Vequo Privacy Policy
Effective date: 9 August 2026
Last updated: 17 August 2026
Vequo is operated by Vequo Pty Ltd (ACN 700 743 719, ABN 84 700 743 719), of 905/50 Lorimer Street, Docklands VIC 3008, Australia (Vequo, we, us, or our).
This Privacy Policy explains how we handle personal information when you use the Vequo mobile application, visit vequo.app, contact us, or otherwise use our related services (together, the Service).
Contact us about privacy at hello@vequo.app.
1. The short version
- Your Vequo design library, edit history, and image files are stored primarily in Vequo’s private storage on your device. Vequo does not provide cloud backup or cloud syncing of your design library.
- Vequo does not scan or upload your entire photo library. When you ask Vequo to generate an edit, it sends the image you selected, the edit instructions you supplied, and any selected reference content to our backend and our production AI service provider, Google Cloud Vertex AI.
- Those images are held in Vequo’s private cloud storage only for as long as the edit needs them. Vequo deletes the uploaded image and the stored edit request as soon as the generation finishes, and deletes the generated image once your device confirms it has the result.
- We do not use your images, prompts, or generated images to train our own AI models. Under Google Cloud’s current terms, Google does not use Vertex AI customer data to train or fine-tune AI models without the customer’s prior permission or instruction.
- We use pseudonymous account and device information to provide credits, purchases, account recovery, security, and fraud prevention. You may use Vequo with an anonymous device-linked account and can optionally secure purchases using Apple or Google sign-in.
- We use PostHog EU Cloud for limited, pseudonymous product analytics and error diagnostics. Vequo records basic app and device context, normalised screen views, selected feature outcomes, and crash information, but does not identify your Vequo account to PostHog. Session recording, broad touch autocapture, console-log collection, and geographic enrichment are disabled.
- Apple or Google processes payments. We do not receive or store your complete payment-card details.
- If you choose to watch rewarded ads, Unity LevelPlay and the ad networks it mediates may process advertising identifiers, approximate location, device and SDK diagnostic information, ad interactions, and purchase history for advertising and analytics. We do not share your photos, prompts, or generated designs with advertising providers.
2. Information we handle
Images and edit content
We handle:
- images you select from your photo library or take with your camera;
- generated images and the relationships between versions in a design;
- brush strokes, highlighted regions, position markers, selected colours, textures, makeover choices, and similar edit instructions;
- reference images and optional descriptions or extra instructions you provide; and
- technical information about the image Vequo prepares from your selection, such as file type, dimensions, byte size, and a checksum used to verify that the upload arrived intact.
We use this information to save your designs locally, prepare the requested edit, send the generation request, return the generated result, troubleshoot a generation failure, and protect the Service from misuse.
When you add a photo to a design, Vequo re-encodes it on your device before saving or uploading it. That drops metadata embedded in the original file, including EXIF camera and location tags, so this metadata is not sent to Vequo or to the AI provider. The image itself may still reveal personal information, people, objects, or location clues, so review what is visible before submitting it.
To generate an edit, the app uploads the image files to Vequo’s private cloud storage bucket and the backend stores the accompanying edit request there. Section 4 explains that path, and section 8 explains how long each item is kept.
Vequo requests access to your camera or photo library only when needed for a feature you choose. You can change those permissions in your device settings. Vequo does not intentionally request precise location metadata from your photo library.
Account and sign-in information
Vequo creates an anonymous Firebase account and assigns random Vequo and Firebase identifiers. We also keep account information such as:
- platform type;
- credit balance and credit transactions;
- plan and entitlement status;
- account creation time;
- whether the account has been linked to a sign-in provider; and
- limited rewarded-ad progress and event identifiers used to verify and deduplicate rewards.
If you choose to secure or recover an account using Sign in with Apple or Google Sign-In, Firebase Authentication and the chosen provider may process a provider identifier, email address, display name, a profile-photo URL when the provider supplies one, and authentication tokens. Vequo’s small Firestore account record stores the account link and a provider-linked status; the authentication provider information is managed through Firebase Authentication.
