Privacy Policy
Our Commitment
idori is offered by Ess X LLC. We believe creative tools should be transparent about how they handle your data. This policy explains exactly what we collect, why we collect it, and who processes it.
Introduction
idori ("we," "our," or "the App") is committed to protecting your privacy. This Privacy Policy explains how we handle information when you use our iOS application.
In short: We collect only what's needed to deliver the service. Your design projects stay on your device. Uploaded photos are used only during generation and are not stored on our end.
Data Collection
What We Collect
We collect the minimum data necessary to provide the idori service:
- Authentication identifiers - Anonymous ID, Apple ID, or Google account identifier used for sign-in via Firebase Auth
- Purchase metadata - Subscription status and credit balance, processed through RevenueCat and Apple's App Store
- Generation payloads - Uploaded photos, text prompts, spot coordinates, and optional reference photos you submit for AI redesign, sent to our backend for processing
What We Don't Collect
- Behavioral analytics or usage profiling
- Location data
- Contacts, calendars, or other personal data
- Cookies or similar tracking technologies
How Your Data is Processed
Authentication
You can sign in anonymously or with your Apple or Google account via Firebase Auth. Authentication identifiers are used solely to:
- Identify your account for credit and subscription management
- Enable purchase restoration across devices
We do not use authentication data for marketing, profiling, or advertising purposes.
AI Decoration
When you submit a photo and prompt for redesign:
- Your uploaded photos, prompt, and spot coordinates are sent to our backend server
- Our backend uses OpenRouter to generate the decoration output
- The generated image is returned to your device
- Uploaded photos, prompts, and spot coordinates are used only for the generation request and are not stored on our end
- Your project history, versions, and generated results are stored locally on your device
Billing and Credits
Subscription and credit status are validated server-side to ensure accurate entitlement. Payment processing is handled entirely by Apple through the App Store. We never see or store your payment details.
On-Device Storage
Your design projects, iteration history, and generated images are stored locally on your device. This data is not uploaded to our servers or shared with third parties.
Third-Party Services
We use the following third-party services to deliver the idori experience:
Firebase Auth (Authentication)
RevenueCat (Billing & Subscriptions)
- Manages subscription entitlements and consumable credit packs
- Processes purchase receipts and subscription status
- Does not track app usage or behavior
- Payment is handled entirely by Apple
- Privacy policy: revenuecat.com/privacy
OpenRouter (AI Decoration Infrastructure)
- Processes uploaded photos and prompts to generate redesign outputs
- Accessed through our backend; your device does not communicate with OpenRouter directly
- We use enterprise-tier billing with AI training explicitly disabled
- Under our premium plan with training opted out, OpenRouter does not retain your input data or generated outputs
- Your content is never used to train AI models
- Privacy policy: openrouter.ai/privacy
Services We Don't Use
- Behavioral analytics providers
- Social media tracking integrations
- Crash reporting services that collect personal data
Data Security
We take appropriate measures to protect your data:
- All communication between the app and our backend uses encrypted connections (HTTPS/TLS)
- Authentication is handled by Firebase's enterprise-grade security infrastructure
- Project data stored on your device is protected by iOS built-in security features, your device passcode/biometric authentication, and app sandbox isolation
- We do not store your uploaded photos or generated designs on our servers beyond the time needed to complete a generation request
Data Retention and Deletion
Server-Side Data
Generation payloads (uploaded photos, prompts, and spot coordinates) are processed in real-time and are not retained on our servers after the generation is complete. Authentication identifiers and subscription status are retained as long as your account exists.
On-Device Data
You can delete your project data at any time by:
- Deleting individual projects within the app
- Deleting the app to remove all local data
Account Deletion
You can delete your account and all associated server-side data directly from the app by going to Settings > Delete Account. This action is immediate and permanent. You can also contact support@idori.app if you need assistance.
Children's Privacy
idori is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information promptly.
Your Privacy Rights
Permission Management
You can manage app permissions at any time through:
- iOS Settings > idori
- iOS Settings > Privacy (for Camera and Photo Library access)
Compliance
GDPR (European Union)
We process personal data based on legitimate interest (service delivery) and consent (account creation). You have the right to access, correct, delete, and port your data. You can delete your account directly from Settings > Delete Account, or contact us for other requests.
CCPA (California)
We do not sell personal information. California residents have the right to know what data we collect and to request its deletion. You can delete your account directly from Settings > Delete Account, or contact us for other requests.
Other Regulations
We comply with applicable privacy regulations worldwide, including but not limited to:
- Brazil's LGPD (Lei Geral de Proteção de Dados)
- Canada's PIPEDA (Personal Information Protection and Electronic Documents Act)
- Australia's Privacy Act
- Japan's APPI (Act on the Protection of Personal Information)
Cross-Border Transfers
Your data may be processed in jurisdictions outside your country of residence, including the United States, where our servers and third-party service providers operate. We ensure appropriate safeguards are in place for such transfers in accordance with applicable data protection laws.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be reflected by updating the "Last Updated" date at the top of this policy.
We will notify users of significant changes through:
- An in-app notification
- App Store update notes
Continued use of the App after changes constitutes acceptance of the updated policy.
Contact Us
What idori Does
- Generates AI-powered interior and exterior decorations from your space photos
- Provides a one-screen iterative design workspace with precision Spot Edit
- Stores your projects and version history locally on your device
- Processes uploaded photos through secure backend AI infrastructure
- Manages subscriptions and credits through Apple's App Store and RevenueCat
What idori Doesn't Do
- Track you with advertising SDKs
- Personalize ads based on your behavior
- Store your uploaded photos or designs on our servers permanently
- Share your design projects with third parties
- Sell your personal information
- Use your content to train AI models
Transparent by Design
We built idori to keep your creative work yours. Projects stay on your device. We use trusted providers for authentication and billing. No ad tracking SDKs. Clear subscription controls through your Apple ID account settings.