Privacy
Your iris photo is used to make your art. That’s it.
That’s the promise. What follows is the policy behind it — who we are, what we collect, why we’re allowed to, who helps us, how long we keep it, and how to make us stop.
Who is responsible
EyeJoy is a trading name of Mad Growth BV. Mad Growth BV is the controller of the personal data described on this page.
Mad Growth BV
[[REGISTERED_ADDRESS]]
Amsterdam, the Netherlands
KvK 87186136 · BTW NL004370105B09
Anything about your data — a question, a copy, a deletion — goes to privacy@eyejoy.art. We’re a small studio and we haven’t appointed a data protection officer; that address reaches us directly.
Your iris photo, and why we ask permission for it
A close-up photograph of an iris can be biometric data — a special category under Article 9 of the GDPR — because in the wrong hands it could be used to recognise someone.
We don’t do that with it. Your photo is never matched against another image, never turned into a biometric template, never used to identify or verify anyone. It exists to make one artwork.
Because it can still count as special-category data, we rely on your explicit consent under Article 9(2)(a) — given when you upload the photo and carry on through the flow — alongside Article 6(1)(a). You can withdraw that consent whenever you like by writing to privacy@eyejoy.art. Withdrawing doesn’t undo a render that already happened, and it doesn’t take back an artwork you’ve already paid for.
What actually happens to the photo
- It reaches our server and is held in memory — nothing more.
- It’s sent to OpenAI’s image model, which renders the iris artwork. That is the only place it goes. If OpenAI fails or is unreachable, the render simply fails and you are not charged — your photo is not sent anywhere else.
- It is never written to disk and never written to our database. When the render finishes — or fails — the copy in memory goes with it.
- The generated artwork, not your photo, is then sent to Replicate to be upscaled, and stored in our database so a paid download keeps working later.
- Nobody at EyeJoy looks at your photo along the way. The render is automatic from upload to finished file. We only ever see an image if you email one to us yourself.
The image providers act as our processors under their data-processing terms: they render for us and may not use your photo for their own purposes. Their own abuse-monitoring systems may hold a short-lived copy on their side, which is governed by their terms rather than ours.
What we never do
- We never use your photo to identify you or anyone else.
- We never use it to train any AI or machine-learning model, and under the business terms of the image providers we use, data sent through their APIs isn’t used to train their models either.
- We never sell it, and we never share it with advertisers or data brokers.
- Advertisers and analytics tools never receive your source photo or your finished artwork.
- There is no profiling and no automated decision-making that has a legal effect on you.
What we collect, and on what basis
- Your iris photo — to render the artwork you asked for. Consent, Article 6(1)(a), plus explicit consent under Article 9(2)(a).
- Your order and email address — to take payment, deliver the files, and answer you if something breaks. Performance of our contract with you, Article 6(1)(b). Keeping the accounting record afterwards is a legal obligation, Article 6(1)(c).
- Your account, if you make one — email address, sign-in codes, session records. Article 6(1)(b).
- Your IP address, an anonymous device id, and a bot check — every render costs us real money at an image provider, so we count them and block abuse. Our legitimate interest in preventing fraud and cost abuse, Article 6(1)(f).
- Technical error reports — so a broken checkout or render surfaces instead of silently failing. Article 6(1)(f).
- Analytics and advertising events — only if you accept them in the cookie banner. Consent, Article 6(1)(a).
- Your email on the waitlist, if you joined one. Consent, Article 6(1)(a).
Who processes it with us
These are every provider that touches your data, what they do, what reaches them, and where they process it.
- OpenAI — renders the artwork. Receives your iris photo and our prompt. United States.
- Replicate — upscales the finished artwork and hosts the upscaled file. Receives the generated artwork, never your photo. United States.
- Stripe — takes the payment. Receives your email address, your card and billing details (entered on Stripe’s own page — we never see a card number), the amount, and your IP address. Ireland and the United States.
- Resend — sends your sign-in code and your download email. Receives your email address and the contents of that message. United States.
- Cloudflare (Turnstile) — the “are you a person” check before a free render. Receives your IP address and browser signals. Global network, including the United States.