Device, network, and security information
We and our infrastructure providers may process:
- IP address, request time, request route, response status, user-agent and similar server-log information;
- app version, operating system, device model or manufacturer, language, region, connection type, and SDK version;
- Firebase App Check, Apple App Attest or DeviceCheck, and Google Play Integrity attestation information;
- on Android, an app-scoped Android identifier used to prevent repeated one-time promotional grants; Vequo sends it to our backend over HTTPS and stores only a keyed HMAC hash of it; and
- on Apple devices, an ephemeral DeviceCheck token and a one-bit promotional-grant state maintained by Apple for Vequo.
We use this information to authenticate requests, rate-limit traffic, keep the Service secure, diagnose failures, prevent fraudulent credit claims, and maintain reliability.
Product analytics and error diagnostics
Vequo uses PostHog EU Cloud to understand whether core features work, improve the app, and diagnose crashes. The app sends:
- a random analytics identifier generated and stored by the PostHog SDK, which is not the Vequo account identifier, Firebase identifier, RevenueCat App User ID, or advertising identifier;
- app lifecycle events, normalised screen names, and deliberately selected feature events, such as creating a design, selecting and submitting an edit, the tool and tool mode used, the type of selection used, generation outcomes, version comparison, export outcomes, paywall views, purchase outcomes, and rewarded-ad outcomes;
- limited properties attached to those events, such as the app environment, plan category, edit resolution, makeover identifier, built-in texture identifier, and whether optional instructions were present; and
- app version and build, operating system, device type or model, SDK information, and uncaught JavaScript errors, unhandled promise rejections, native crash reports, stack traces, and limited event breadcrumbs used to diagnose an error.
Our deliberately selected product events are designed not to send PostHog your photos, generated images, reference images, prompts or instruction text, masks, brush strokes, marker coordinates, selected colour values, image or request URLs, design identifiers, edit-job identifiers, account identifiers, or purchase identifiers. Error reports separately include technical error messages and stack-frame module or file names needed for diagnosis; they are not intended to include your design content. We disable session recording, broad touch autocapture, console-log collection, user profiles, and IP-based geographic enrichment. Like any internet service receiving an app request, PostHog processes the source IP address needed for the network connection.
Purchase and subscription information
Apple App Store or Google Play processes your purchase and payment. Vequo and RevenueCat receive information needed to validate and fulfil the purchase, such as product identifier, store, transaction or purchase identifier, purchase time, subscription entitlement, expiry status, and a pseudonymous RevenueCat App User ID derived from your random Vequo account identifier. We use it to grant credits, provide plan features, restore purchases, prevent duplicate fulfilment, and handle support.
Before opening a store purchase screen, the app temporarily saves one account-scoped billing-sync marker in protected local storage. It can contain the pseudonymous Vequo account identifier, a random client request and server purchase-intent identifier, logical and store product identifiers, optional source product, purchase phase, and an optional store callback transaction identifier. The server intent—not the client callback—controls settlement after interruption or restart and prevents a second purchase screen while the result is unresolved.
Purchase restoration uses a separate protected marker containing the account, random client request and server restore identifiers, store, and restore phase. The server guard remains authoritative if the app closes after native restore begins; background recovery checks it but never starts another native restore automatically.
If a store confirms that a purchase was refunded, Vequo removes the related plan access and corrects credits tied to that purchase. When those credits have already been used, the account can hold a nonnegative credit-debt amount while the displayed credit balance remains at zero. Credits later earned or purchased for that account are applied to that amount before increasing the displayed balance. A live source account keeps its historical balance and debt after a provider transfer. Only debt retained for a deleted billing account may follow a successor that RevenueCat and the stores authenticate. A verified refund reversal restores the appropriate value once.
To prevent double fulfilment and apply verified refunds, Vequo keeps limited pseudonymous billing records under keyed HMAC identifiers. They can include logical products and entitlements, credit values, allocation/refund state, exact paid and ownership-effective times, installment and cycle state, links between subscription credit schedules and billing records, HMAC-derived billing account ID hashes, and purchase-intent or restore lifecycle state. A deleted billing account state can retain a nonnegative debt amount, a subscription credit schedule ID, and an authenticated successor billing account ID hash and transfer time. These retained records do not contain a raw Vequo account identifier, Firebase user identifier, RevenueCat App User ID, device identifier, email address, or raw store/RevenueCat transaction or original-transaction identifier. Because billing account ID hashes are derived from account identifiers and can enforce debt or ownership, this is pseudonymous—not anonymous— transaction and fraud-prevention information. It is not used for advertising or profiling.
