Picnumo Privacy Policy
Last updated 30 September 2026
This policy explains how data is processed in the Picnumo Android app and on picnumo.app. The photos you select are sent for AI analysis, and successful analyses and compressed photos are stored with your account so that you can access them again, including from another phone.
1 Who processes your data and how to contact us
The data controller is IZUMIQ D.O.O., Partizanska 10, 17500 Vranje, Republic of Serbia (“Picnumo”, “we”, “us”).
For privacy questions, support and deletion requests, contact support@picnumo.app.
This policy covers the Picnumo Android app, including its mandatory accounts, AI analysis, private album, advertising and subscriptions through the Google Play store, and the picnumo.app website.
2 Account and usage data
An account is required. You can register with an email address and password, with email verification, or sign in using a Google account. Your Picnumo profile stores your email address and a unique user identifier (UID). We do not request or store your name, profile photo, date of birth or gender as profile data.
Firebase Authentication processes the data needed for sign-in and security, including authentication data, email verification status and technical data such as IP addresses. Google sign-in uses the identifiers and tokens needed to link and verify the account.
To enable analyses, we process credit balances and usage, request status and the associated UID. For rewarded ads, we process confirmation that the conditions for awarding credits have been met. Linking data to a UID does not make it anonymous.
We record your confirmation of the AI analysis notice, including the notice version and the date and time of confirmation, with your account.
We also record your confirmation that you meet the minimum age requirement, including the date and time of confirmation, with your account.
When you contact us, we process your email address, message and any attachments you choose to send so that we can respond and handle your request.
3 Photos and results
We process the individual photo you select using the system photo picker or capture with the camera. A photo may contain identifiable people, objects, text and details of the surroundings. Picnumo does not automatically access your phone’s entire photo gallery.
We create a compressed JPEG copy for your private album, with a shorter side of approximately 1600 pixels and a file size typically measuring a few hundred kilobytes. We do not alter the original photo in your phone’s gallery or store it on our servers. During processing, we remove location metadata, including GPS coordinates, from the compressed copy. Some technical metadata, such as colour profiles, may remain.
After each successful analysis, we automatically store the compressed photo on your device and in Firebase Storage, and the results in Firestore. Results include scores, a vibe description, suggested hashtags and social media captions, the category and the analysis date. Captions and hashtags are generated from the photo in the same AI request as the analysis. You can edit a caption in the app before copying it. Storage is part of the private album feature and does not require additional confirmation for each successful analysis.
If the compressed photo or the result cannot be uploaded, for example because there is no internet connection, both remain on your device. The app automatically tries to upload them again the next time it is opened while you are signed in and connected. A result is not stored in Firestore until its photo has been uploaded.
If an analysis fails, we do not save the photo or result to our persistent cloud album. A photo already sent to the AI provider remains subject to that provider’s processing and retention rules described in this policy, regardless of whether the analysis succeeds.
Add Memory. You can add a short personal note of up to 300 characters to a saved result, for example where the photo was taken or why it matters to you. You write the note yourself; it is not generated by AI and is not sent to any AI provider. It is stored on your device and with your account in Firestore, so that it is also available on your other devices. Once changes have been uploaded, they appear on another device signed in to your account when you next open the gallery on that device with an internet connection. You can edit or delete a note at any time. Because a note may mention other people, please add only information appropriate for storing in your private album.
4 AI analysis and its limitations
We use the OpenAI API to categorize and analyze photos. A compressed copy of the photo is sent within the request, together with the instructions needed for processing. Processing takes place outside your phone.
Before your first AI analysis, the app displays a notice explaining that the photo will be sent, who will receive it and for what purpose. Your photo is sent only after you select “Agree and analyze”. If you cancel, it is not sent. Your confirmation is recorded with your account, so you do not need to repeat it for every analysis under the same notice version.
By default, OpenAI does not use API content to train its general-purpose models unless the API customer specifically enables data sharing. We do not enable sharing of your photos or results for that purpose. Picnumo does not use user content for its own model training, as explained in Section 5.
Scores and descriptions are generated through automated analysis of visual content. They may be inaccurate and are not established facts about a person. We do not use them to make decisions about employment, credit, insurance or other rights and similarly significant interests of users.
We do not use facial recognition to establish identity or create biometric templates for identification. We do not estimate age, ethnic origin, health status or other sensitive characteristics. Our AI instructions prohibit scoring on those grounds. A photo itself may nevertheless reveal private or sensitive information; please select content appropriate for this service.
Reporting a result. If you believe a result is inaccurate, offensive or inappropriate, you can report it in the app using “Report this result”. A report contains:
- Your user identifier, the result identifier and the category.
- The reason you select and an optional comment of up to 300 characters.
- A copy of the AI-generated text of that result, including its description, captions and badges.
Your photo is not attached to the report. We review reports to deal with the problem you raised. The number of reports per account per day is limited to protect the service from misuse.
5 Photos are not used for training
We do not use users’ photos or their results to train AI models, whether our own or those of other providers, or to run advertising campaigns. We do not copy content from users’ albums into training datasets. We do not use your photos to test or calibrate the system, and we use the text of your results for that purpose only if you report it yourself, as described below. We process photos and results for the requested analysis, the private album and the other direct purposes described in this policy, including support and deletion on request.
