Skip to content

Vequo Privacy Policy

Effective date: 20 August 2026
Last updated: 22 September 2026

Vequo is operated by Vequo Pty Ltd (ABN 84 700 743 719), trading as Vequo (Vequo, we, us, or our).

This Privacy Policy explains how we handle personal information when you use the Vequo mobile application, visit vequo.app, contact us, or otherwise use our related services (together, the Service).

Contact us about privacy at hello@vequo.app.

1. The short version

2. Information we handle

Images and edit content

We handle:

We use this content to keep your designs locally, perform the edit you requested, return the result, recover or investigate a failed edit, moderate reported output, and protect the Service from misuse.

Vequo removes embedded camera and location metadata from selected photos before saving or uploading them. The visible image can still reveal people, objects, or location clues, so review it before submission.

Vequo requests access to your camera or photo library only when needed for a feature you choose. You can change those permissions in device settings. Vequo does not scan or upload your entire photo library and does not intentionally request precise location metadata from it.

Account and sign-in information

Vequo creates a device-linked account identified by a generated identifier rather than your name. We keep account identifiers, device platform, credit balance and transactions, plan status, account creation time, sign-in status, and rewarded-ad progress and verification records.

If you choose Apple or Google sign-in to secure or recover an account, our sign-in providers may process account identifiers, email address, display name, profile photo when supplied, and sign-in tokens. We use the account association and sign-in status to provide account access and recovery.

Device, network, and security information

We and our service providers may process:

We use this information to provide secure access, diagnose failures, prevent fraud and abuse, and maintain reliability. Device information retained for fraud prevention is not used for advertising.

Edit-ready notifications

After you submit an edit, we may set up notifications and ask for your device’s notification permission. Our notification-delivery provider may process an app installation identifier, app version, and limited device information during setup. If you allow notifications, we also process a notification identifier, account association, device platform, and registration time to deliver edit-ready messages.

A notification contains generic text and a reference to the relevant edit. It does not contain your photo, instructions, generated result, result link, credit balance, or account identifier.

You can deny or disable notifications in device settings without losing access to editing or results. We remove notification registrations when the app detects withdrawal, when delivery is no longer possible, when the account changes, or when account deletion completes.

Product analytics and error diagnostics

Our analytics and diagnostics provider may receive:

These product analytics events exclude your photos, generated images, reference images, instruction text, detailed editing marks, selected colour values, design and edit identifiers, Vequo account identifier, and purchase identifiers. Diagnostic reports can contain technical error details. For this product analytics and diagnostics collection, we do not record your screen, collect all touches or device console logs, build user profiles, or infer location from your IP address. The provider processes your IP address to receive the connection.

Optional app and campaign measurement

On iOS, if you allow campaign measurement, we use Google Analytics to understand app use and measure the effectiveness of Vequo’s advertising. It receives a generated app-installation identifier, app activity, app and device information, approximate location derived from your IP address, and purchase or subscription details such as the product and price. We do not send your photos, edit instructions, generated designs, name, email address, or Vequo account identifier for this purpose.

This measurement stays off until you allow it and is not used to personalise ads. You can withdraw permission for future collection under Profile → Privacy choices → Campaign measurement. This choice is separate from product analytics, error diagnostics, and rewarded-ad preferences. Learn how Google uses information from apps that use its services.

Purchase and subscription information

Your app store processes your payment. We and our purchase-management provider receive information needed to validate and fulfil it, including store and product details, receipts or purchase tokens, transaction identifiers, purchase time and history, subscription status and expiry, limited device information, and a pseudonymous account reference.

We retain limited account, transaction, product, and progress information on your device to recover interrupted purchases, restorations, and account deletions and prevent duplicate charges or benefits.

Refunds can result in the removal of related benefits. If refunded credits were already used, later credit grants may first repay the resulting credit debt, as explained in our Terms.

We retain limited pseudonymous transaction and fraud-prevention records, including purchase benefits, dates, status, refunds, account references, and credit debt. These prevent duplicate benefits and refund abuse, including after account deletion. After processing, these records exclude your name, email, direct Vequo account and device identifiers, and direct store transaction identifiers. They are not used for advertising or behavioural profiling.

While a billing issue is unresolved, we may retain the transaction evidence and account information needed to investigate it. We reduce that information after resolution. We do not receive or store your complete card number, card security code, or store-account password.

Rewarded-ad information

Rewarded ads are optional. If you open or use that feature, participating advertising providers may process:

The active advertising providers can vary by device, country, availability, and future configuration. We will update this Policy if those practices materially change.

Where required, Vequo asks whether you want personalised or limited ads before enabling the feature. On iOS, Apple separately controls access to the device advertising identifier through App Tracking Transparency. Limited ads may still process contextual and limited device information for delivery, frequency capping, measurement, security, and fraud prevention.

Vequo does not give advertising providers your selected photos, edit instructions, prompts, or generated images, and does not target ads from the contents of your designs.

AI-output and ad reports

If you report an AI-generated output or an inappropriate ad, we collect the report category and reason, optional details you type, a pseudonymous report identifier, and limited information about the affected edit or advertisement.

