10951811 Canada Inc. ("we", "us" or "our") operates Floral Studio. This policy explains how we handle information when you use the iOS app, its online services and floralstudio.app. Your work is private in our service; you choose what to export or share. Selected content is sent to our cloud and AI providers when you use online app features, as explained below.
This website
Our informational website uses Cloudflare hosting. Cloudflare processes ordinary connection information, such as your IP address, requested page and browser information, to deliver and protect the website. We do not add advertising trackers, analytics scripts or analytics cookies to these pages. The website has no account sign-in, purchase or AI-generation form. Its contact links open your email application; correspondence you send is handled as described under Purchases and support. Cloudflare's own infrastructure and security processing is described in its Privacy Policy.
Account and service information
When you first request an online feature, the app may create a guest account with Supabase. We use its account identifier and authentication records to protect your library, associate requests with you and manage credits. No sign-in email is required for the current guest flow. Session credentials are stored in the device's protected Keychain.
We store submitted requests, selected settings and instructions, work and collection identifiers, generation status, outputs and credit usage. Work names, notes, pictured sizes, manually entered prices and collection details may sync to your private cloud library. Information you put in these fields may include personal information, so include only what you need.
Photos and information on your device
We receive photos you select for online processing, including product or event photos, venue photos and selected flower, backdrop or style references. Images can contain faces, venue details, signs or other identifying information. The app prepares imported camera and photo-library images for upload without their original camera and location metadata; visible information in the picture remains. We do not request device location or browse your entire photo library.
Saved reference names, favourites, shop identity, logo, watermark settings, website, phone number and brand colours are stored on your device. Saving a reference or importing a watermark logo does not by itself upload it. Selecting a reference, backdrop or studio style for an online feature may upload it, including when you ask the app to learn its photographic look or sync a collection style. Content retained for an earlier request may remain in that request even after you remove a local favourite or change your saved settings.
Watermark rendering, logo background removal and export layouts run on the device. Exported images or documents can include the branding and contact details you choose. Photos saved to your photo library or shared to another app are then subject to your device settings and that destination's privacy practices.
What is sent to OpenAI
OpenAI processes the selected content needed to provide the AI feature you request. Photo editing and planning can include your source image, chosen backdrop, flower or style references, saved staging guidance and written instructions. Arrangement ideas can include your brief and selected references or an earlier concept. Captions can include the selected finished photo, its source where applicable, work name, notes, pictured size and caption voice.
If you choose to include your public shop profile in a caption request, we also send your shop name and Instagram handle. The app does not add your saved logo, phone or website as profile fields to these requests. Numeric manual prices are excluded from caption model input; a price you type into a note, brief or image can still be included as part of that content.
Do not submit unnecessary client names, contact details, payment details, confidential records or sensitive personal information. Obtain any permission needed from people whose information appears in your images or requests. AI results may reveal or reproduce information included in the inputs; review them before sharing.
Your choices and consent
The app explains photo and reference sharing before the first relevant submission and asks you to continue or decline. You choose which content and optional public shop details to use. You can decline new AI processing by declining the prompt or by not submitting another AI request, while continuing to use available local features and saved work.
To withdraw consent for processing already associated with your account or to request deletion, contact us using the details below. Withdrawal applies to future processing where consent is the legal basis and may prevent features that need that processing. It cannot recall information already sent to a provider or erase copies you have shared elsewhere. Withdrawing consent does not cancel an Apple subscription.
Purchases and support
When purchases are available, Apple processes payments. We receive purchase-verification information such as transaction and product identifiers, purchase and expiry dates, refund or revocation status and an account-linked purchase token. We use this information to verify entitlements, allocate credits and prevent duplicate fulfilment. We do not receive your complete payment-card details from Apple.
If you contact support, we receive your email address, correspondence and information or attachments you provide. We use them to respond, investigate your request and keep a record of its resolution. Email services also process that correspondence. Do not send passwords, session tokens or full payment-card information.