- PostHog — product analytics, only after you accept. Receives event names, page URLs, and a SHA-256 hash of your email address as the identifier rather than the address itself. Session recording and autocapture are switched off, so it never receives your artwork or the contents of the pages you see. European Union.
- Meta — advertising measurement, only after you accept. Receives your IP address, browser user-agent, page URL, the event and its value, and a SHA-256 hash of your email address rather than the address itself. Ireland and the United States.
- TikTok — advertising measurement, only after you accept. Receives the same set as Meta, with the email address likewise hashed. Ireland and the United States.
- Sentry — error monitoring, when enabled. Receives crash details, the URL, and your IP address. No session recording. United States.
- Hetzner — hosts our application and our database. Everything we store lives here. Germany.
- Gelato — print production. Not used for the €29 digital pack; it only receives a name, a delivery address and a print file if we ever ship you a physical piece. Norway (European Economic Area).
Accounts are our own: sign-in runs on our server and our database, not on a third-party identity service. If you choose to sign in with Google or Apple instead of an email code, that provider tells us your email address. Analytics and advertising tools load only after you accept them, and a tool we haven’t configured never loads at all.
Data leaving the EU
Several providers above process data outside the European Union, mostly in the United States. Where they do, the transfer rests on the European Commission’s Standard Contractual Clauses in that provider’s data-processing terms — and, where the provider is certified, on the EU–U.S. Data Privacy Framework. Ask us and we’ll tell you which applies to which.
How long we keep things
- Your iris photo — not kept at all. It lives in memory for the length of the render (three minutes at the very most) and is gone when the render ends.
- The generated artwork and its technical record — deleted 14 days after the last activity on it. One exception, and it’s worth being plain about: if the artwork belongs to a paid order, we currently keep it indefinitely so you can re-download it whenever you like. Ask us and we’ll delete it.
- Order records — email address, amount, status, Stripe reference. Kept for as long as Dutch tax law requires us to keep our books, which is seven years.
- Account records — for as long as you keep the account.
- A small photo-quality report — measurements only, no image data, used to tune the pipeline. Deleted after 30 days.
- Anti-abuse counters — a date, an IP address or device id, and a number, so a free render can’t be farmed. The IP-linked counters are deleted after 7 days. The device and account counters have no date on them and are kept while the allowance applies; ask us and we’ll clear yours.
- A waitlist email address — until the thing you asked about launches, or until you ask us to remove it.
Cookies
- ej_consent — 180 days. Remembers whether you accepted or declined analytics and advertising. Ours.
- ej_did — one year, HttpOnly. An anonymous device id so we can tell whether this browser has already used its free render. Ours.
- The Better Auth session cookie — only if you sign in. Keeps you signed in; it disappears when you sign out or the session expires. Ours.
- _fbp and _fbc (Meta), _ttp (TikTok), and PostHog’s own cookies — set only after you accept them in the banner. Decline and they never appear.
The banner asks once. To change your answer at any time, use Cookie settings at the bottom of any page — the banner comes straight back and your previous choice is discarded.
Your rights
- Access — a copy of what we hold about you.
- Rectification — fix anything that’s wrong.
- Erasure — delete it, except the parts we’re legally required to keep.
- Portability — your data in a machine-readable file.
- Restriction — pause what we do with it while something is disputed.
- Objection — object to anything we do on a legitimate-interest basis.
- Withdrawal of consent — for the iris photo, for analytics, for the waitlist, at any time.
Write to privacy@eyejoy.art and we’ll answer within one month. We may ask a question or two to be sure you’re the person whose data it is — usually the email address used at checkout is enough.
If we get it wrong, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens. We’d rather you told us first, but the right is yours either way.
Children
EyeJoy isn’t made for children. Don’t upload a photo of a child’s eye unless you’re their parent or guardian and you’re giving that consent on their behalf.
We’re an art studio, not a data product
That sentence is the whole policy in miniature. We make one thing — a one-of-one artwork — and your photo exists only to make it. Nothing about our business depends on keeping or mining your data.
Changes
If we change how any of this works, we’ll change this page and move the date below. Material changes to how we use your photo will be put to you, not slipped past you.
Last updated: 26 July 2026. EyeJoy is operated by Mad Growth BV, Amsterdam.