Reports. When you report a result, we review the reported text and your comment to deal with the problem you raised. What we learn from reports may be used to refine the instructions our AI analysis follows. Reports do not include your photo and are not used to train AI models.
6 Purposes and legal bases
We process the data needed for your account, the requested analysis of your photos, the private album, personal memory notes, credits and subscription activation to provide the contracted service. Without the necessary data, we cannot provide the relevant feature.
For advertising identifiers and other processing that requires consent under applicable rules, we request your choice before that processing takes place. Withdrawing consent does not affect the lawfulness of processing already carried out.
We process reports you submit to investigate reported issues, prevent misuse and improve the safety and reliability of our responses, including by refining AI instructions. We rely on our legitimate interests in operating a safe and reliable service, taking your rights and interests into account.
We use limited technical logs for reliability, troubleshooting and protection of the service, based on our legitimate interests and taking your rights into account. We keep records of your confirmation of the analysis notice to document your choice and manage which notice version you have accepted.
We process data that we are required to retain or disclose by law to comply with our legal obligations.
7 Who receives your data
Google Firebase and Google Cloud provide sign-in and account management (Authentication), result and memory note storage (Firestore), photo storage (Storage) and server-side processing (Cloud Functions).
An authorized administrator can technically access data through the console. Access to album content is limited to support and deletion on request. We also access the text and account identifiers included in reports you submit to review and address reported issues, as described in Sections 4 and 5.
OpenAI receives the photo and the instructions needed for AI processing. Google AdMob and the advertising providers involved in serving a particular ad process the advertising and technical data described in Section 8. Google Play handles billing. Cloudflare provides website delivery and support email forwarding.
Our email service providers process support correspondence to deliver, forward and store the messages you send us.
Providers may use subcontractors under their agreements. For certain functions, they process data on our instructions; for their own responsibilities, such as payment processing or certain security records, they may act as independent data controllers.
We disclose data to competent authorities when required by law. We limit professional advisers’ access to what is necessary for the relevant matter. Your album is not a public database, and photos and results are not sent to advertising networks.
8 Advertising and privacy choices
Picnumo displays non-personalized banner ads and optional rewarded video ads through Google AdMob. We do not send advertising networks your photos, photo categories, scores, vibe descriptions, hashtags, captions, personal memory notes or any other analysis content.
Non-personalized ads still involve data processing. Depending on the settings and your choices, the advertising SDK may process IP addresses and approximate location derived from them, device and advertising identifiers, app and ad interactions, and diagnostic data. It uses this data to deliver and measure ads and prevent fraud.
Where required, we request consent before using advertising identifiers and carrying out the related processing. You can review and change your choices through the privacy options provided in the app. If you decline, we do not carry out processing that requires that consent; ad availability depends on the permitted ad-serving mode.
Rewarded ad verification data is used to award credits. Choosing to watch an ad does not replace consent for advertising data processing where that consent is required.
We do not currently use Firebase Analytics, Crashlytics, the Meta pixel or separate tools for tracking installations for marketing purposes. This does not exclude technical and advertising measurement that forms part of the active services listed above. Before introducing new tools and processing, we will provide updated information and the required choices.
9 Subscriptions
Subscriptions are paid for exclusively through Google Play Billing. Google processes payment data under its own policies. Picnumo processes the data needed to verify the purchase and provide the benefits; it does not receive your full payment card number or security code.
Purchase verification may involve product and transaction identifiers, purchase tokens, subscription status and relevant dates. We use this information to verify purchases, activate or restore subscription benefits, and handle billing-related requests.
10 Where data is processed
We have selected European locations within Google’s infrastructure for the results database, photo storage and server-side functions. This does not mean that all data is processed exclusively in Europe: Firebase Authentication uses data centers in the United States, and OpenAI, Google advertising and payment services, and Cloudflare may also process data in other countries.
International transfers are subject to the safeguards required by applicable data protection laws. Depending on the recipient and transfer, these may include an applicable adequacy decision or contractual safeguards, such as standard contractual clauses.
You may request information about the safeguards and an appropriate copy of the relevant documentation through our privacy contact, subject to the protection of confidential information.
11 How long we retain data
We retain account data, successful analyses, the associated compressed photos and credit records while you use your account, or until individual content or the account is deleted, as applicable. Uninstalling the app does not delete your cloud account or album.
Memory notes are kept together with the result they belong to and are deleted with it. Records of your confirmations of the analysis notice and the age requirement are kept with your account and deleted when you delete the account.
Reports are deleted 90 days after they are resolved, and in any case no later than 12 months after submission. They are also deleted when you delete your account.
Server logs contain the UID, status and credit balance, but not photos or the content of AI responses. Technical and security records are kept for the period necessary to investigate errors, protect the service and meet applicable audit requirements. These records are separate from credit records in Firestore and may remain after an account is deleted.
