Privacy Policy
Last updated: October 7, 2026
This Privacy Policy explains what information Deskria collects, how it's used, and the choices you have.
Deskria (deskria.top) is operated by Bojan Pavlukovic PR / Kreativni Kliker, Republic of Serbia, registration no. (MB) 67424042, PIB (tax ID) 114239265. We are the controller of the personal data described on this page. Contact: ask@deskria.top.
1. Information We Collect
- Account information: email address, password (stored as a secure hash), optionally your name, and whether and when you confirmed your email address.
- Google sign-in: if you choose "Continue with Google", Google gives us your email address, your name and a Google account identifier. We never receive your Google password.
- Purchases: when you buy credits, we record the order: which pack, the price, the date, its status (paid, refunded or disputed) and the order ID from our payment provider. You give your name and payment details directly to our payment provider, not to us. We never see or store your card details.
- Uploaded photos: we do not store your photos. Images are held on our servers only temporarily — long enough to generate metadata, embed it into the files, and let you download the result. Once you download a batch (the ZIP or the CSV), everything is deleted after a short 5-minute grace period (kept only in case the download needs to be retried). Batches that are never downloaded are deleted automatically within 6 hours. See Data Retention below.
- Feedback: any message you submit through our Feedback form, and the email address you provide with it.
- Sign-in and network information: the IP address used to create your account, and the time and IP address of your most recent sign-in.
- Usage records: how many photos you process each month. For each AI request we record the time, the AI provider and model used, the amount of data processed (tokens), and whether the request succeeded or the error it returned. These records do not include your photos or the generated metadata.
- Error logs: technical details of errors that occur while processing your requests, used to find and fix problems.
2. How We Use Information
- To authenticate you and maintain your account.
- To process your uploaded photos and generate titles, descriptions and keywords.
- To enforce plan limits, such as the one-time free photos and the monthly photo allowance.
- To deliver the credits you buy, handle refunds, and keep the business records the law requires.
- To prevent and detect fraud and misuse of the Service. See Preventing Misuse below.
- To keep accounts secure.
- To respond to feedback and support requests.
- To maintain and improve the reliability of the Service, and to monitor its operating costs.
Only Deskria administrators can see account, usage and sign-in information, and only to run and protect the Service. We do not sell your information or use it for advertising.
3. Why We're Allowed to Use It
- To run your account and process your photos: necessary to perform our contract with you.
- To sell you credits, deliver them and handle refunds: necessary to perform our contract with you.
- Accounting and tax records of purchases: legal obligation.
- Security, fraud and misuse prevention, error logs and cost monitoring: our legitimate interest in keeping the Service secure and working.
- Answering feedback and support requests: our legitimate interest, and necessary to perform our contract with you if you are a customer.
We don't send marketing emails. The only emails we send are account emails, such as email confirmation and password reset messages, and replies to your messages.
4. Third-Party Services
These providers process data only to provide their service to us. We don't sell or rent your data, and we don't share it for advertising.
AI providers: to generate metadata, your uploaded images are sent to third-party AI providers (OpenAI and/or Anthropic) for analysis. These providers process the image only to return a title and keyword suggestions, subject to their own privacy practices. Under their API terms, they do not use data sent through their API to train their models, and they may keep it for a limited time for safety and abuse monitoring.
Payments: credit packs are sold through Creem (Armitage Labs OÜ, Estonia), which acts as the merchant of record, meaning it is the seller of the credits. When you press a buy button, you leave Deskria for Creem's secure checkout page, which may set cookies needed for checkout and fraud prevention. You give your name, email address and payment details directly to Creem. They take payment, calculate tax, and send your receipt. Creem is the controller for payment and billing data. See the Creem privacy policy. Creem tells us whether an order was paid, refunded or disputed, so that we can add or remove the credits.
Google sign-in: if you sign in with Google, Google handles the sign-in itself, subject to the Google Privacy Policy.
Security check on sign-up: when you create an account with an email and password, the sign-up form uses Cloudflare Turnstile to check that you are a person and not an automated script. Cloudflare processes technical information for this check, such as your IP address and details about your browser, subject to the Cloudflare Privacy Policy.
Email delivery: account emails, such as email confirmation and password reset messages, are sent through an email delivery provider.
Hosting: Deskria runs on servers of Contabo (Contabo GmbH, Germany), which processes the data described on this page on our behalf and automatically records standard request data (IP address, date and time, page requested, browser type) for security and troubleshooting. See the Contabo privacy policy.
5. Transfers Outside Your Country
Deskria is operated from Serbia, and some of the providers above, including OpenAI, Anthropic and Cloudflare, process data in the United States and other countries outside the European Economic Area and Serbia. Where your data leaves the EEA or Serbia, it is protected by standard contractual clauses or an equivalent legal safeguard.
