PRIVACY POLICY
Your photos, your account, clearly explained.
This policy explains what the current Figory application collects and does when you use the service.
Last updated: 18 August 2026
1. Who we are
Top Trenz UK Ltd, trading as Figory, is the relevant controller for the service where it decides why and how personal data is processed. The registered number, office address and privacy contact email are not confirmed in this project and must be added before publication.
2. Information we collect
Depending on the feature, this includes account email and authentication data; names, addresses and telephone numbers supplied for orders; uploads and information visible in them, including people, children, dogs and vehicles; generated images, previews and 3D models; support and order information; payment transaction metadata; IP and security information; legal-policy confirmations; and a referral cookie. No analytics or advertising pixel was identified in the application search.
3. How and why we use it
We use data to create and save the requested assets, administer accounts and Credits, take payment, fulfil physical orders, prevent misuse, respond to support requests, keep records and improve reliability. The likely UK GDPR bases are contract, legitimate interests and legal obligation; consent is used where the flow specifically asks for it, such as the upload-rights confirmation. The exact lawful basis for images depicting third parties needs legal confirmation.
4. Uploaded images and AI processing
Images, photographs and other content you upload may be processed by trusted artificial intelligence, image-processing and 3D modelling service providers where necessary to create, process or improve the digital model or personalised product you request. Generated assets may be stored with cloud hosting and storage providers alongside related account and job records. We do not promise that every provider uses zero-retention or no-training settings; provider retention, training settings and transfer safeguards are reviewed through our internal compliance records.
5. Children and young people
Figory is not designed for use by children under the age of 13 without the involvement of a parent or legal guardian. If you are under 13, a parent or legal guardian should use the service and place any order on your behalf. Users aged between 13 and 17 should have the permission of a parent or legal guardian before using Figory or placing an order.
Where we process personal information relating to children or young people, we take additional care to handle it fairly, transparently and appropriately. An uploaded photo may show a child or another person who is not the customer, including where Figory is used to create a gift. The person uploading it must have the permissions required by our Upload & Rights Policy. A person shown in a photo can contact Figory through the customer-service route to ask about their data and rights. Figory does not intentionally market the service specifically to children, and customers should avoid providing unnecessary personal information.
6. Service providers and transfers
We use service providers for account management, application data, private file storage, payment processing, photo checks, image generation and 3D generation. Some providers may process data outside the UK. The applicable locations and transfer safeguards depend on the deployed accounts and contracts and should be confirmed before publication. We do not currently identify email, fulfilment, analytics or customer-support providers in the application.
7. Retention and deletion
The application supports customer deletion of selected private library assets, removing their R2 objects and related visible records. It does not expose a complete account-wide retention schedule. The retention periods for source photos, generated assets, D1 jobs, order and financial records, policy confirmations, validation cache, logs and backups are therefore implementation gaps. Do not promise immediate deletion where legal records, fraud evidence or backups remain.
8. Security
The Worker keeps provider secrets server-side, checks authenticated ownership before private asset access, and uses private R2 storage. These are reasonable measures, not a guarantee. No service is completely secure.
9. Your rights and complaints
Subject to legal conditions, you may ask for access, correction, erasure, restriction, objection or portability, and withdraw consent where consent is the basis. Rights relating to automated decision-making may apply where relevant. Contact Figory first using the confirmed privacy contact route; you can also complain to the Information Commissioner’s Office.
10. Marketing, cookies and changes
Transactional account, generation and order messages are service communications, not marketing consent. No marketing-email provider or non-essential tracking technology was identified in the codebase. The app uses a referral cookie named mimora_ref for attribution; account authentication also uses browser-based session storage. See our Cookie Policy. We will publish policy changes there and communicate significant changes where appropriate.