While an authenticated billing event is pending, retrying, or quarantined for manual review, Vequo’s billing work item temporarily retains its provider payload and raw transaction/customer context. Successful settlement scrubs that payload and raw identity context, deletes the identity links, and leaves only a compact processed event marker and timing/dispatch metadata.
RevenueCat processes limited device information such as device type and operating system, purchase history, the time Vequo was last opened, the Apple receipt or Google purchase token, and the pseudonymous App User ID. RevenueCat may use the device’s IP address transiently to determine a country and states that it then drops rather than persists the IP address. Vequo does not send RevenueCat names, email addresses, advertising identifiers, attribution data, or custom customer attributes.
We do not receive or store your full card number, card security code, or store-account password.
Rewarded-ad information
Rewarded ads are optional. If you open or use the rewarded-ad feature, Unity LevelPlay and participating ad networks may process:
- the device advertising identifier, such as IDFA or Android Advertising ID, where available and permitted;
- IP address and approximate location derived from it;
- device, operating system, app, SDK, language, and connection information;
- ad requests, impressions, clicks, completions, placement, and fraud signals;
- SDK diagnostic information, such as initialization, performance, and error events;
- purchase history, which Unity Ads states it collects and shares for advertising and analytics; and
- a pseudonymous Firebase user identifier used by Vequo to verify the reward.
At launch, the mediated advertising providers are ironSource Ads and Unity Ads. The active network can vary by device, country, availability, and future mediation configuration. We will update this Policy when we materially change the advertising providers or practices.
In regions where consent is required, Vequo asks whether you want personalised or limited ads before initialising rewarded ads. On iOS, Apple also controls access to IDFA through App Tracking Transparency. Limited ads may still use contextual information and process limited data for delivery, frequency capping, measurement, security, and fraud prevention.
Vequo does not give ad providers your selected photos, edit instructions, prompts, or generated images, and does not target ads based on the contents of your designs.
AI-output and ad reports
If you report an AI-generated output or an inappropriate ad in Vequo, we collect the report category and reason, optional details you type, a pseudonymous report identifier, and either the edit-job identifier or the LevelPlay provider name. An AI-output report also records whether its short-lived edit-job record was available when you reported it. When that record still exists, the authenticated backend checks that it belongs to your account before accepting the report. If it has expired but the output remains on your phone, Vequo still accepts the report and marks the edit job as unavailable.
Reports enter the restricted Firestore userReports collection with pending status. Vequo does not upload or retain the generated image, source photo, or prompt for review; the AI-output report marks output retention as false. Reports also exclude your raw Vequo account identifier and raw client report identifier. We review reports to investigate safety issues, improve filtering or moderation, and address inappropriate advertising. Please do not put names, contact details, or other unnecessary personal information in the optional report details.
Support communications
If you contact us, we process your email address, message, attachments, and related correspondence so we can respond, investigate problems, protect our rights, and keep an appropriate support record. Please do not email us images or sensitive personal information unless it is necessary to resolve your request.
Website and waitlist information
If you join Vequo’s website waitlist, we collect the email address you submit, the consent wording in effect when you joined, and the time of signup. We use this information only to send Vequo launch updates and administer your opt-out. We do not store the Turnstile security token, your IP address, or your browser information in the waitlist database.
When you visit vequo.app or use api.vequo.app, Cloudflare and our hosting providers may process IP address, browser and device information, requested URL, timestamps, security signals, and similar request metadata. Cloudflare may use strictly necessary cookies or comparable technologies for security and network operation. We do not currently use third-party behavioural analytics on vequo.app.
