← Back to Home

Privacy Policy

Last Updated: October 2, 2025

1. Introduction

Welcome to CosplayMe ("we," "our," or "us"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Progressive Web Application (PWA).

Privacy-First Design: We do NOT have a database. Your photos are processed in memory and immediately deleted. We do NOT persistently store your images, videos, or personal data on our servers.

2. Information We Collect

2.1 Information You Provide (NOT Stored on Our Servers)

  • Photos: You voluntarily upload portrait photos to transform into cosplay images. These are processed in memory and immediately discarded - NOT stored on our servers.
  • Consent Data: Your acceptance of terms (stored only in your browser).

2.2 Temporarily Collected Information (In-Memory Only)

  • IP Address: Used temporarily in server memory for rate limiting only. Cleared on server restart. NOT stored in any database.

2.3 Browser-Side Storage (On Your Device)

  • Theme Preferences: Stored in your browser's localStorage (never sent to our servers).
  • Cookie Consent Status: Stored in your browser's localStorage (never sent to our servers).

3. How We Use Your Information

  • AI Processing: Photos are processed through Google Gemini AI to generate cosplay images and videos.
  • Service Delivery: To provide, maintain, and improve our service.
  • Error Monitoring: To diagnose and fix technical issues.

4. Data Retention and Deletion

Important: We do NOT have a database. We do NOT store your data persistently.

  • Photos: Processed in memory only and immediately discarded. Never saved to disk or database.
  • Generated Images/Videos: Returned to your browser only. Never stored on our servers.
  • IP Addresses: Kept temporarily in server memory for rate limiting. Automatically cleared on server restart (typically every few hours on Vercel).
  • Browser Data: Theme preferences and consent status are stored in YOUR browser's localStorage. Clear your browser data to delete.
  • Third-party Processing: Google Gemini processes your images according to Google's Privacy Policy.

5. Third-Party Services

We use the following third-party service:

6. Your Rights

Note: Since we do NOT persistently store your data on our servers, most data rights are not applicable. However, depending on your location, you have the following rights:

  • Access: We have no persistent data about you to provide (except temporarily in-memory rate limiting).
  • Deletion: Your photos are never stored - they're automatically deleted after processing. Browser data (theme, consent) can be cleared from your browser settings.
  • Objection: You can stop using the service at any time. No data persists on our servers after you close your browser.
  • Portability: We have no stored data to export.

For questions, contact us at: @mustbesimo

7. Children's Privacy

Our service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

8. International Data Transfers

Your data may be processed in countries outside your own. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.

9. Security

We implement appropriate technical and organizational measures to protect your information. However, no method of transmission over the Internet is 100% secure.

10. Changes to This Policy

We may update this Privacy Policy periodically. The "Last Updated" date at the top indicates when the policy was last revised. Continued use of the service after changes constitutes acceptance.

11. Contact Us

For questions about this Privacy Policy, contact us at: @mustbesimo on Twitter/X

12. GDPR Compliance (EU Users)

For users in the European Union:

  • Legal Basis: Processing is based on your explicit consent.
  • Data Controller: Simone Leonelli (@mustbesimo)
  • Right to Withdraw: You can withdraw consent at any time by not using the service.

13. CCPA Compliance (California Users)

For California residents:

  • We do NOT sell your personal information.
  • We do NOT persistently store your personal information. Photos are processed in memory only.
  • You have the right to know what data we process (see Section 2).
  • You have the right to request deletion - though we already don't store your data beyond temporary processing.