Privacy Policy
Scevia · Last updated 24 September 2026
This policy explains what Scevia collects, why, and what you can do about it. It describes how the app actually behaves — not a generic template.
1. What we collect
If you use Scevia as a guest
You can browse and use the app without an account. In guest mode we store a random device identifier in the iOS Keychain. We use it for one purpose: to make sure the free welcome credits can only be claimed once per device. It is not linked to your name, email or Apple ID.
If you create an account
- Email address — from email sign-up, or from Apple/Google if you use those buttons.
- Display name — the name you type at sign-up, or the one Apple/Google provides.
- A user ID we generate.
If you sign in with Apple and choose Hide My Email, we only ever receive Apple's relay address. We never see your real one.
What you create
- The prompts you write or generate.
- The images and videos you generate, and any photos or videos you upload to edit or animate.
- Your generation history and favourites.
Purchases and credits
- Your credit balance and the record of every credit added or spent.
- Purchase confirmations from Apple (product purchased, transaction identifier, amount, currency).
We never see your payment details. Card numbers, Apple ID password and billing address are handled entirely by Apple and are never sent to us.
Notifications
If you allow notifications, Apple issues your device a push token. We store it with your account, along with your app language and your device's time zone.
- The token — so we can reach the device.
- Your language — so the message is written in the language you use the app in.
- Your time zone — so a promotional message arrives at a reasonable hour where you are, rather than in the middle of your night.
We use notifications for two things: telling you that a generation you started has finished, and — only while the promotional switches are on in Settings → Notifications inside the app — telling you about new templates, at most three times a day. You can turn the promotional ones off there at any time without affecting the rest; you can also switch notifications off entirely in iOS Settings.
Diagnostics
Error and crash information, app version, device model and iOS version, so we can find and fix faults.
2. Why we process it
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running your account | Performance of a contract |
| Generating images and video you request | Performance of a contract |
| Tracking and charging credits, processing purchases | Performance of a contract |
| Preventing repeat claims of free credits and other abuse | Legitimate interest |
| Telling you a generation you started has finished | Performance of a contract |
| Sending promotional notifications about new templates | Consent (the switches in Settings → Notifications) |
| Diagnosing crashes and errors | Legitimate interest |
| Keeping purchase records | Legal obligation |
We do not sell your data, we do not share it with advertisers, and we do not use it to build advertising profiles. Scevia contains no advertising SDK.
3. Who else processes your data
To run the app we pass certain data to the following providers. Each acts on our instructions.
| Provider | What it receives | Policy |
|---|---|---|
| Supabase | Account, credits, generation history, uploaded and generated media | supabase.com/privacy |
| Fal.ai | Your prompt and any image or video you submit, in order to generate the result | fal.ai/privacy |
| Anthropic | What you give the Prompt Assistant — the rough idea you type, and the photo you add if you choose to add one | anthropic.com/legal/privacy |
| Fly.io | Hosts the server that forwards generation requests | fly.io/legal/privacy-policy |
| Adapty | Purchase and subscription events | adapty.io/privacy |
| Apple | Handles all payments; we receive only the confirmation. Apple also delivers push notifications to your device and issues the token we send them to. | apple.com/legal/privacy |
About the Prompt Assistant. When you ask it for help, what you gave it is sent to Anthropic's API: the text you typed, and — only if you added one — the photo. Photos are scaled down before they are sent, are used solely to produce that one answer, and are not stored by us. Your account identity is not sent with either. Anthropic does not use API inputs to train its models. If you would rather nothing leave the app for this purpose, simply don't use the assistant — every other part of Scevia works without it.
4. Where your data is stored
Our database and file storage run in Paris, France (EU). Our request-forwarding server runs in Frankfurt, Germany (EU). Generation providers may process your prompt and media outside the EU, including in the United States, under the safeguards described in their own policies.
5. Security
- Everything is transmitted over HTTPS/TLS.
- Database rows are protected by row-level security, so one account cannot read another's data.
- Your credit balance can only be changed by our servers. The app cannot write to it.
- Purchases are confirmed server-to-server with Apple through Adapty, and each transaction is recorded once so a purchase cannot be replayed.
- No API keys for any generation provider are stored in the app.
6. How long we keep it
- Account and generated content — while your account exists.
- Purchase records — retained after deletion where tax and accounting law requires it.
- Diagnostics — short-lived, typically weeks.
- Guest device identifier — kept so the welcome credit cannot be claimed twice.
- Push token, language and time zone — while the app is installed. Deleted when Apple tells us the device can no longer be reached, and when you delete your account.
7. Deleting your account
Open Profile → Settings → Privacy → Delete Account. This is immediate and permanent. It removes your profile, generations, uploaded media, credit history and the sign-in record itself. Any unused credits are lost and are not refundable. We cannot restore a deleted account.
8. Your rights
You can ask us to give you a copy of your data, correct it, delete it, or restrict how we use it. You can object to processing we base on legitimate interest. Write to the address in section 11 and we will respond within 30 days. If you are in the EU or UK and are not satisfied, you may complain to your national data protection authority.
9. Children
Scevia is not intended for children. You must be 13 or older to use it, and older if the law where you live sets a higher age for consent to online services. We do not knowingly collect data from children below that age. If you believe a child has given us data, contact us and we will delete it.
10. AI-generated content
Everything Scevia produces is generated by artificial intelligence. Output can be inaccurate, unexpected, or unsuitable for a given purpose, and may be subject to third-party rights. You are responsible for what you generate and for how you use it.
11. Contact
Email: info@gudertech.co
Scevia is operated from Türkiye. Write to us at the address above for any privacy request, including data access and deletion.
12. Changes
If this policy changes we will update the date at the top of this page, and tell you in the app if the change is significant.