Living Pages — privacy notice
Preview notice 2026-09-09-v4; public generation and purchases are closed. This version accompanies the adult-operated “Bring your drawings to life” preview when offered for acceptance. Android 0.11.0 adds illustrated guidance, drawing backup/import and private wallet screens. Wallet service deployment and store purchasing checks remain pending; the sections below distinguish these staged features. Android 0.10.1 and later use the personal Vercel preview. Older builds through 0.10.0 use Sites, which retains earlier cloud copies; installing an update does not delete them.
Who is responsible
Georgi Kostov, trading as Studio Kostov, Breitwiesenstraße 22, Tür 7, 4481 Asten, Austria, is responsible for the Living Pages service. Contact privacy@studiokostov.com. Further operator details are in the legal notice.
What stays on the phone
Camera frames used for scanning, local image tracking and the saved library stay on your device. We do not stream your camera to our servers. The app has no public feed or app-hosted cloud library. You can delete saved pages in the library. Automatic Android backup and device transfer of app data are excluded by app configuration; device loss or uninstall may permanently remove saved media.
Android 0.11.0 offers Settings → Back up or import drawings. A backup contains saved reference pictures, videos, names and drawing metadata, but no credit balance or wallet credentials. You select its destination using the system file picker. Anyone with the file can read its contents. If you choose a cloud drive or send the file to someone, that service or recipient receives your copy under its own arrangements. Keep a backup off the phone to protect against phone loss. Import rebuilds local tracking information; it does not restore files that were never backed up. Native iOS backup compatibility has not been tested.
The introduction's adult acknowledgement is remembered locally; it does not create a child profile, collect an age/date of birth or accept the separate cloud-upload terms. Library names are stored locally and in any backup you export; they are not sent with generation requests.
Private wallet and store purchases
When wallet registration is available, you can create a private wallet without an email address or password. The app creates a random wallet identifier and separate access and recovery secrets. Credentials are encrypted on this Android device with an Android Keystore key. The service stores hashes of the secrets, the identifier and credit/service records. These records are pseudonymous personal data, not anonymous information. A salted daily network-address hash limits wallet creation and is cleared after the short admission window (up to two calendar days).
Save the separate wallet recovery file somewhere private away from the phone. Anyone holding its code can take over the wallet. Recovery changes the access secret and disconnects the previous device; it keeps the remaining server balance and does not merge wallets or restore drawings. Losing every access/recovery credential can prevent us from verifying ownership. A store receipt alone does not establish the remaining credit balance.
When store purchasing is enabled and you open the credit shop, RevenueCat receives the wallet identifier, purchase/receipt information and technical connection/app/device information needed to verify purchases. Google Play handles Android checkout and payment details. We do not send drawings or wallet access/recovery secrets to RevenueCat. Optional SDK diagnostics and automatic device-identifier collection are disabled; the app does not set advertising-attribution, email or telephone attributes. These settings do not mean the payment service receives no technical data. RevenueCat's applicable processing terms and retention must be recorded before paid launch.
Settings → Credit wallet and recovery → Close wallet and request deletion revokes wallet access and recovery and queues a service-data erasure request when the wallet service is available. It does not claim immediate erasure of all supplier or financial records, automatically refund purchases, or delete local drawings/exported backups. Keep the wallet ID for follow-up with privacy@studiokostov.com. The operator reviews the request and explains the outcome and any required retention.
Parents and children's drawings
Living Pages is operated by adults, including parents or guardians animating their children's original drawings. The adult handles scanning, chooses the crop and approves cloud processing. Children can create on paper and watch a result the adult has reviewed. We do not offer child accounts, profiles, chat or a public feed, and do not ask for a child's name, age, school or photograph.
Before scanning, cover names, signatures, school labels and personal details; keep people and personal photographs out of the crop. Choose imaginary subjects without sensitive or identifying details. The app does not automatically redact them. A drawing can still identify or reveal information about someone, including through its contents or its connection with other records. A child's artwork is not automatically anonymous just because it is a drawing.
The adult's contract and rights declaration do not automatically establish a legal basis for every child's or third party's personal data. We restrict inputs to minimise this information; sensitive or identifying child content and classroom collections are outside the intended preview. If you think personal information or a child's independent use has reached the service, contact privacy@studiokostov.com without attaching the drawing by default. We investigate, restrict inappropriate access and handle deletion and any lawful retention as required. This notice does not claim that an adult checkbox removes children's privacy obligations.
What is sent when you request an animation
After you review a crop and explicitly choose generation, the selected still picture travels over an encrypted connection to our Vercel API and the AI providers shown in the upload notice. We send the picture with a short, fixed motion instruction to generate an animation. We do not send the surrounding camera stream or your local marker library. The resulting video is temporarily processed for delivery to your device.
Android 0.10.4 and the current Vercel API use only direct fal H3 video generation. There is no separate image-analysis request. Earlier comparison builds offered OpenAI or fal MoonDream analysis; removing those routes does not erase data already processed under the earlier notices. A future change of provider requires an updated notice and permission where applicable.
