1Who is responsible
Wisnu Nugroho, an individual trading as TarsiLabs (tarsilabs.com), is the controller of your personal data. Based in: Klaten, Central Java, Indonesia. Privacy contact: support@tarsilabs.com.
This policy follows Indonesia’s Personal Data Protection Law (UU No. 27 Tahun 2022) and, for visitors from the EU and the UK, the GDPR and the UK GDPR.
2What we collect and why
| Data | Why | Legal basis |
|---|---|---|
| Email address, and a normalised form of it (lowercase, without +tags or Gmail dots) | Your account and sign-in links; service messages (receipts come from Paddle); one set of free pictures per inbox | Contract; legitimate interest (preventing abuse of the free pictures) |
| Google account identifier (only if you sign in with Google) | Signing you in with Google. We keep your Google account id and email address, not your name or photo | Contract |
| Pictures you upload, their previews, the results and the edits you save | To make, show and deliver your results | Contract |
| Usage records (pictures with their file names, sizes, times and status; unlocks, downloads, balance) | Your balance, daily limits and fair use, support, preventing abuse | Contract, legitimate interest |
| Messages you send us (address, subject, message, the picture you name, a keyed hash of your IP address) | Answering you; limiting spam | Legitimate interest; contract when it is about your account |
| Your rating of a result (thumbs up or down) and the optional note you add | Learning where our results fall short, and improving them | Legitimate interest; consent for keeping a picture longer (below) |
| Where your first visit came from, kept with your account: the campaign tag in the link you followed, the name of the referring site (never its full address) and the first page you opened (without its address’s query) | Learning which channels bring us users. We read it ourselves: no tracker, no third-party cookie, no advertising network. When you buy, we also pass the campaign tag and the name of the referring site to our payment provider (Paddle) with the order, for its sales reports | Legitimate interest |
| Your country, as a two-letter code: when you sign up, the one Cloudflare reports for your connection; when you pay, the one of the billing address you give Paddle. We never store your IP address with it | Knowing where our users and customers are (prices, languages, taxes) | Legitimate interest |
| Page counts of this website: per day, page and where the visit came from (a campaign tag, the referring site’s name). No IP address, no cookie and nothing that tells one visitor from another | Seeing which pages and channels work | Legitimate interest |
| Technical data (IP address, browser, error logs) | Security, rate limits, keeping the service running | Legitimate interest |
| Purchase records (product, amount, currency, the payment provider’s payment and subscription ids) | Your balance and plan; accounting | Contract; legal obligation |
| Your place on the waitlist before TarsiLabs opens: your email address and its normalised form, what you would use TarsiLabs for, the page you signed up on, and where your visit came from: the campaign tag in the link you followed, the name of the referring site (never its full address) and the first page you opened (without its address’s query), when you agreed and when you confirmed | A confirmation mail, then mails about the opening of TarsiLabs only | Consent: you tick the box and confirm it from the mail; you can withdraw it at any time |
| Feedback you send from the website: your message and the page, and, if you give them, your email address and what you would use TarsiLabs for | Reading your criticism and suggestions; answering you if you left an address | Legitimate interest |
| Your answer about our prices (what you think of them, the plan, what you would pay, a comment) | Setting fair prices. Anonymous: we don’t ask for your address and keep no IP address with it; deleted after 24 months | Legitimate interest |
Paddle, our merchant of record, collects your payment and billing details itself; we never see your card. We don’t sell your data or show ads, and we don’t use customers’ pictures or results to train our models or any other model.
3How long we keep it
- Uploaded pictures, and the files we make from them while processing: deleted 24 hours after upload, on every plan.
- Previews and results you have not unlocked: deleted after 7 days. A short record that the picture existed (its time and status) stays with your usage records.
- Unlocked results (the SVG, its preview and the edits you saved): kept while your account exists, until you delete the picture or the account.
- Your rating and note are stored with the picture and go when it goes. A picture you rate thumbs-down is kept longer for our quality review only if you tick “you may use this picture to improve results”; otherwise the times above apply. With that consent we use the picture only as a test case to check and fix our results, never to train a model, and we delete it after 180 days or once the fault is fixed, whichever comes first. You can withdraw that consent, or delete the picture, at any time.
- Where your first visit came from and your sign-up country: kept with your account, and deleted with it. The website’s page counts hold no personal data and are kept as statistics.
- Deleting a picture removes its files at once. If you kept it, the record that it used a picture stays in your history, without the picture or its name.
- Sign-in links: deleted a day after they expire. Sessions: at most 30 days.
- Messages you send us: kept as support correspondence for 24 months after you send them, also after you delete your account.