AI-output reports do not include the generated image, source photo, prompt, or direct account identifier. We use reports to investigate safety issues, improve moderation, and address inappropriate advertising. Please do not include names, contact details, or other unnecessary personal information in optional report details.

Support communications

If you contact us, we process your email address, message, attachments, and correspondence to respond, investigate problems, protect our rights, and keep an appropriate support record. Do not send images or sensitive personal information unless necessary for your request.

Website and waitlist information

The website no longer accepts waitlist signups. If you previously joined, we use your retained email address, signup consent record, and signup time only to send requested launch updates and administer your opt-out, subject to section 8.

When you visit vequo.app, our website, hosting, and security providers may process IP address, browser and device information, requested page, timestamps, security signals, and similar request metadata. Strictly necessary cookies or comparable technologies may be used for security and network operation. We do not currently use third-party behavioural analytics on the website.

3. Where information comes from

We receive information:

4. AI editing and your choices

When you request an edit, we send only the selected photo, edit marks or choices, optional instructions, and reference content needed for that request to our third-party AI processing provider. The result is returned to your device. Edit content is temporarily retained as described in section 8.

Submitted content and results may undergo safety and abuse screening, and a request may be refused. Our AI processing provider can retain edit content for up to 24 hours. Content flagged for suspected abuse may be retained for up to 90 days and reviewed by authorised personnel. Our provider does not use this content to train or fine-tune AI models without our prior permission or instruction. Any material expansion of how we use your content is subject to section 13 and any consent required by law.

On iOS, Vequo identifies the AI recipient and asks for explicit permission before uploading edit content. You can decline, and you can withdraw future permission under Profile → Privacy choices. Withdrawing permission prevents new AI edit uploads until you allow them again.

5. Why we process information

We process information to:

Where the GDPR, UK GDPR, or a similar law requires a legal basis, we rely on:

6. When we disclose information

We disclose information only as needed for the purposes above:

Recipient Role and information involved
AI processing providers Generate requested edits and perform safety and abuse screening using the selected photo, edit instructions, reference content, and generated result.
Hosting, authentication, and security providers Host and protect the Service, authenticate users, store temporary edit content and limited account, report, and operational information, and deliver website traffic. This can include account identifiers, authentication information, IP address, request metadata, report data, and temporary edit content.
Notification-delivery providers Deliver requested edit-ready messages using installation and notification identifiers, limited app and device information, generic text, and an edit reference, but not your photos, instructions, or generated results.
App stores, device-platform and sign-in providers App distribution, purchases, optional sign-in, device and app authenticity checks, permissions, and subscription management using the account, purchase, and device information needed for those functions.
Purchase-management providers Purchase validation, subscription management, restoration, and fulfilment using pseudonymous account, device, receipt or purchase-token, purchase-history, and subscription information.
Analytics and diagnostics providers Limited app and device information, an analytics identifier, feature usage and outcomes, and error and crash reports. Optional app and campaign measurement also uses approximate location and purchase or subscription details where you allow it. These providers do not receive design content or Vequo account identifiers for these purposes.
Rewarded-ad providers Optional ad delivery, measurement, analytics, fraud prevention, personalisation where permitted, and reward verification using identifiers, approximate location, device and diagnostic information, ad interactions, and purchase history, but not design content.
Professional advisers and authorities Lawyers, accountants, insurers, regulators, courts, law enforcement, or other parties where reasonably necessary to comply with law or protect rights and safety.
A successor to the business A buyer, investor, or successor involved in a merger, financing, reorganisation, or sale, subject to appropriate confidentiality and notice where required.

We require providers that process data for us to protect it and use it only for the contracted service. Some providers, particularly advertising providers and app stores, may also be independently responsible for their use of information under their own privacy policies. You can request information about recipients of your personal information at hello@vequo.app.

7. Sale, sharing, and targeted advertising

We do not sell your photos, prompts, generated images, account information, or other personal information for money.

When you use rewarded ads, advertising identifiers where available, approximate location, device and diagnostic information, ad interactions, and purchase history may be disclosed to advertising providers for delivery, measurement, analytics, security, fraud prevention, and, if you choose it, personalisation. Some United States privacy laws may define this as sharing, targeted advertising, or a sale, even though Vequo does not receive money for the data.

You can choose limited ads when Vequo presents the choice, deny or revoke iOS tracking permission in device settings, use Android advertising privacy controls, or contact us at hello@vequo.app. You may still receive contextual or limited ads. We do not discriminate against you for exercising a privacy right, although an optional feature may work differently when necessary information is unavailable.

