PRIVACY POLICY
Your photos, your account, clearly explained.
This policy explains what the current Figory application collects and does when you use the service.
Last updated: 22 September 2026
1. Who we are
Top Trenz UK Ltd, trading as Figory, is the relevant controller for the service where it decides why and how personal data is processed. Company number: 06481792. Registered office: 40 Ffordd Byrnwr Gwair, Mold, Clwyd, Wales, CH7 1FQ. For privacy enquiries, email hello@myfigory.com. View our Companies House record.
2. Information we collect
Depending on the feature, this includes account email and authentication data; names, addresses and telephone numbers supplied for orders; uploads and information visible in them, including people, children, pets and vehicles; privacy-reduced source references; generated images, previews and 3D models; support reasons and access records; support and order information; payment transaction metadata; IP and security information; legal-policy confirmations; privacy preferences; and, with Marketing consent, a referral cookie. After Analytics consent on the production website, Google Analytics may process page views, interactions, device/browser information and approximate location derived from network information.
3. How and why we use it
We use data to create and save the requested assets, administer accounts and Credits, take payment, fulfil physical orders, prevent misuse, respond to support requests, keep records and improve reliability. When you ask for help with an output, an authorised administrator may compare it with a time-limited source reference to investigate the issue. That access is restricted, purpose-bound and recorded. The likely UK GDPR bases are contract, legitimate interests and legal obligation; consent is used where the flow specifically asks for it, such as the upload-rights confirmation. The exact lawful basis for images depicting third parties needs legal confirmation.
4. Uploaded images and AI processing
Images, photographs and other content you upload may be processed by trusted artificial intelligence, image-processing and 3D modelling service providers where necessary to create, process or improve the digital model or personalised product you request. After a successful Digital Double creation, Figory may retain a metadata-free, size-limited JPEG copy of each source photograph in private storage for the support period described below. Generated assets may be stored with cloud hosting and storage providers alongside related account and job records. We do not promise that every provider uses zero-retention or no-training settings; provider retention, training settings and transfer safeguards are reviewed through our internal compliance records.
5. Children and young people
Figory is not designed for use by children under the age of 13 without the involvement of a parent or legal guardian. If you are under 13, a parent or legal guardian should use the service and place any order on your behalf. Users aged between 13 and 17 should have the permission of a parent or legal guardian before using Figory or placing an order.
Where we process personal information relating to children or young people, we take additional care to handle it fairly, transparently and appropriately. An uploaded photo may show a child or another person who is not the customer, including where Figory is used to create a gift. The person uploading it must have the permissions required by our Upload & Rights Policy. A person shown in a photo can contact Figory through the customer-service route to ask about their data and rights. Figory does not intentionally market the service specifically to children, and customers should avoid providing unnecessary personal information.
6. Service providers and transfers
We use Supabase for account management and application data, Cloudflare for Worker infrastructure, private file storage, queues and transactional email, Stripe for payment processing, Google Analytics for consent-gated production audience measurement, and configured providers for photo checks, image generation and 3D generation. Supabase Auth sends account and security emails through the configured Supabase mail transport; Figory transactional notifications use Cloudflare Email Service. Some providers may process data outside the UK. The applicable locations and transfer safeguards depend on the deployed accounts and contracts and should be confirmed before publication. We do not describe a printer or fulfilment provider until one is actually integrated.
7. Retention and deletion
Privacy-reduced source references are normally kept for 90 days after they are saved and are then scheduled for automatic deletion from private storage. Viewing a reference does not extend that period. A source reference is deleted earlier when the customer deletes the last linked Digital Double, or when a verified erasure request applies.
When you approve a physical Figory, we keep a private copy of the approved print package and the preview files, together with the approval time and associated order record. These copies help us manufacture the agreed model and investigate order or consumer-rights disputes. Approval copies that are not linked to an order are scheduled for deletion after 30 days. Copies linked to an order are separate from your editable library and may remain after you remove a library model, subject to applicable retention and erasure rights.
A source reference may exceptionally be preserved for a documented legal claim, dispute or regulatory obligation until a recorded review date. Generated library assets remain available until the customer deletes them or the account is erased, subject to applicable exceptions. Order, payment, rights-confirmation, security, fraud, access-log and backup records may need different periods. We review those periods and do not use them as a reason to retain source images automatically.
8. Security
The Worker keeps provider secrets server-side, checks authenticated ownership before private asset access, and uses private R2 storage. Source references have no public or download link: an authorised administrator must provide a support reason before previewing one, and the access is recorded. Private file responses are non-cacheable. These are reasonable measures, not a guarantee. No service is completely secure.
9. Your rights and complaints
Subject to legal conditions, you may ask for access, correction, erasure, restriction, objection or portability, and withdraw consent where consent is the basis. Rights relating to automated decision-making may apply where relevant. Contact Figory through the customer-service route shown on the site to make a privacy request; you can also complain to the Information Commissioner’s Office.
10. Marketing, cookies and changes
Transactional account, generation and order messages are service communications, not marketing consent. Google Analytics is used only after Analytics consent and does not enable advertising consent. With Marketing consent, the app may use a referral cookie named mimora_ref for creator/affiliate attribution. Account authentication uses Necessary browser storage. You can change or withdraw optional choices through Cookie settings. See our Cookie Policy. We will publish policy changes there and communicate significant changes where appropriate.