3. Where information comes from
We receive information:
- from you, when you select or capture an image, make an edit, submit a report, choose an ad preference, link a sign-in provider, buy a product, or contact support;
- automatically from the app, device, and network, including pseudonymous identifiers, app-attestation material, IP address, region, device information, permissions, and feature interactions needed to provide or secure the Service; and
- from service providers, including Apple or Google sign-in, app stores, RevenueCat, Firebase, Google Cloud, Cloudflare, PostHog, Unity LevelPlay, and mediated ad networks.
4. How an AI edit is processed
When you press the control to generate an edit:
- Vequo prepares the request on your device. Only content needed for that request is included: the selected environment image, the resolution, and the marks, colour, texture, reference image, makeover choice, or optional text you actually used.
- The app sends the edit request and a pseudonymous authenticated request to
api.vequo.appover HTTPS. Cloudflare proxies it to Vequo’s Google Cloud Run backend, which records a small job record in Firestore, writes the edit request to Vequo’s private Cloudflare R2 storage bucket, and returns short-lived signed upload links. - The app uploads the image files directly to that private bucket over HTTPS using those links. Image files are not routed through
api.vequo.app. - The backend verifies the uploaded files and queues the job on Google Cloud Tasks. A private Vequo worker service then downloads them, prepares the model input, and sends it to Google Cloud Vertex AI, which generates the image using a Google Gemini image model.
- The generated image is written back to the same private bucket. Vequo deletes the stored edit request and the uploaded input images as soon as the generation succeeds, and deletes all of them together with the generated image if the edit fails.
- The app requests a short-lived signed download link, downloads the generated image directly from the private bucket, copies it into Vequo’s private local storage on your device, and then tells the backend that the stored copy can be deleted.
The storage bucket is private. It has no public address, no public development URL, and no content delivery network in front of it; access is only through signed links that expire within ten minutes. The Firestore job record holds control-plane information such as the account identifier, status, timing, credit cost, and result checksum. It never contains image content, edit instructions, or your text.
Production model-input file logging is disabled. Google automatically screens submitted content and model responses for safety, prohibited content, sensitive personal information, and abuse, and may refuse a request. Google currently applies project-isolated, in-memory caching to Gemini inputs, outputs, and derived data for up to 24 hours by default. Google may also log prompts when automated safety systems detect potential abuse, as described in Google Cloud’s generative AI terms and abuse-monitoring documentation. Google does not use this customer data to train or fine-tune AI models without prior permission or instruction from Vequo.
5. Why we process information
We process information to:
- provide AI image editing and save designs on your device;
- administer the website waitlist and send launch updates you requested;
- create, secure, recover, and delete accounts;
- manage plans, credits, purchases, and purchase restoration;
- deliver rewarded ads you choose to watch and verify rewards;
- receive and review AI-output and inappropriate-ad reports for safety and moderation;
- obtain and record privacy choices;
- authenticate requests, prevent fraud and abuse, and enforce limits;
- maintain, debug, and secure the app, website, and backend;
- measure feature adoption and improve app usability and reliability using limited product analytics;
- respond to support and privacy requests;
- comply with law, court orders, and valid regulatory requests; and
- establish, exercise, or defend legal claims.
Where the GDPR, UK GDPR, or a similar law requires a legal basis, we rely on:
- contract: to provide requested edits, account functions, purchases, credits, and support;
- legitimate interests: to secure and operate the Service, prevent fraud, keep limited operational records, and improve reliability in ways that do not override your rights;
- consent: for personalised advertising, tracking where legally required, and other optional processing for which we ask permission; and
- legal obligation: when processing is necessary to comply with applicable law.
