Privacy Policy
Last updated: 2026-08-19
This Privacy Policy explains how Linewright handles data in the Linewright iPad app, TestFlight beta, and related support channels.
Linewright is built around two routes:
- Local route - the core stencil workflow runs on the iPad.
- AI route - optional signed-in cloud help for selected reference material, including AI Reference Analysis and AI Quick Stencil when enabled.
This policy is written for the beta version of Linewright. It will be updated before public launch if the app, account model, providers, payments, analytics, or cloud features change.
1. Who we are
Linewright is operated by Linewright Ltd, a UK private limited company (company number 17381029).
Privacy: privacy@linewright.app
Support: support@linewright.app
Website: https://www.linewright.app
2. What Linewright does
Linewright helps tattooists prepare stencil work on iPad.
The app can be used to:
- create and manage local tattoo project shells;
- import reference images and finished stencils from Photos or Files;
- prepare stencil drafts through local deterministic tools;
- use AI Reference Analysis for recommendations on selected references when signed in and enabled;
- use AI Quick Stencil to create AI Draft candidates from selected references when signed in and enabled;
- edit, size, tile, mirror, and export stencil output;
- preview placement on generic body display models;
- save local notes, placement recipes, stencil sessions, exports, and evidence packs.
Linewright is not a public social network, client chat app, booking system, CRM, cloud backup product, or hosted review platform in this beta.
3. The local route
Most Linewright work stays on the iPad.
The following are stored locally in the app’s iPad storage for the beta:
- projects;
- local client labels and project notes;
- imported references;
- generated stencil drafts;
- stencil edit sessions;
- saved stencil versions;
- exported files;
- placement recipes;
- evidence packs.
Signing in does not automatically upload local projects, references, stencils, notes, exports, placement recipes, or evidence packs to Linewright servers.
Deleting your Linewright account does not automatically delete files already stored on your iPad. To remove local iPad files, delete them in the app where available, or remove the app from the device.
4. When data leaves the device
Data may leave the iPad only in these situations:
| Situation | What may be sent | Why |
|---|---|---|
| Sign in with Apple or Google | OAuth account data such as account identifier, email where supplied, session tokens, IP address, and user agent | To let you use signed-in account and AI features |
| AI Data Use authority | Account identifier, current/accepted disclosure version, accepted or withdrawn status, accepted/withdrawn times, and audit timestamps | To require one current account-level acknowledgement before new image-bearing AI work and to honour withdrawal |
| AI Reference Analysis | A reduced, metadata-stripped copy of the selected reference image plus bounded source diagnostics | To return stencil-prep recommendations when you explicitly request or enable analysis |
| AI Quick Stencil | A reduced, metadata-stripped provider-input copy of the selected reference image, canvas dimensions, prompt/profile information, source diagnostics, and run/credit identifiers | To generate an AI Draft when you explicitly request it and recover dropped paid runs |
| AI credits and usage | Credit balance, quote, reservation, run, finalize, cancel, refund, and usage records | To prevent double charging, recover runs, and enforce AI caps |
| Account deletion | Signed-in account identifier and deletion request | To delete the cloud account and retained AI/account records |
| Support | Whatever you send to support, such as email address, device/build details, screenshots, and message content | To respond to support requests |
| TestFlight feedback | Feedback, screenshots, crash/session details, and tester information made available through Apple TestFlight | To diagnose beta issues |
| Studio accounts interest on linewright.app | The email address you submit, plus a salted one-way hash of your connection address used only for rate limiting | To email you when multi-seat studio accounts open and to keep the public form abuse-resistant |
| Solo launch list on linewright.app | The email address you submit; optional short campaign labels carried by the link you followed (for example utm_source) and the referring site’s hostname; plus a salted one-way hash of your connection address used only for rate limiting |
To send you one email when the Linewright Solo trial is ready, to understand which channel brought you (first-party only — no cookies, tracking pixels, or third-party analytics), and to keep the public form abuse-resistant |
5. AI Reference Analysis
AI Reference Analysis is optional and analysis-only. It can inspect a selected reference and return Clean or Generate recommendations.
AI Reference Analysis does not create an AI Draft, does not spend credits, and does not automatically start AI Quick Stencil.
Before preparing or sending source bytes, Linewright checks that the signed-in account accepted the current AI Data Use disclosure version. After that acknowledgement, selected body or placement photos, client-supplied references, existing tattoo photos, and private or commissioned designs may be analysed when the tattooist has the right, permission, or authority to process them.
Linewright does not send client identity/contact information, project history/IDs, hosted review links/assets, editable stencil history, notes, placement recipes, evidence packs, unrelated project files, private image metadata, or raw support diagnostics through AI Reference Analysis.