Service records and purposes
| Information | Purpose and proposed legal basis |
|---|---|
| Account identifier and sign-in information | Protect purchases and access; performance of the account contract |
| Selected image, temporary description/prompt and generated result | Fulfil the requested animation; contract necessity for the user's ordinary personal data where applicable. The upload-permission checkbox is a product permission and provider disclosure, not a claim that the user can consent for everyone pictured |
| Job identifier, selected options, timestamps, status and temporary provider request reference | Deliver, reconcile and delete the requested generation; contract and proportionate security interests |
| Purchase identifiers, credit reservations, balance and transaction records | Supply paid services, prevent duplicate crediting and comply with applicable accounting obligations |
| Minimal connection/security records, including IP data held by infrastructure providers | Protect the service; documented legitimate interests |
| Information deliberately submitted in a support, privacy-rights or safety request | Resolve the request, investigate misuse and meet legal duties; contract, legitimate interests or legal obligation as appropriate |
| Version and time of terms acceptance | Record the agreed service; contract and accountability. Android 0.10.3 and later remember the accepted version and approved AI routes on the device, scoped to the service/account credential. Each upload still confirms rights and AI processing to the API; version 0.10.5 also records the agreed version, first acceptance time and adult/rights/AI declarations on the server, without retaining an ID document, date of birth, licence file or an image as evidence |
We do not sell personal information or operate advertising, tracking analytics or session replay in the production design. We do not train our own models on scans. Any claim about provider training is limited to the applicable contractual coverage for the exact endpoints.
A picture can contain someone else's personal data. Your contract does not automatically provide a legal basis for processing another person's data, and you cannot give consent on behalf of every person pictured. The permitted-input rules therefore restrict what may be uploaded. Sensitive documents and sensitive personal content are not supported. A photograph is not automatically biometric identification data; Living Pages does not identify people or infer sensitive traits for tracking.
Providers and international transfers
Vercel hosts the API with a Frankfurt function region. Neon hosts account and service metadata in Frankfurt; the new private wallet route authenticates against stored credential hashes. fal supplies H3 video inference. The current service does not send new crops to OpenAI or MoonDream; earlier comparison requests may have used them as described above. RevenueCat provides purchase verification when enabled; Google processes Android store payments. Native iOS and Apple purchasing are not implemented. Studio Kostov's email provider processes email you send to support.
Android AR uses Google Play Services for AR (ARCore), which processes information under Google's privacy policy. This preview uses local image tracking, not Cloud Anchors or Geospatial features. Local tracking does not mean Google receives no service/device information. The app's introduction and Privacy screen disclose ARCore and link to Google's policy.
An EU hosting region does not mean every provider's support, security or inference processing stays within the EU. International processing must be covered by applicable adequacy decisions or contractual safeguards, including the relevant Standard Contractual Clauses where required. Copies of the relevant safeguards can be requested from privacy@studiokostov.com, with confidential information protected. The completed processor register must identify actual contracting entities, regions, subprocessors and safeguards before launch.
Retention
The preview implements the following application controls. One H3 output passed restricted delivery and immediate deletion verification on 9 September 2026. One-hour provider expiry, provider-internal retention and all failure cases have not been independently verified. Complete the remaining contractual and operational evidence before activating the paid service:
| Data | Target treatment |
|---|---|
| Our copy of an input, motion instruction or output | Process in memory for the request; no application media bucket or durable content log |
| fal request history | Request history opt-out on inference calls; confirm exact endpoint handling |
| fal temporary output | Restricted access; request one-hour expiry and earlier deletion after verified local save; retry failed cleanup independently of the phone |
| Active delivery metadata | One-hour delivery window; remove media/request references after confirmed cleanup and purge cleaned jobs after 24 hours; minimal duplicate-request/credit records remain |
| Ambiguous submissions without a provider reference | Refund upon application expiry; remove the expired application job after 30 days. This does not certify deletion of unknown provider copies. Known-provider cleanup failures remain subject to retry and documented operational review |
| Accounts and credit records | Account lifetime plus necessary legal/financial retention; deletion does not require destruction of legally required records |
| In-app reports | Delete 30 days after creation; email correspondence follows the mailbox policy, still to be confirmed |
| Privacy requests | Keep open requests until resolved; a normal reply deadline is one calendar month. Remove the request record 30 days after resolution, unless a separately documented legal obligation requires a case record |
| Acceptance records | Account-linked policy version, declarations and timestamp; keep while needed for the active service and include in the account-erasure assessment |
| Infrastructure logs and backups | Provider-specific periods in the final register; deletion from the live database does not instantly remove backup copies |
AI providers may retain some security, billing or legally required information separately. Their exact exceptions must be disclosed from the applicable agreements. We cannot promise that third parties keep no information at all.
Your choices and rights
You may decline each cloud upload and keep using available local features. In Android 0.10.3 and later, first-use permission checkboxes start unchecked. Accepted terms and approved AI routes are remembered on this device until reset, a relevant version/account/service change, or removal of app data. A previously unapproved AI route asks for permission once. Every image still requires your explicit Create loop action, with the route and rights reminder shown in the cost review. Use Privacy → Reset upload permissions to require fresh approval; it does not undo already submitted processing. Delete local saved media through the library. Contact privacy@studiokostov.com for access, correction, portability, restriction, objection or an erasure request. Privacy → Privacy requests accepts access, correction, erasure, restriction and objection requests and provides a receipt and status. Erasure, restriction and objection requests stop new generation while handled; submitted work may finish. Requests are reviewed by Studio Kostov, not silently treated as completed deletion. The private wallet features described above are staged for coordinated service deployment; complete service/provider erasure operations before public wallet launch. We verify identity proportionately and normally respond within one month; lawful extensions will be explained.
You may complain to the Austrian Data Protection Authority at dsb.gv.at or another competent EU supervisory authority. We do not make decisions about you with legal or similarly significant effects using the animation model. We use appropriate access controls and encrypted transmission, and handle personal-data breaches under applicable notification rules.