6. When we disclose information
We disclose information only as needed for the purposes above:
| Recipient | Role and information involved |
|---|---|
| Google Cloud, Firebase, and Vertex AI | Cloud hosting, Firestore job, account, and user-report records, work queueing, anonymous and optional federated authentication, app attestation, operational logs, and AI generation. This can include account identifiers, authentication information, request metadata, report data, images, edit instructions, and generated output. |
| Cloudflare | Website delivery, D1 waitlist storage, Turnstile bot protection, API proxying, private R2 storage of edit images and edit requests while an edit is processed, TLS, network security, and abuse prevention. This can include waitlist email addresses and consent records, IP address, headers, request metadata, and edit content while it is transmitted or briefly stored. |
| Apple | App distribution, purchases, Sign in with Apple if chosen, App Attest or DeviceCheck, device permissions, and subscription management. |
| App distribution, purchases, Google Sign-In if chosen, Play Integrity, and subscription management. | |
| RevenueCat | Store-product retrieval, purchase validation, subscription entitlement management, purchase restoration, and fulfilment. This includes a pseudonymous App User ID, limited device information, store receipts or purchase tokens, purchase history, and entitlement information. RevenueCat acts as Vequo’s service provider for these functions; it is not Vequo’s merchant or payment processor. |
| PostHog | EU-hosted product analytics and error diagnostics. This includes a random analytics identifier, limited app and device context, normalised screen views, selected feature events and outcomes, exception details, stack traces, native crash reports, and limited event breadcrumbs, but not Vequo design content or Vequo account identifiers. |
| Unity LevelPlay and mediated ad networks | Optional rewarded-ad delivery, measurement, analytics, fraud prevention, personalisation where permitted, and server-side reward verification. This can include identifiers, approximate location, device and SDK diagnostic information, ad interactions, and purchase history, but not Vequo design content. |
| Professional advisers and authorities | Lawyers, accountants, insurers, regulators, courts, law enforcement, or other parties when reasonably necessary to comply with law or protect rights and safety. |
| A successor to the business | A buyer, investor, or successor involved in a merger, financing, reorganisation, or sale, subject to appropriate confidentiality and notice where required. |
We require service providers that process data on our behalf to protect it and use it only for the contracted service, with the same or equivalent protection required by this Policy and applicable law. Some providers, particularly advertising providers and app stores, may also act as independent controllers under their own privacy policies.
Provider information is available in the Google Cloud Privacy Resource Center, Cloudflare Privacy Policy, RevenueCat Privacy Policy, PostHog Privacy Policy, Unity Game Player and App User Privacy Policy, Apple Privacy Policy, and Google Privacy Policy.
7. Sale, sharing, and targeted advertising
We do not sell your photos, prompts, generated images, account information, or other personal information for money.
When you use rewarded ads, advertising identifiers where available, approximate location, device and SDK diagnostic information, ad interactions, and purchase history may be disclosed to Unity and participating ad networks for ad delivery, measurement, analytics, security, and fraud prevention. If you choose personalised rewarded ads, those recipients may also use permitted identifiers and related information to personalise advertising. Some United States privacy laws may define that activity as sharing, targeted advertising, or a sale, even though Vequo does not receive money in exchange for the data.
You can limit this processing by choosing limited ads when Vequo presents the choice, denying or revoking iOS tracking permission in device settings, using the advertising privacy controls provided by Android, or contacting us at hello@vequo.app. You may still receive contextual or limited ads. We do not discriminate against you for exercising a privacy right, although an optional feature may work differently when the information needed for it is unavailable.
8. Retention and deletion
We keep information only for as long as needed for the purposes described here:
| Information | Normal retention |
|---|---|
| Design library, edit graph, and app image files | Stored on your device. The design remains visible until you delete it in Vequo, clear the app’s data, or uninstall the app. When you delete a design or image in Vequo, the app immediately attempts to delete each private image file that is not still used by another retained design. Clearing app data or uninstalling Vequo also removes its private storage, subject to device backups and operating-system behaviour. |
| Uploaded edit images in Vequo’s private storage | Held in Vequo’s private Cloudflare R2 bucket only while the edit is processed, then deleted when the generation succeeds or fails. A storage lifecycle rule deletes anything left behind within one day. |
| Stored edit request in Vequo’s private storage | The marks, colour, texture, makeover choice, reference details, and optional text for that edit. Deleted with the uploaded images when the edit finishes. A storage lifecycle rule deletes anything left behind within seven days. |
