BOPINK Privacy Policy & GDPR Data Rights
Information on data collection, encrypted selfie storage, automatic image purge cycles, GDPR compliance, and user privacy protection on BOPINK (bop.ink).
Privacy Policy & GDPR Compliance
Last updated & effective: July 25, 2026
1. Data Controller Declaration
BOPINK (accessible at https://bop.ink) acts as the Data Controller responsible for safeguarding personal data collected during your use of our AI portrait generation platform.
Our Data Protection Officer can be reached directly for inquiries or deletion requests at [email protected].
2. Categories of Information We Collect
A. Authentication & Profile Data
Email address, profile display name, avatar, and unique user identifiers provided via Google SSO or email registration.
B. Source Selfies & Input Media
Facial photographs uploaded strictly for AI zero-shot face-swapping algorithms. Source selfies are encrypted in transit via SSL/TLS 1.3 and stored in isolated cloud buckets.
C. Analytics & Feed Interaction Logs
To power our personalized feed algorithms, we temporarily record up to 20 recent interaction events (views, likes, hashtag filters). Older events are automatically purged.
3. Strict Source Photo Retention & Immediate Automatic Purge Policy
We operate under a strict principle of data minimization and privacy protection:
- Third-Party Consent Verification: Users are strictly prohibited from uploading photos of third parties without prior consent. You must own or hold explicit permission for any face reference image uploaded.
- Immediate Automatic Purge: All uploaded source reference selfies and input media used to generate AI face-swap portraits are automatically deleted from active server storage files immediately after AI processing and image rendering are completed.
- No Biometric Sale: We do NOT extract, store, or sell facial biometric signatures to any third parties or advertising networks.
- User Deletion Control: You can delete any uploaded photo or generated output from your account profile at any time with instant 1-tap removal.
4. Legal Bases for Processing Under GDPR
We process your personal information under the following legal bases recognized by the EU General Data Protection Regulation:
- Contract Performance: Delivering requested AI portrait generations, credit balances, and creator earnings payouts.
- Explicit User Consent: Processing source selfies you voluntarily upload for visual face swapping.
- Legitimate Interest: Preventing fraud, bot abuse, and maintaining platform infrastructure security.
5. Your Full Rights Under GDPR
As a global user, you enjoy comprehensive control over your personal data:
6. Privacy Officer Contact
To exercise any GDPR data right or submit a privacy query, contact our team:
Email: [email protected]