you live. Their own terms and privacy practices also apply to their services. This website links to external museum and Apple pages; those sites operate independently.

How long information stays

DataCurrent beta handling
Uploaded generation referencesRemoved from the active service database after the job’s completion or failure has been saved. Unused uploads become eligible for cleanup after 24 hours, unless an active job still needs them. Cleanup is periodic, not an exact-time deletion guarantee.
Completed paintings and job recordsKept for result recovery and related service functions. The current beta does not apply an automatic expiry to these records.
Support attachmentsImage attachments are removed from the active database when a case is decided. Unresolved cases retain their attachments. Report text and decision records have separate retention.
Account, purchase, and credit historyRetained to protect balances, verify transactions, and prevent duplicate grants or abuse. Deleting service content does not currently delete all account and financial records.
BackupsThe beta backup setup retains the latest seven completed database backup files and configures seven-day hosting snapshots. Deleted content can remain in an older backup until that copy expires.

Removing data from the active database is not a promise of immediate removal from provider safety systems, logs, older storage copies or backups. We are finalizing the retention windows and deletion process for the public release.

Your choices and deletion

You choose which reference photos are used for a creation. Notifications and iCloud sync are optional where those features are available. Turning either off does not prevent access to paintings already saved locally.

During the current beta, deleting a painting or profile in the app removes its local library record and, when configured, its synced library record. It does not currently erase every copy held by the generation service or delete your purchasing account. Signing out disconnects the installation from the purchasing account; it is not account deletion.

Beta participants can ask about service-held content, access, correction, or deletion using the contact provided with their beta invitation. We may need to verify that a request relates to your installation or account. Retained purchase and abuse-prevention records may need different handling from photos and artwork. See privacy help.

A remembered photo-processing permission and a complete in-app account-deletion flow are being prepared for public release. They are not controls offered by this website. You can avoid further generation uploads by not starting new creations; existing service requests may already be processing.

Using this website

The current website does not add advertising pixels, behavioral analytics, cookies, or a mailing-list form. Fonts and artwork are served with the site rather than loaded from third-party font or image services. It does not collect photos or process purchases.

Web hosting necessarily processes connection information to deliver pages and may produce security or operational logs. Following an external link takes you to that service’s own website and privacy practices.

Photos of other people

The private beta is intended for adults. Only submit another person’s photo with the appropriate permission. A parent or legal guardian must have authority to authorize processing of a child’s photo. Do not upload images you do not have permission to use or sensitive documents that are unrelated to a painting.

Changes and contact

We will update the date and version on this page when the policy changes. A material change in how photos are shared or used will require an updated disclosure and any applicable permission before that new use.

For the current private beta, use the contact supplied with your invitation. Public support contact details will be provided before public release. Our Support page explains the available help and current limitations.

Back to top
Painted In.

A personal place in art.

Privacy PolicyTerms of UseSupport
© 2026 Painted InAn independent app. Not affiliated with Samsung, Apple, or the featured museums.Artwork credits