Home

CleanPhoto

Privacy Policy

Effective date: July 25, 2026

This Policy covers the CleanPhoto mobile app, photo-clean.ru, and the account portal. Photos and videos are processed locally and are not uploaded to CleanPhoto servers.

1. Controller and scope

This Policy covers https://photo-clean.ru, the account portal, the API, and the CleanPhoto mobile application. The CleanPhoto service owner, personal data controller, rights holder, and service provider is Васильева Анастасия Олеговна, an individual applying the Russian Professional Income Tax regime (self-employed; not registered as an individual entrepreneur), Russian TIN 027619297120. Business location: Ufa, Republic of Bashkortostan, Russian Federation. Contact: info@photo-clean.ru.

2. Your media stays on the device

The app requests operating-system permission to review, compare, edit, and delete media with your confirmation. Media contents are not sent to the account or billing databases. Technical media identifiers, decisions, and statistics remain in the app sandbox.

3. Server data

For sign-in, the server receives a normalized phone number over TLS and sends it to the SMS provider solely to deliver a one-time code. The Accounts database stores only a keyed HMAC of the number, its last four digits, account UUID, language, verification time, sessions, accepted document versions, support messages, and security events. Billing data is stored separately and may include a pseudonymous account UUID, plan, purchase source, status, subscription period, renewal state, transaction identifiers, and amounts. CleanPhoto does not receive or store full card details, CVV, or Apple Account credentials.

4. Demo access

Without registration, the device counts the first 100 unique media items on which you make a decision. If you sign in, only an aggregate reviewed count may be sent to the server—never media contents or library identifiers.

5. Purposes and legal bases

We process data to create and secure accounts, perform the user agreement, provide and renew Premium, prevent abuse, provide support, comply with law, and protect users and the operator. Legal bases include contract, consent where required, and legal obligations. Marketing requires separate consent.

6. Separated storage and Russian localization

Identity and billing use two physically separate PostgreSQL databases and credentials. Billing uses a pseudonymous UUID and does not store the phone number; only the server API links the records. Data initially collected from Russian citizens is recorded and stored in databases located in the Russian Federation.

7. Processors and international transfers

Apple processes iOS purchases under its own terms. Robokassa and the acquiring bank will process website payments after integration. One-time authentication codes are planned to be delivered by Stream Telecom (an Omnicom platform), which receives the destination number and authorization-message text and processes technical delivery logs under its contract and policies. SMS registration will remain disabled until the provider agreement, sender name, and authorization template are approved. Apple may process its own customer data outside Russia; CleanPhoto links purchases using a pseudonymous identifier rather than the account phone number. Other international transfers require a valid legal basis and applicable procedures.

8. Cookies and sessions

The account portal uses strictly necessary secure cookies or session tokens for sign-in and request protection. On public pages, and only after separate consent, CleanPhoto loads Yandex Metrica (counter 111025669, including Session Replay, click maps and link tracking) and Google Analytics (stream G-R7VYQPZQWL). Under their respective policies, these providers may process the page URL, referrer, page interactions, browser and device attributes, IP address and approximate location. Sign-in and account pages are excluded, and phone or one-time-code field contents are not recorded. Analytics is not used for advertising personalization. Visitors can refuse or change their choice through Cookie settings in the site footer; analytics scripts do not load before consent.

9. Retention and deletion

Accounts remain until deletion. SMS challenges remain until expiry or revocation; sessions expire after 30 days of inactivity and no later than 180 days without reauthentication unless revoked earlier. Security events are generally retained up to 12 months and support correspondence up to 3 years unless needed for a dispute. Payment and accounting records remain for the statutory period. Deletion is normally completed within 30 days, except where law requires retention.

10. Security

Controls include encrypted transport, separate database roles, keyed HMACs for phone lookup and one-time codes, rotating refresh tokens, system-protected mobile storage, rate limits, administrative audit logs, encrypted backups, and least privilege. Raw SMS codes and full phone numbers are not stored in the Accounts database. Client apps never receive database, SMS-provider, or payment secrets.

11. Your rights

You may request access, correction, restriction, export, or deletion, withdraw consent, and terminate sessions by contacting info@photo-clean.ru. Account deletion will also be available in the app and portal. Withdrawal does not affect prior lawful processing.

12. Children, changes, and contact

The service is not directed at collecting children’s data. Users who require guardian consent must obtain it before registering. Material changes receive a new effective date and, where required, renewed acceptance. Privacy and subscription questions: info@photo-clean.ru.