Deletion from the active service does not necessarily remove every technical copy immediately. Where the infrastructure retains recovery or backup copies, those copies remain until the applicable recovery or backup retention period expires. Their retention is separate from access to your account and album.
According to Firebase Authentication’s published policies, after user deletion is initiated, removing authentication data from its live and backup systems may take up to 180 days. This is separate from removing the Picnumo account and album from the app.
OpenAI may retain content and metadata in security logs for up to 30 days, and longer where required by law or to protect against harm. We disable optional storage of API responses where supported by the API configuration we use. This does not eliminate security logs or mean that Zero Data Retention applies.
We keep support correspondence for as long as needed to resolve the request and deal with related follow-up or claims. Purchase verification data is retained as necessary to manage the subscription and resolve payment issues; records required by law are retained for the applicable statutory period. Google and other providers may retain data they process independently, including transactions and their own security records, under their policies and obligations.
12 Deleting photos and your account
You can delete an individual result from the Picnumo gallery. Deletion removes the result, including any memory note, from Firestore and the photo from Firebase Storage, subject to the retention periods for remaining technical copies described above. It also removes the copies Picnumo saved on the device you delete it from.
On other devices signed in to your account, the deletion is reflected when you next open the gallery with an internet connection. A device that is offline retains its local copies until it can synchronize.
If the result was still waiting to be uploaded, the pending upload is cancelled. Pending memory changes associated with a deleted result are also removed.
Deleting a result does not delete a report you submitted about it; reports are deleted as described in Section 11 or when you delete your account.
To delete your account, open your profile, select Delete account, read the warning and confirm by typing DELETE. The server-side process starts immediately and automatically deletes photos from Storage, results and memory notes from Firestore, reports you submitted, credit records, records of your confirmations of the analysis notice and the age requirement, and the Authentication account.
Pending uploads and memory changes on the device you delete your account from are cancelled. Starting the deletion process does not mean that every copy held by every provider has disappeared at that same moment.
If you cannot access the app, visit picnumo.app/delete-account or email support@picnumo.app. We carry out deletion after reasonably verifying that the request comes from the account owner. We do not ask for your password. We respond within the period required by applicable law.
Deletion in Picnumo does not remove original photos, exported cards or copies that you have saved or shared outside the app.
Deleting your account or uninstalling the app is not the same as cancelling your subscription. Manage your subscription in the Google Play store; cancel it before deleting your account if you do not want further renewals. Google may retain purchase records under its own policies.
13 Album privacy and security
Your album is private. Access rules are designed to allow users to access only their own account data. Authorized administrative access and processing by providers are limited to the purposes described. Server-side functions do not write photos or the content of AI responses to application logs.
A Picnumo card is created as a file that you choose to save or share. The image is passed to the system sharing function without creating a public link to your private album. Recipients and apps you send it to manage their copies under their own policies.
We apply technical and organizational measures to restrict access and protect data. No system can guarantee absolute security; keep your account access secure and let us know if you suspect unauthorized access.
14 Age requirements and photos of other people
Picnumo is intended for users aged 16 or older. People under 16 are not permitted to create accounts. If we learn that a person under 16 has an account, we will take steps to remove it and delete the associated data in accordance with applicable rules.
Photos of children may be used within appropriate features, such as family photos. Users must have the right and the necessary authorization to upload the content and enable the described processing of the people shown in it, including authorization from a parent or guardian where required. Such confirmation does not diminish the rights of the people shown.
If you or a child you are responsible for appear in a photo and you have a question or removal request, contact us with information that allows us to locate the content. You do not need a Picnumo account to exercise rights relating to your own data.
15 Website and device permissions
The picnumo.app website uses Cloudflare Pages. Images and videos are served directly from the website; there are no embedded video platforms. We do not use a contact form, newsletter, separate website analytics or marketing pixels.
When you visit, technical data needed to deliver and protect the website is processed, such as your IP address, browser information and request details. Cloudflare may process this data as part of its infrastructure and service protection.
The app uses the system picker to select individual photos and, when you choose to use it, the camera. It does not request access to your location, microphone or contacts. Providers may nevertheless use an IP address to estimate approximate location, which is different from accessing your phone’s GPS. Push notifications are not enabled.
16 Your rights
Under applicable law, you may request information and access to your data, rectification, erasure, restriction of processing and data portability to the extent that this right applies. You may withdraw consent and object to processing based on legitimate interests. These rights also apply to other people whose data appears in the content.
Send requests to support@picnumo.app. We verify identity in a manner proportionate to the request. We respond without undue delay, generally within 30 days under Serbian law or one month where the GDPR applies; we notify you of any permitted extension, the reasons for it or any refusal in accordance with the relevant law.
You may lodge a complaint with Serbia’s Commissioner for Information of Public Importance and Personal Data Protection (www.poverenik.rs), or with the competent data protection authority in your country where applicable.
17 Changes to this policy
We update this policy when features, providers or processing practices change. We publish each new version with its effective date. We notify users of material changes in an appropriate way and, where a new purpose requires consent, request it before starting that processing. Publishing an amended policy does not provide consent for a new purpose that requires it.
For any questions, contact support@picnumo.app.