- Account data and usage records: while your account exists. When you delete your account we delete your sessions, sign-in links, pictures and results at once and remove your email address from the account. We keep: the record of purchases, kept pictures and refunds, under an anonymous account number, for as long as tax and accounting law requires; and a keyed hash of the normalised form of your address (not the address itself), so that a new account of the same inbox gets no new free pictures, for 24 months. Paddle keeps its own tax records.
- Waitlist: an address that is not confirmed is deleted 30 days after the first confirmation mail. A confirmed address is kept until you unsubscribe (every waitlist mail links to a page that deletes it with one click) or ask us to delete it at support@tarsilabs.com, and at most 12 months after TarsiLabs opens.
- Feedback from the website’s form: 24 months, like messages you send us; write to support@tarsilabs.com to have it deleted sooner. For their rate limits the waitlist and feedback forms and the price question keep a keyed hash of your IP address, never the address itself, and delete it within about a day (at most 25 hours). Deleted entries of the waitlist, the feedback form and the price question can still be restored from Cloudflare’s database history (D1 Time Travel) or from our weekly backups (kept on our own computer in Indonesia) for up to 30 days, and are gone after that.
- Server logs: at most 30 days.
- Backups of the database (accounts and records): one a day; the newest 14 are kept, on our server and in Cloudflare’s storage. Before each update of the service we also save a copy of the database on our server, and keep the newest five of those. Each night we also copy the result files (the SVG, its preview and the edits you saved) to Cloudflare’s storage, so a result you unlocked survives a failure of our server; a file deleted on our server, by you or by the times above, leaves that copy the next night. Uploaded pictures are never in a backup.
4Who processes data for us
| Processor | Purpose | Location |
|---|---|---|
| Our server provider in the EU, named here before the app opens | Hosting, storage and the database of the app (accounts, pictures, results) | EU |
| Cloudflare, Inc. | Hosting this website (Cloudflare Pages and Workers) and the database of the waitlist, the feedback form and the price question (Cloudflare D1, kept in the EU); network and security; the bot check (Turnstile) on sign-in, the contact form, the waitlist, the feedback form and the price question; backup storage; forwarding mail sent to our addresses to our inbox (Email Routing) | Global / USA |
| Resend, Inc. | Sending sign-in links, service emails and the waitlist’s mails; forwarding contact messages and feedback to our inbox, and a daily summary to our inbox (the feedback in full, the price answers, and the waitlist as counts only, without addresses) | USA |
| Google LLC (Gmail) | Our support inbox, where your messages arrive (Cloudflare Email Routing forwards mail sent to our addresses there) | USA |
Independent controllers. Paddle.com Market Ltd (UK) sells you the pass and the plans as our merchant of record and handles payment, tax and invoices under its own privacy notice. If you sign in with Google, Google (Google LLC; in the EU and the UK, Google Ireland Limited) handles that sign-in under its own privacy policy.
Some of these providers are outside Indonesia, the EU and the UK. For these transfers we rely on an adequacy decision or the EU-US Data Privacy Framework where it applies, otherwise on the providers’ data processing agreements with standard contractual clauses, and on the safeguards UU PDP Article 56 requires.
6Your rights
You can ask us to:
- give you access to your data or a copy of it;
- correct it;
- delete it: your account page has a Delete account button, and every picture can be deleted on its own;
- give you your data in a common machine-readable format;
- restrict or object to processing;
- withdraw consent where we rely on consent.
Write to support@tarsilabs.com. We act on requests to see or correct your data, and stop processing after you withdraw consent, within 3 × 24 hours where UU PDP requires it, and answer any other request within one month. You can also complain to the data protection authority in Indonesia or, in the EU or the UK, where you live.
7Security
- Connections use HTTPS.
- Sign-in links and session tokens are stored hashed.
- Uploads are stored on servers only we can reach, are deleted as described above, and every time we open one for support it is recorded.
- If a breach affects your data, we tell you and the authorities as the law requires (UU PDP: within 3 × 24 hours).
8Children
TarsiLabs is not meant for children under 16; users aged 16 or 17 need a parent’s or guardian’s permission. We don’t knowingly collect children’s data.
9Changes
We announce material changes on tarsilabs.com or by email before they apply.
10Language of this policy
This policy is published in English and in Indonesian (Bahasa Indonesia), and both versions are equal in meaning. For users in Indonesia the Indonesian version is the valid and binding one, as Indonesian law requires (Law No. 24 of 2009, Article 31); for everyone else the English version is the main one. If the two versions are ever read differently, the Indonesian version prevails for users in Indonesia.
Questions about this page? Write to support@tarsilabs.com.