| Generated image in Vequo’s private storage | Deleted once the app confirms it has saved or discarded the result, and deleted immediately if the edit fails. A storage lifecycle rule deletes anything left behind within seven days. |
| Edit job record in Firestore | Control-plane information only, with no image content or edit instructions. Deleted about seven days after the edit reaches a final state, so a lost result can still be recovered without charging you again. |
| AI-output and ad reports | A pending record in the Firestore userReports collection contains the report category and reason, optional details, pseudonymous report identifier, and an edit-job identifier and availability state or the LevelPlay provider name. An AI-output report marks output retention as false. It contains no image, prompt, raw account ID, or raw client report ID. Its expiresAt time makes it eligible for automatic deletion by Firestore TTL after 90 days, and an operator can delete it sooner. Deleting your Vequo account does not immediately remove this already-pseudonymised safety record. |
| Data processed by Vertex AI | Subject to Google Cloud’s configured retention and abuse-monitoring rules. Project-isolated in-memory cache data may remain for up to 24 hours by default. Production model-input file logging is disabled. |
| Vequo account and credit ledger | Kept while the account is active, then deleted when you use Delete account, except for the limited pseudonymous billing, fraud, transaction, legal, and backup records described below. The live account can include nonnegative credit debt; later grants pay it before increasing the displayed balance. |
| Firebase Authentication record | Deleted when Vequo completes an in-app account deletion. Firebase states that authentication data is then removed from live and backup systems within 180 days; logged authentication IP addresses are normally kept for a few weeks. |
| Vequo purchase and subscription records | Kept while the account is active and, where needed, for up to 7 years after the transaction for fulfilment, accounting, tax, fraud prevention, disputes, and legal compliance. |
| Purchase billing-sync marker on your device | Kept in protected local storage while a server purchase intent is open. It is deleted only when the server says the intent expired, or says it completed and the expected purchase was reconciled; product/transaction observation diagnostics alone do not delete it. A local pre-intent marker can clear after 15 minutes, but an intent already created on the server remains authoritative. Android app-data clearing normally removes it; Apple’s Keychain may retain it across an iOS reinstall until Vequo clears it, subject to backups and operating-system behaviour. |
| Restore marker on your device | Kept while a server restore guard is open. A created guard can expire; after native restore is launched it is not closed merely because RevenueCat returns no purchase. Background recovery checks but does not automatically rerun native restore. The user can explicitly rerun the non-charging restore under the same guard after a crash. Device-storage and backup caveats are the same as for the purchase marker. |
| Account-deletion recovery markers on your device | While a deletion or its provider cleanup is unresolved, protected local storage can hold the old Vequo account ID, Firebase UID, old and retired RevenueCat App User IDs, and deletion phase. The app uses these values only to keep the old purchaser disabled, recover a lost response, and prevent purchases or restores until provider deletion completes. The local operation marker clears after the live-account transition; the purchaser-retirement marker clears only after verified provider completion. Android app-data clearing normally removes them, while Apple’s Keychain and device backups may retain them across reinstall. |
| Retained pseudonymous billing records and deleted billing account state | HMAC-keyed consumable purchases, paid subscription periods, subscription credit schedules and cycles, billing-account ownership changes, signed product changes, and guarded purchase-intent/restore state are retained separately from the live Vequo account for the life of the Service. They hold limited logical product, credit allocation/refund, exact paid/effective-time, billing account ID hash/reference, and lifecycle metadata. After deletion, the state retains the billing account ID hash, nonnegative debt, optional subscription credit schedule ID, optional successor billing account ID hash and effective time, and update time. The state prevents double fulfilment and applies a verified refund or reversal once. It contains no raw Vequo account ID, Firebase UID, RevenueCat App User ID, device ID, email, or raw store/RevenueCat transaction or original-transaction ID. It is pseudonymous rather than anonymous. An authenticated financial event received after account deletion can update this state without recreating the account. |
| Account-deletion status and anti-recreation receipts | The server retains a compact HMAC-keyed Firebase-auth deletion fence and a permanent HMAC-keyed lookup from the pre-issued 128-bit retirement capability to the compact deletion-job ID. After settlement, these records contain no raw Vequo account ID, Firebase UID, or RevenueCat App User ID. They prevent the deleted identity from silently recreating the account and let the app use valid Firebase App Check plus that capability to recover only pending, manual review, or completed status after Firebase deletion. |