8. Retention and deletion

We keep information only for as long as needed for the purposes described here:

Information Normal retention
Designs and edit history Stored on your device until you delete them, clear app data, or uninstall the app, subject to device backups. Images still used by a retained design remain available to that design.
Uploaded edit inputs held by Vequo Deleted when processing finishes. Any remaining uploaded images are deleted within one day and stored instructions within seven days.
Generated results held online by Vequo Deleted after the app saves or discards the result, or when an edit fails. Any remaining copy is deleted within seven days.
Edit activity records Limited status, timing, credit, and file-integrity information, without images or instructions, is normally deleted about seven days after processing finishes.
Edit-ready notification data Kept while the account is active, unless removed earlier following permission withdrawal, an account change, or invalid delivery details. Account deletion removes the live registration. The delivery provider may retain an undelivered message and edit reference for up to four weeks before discarding it.
AI-output and ad reports Report category and reason, optional details, pseudonymous report identifier, and a limited edit or ad-provider reference are retained for up to 90 days and can be removed sooner. AI reports contain no source photo, result image, prompt, or raw account identifier. Deleting an account does not immediately remove an already pseudonymised safety report.
Edit content held by AI processing providers May be retained for up to 24 hours. Content flagged for suspected abuse may be retained for up to 90 days for review by authorised personnel.
Vequo account and credit ledger Kept while active, then deleted through Delete account, except for the limited transaction, fraud, safety, legal, and backup records below. Later credit grants first repay any credit debt before increasing the displayed balance.
Authentication records Deleted from live systems when account deletion completes. Our authentication provider may take up to 180 days to remove data from backups, and authentication IP logs can remain for a shorter operational period.
Purchase and subscription records Kept while the account is active and, where needed, for up to seven years after a transaction for fulfilment, accounting, tax, fraud prevention, disputes, and legal compliance.
Purchase, restore, and deletion recovery information on your device Kept until an interrupted operation is resolved. Device backups and operating-system behaviour can retain this information across reinstall until it is cleared.
Pseudonymous transaction and fraud-prevention records Limited purchase, benefit, refund, account-reference, and credit-debt information can remain for the life of the Service to prevent duplicate benefits and refund abuse. Direct account and direct store transaction identifiers are excluded after processing. Credit debt can apply after account deletion if a later store restoration or purchase is associated with the same purchasing account.
Unresolved billing records Transaction evidence and account information remain until the issue is resolved, subject to legal holds. We then reduce the information to the records needed for fraud prevention and legal obligations.
Purchase-management records held by service providers Kept while needed to manage or restore purchases. Deletion can remain pending or require manual review. A later store restoration or purchase can recreate these records. Deletion does not cancel a store subscription.
Device fraud-prevention records May remain for the life of the device identifier or Service to prevent repeated promotional and other abuse. Not used for ad targeting or behavioural profiling.
Reward verification records Limited event references and timing information remain for up to 11 days to prevent duplicate rewards.
Operational application logs Normally retained for up to 30 days. Website and network logs are normally retained for up to seven days. Security incidents, disputes, required audit logs, and legal holds may be retained longer.
Product analytics and error diagnostics Retained for up to one year, subject to additional backup-deletion time.
Optional app and campaign measurement Individual app and event records have a two-month retention period and are deleted in the next monthly deletion cycle. Aggregated reports may be retained longer.
Support correspondence Normally retained for up to 24 months after the matter closes, or longer for a dispute or legal obligation.
Website waitlist Kept until you opt out or for 12 months after public launch, whichever comes first, unless you separately ask to keep receiving updates.

Backups and provider systems may take additional time to erase information. We may retain information required by law or transform it so it can no longer reasonably identify you.

Delete your Vequo account

In the app, go to Profile → Delete account. Deletion removes the live Vequo account and credits and clears locally managed designs and image files that the app can reach. An active edit, purchase, restoration, or billing review may need to settle first. Purchase and restoration features remain unavailable while deletion is unresolved.

Deleting your Vequo account does not:

To cancel a subscription, use the subscription-management link in Vequo or the Apple App Store or Google Play. You can also request account deletion through https://vequo.app/delete-account or email hello@vequo.app. We may need enough information to verify your request and locate the account. We normally respond within 30 days, subject to any permitted extension.

9. Your privacy rights

Depending on where you live, you may have rights to:

Use Profile → Privacy choices, Profile → Delete account, or email hello@vequo.app. We may ask for proportionate verification. An authorised agent may submit a request where local law permits, subject to proof of authority. We will respond within the period required by applicable law.

Australian users can complain to us first and, if unresolved, contact the Office of the Australian Information Commissioner. European Economic Area or United Kingdom users can contact their local supervisory authority. You may also have a right to complain to another applicable regulator.

10. International processing

Vequo is based in Australia. We and our service providers may process personal information in Australia, the United States, Germany, Israel, and other countries where they operate.

Those countries may have different privacy laws. Where required, we use contractual safeguards or another lawful transfer mechanism and require service providers to protect information consistently with this Policy and applicable law.

11. Security

We use reasonable technical and organisational safeguards to protect personal information against unauthorised access, use, disclosure, alteration, or loss. No method of transmission or storage is completely secure.

12. Children

Vequo is intended only for people aged 18 or older. We do not knowingly collect personal information from children. Contact hello@vequo.app if you believe a child has provided information, and we will take appropriate steps to remove it.

13. Changes to this Policy

We may update this Policy when the Service, law, or our practices change. We will post the updated version at vequo.app/privacy and update the date above. If a change materially reduces your rights or materially expands how we use personal information, we will provide reasonable advance notice in the app or by another appropriate method.

14. Contact us

Vequo
Operated by: Vequo Pty Ltd
ABN: 84 700 743 719
Email: hello@vequo.app