6. Preventing Misuse
Some people try to misuse the free allowance, for example by creating many accounts with scripts. To prevent this, the sign-up form includes a security check, and you must confirm your email address before you can process photos. We also look for signs of misuse such as:
- several accounts created from the same IP address;
- accounts whose email addresses are variations of the same inbox (for example
name+1@gmail.com); - accounts registered with disposable email addresses;
- accounts that use unusual amounts of the service right after signing up.
These signals only flag an account for review. A person decides on any action, and no account is suspended or deleted automatically. If we conclude that an account breaks our Terms of Service, we may suspend it, delete it, or block new sign-ups from the IP addresses involved. See Suspension and Termination.
- Suspended accounts: the account can no longer sign in, and any photos still on our servers are deleted right away. We keep the account's email address, IP addresses and the reason for the suspension for as long as the suspension applies. This lets us enforce the suspension, for example by preventing the same email address from registering again.
- Accounts we delete: the same data is removed as when you delete your account yourself (see Data Retention).
- Blocked IP addresses: we keep a list of IP addresses that may not create new accounts, until we remove the block.
If you believe your account was suspended by mistake, or you want to ask about the data we hold about a suspended account, contact us via the Feedback page.
7. Data Retention
Uploaded photos are kept only for as long as needed to process and download them:
- Once you download a batch (the ZIP or the CSV), it is deleted from our servers shortly after — a 5-minute grace period is kept in case the download needs to be retried, and is renewed each time you download again. Once that window passes with no further download, everything is removed.
- If a batch is never downloaded, it is automatically deleted within 6 hours of upload.
- You can also delete a batch manually at any time.
The metadata generated for a batch — file names, titles, descriptions and keywords, but not the photos — is kept in your History for 90 days after the batch was last changed, so you can download its CSV again. You can remove a batch from your History at any time, and your History is deleted when your account is deleted.
Records of purchases (the pack, price, date, status and order ID, but not your name or email address) are kept after you delete your account, no longer linked to it, for as long as tax and accounting law requires, then deleted. Payment and billing data held by Creem is kept by Creem under its own privacy policy.
Account information (email, name), sign-in and network information, and your photo usage are kept until your account is deleted. You can delete your account at any time from Settings → Delete account. This permanently removes your account, any photos still on our servers, your sign-in information, your photo usage history, your two-factor settings and any feedback you have sent. The exceptions are suspended accounts, which are described in Preventing Misuse, and the purchase records described above.
Records of individual AI requests (time, model, amount of data processed and outcome) are kept for cost and usage statistics. When an account is deleted, these records are disconnected from it, so they no longer identify you.
Error logs are deleted automatically after 90 days.
8. Data Security
Passwords are stored using industry-standard hashing (bcrypt) and are never stored or transmitted in plain text. We take reasonable technical measures to protect your data, but no system can be guaranteed 100% secure.
9. Your Rights and Choices
You may delete a processed batch of photos at any time from within the app. You can also permanently delete your account and all associated data yourself, at any time, from Settings → Delete account — no need to contact us.
Depending on where you live (for example under the EU/UK GDPR, the Serbian Law on Personal Data Protection, or US state privacy laws), you can also ask us to:
- give you a copy of your data;
- correct it;
- delete it;
- restrict or object to how we use it;
- move it to another service.
Email ask@deskria.top from the address of your account. We'll reply within 30 days. For payment and billing data, contact Creem directly. You can also complain to a data protection authority: in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection, or the authority in your own country.
10. Children
Deskria is for adults and businesses, and credits can only be bought by adults. We don't knowingly collect personal data from children. If you think a child has given us personal data, contact us and we'll delete it.
11. Cookies and Local Storage
Deskria does not use tracking or advertising cookies, and we do not run any analytics or advertising scripts. Nothing we store in your browser is used to profile you or to follow you across other websites, so no cookie consent banner is needed. What we do store is:
- A session cookie (
connect.sid) — this keeps you signed in. It holds no personal data, only an identifier for your session on our server. It cannot be read by scripts in the page, is sent over HTTPS only, and expires after 30 days or when you sign out. - Your settings, saved in your browser's local storage — the keyword style and CSV format you last chose, and the batch you were last working on, so the app looks the way you left it. This never leaves your browser, and clearing your browser data removes it.
- Cloudflare Turnstile — the anti-bot check on the sign-up form may store a short-lived token in your browser while it verifies you are a person. See section 4 for what Cloudflare receives.
When you buy credits, the payment takes place on Creem's own checkout page. Any cookies it sets there are governed by the Creem privacy policy, not this one.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
13. Contact
Questions about this Privacy Policy can be sent to ask@deskria.top or via our Feedback page.