| Billing work items | A signed provider event or repair job can retain raw provider, transaction, customer, and identity context while pending, retrying, or quarantined for manual review. Successful settlement scrubs the raw event/job and identity context and deletes its identity links; a compact processed event and timing/dispatch marker remains for the life of the Service to prevent duplicate processing. Unsettled evidence remains until it succeeds or is manually reviewed, and account deletion is refused meanwhile. |
| RevenueCat customer, purchase, and entitlement data | Kept while needed to manage or restore purchases. Production in-app account deletion admits a monitored job that deletes and rechecks both the old and temporary retired RevenueCat customers until the provider confirms they are absent. The status can remain pending, or enter manual review when shared, anonymous, cross-environment, unknown, or otherwise ambiguous aliases make automatic whole-customer deletion unsafe. RevenueCat states that deletion clears the customer data, including purchase history, but does not cancel an Apple or Google subscription. A later store restore or purchase can send a current receipt to RevenueCat and recreate provider data. |
| Fraud-prevention device state | A keyed HMAC hash of the Android app-scoped identifier or Apple’s one-bit DeviceCheck state may remain after account deletion for the life of the device identifier or the Service. It is retained only to enforce one-time promotional grants and prevent repeated abuse, not for advertising. |
| Rewarded-ad replay facts | A compact one-way hash of each processed LevelPlay event identifier, creation time, and expiry time remains for ten days, after which Firestore TTL makes it eligible for deletion. It contains no raw Firebase or Vequo account identifier and is used only to stop the same signed reward callback from granting progress again during Vequo’s nine-day accepted callback window, which includes margin beyond LevelPlay’s approximately eight-day retry schedule. |
| Operational application logs | Normally retained in Google Cloud’s default log bucket for 30 days unless a shorter period is configured. Security incidents, required audit logs, disputes, and legal holds may be retained longer. Cloudflare Workers logs, when enabled, are ordinarily retained for up to 3 days on the free plan or 7 days on the paid plan. |
| Product analytics and error diagnostics | PostHog EU Cloud retains events and exception data for up to 1 year under Vequo’s current free workspace settings, unless Vequo deletes the project or data earlier. PostHog may take additional time to remove data from backups and systems after deletion. |
| Support correspondence | Normally retained for up to 24 months after the matter closes, or longer when needed for a dispute or legal obligation. |
| Website waitlist | Kept until you opt out or for 12 months after Vequo’s public launch, whichever comes first, unless you separately ask to keep receiving updates. |
Backups and provider systems may take additional time to erase information after a deletion request. We may retain information that we are legally required to keep, and may retain or transform information so it can no longer reasonably identify you.
Delete your Vequo account
In the app, go to Profile → Delete account. Vequo durably removes the live account and forfeits remaining credits, then a private worker finishes terminal edit-object cleanup, Firebase Authentication deletion, and monitored RevenueCat deletion/rechecks. The app keeps the old RevenueCat identity disabled and blocks purchase/restore operations until provider deletion is confirmed; a manual-review status requires support handling. Deletion is refused while an edit is still generating or while a billing event, purchase intent, or restore guard is unresolved, so let those operations settle first. Deleting a Vequo account does not:
- cancel an Apple App Store or Google Play subscription;
- guarantee immediate RevenueCat erasure when the monitored deletion is pending or requires manual review, or prevent a later store restore/purchase from recreating provider data;
- erase transaction records that Apple, Google, or Vequo must retain for accounting, tax, fraud prevention, disputes, or law;
- reset Vequo’s retained pseudonymous HMAC-keyed billing records or deleted billing account state, which remain so the same transaction or subscription period cannot be granted twice, a verified refund/reversal is applied once, and deleted-account debt can follow an authenticated provider successor;
- reset the limited anti-fraud device state used to prevent repeated promotional grants;
- immediately delete a pending AI-output or ad safety report, which contains no raw account identifier and remains until operator deletion or its 90-day TTL;
- allow a server or email deletion request to erase private files on an offline or uninstalled device.
Manage or cancel a subscription through the subscription-management link in Vequo or directly through Apple App Store or Google Play. After the server commits an in-app account deletion, Vequo clears its local design metadata and immediately attempts to delete all files in its managed private image storage, including while RevenueCat cleanup remains pending or requires manual review. A server or email deletion request cannot perform that on-device cleanup, so delete through the app first where possible, or clear Vequo’s app data or uninstall it. Device backups and operating-system behaviour may retain additional copies.
