← Storpix
TürkçeEnglish

Privacy Policy

Last updated: 6/26/2026

Introduction

This Privacy Policy explains how your personal data is collected, processed, stored and protected through the Storpix application and services ("Storpix", "App", "Service"). Storpix is an event memory application designed for special occasions such as weddings, engagements and birthdays. It offers a QR-based guest album, digital invitations with RSVP tracking, artificial intelligence image and text tools, physical printing and e-commerce, and a permanent family-only album.

This document is prepared to fulfil both our disclosure obligation under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and our transparency obligation under the EU General Data Protection Regulation (GDPR).

This policy should be read together with the User Agreement (https://storpix.net/sartlar) and the Privacy Choices and Data Deletion page (https://storpix.net/gizlilik-tercihleri). The current, official version of this policy is always published at https://storpix.net/gizlilik, which is also the privacy policy link provided in the app stores.

Effective / last updated: June 26, 2026.

Identity of the Data Controller

The data controller (KVKK) and controller (GDPR) of your personal data is:

You may direct all data protection requests and questions to info@storpix.com. The data controller's current registered business address and registry details are available on request from info@storpix.com.

Personal Data We Collect

Below we declare the categories of personal data we collect and the concrete fields within each category. We aim to keep this declaration consistent with our Apple Privacy Nutrition Labels and Google Play Data Safety disclosures.

1. Account and Identity Data (registered users): Email address, full name, user role and language preference. When you sign in with Apple or Google, your full name may be transferred from that provider. Our authentication is handled on Supabase Auth.

2. Subscription and Account Lifecycle Data: Your subscription plan (Free, Plus, Ultimate), plan start and expiry dates, account lifecycle state and AI credit ledger records (transaction amount, reason, source and store/order reference).

3. Event and Invitation Content: Event name, date, venue and street address, access code; and on invitations the bride/groom name, message, venue and address that you provide.

4. User and Guest Content / Media: Uploaded photos, videos, audio and messages; their file paths, message/note text, uploader information, guest name and guest session identifier, file size and, where available, the capture date of a photo (sourced from EXIF/media library).

5. Family Album Profiles and Social Interaction: Name, birth date and avatar of persons defined in a family album; family membership and invitation information; likes, comments and emojis. On the event side, likes and comments (guest name, guest session, comment text) and participant/collaborator records.

6. Invitation RSVP Data: Guest name, phone number, attendance status (coming/not coming/maybe), party size, note and guest session identifier.

7. Support Requests: Support case code, subject, status, whether you granted access to your event data, message text and file paths of photo attachments only.

8. E-Commerce and Purchase Data: Customer name, phone, shipping address (including city, country, postal code), order note, amount and currency (TRY/USD/EUR), order items, photo paths selected for printing and payment status/provider/reference information. When you start a physical product payment, the buyer email passed to the payment provider is your registered account email; no separate email is collected in the payment flow.

9. Device, Usage and Notification Data: Push notification token, platform (iOS/Android/web), notification provider, device name, last used time and records of sent notifications.

10. Guest Identifier Data: For non-registered guests, only a session identifier (sx_guest cookie, uuid, 1 year) and a readable guest name cookie.

11. Automatically Collected / Analytics / Log Data: In-app event and screen tracking (e-commerce events such as screen name, item view, add to cart, begin checkout, purchase), session and general usage information; error/crash records; anonymised logs for system security. On RSVP submission, the IP address is used only in memory for temporary rate-limiting and is not stored in the database. In addition, during a physical product payment, your IP address is passed to the payment provider for its fraud-check purposes.

Data we do not collect: We do not collect structured location data such as GPS/coordinates, biometric data, health data, fingerprints or other special category (sensitive) data. "Location" consists only of the venue and address fields you enter as free text. Payment card details are not stored in our systems.

Purposes of Processing

We process your personal data for the following purposes:

Legal Bases

We process your personal data on the following legal bases.

Performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6/1-b): Account creation, provision of the album/invitation/RSVP service, subscription and credit management, processing and delivery of physical product orders.

Explicit consent (KVKK Art. 5/1; GDPR Art. 6/1-a): Sending your content to AI providers when you use AI features, optional notifications and non-essential analytics/functional technologies. You may withdraw your consent at any time.

Legitimate interests (KVKK Art. 5/2-f; GDPR Art. 6/1-f): Service security, prevention of fraud and abuse, error monitoring, measuring and improving the Service. A balancing test is applied and your fundamental rights and freedoms are protected.

Legal obligation (KVKK Art. 5/2-ç; GDPR Art. 6/1-c): Tax, invoicing and commercial record-keeping obligations and responding to requests from competent authorities.

Content uploaded by guests and RSVP data are processed within the scope of the relevant event owner's use of the Service and for the purpose of providing the Service.

Subscriptions, Auto-Renewal and AI Credits

Storpix offers Free, Plus and Ultimate plans. Plus and Ultimate are paid, auto-renewable subscriptions.

AI credit packs are acquired separately from subscriptions through one-time in-app purchases and do not auto-renew. If an AI operation fails, the credit spent is refunded.

Artificial Intelligence Features and Data Processing

When you use the AI image and text tools, the content to be processed is transferred to third-party AI providers. These features are optional and run on credits.

Photo/image tools: For photo enhancement, restoration and dynamic AI effects, your photo is sent to the provider not as a direct file upload but as a temporarily accessible link (CDN URL); the provider fetches the image from this link and processes it. We use Replicate and fal.ai (both based in the USA) for these operations. The processed output is downloaded by our servers and stored in our storage.