6. AI Quick Stencil
AI Quick Stencil is optional. It runs only after the artist chooses an AI action such as Create AI draft or Generate AI draft, and only after a live server check confirms current account-level AI Data Use authority.
When you use AI Quick Stencil, Linewright sends a reduced, metadata-stripped copy of the selected reference image through Linewright’s backend proxy to an enabled AI image provider.
After acknowledgement, eligible selected images include body or placement photos, client-supplied references, existing tattoo photos, and private or commissioned designs when the tattooist has the right, permission, or authority to process them.
Linewright does not send this unrelated context through AI Quick Stencil:
- client identity or contact information;
- full project history;
- project IDs;
- hosted review links or review assets;
- editable stencil session history;
- undo/redo state;
- local notes;
- placement recipes;
- evidence packs;
- unrelated project files;
- private image metadata;
- raw support diagnostics.
The AI provider returns image output. Linewright stores the returned raw provider output temporarily in private storage so a paid run can be recovered if the app loses connection after the provider succeeds. The app then validates and converts the output locally into an AI Draft candidate that the artist can inspect, edit, size, and export like other stencil candidates.
Current beta AI provider routes may include Google, OpenAI, and xAI, depending on backend feature flags. The app may show task/detail labels rather than provider company names inside the workflow.
Do not use AI Quick Stencil for any image you do not have the right, permission, or authority to process with a third-party AI provider.
More detail: AI Data Use.
7. What Linewright does not do in this beta
Linewright does not currently:
- sell personal data;
- use third-party advertising;
- use third-party tracking SDKs;
- use behavioural analytics SDKs;
- use ad identifiers;
- upload local projects to cloud storage;
- provide cloud sync, cloud backup, or cloud restore;
- provide hosted project rooms or client review links;
- give clients or reviewers AI generation controls.
If any of these change, this policy must be updated before the changed build is submitted or released.
8. Account data
If you sign in, Linewright uses Supabase Auth with Sign in with Apple and/or Google.
Supabase may store account and session records such as:
- account ID;
- provider identity;
- email address where the provider supplies it;
- session and refresh-token records;
- IP address and user agent associated with session activity;
- timestamps for account/session events.
The iPad app stores signed-in session tokens in the iOS Keychain. Local-only users do not create a Supabase account.
9. AI credits and run records
When AI Quick Stencil is enabled, Linewright keeps server-side records for AI credits and AI runs, including:
- credit balance;
- quote and reservation records;
- ledger entries for reserve, finalize, cancel, refund, or usage events;
- AI run identifiers;
- provider/model routing metadata;
- cost snapshots;
- run status and client-result status.
These records are used to charge credits correctly, avoid duplicate charges on retry, recover completed output, enforce caps, and support account deletion.
10. Photos, Files, and imported material
Linewright may ask for access to Photos when you choose to import a reference or stencil source from Photos. The app may also use Apple’s file picker when you choose to import from Files.
Imported references and stencil sources are stored locally in the app’s iPad storage unless you explicitly use an AI lane on a selected reference.
When the app prepares an image for AI, it uses a reduced copy intended for the provider request, not the full local project folder.
11. Support and beta feedback
If you contact support, Linewright processes the information you choose to send. This may include your email address, issue description, screenshots, device details, iPadOS version, TestFlight build number, and any attachments you include.
Do not send body photos, client-private material, confidential client references, or private studio records through support unless support specifically asks for a safe redacted example.
Apple TestFlight may provide Linewright with tester feedback, screenshots, session information, crash information, and tester details depending on how the tester was invited and how feedback was submitted.
Studio accounts interest
The linewright.app site offers an optional signup to hear when multi-seat studio accounts open. If you submit it, Linewright stores your email address (normalised, once) so we can send you one email when studio accounts are available. Submitting the form is your consent to that single email; it is not used for any other marketing.
To keep the public form abuse-resistant, the backend also stores a salted one-way hash of the submitting connection address for rate limiting. The raw address is never stored and the hash is not used for anything else.
To be removed from the list at any time, reply to that email or contact privacy@linewright.app and the entry will be deleted.
Solo launch list
The linewright.app site also offers a separate optional signup to hear when the Linewright Solo plan and its trial are ready. If you submit it, Linewright stores your email address (normalised, once) so we can send you one launch email. Submitting the form is your consent to that single email; it is not used for any other marketing, and the Solo launch list and the studio-accounts interest list are never combined.
If the link you followed carried short campaign labels (for example
utm_source=instagram), the site stores those labels and the referring
site’s hostname with your signup so we can tell which channel brought you.