Vequo requires a pseudonymous guest account for online features. If you continue using the app after deletion, Vequo may immediately create a new guest account that is separate from the deleted account. Uninstall Vequo if you do not want a new guest account to be created.
Deletion removes the live account and reverse mapping but retains its nonnegative debt, optional subscription credit schedule, and optional authenticated successor in the pseudonymous deleted billing account state described above. A live source account keeps its own historical credits and debt; only deleted-account debt can follow a provider- authenticated successor. Vequo does not transfer all balances between accounts.
If you cannot access the app, request deletion at https://vequo.app/delete-account or email hello@vequo.app.
9. Your privacy rights
Depending on where you live, you may have rights to:
- know whether and how we process your personal information;
- access or receive a portable copy of it;
- correct inaccurate information;
- delete information;
- restrict or object to processing, including targeted advertising;
- withdraw consent at any time, without affecting earlier lawful processing;
- appeal a refusal of a privacy request; and
- complain to a privacy or data-protection regulator.
Send requests to hello@vequo.app. Please identify the Vequo account or device involved without sending passwords, store credentials, or unnecessary identity documents. We may need to verify that you control the account or email address. We will not discriminate against you for making a request, and an authorised agent may submit a request where applicable law permits it.
Australian users may complain to the Office of the Australian Information Commissioner. EEA users may complain to their local supervisory authority, and UK users may complain to the Information Commissioner’s Office.
10. International processing
Vequo is operated from Australia, while the production backend is currently hosted in the United States. Vequo’s private storage bucket is placed in Cloudflare’s Eastern North America region, which is a placement hint rather than a data-residency guarantee. Vequo currently uses Google’s global model endpoint, so a generation request may be processed in any region where Google serves that model. RevenueCat states that customer data is persistently stored on Amazon Web Services in the United States and that it may use providers or other parties in other countries subject to contractual and technical safeguards. Vequo’s PostHog event and error data is hosted in PostHog EU Cloud in Frankfurt, Germany; PostHog may process Vequo’s administrative customer information elsewhere through its global business and subprocessors. Unity or ironSource operations may involve Israel and the United States. Google, Cloudflare, Apple, RevenueCat, PostHog, Unity, and their subprocessors operate global infrastructure, so information other than the EU-hosted PostHog event and error data may also be processed in other countries where those providers or their subprocessors operate.
Those countries may have privacy laws different from yours. Where required, we use contractual protections and other lawful transfer mechanisms, and we take reasonable steps to require recipients to protect information consistently with applicable law.
11. Security
We use safeguards appropriate to the nature of the Service, including HTTPS in transit, provider-managed encryption at rest, access controls, short-lived authentication and attestation tokens, pseudonymous account identifiers, keyed hashing of Android anti-fraud identifiers and billing identifiers with separate restricted secrets, and restricted cloud-service credentials. Edit images are held in a private storage bucket that has no public address and is reachable only through signed links that expire within ten minutes and are bound to the exact file being transferred. Designs are stored in the app’s private device storage rather than a Vequo cloud design library.
No system is completely secure. Protect access to your device and linked Apple or Google account, keep the app and operating system updated, and contact us promptly if you believe an account has been compromised.
12. Children
Vequo is intended for adults and is not directed to anyone under 18. Do not use the Service or provide personal information if you are under 18. If we learn that we collected personal information from a person under 18, we will take reasonable steps to delete it. A parent or guardian can contact hello@vequo.app.
13. Changes to this Policy
We may update this Policy to reflect changes to the Service, providers, or law. We will post the updated version at vequo.app/privacy and change the date above. If a change materially affects your rights or how we use information, we will provide additional notice in the app or by another reasonable method before the change takes effect where required.
14. Contact us
Vequo
Operated by: Vequo Pty Ltd
ACN: 700 743 719
ABN: 84 700 743 719
Address: 905/50 Lorimer Street, Docklands VIC 3008, Australia
Email: hello@vequo.app