Text generation: For outputs such as invitation text, thank-you notes, stories, album analysis and social media text, only text is sent to the AI provider; no photo is sent. The context sent may include fields such as bride/groom name, date and venue depending on your request. We use an OpenAI-compatible text provider operating via OpenRouter (based in the USA) for text generation.

If an AI operation fails, the credit spent is refunded. You can prevent your content from being transferred to these providers by choosing not to use the AI features.

Cookies and Similar Technologies / SDKs

We use certain cookies and similar technologies for the Service to function.

In the mobile app, software development kits (SDKs) are used for analytics and error monitoring: Firebase Analytics (GA4) for screen and e-commerce events, and Sentry for error/crash monitoring. No personally identifiable information (PII) is sent to analytics and no advertising identifier is used; error monitoring does not send IP/user information by default.

Parties with Whom Data Is Shared and Processors

We share your data only to the extent necessary to provide the Service and with processors bound by contract. We do not sell your data for marketing purposes.

Although Stripe infrastructure exists in the code, it is currently disabled and no data transfer takes place; if it is enabled in the future, this policy will be updated.

International Transfers

Some of the service providers listed above are located abroad. Your personal data is therefore transferred internationally.

These transfers are necessary to provide the Service. Under KVKK, they are carried out on the basis of your explicit consent and/or the necessity of contract performance. Under GDPR, where the recipient country is not covered by an adequacy decision, the transfers rely on appropriate safeguards; these safeguards are primarily the Standard Contractual Clauses (SCCs) applied under the data processing agreements concluded with the relevant providers. You may request detailed information about these mechanisms and the related safeguards from info@storpix.com. As payment card data is not stored in our systems, it is not transferred in this scope.

Retention Periods

We retain your personal data only for as long as the processing purpose requires and to the extent of applicable legal retention obligations.

Data Security

We apply technical and administrative measures to protect your data. Database access is restricted with row-level security (RLS); privileged server keys are kept server-side only and are never sent to the client. Guest write operations are performed only with an authorised server role. Payment card data is not stored in our systems; payments are taken via hosted payment pages and the result is verified server-side. AI credit spending is processed through an atomic mechanism that prevents double charging and overdraft.

Children's Privacy

Storpix is not a service directed at children, and we do not knowingly collect personal data from persons below our app store age rating. To create an account and manage a subscription, you must meet the age required by the relevant store and applicable law; minors should use the Service only under the supervision and with the consent of a parent/guardian.

In the family album feature, information such as a child's name and birth date is entered only by the authorised adult account holder. This information is processed for the purpose of the account holder managing their album, and responsibility for the accuracy of the entered content and for obtaining the necessary consents/permissions relating to it lies with that account holder. If we determine that we have processed a child's personal data without the necessary authority, we take steps to delete it.

Guest / Invitee Data

When you, as a guest (without registering), upload content to a QR album or submit an RSVP response to an invitation, we associate you only with a session identifier (sx_guest cookie) and the guest name you provide; no account or email is created. The photos, videos, messages, likes and comments you upload, and your RSVP information (name, phone, attendance status, party size, note), are processed in connection with the album of the user who created the relevant event.

Guest data depends on the event owner's data: when the event is deleted or the account holder deletes their account, this data is deleted along with it. As there is no independent self-service deletion/access interface for guests in the app, you may direct requests regarding your own guest data to info@storpix.com or contact the relevant event owner.

Your Rights and How to Exercise Them

Your rights under KVKK Art. 11: To learn whether your personal data is processed; to request information if it has been processed; to learn the purpose of processing and whether it is used in accordance with that purpose; to know the third parties to whom data is transferred domestically or abroad; to request correction if processed incompletely or incorrectly; to request erasure or destruction if the grounds for processing cease to exist; to request that correction/erasure operations be notified to third parties to whom the data was transferred; to object to a result against you arising from analysis solely by automated systems; and to claim compensation for damages arising from unlawful processing.

Your rights under GDPR: Right of access (Art. 15), right to rectification (Art. 16), right to erasure/to be forgotten (Art. 17), right to restriction of processing (Art. 18), right to data portability (Art. 20), right to object (Art. 21) and the right to withdraw consent for processing based on explicit consent (Art. 7). In addition, if you are located in the EEA, you have the right to lodge a complaint with the competent data protection supervisory authority.

To exercise your rights: You may submit requests to info@storpix.com or use the Privacy Choices and Data Deletion page (https://storpix.net/gizlilik-tercihleri). We conclude requests within 30 days at the latest.

You can delete your account directly within the app: open the Storpix app and sign in, go to the Profile tab, tap "Delete my account" and confirm. The operation is immediate and permanent; it cannot be undone. Alternatively, you may send a request from your registered email to info@storpix.com; after your identity is verified, deletion is performed within 30 days at the latest.

Important note: Deleting your account does not automatically cancel a subscription started through the App Store or Google Play. Subscription cancellation and refunds are subject to the policies of the relevant store.

Changes

We may update this Privacy Policy from time to time. We will inform you by appropriate means in case of material changes. The current version is always published at https://storpix.net/gizlilik and takes effect on the effective date shown on the page.

Contact

For any questions, requests and complaints regarding this policy or your personal data, you may contact us:

This policy is governed by Turkish law. The Courts and Enforcement Offices of Trabzon shall have jurisdiction over disputes. Your rights under GDPR are reserved.