Privacy Policy
Effective 17 September 2026. This policy covers the iOS app HMD Studio AI ("Studio AI") and the service behind it, both operated by Half Moon Digital SL, Spain ("we").
The short version
Studio AI edits and creates images. To do that, the photos you pick and the words you type are sent to our server and processed there or by an AI service we use on your behalf. We have no accounts, no advertising, no analytics SDKs, no tracking, and we do not sell or share data for anyone else's purposes. Results are visible only on the device that created them.
What we receive and why
- A name and a device identifier. The name you type on the welcome screen and a random identifier the app creates, so your device can be recognised by our server. No email, phone number or account.
- Photos. If you allow access to your photo library, the app sends our server a list of your photos with small thumbnails, and full-resolution copies of the photos you pick for editing (or that the operator requests to prepare an edit). This is what lets you edit your own photos from the app. Photos are stored on our server in the EU, belong to your device only, and can be removed per photo or all at once from the operator's console.
- Prompts and results. The text you type and the images generated from it are kept in your history on our server so the app can show them to you, and can be deleted from the app.
- Usage events. The app records which screens and buttons you used and how long generations took, tied to the device identifier, so the operator can fix problems. No third-party analytics.
- Device details such as iOS version, app version and battery state, sent with the sync so the operator can see that the app is working.
Where processing happens
- Our server, operated by Half Moon Digital SL on Hetzner Cloud in the European Union: receives everything above, stores photos, prompts, results and events.
- GPU computing rented from RunPod (data centres in the EU and the United States), where our own image-model software runs. Photos and prompts for a generation are sent there and are not kept after the result is produced.
- Google's Gemini API, for devices configured to use our content-filtered engine: the photo and the prompt of a generation are sent to Google, which produces the image and applies its own content safety filters. Google's API terms and privacy notice apply to that processing; we do not send names or identifiers with the request.
- Cloudflare for DNS and transport security in front of our servers.
Content rules
Devices configured with the content filter can only use the filtered engine, which refuses adult, violent, hateful and dangerous content and anything involving minors; a refused request returns a black image saying so. Operators may block a device.
Retention and your rights
Photos, results and events stay until you or the operator delete them; deleting a photo in the operator's console also excludes it from future syncs. To have all data about your device removed, ask the operator to revoke the device, which deletes its photos, results and events, and delete the app. Contact: info@halfmoondigital.com.
Permissions the app asks for
- Photos: optional. Text-to-image works without it. If granted, the library is prepared on our server as described above; you can allow only selected photos.
Contact
Half Moon Digital SL · info@halfmoondigital.com. Changes to this policy will be posted at this address.
