Skip to main content
Kindler Dev

App · iPhone, iPad and Mac

EngraveKit — Privacy Policy

Last updated: 2026-09-29

EngraveKit processes your images on your device. For credits and purchases, the app creates an anonymous account with no name, no email address and no login. An image only leaves your device if you use an AI style and have explicitly agreed to it beforehand. The app contains no analytics, no tracking, no advertising identifiers and no third-party SDKs.

Controller

Björn Kindler
Kindler Dev
Bischofshofener Str. 9
82008 Unterhaching, Germany
Phone: +49 89 62084444
Email: info@kindler-dev.de

What stays on your device

Import, subject cut-out (Apple Vision), depth estimation (Core ML), tone, dithering, vectorisation and export run entirely on your device, without a server. These images never leave your device. You can use every on-device feature without giving consent. Exported files go only where you save or share them.

Anonymous account

On first launch, the app creates an account through my server, consisting of a random ID (UUID) and a random secret (256 bits). Both are stored in your device's keychain with iCloud sync; Apple syncs them to the devices signed in with the same Apple ID. The server stores the account ID, a SHA-256 hash of the secret, the platform (iOS or macOS) and the time of creation. There is no name, no email address and no login.

Balance (credits)

The server keeps your balance as a ledger. Each entry (free credits, purchase, hold, release, correction) contains the account ID, amount, reference and time. Entries are only appended, never changed afterwards.

Purchases and restore

Payment is handled exclusively by Apple (App Store). I do not receive any payment details. After a purchase, the app sends the transaction signed by Apple to my server. The server stores the transaction ID, original transaction ID, product, environment (sandbox or production), credits, refund status and signing date, linked to your account ID. For this, the account ID is passed to Apple as the appAccountToken when you buy.

Apple sends my server notifications about purchases, for example about refunds. The server stores their ID, type, subtype and time of receipt.

With “Restore Purchases”, the app sends a signed purchase transaction to the server. The server uses it to restore access to your account.

Payment itself, your Apple account and purchase processing are subject to Apple's privacy policy.

Abuse protection

To make sure free credits are granted only once per device, the app uses Apple DeviceCheck. The app sends a DeviceCheck token to my server. The server uses it to query and set two device-related bits at Apple. The token is not stored. As long as DeviceCheck is not active, a daily quota of free accounts applies instead.

For rate limits, the server uses your IP address only as a salted HMAC-SHA-256 hash in short-lived counters. These entries are deleted once the time window has passed.

AI styles

You can use the AI styles only after giving explicit consent. The app asks for it in a dialog before the first upload. You can withdraw your consent in the settings; the on-device features are not affected.

Only the selected image is transferred, scaled down and encrypted via TLS, to my serverengravekit-api.kindler-dev.de. The server passes it on to the Google Gemini API (model Gemini 3.1 Flash Image, paid tier) and returns the result to the app.

My server keeps the input and result images in memory only. It never writes them to disk and never to a log. The result stays in memory for at most 10 minutes so that the app can fetch it again if the connection drops. For each job, the server stores only the account ID, style, size, credits, status, cost and timestamps. This job data is deleted automatically 90 days after the job has finished.

Result images from Gemini carry an invisible SynthID watermark from Google.

Google as recipient

The contracting party for the Gemini API is Google Cloud EMEA Limited, Ireland. Under the Gemini API terms, the paid tier is governed by Google's Data Processing Addendum, under which Google acts as a data processor. In the paid tier, Google does not use prompts or responses to improve its products. Google logs them for a limited period solely to detect and prevent violations of its Prohibited Use Policy; according to Google, this period is 55 days. Within this scope, authorised Google employees may review the data.

Google may process the data in any country where Google or its agents maintain facilities, including the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework; the Data Processing Addendum additionally provides Standard Contractual Clauses for transfers outside the EEA. More information:ai.google.dev/gemini-api/terms.

Server and logs

The server engravekit-api.kindler-dev.de is hosted by Hetzner Online GmbH in its Nuremberg data centre. For hosting with Hetzner, see section 2 of the website privacy policy.

The server's system log (journald) records, per request, the method, path, status, duration and the first 8 characters of the account ID. Error messages contain no image content. The Caddy web server keeps no access logs for this domain. This service's log is kept separately and deleted automatically after 30 days. IDs of Apple's server notifications are deleted after 180 days.

Backups

The database (accounts, ledger, transactions, jobs; no images) is backed up daily to Hetzner Object Storage in Germany. Daily backups are deleted after 7 days, weekly backups after 28 days and monthly backups after 180 days. Deleted data therefore leaves the backups no later than 180 days afterwards.

Deleting your account

You can delete your account in the app. This deactivates the account and deletes the hash of the secret; the account cannot be restored afterwards. Any remaining credits are forfeited, and the app warns you beforehand. The ledger and transactions remain under the random account ID so that refunds can be matched and abuse protection keeps working. They contain no other personal data. Three years after the deletion, the account, its ledger, transactions and job data are deleted completely.

Legal bases

  • Art. 6 (1)(b) GDPR: account, balance, purchases and carrying out the AI style you request.
  • Art. 6 (1)(a) GDPR: your consent to transferring the image to Google.
  • Art. 6 (1)(f) GDPR: abuse protection, rate limits and server logs. My legitimate interest is secure operation and protecting the free credits against abuse.

What the app does not do

  • No analytics, no tracking.
  • No advertising identifiers.
  • No third-party SDKs.
  • No storage of your images on my server's disk.

Notifications that inform me about the service's cost limits (via Pushover) contain no personal data.

Your rights

You have the right at any time:

  • to information about the data stored about you (Art. 15 GDPR),
  • to rectification of inaccurate data (Art. 16 GDPR),
  • to erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR),
  • to data portability (Art. 20 GDPR),
  • to object to processing (Art. 21 GDPR) where processing is based on Art. 6 (1)(f) GDPR,
  • to withdraw any consent given, with effect for the future (Art. 7 (3) GDPR),
  • to lodge a complaint with a supervisory authority; the authority responsible for me is the Bavarian State Office for Data Protection Supervision (BayLDA), Ansbach.

To exercise your rights or for any data protection questions, please use the contact details under “Controller” above.

As the account has no name or email address, please include the account ID shown in the app (Settings, section “Account”) so that I can match your request to the right account.

Changes to this policy

Updates will be posted on this page with a revised "Last updated" date.

See also: website privacy policy