This is first-party measurement only: no cookies, tracking pixels, device
profiles, or third-party analytics are used, and a full referring URL is
never stored.
To keep the public form abuse-resistant, the backend also stores a salted one-way hash of the submitting connection address for rate limiting. The raw address is never stored and the hash is not used for anything else.
To be removed from the list at any time, reply to that email or contact privacy@linewright.app and the entry will be deleted.
12. Legal bases
Where UK GDPR or similar law applies, Linewright relies on these legal bases:
| Processing | Legal basis |
|---|---|
| Providing the app, account access, AI quotes, AI runs, credits, and account deletion | Contract or steps taken at your request |
| Security, abuse prevention, run recovery, credit integrity, diagnostics from support, and beta operation | Legitimate interests |
| Responding to support and privacy requests | Legitimate interests and legal obligation where applicable |
| Complying with legal duties | Legal obligation |
| Device permissions such as Photos access | Your action/permission through iOS controls |
| Studio accounts interest email | Consent (you submit the form asking to be told when studio accounts open) |
| Studio interest rate-limiting hash | Legitimate interests (abuse prevention on a public form) |
| Solo launch list email and optional campaign/referrer labels | Consent (you submit the form asking to be told when the Solo trial is ready; the first-party campaign labels arrive only with that submission) |
| Solo launch list rate-limiting hash | Legitimate interests (abuse prevention on a public form) |
| Other optional marketing, if added later | Consent or legitimate interests depending on the channel and law |
Linewright does not currently use personal data for third-party advertising or tracking.
13. Retention
Retention depends on the type of data:
| Data | Retention |
|---|---|
| Local iPad projects, references, stencils, exports, notes, placement recipes, and evidence packs | Until you delete them or remove the app/device data |
| Signed-in account data | Until account deletion or until no longer needed to operate the beta/account |
| AI credit ledger records | Kept as long as needed for credit integrity, accounting, support, abuse prevention, and deletion handling |
| AI source images sent for a provider request | Kept temporarily in private storage as reduced provider-input copies for paid-run recovery and deletion handling; not stored as project assets |
| Raw AI provider output | Kept temporarily in private storage for paid-run recovery, expiry cleanup, and deletion handling during beta |
| Support emails and attachments | Kept while handling the request and for a reasonable support/audit period |
| TestFlight feedback and crash/session data | Managed through Apple TestFlight and retained as needed for beta diagnostics |
| Studio accounts interest entries (email + rate-limit hash) | Until studio accounts open and we have contacted you, or you request deletion, whichever comes first |
| Solo launch list entries (email + campaign/referrer labels + rate-limit hash) | Until the Solo launch email is sent and the list is retired, or you request deletion, whichever comes first |
Before public launch or paid distribution, retention periods should be reviewed against the live backend cleanup process, support tooling, and legal entity requirements.
14. International processing
Linewright uses cloud services and AI providers that may process data outside the UK or your country. Where required, Linewright will rely on appropriate safeguards, provider terms, and transfer mechanisms.
Current beta subprocessors may include:
- Supabase - authentication, database, Edge Functions, storage for transient AI output, and account/AI records;
- Apple - TestFlight distribution, tester feedback, crash/session reporting, and Sign in with Apple;
- Google - Google sign-in and, if enabled, AI image processing;
- OpenAI - if enabled for AI image processing;
- xAI - if enabled for AI image processing;
- email/provider tools used for support, if configured.
This list should be reviewed before each external beta or public release.
15. Your choices and rights
Depending on where you live, you may have rights to:
- ask for a copy of personal data held about you;
- ask for incorrect data to be corrected;
- ask for deletion of personal data;
- object to some processing;
- restrict some processing;
- request data portability;
- withdraw consent where processing is based on consent;
- complain to a data protection authority.
To make a request, email privacy@linewright.app.
If you are in the UK, you can also complain to the Information Commissioner’s Office at https://ico.org.uk.
16. Account deletion
Signed-in users can request account deletion in the app:
Workspace account chip -> Settings -> Delete account
Account deletion removes the cloud account and retained account/AI credit records associated with that account. It does not remove local files already stored on your iPad.
Local-only users do not have a cloud account to delete.
17. Children
Linewright is intended for tattoo professionals, apprentices, and adult beta testers. It is not intended for children.
18. Changes to this policy
Linewright may update this Privacy Policy as the beta changes. The latest version will be posted on this page with the updated date.
Material changes should be made before submitting a build that changes privacy, permissions, AI routing, provider use, analytics, payments, account behavior, or cloud storage behavior.
19. Contact
Privacy: privacy@linewright.app
Support: support@linewright.app