Why we use information
We use information to provide requested features, keep your private work available, authenticate access, sync eligible content, manage purchases and credits, answer support requests, diagnose failures, prevent fraud and abuse, and meet legal obligations. Our providers may receive ordinary connection information, including IP addresses, request times and technical error information, to deliver and protect their services. Request and usage records help us recover interrupted work and avoid duplicate charges.
Floral Studio has no third-party advertising or cross-app tracking SDKs. We do not sell personal information or share it for cross-context behavioural advertising. Sending selected content to a provider to fulfil an AI request is service processing, not advertising sharing. We do not use your private photos or designs in public marketing without separate permission.
Service providers and other disclosures
Supabase provides authentication, database and private file storage. Google Cloud runs application services and task processing. OpenAI provides AI assessment, planning, image generation and caption generation. Apple provides the App Store and in-app purchase processing. Providers receive information needed for their roles and may use subprocessors under their applicable agreements.
Access by us is limited to people who need it to operate the service or handle a request. We may disclose information when required by law, to protect rights or safety, or to investigate fraud or security incidents. If the business is reorganized or transferred, relevant information may be transferred subject to applicable privacy law and any required notice or consent.
Information may be processed or stored outside Quebec or Canada, including in the United States. Local law may allow authorities in those jurisdictions to access information. We remain responsible for the personal information we entrust to providers and apply the safeguards required by applicable law.
AI training and provider retention
OpenAI's API policy excludes model training by default unless the customer opts in. Standard abuse-monitoring content may remain for up to 30 days, with legal and safety exceptions. Image safety reviews and prompt caching can also retain data. Disabling response storage in our text requests does not guarantee zero retention. See OpenAI's data controls for current practices.
Retention and deletion
We keep hosted photos, requests and library records while needed to provide your saved work and associated services. Delete individual photos or versions using the available controls in Work. Deletion removes their access in the library and initiates removal of eligible cloud files. Files still used by other work, collections or accepted requests can remain until no longer needed. Removing a collection does not delete the work within it; removing a local favourite does not delete its source photo or request.
Full account deletion is currently handled by contacting support; the app does not yet offer a verified account-wide deletion control. We will verify your relationship to the account, explain the scope and process your request subject to applicable law. Because guest accounts may not have an email address, contact us from the device you used where possible. Do not uninstall the app before contacting us if you need help identifying your hosted account. We will never ask for your password or authentication token.
Deleting the app does not itself delete hosted content or cancel a subscription, and protected session information may persist separately from ordinary app files. Exports, copies sent to others and information on other devices are not erased by a hosted deletion request. Backups and provider safety records may take longer to expire than active files. Limited purchase, credit, security and dispute records may remain where necessary to meet legal duties or prevent fraud. We do not promise immediate erasure from every system; contact us for the retention details relevant to your request.
Security
We use HTTPS for online connections, account-scoped access controls, private cloud storage and temporary links for media access. Device access and your chosen sharing destinations also affect confidentiality. No storage or transmission method is completely secure. Contact us promptly if you suspect unauthorized access.
Your privacy rights
Depending on the law that applies, you may request access to your personal information, correction, deletion, withdrawal of consent, or a portable copy of eligible information. You may also have rights to object to or restrict certain processing or to request cessation of dissemination or de-indexing where applicable. We do not make decisions with legal or similarly significant effects about you solely through AI.
Send a request to the contact below with "Floral Studio privacy" in the subject line. We may request proportionate information to verify your authority without collecting unnecessary information. We respond within applicable legal deadlines, normally within 30 days for Quebec access and correction requests. We will explain any lawful exception or refusal and applicable review rights. You may use an authorized representative where allowed and will not be penalized for exercising a privacy right.
You can raise a concern with Quebec's Commission d'accès à l'information or the Office of the Privacy Commissioner of Canada, as applicable. Other jurisdictions may have their own supervisory authority. Rights under California, European or other privacy laws apply where their legal requirements are met; ordinary provider processing is not described here as a sale of information.
Children and policy changes
Floral Studio is intended for adults aged 18 and over. We do not knowingly collect personal information from children. Contact us if you believe a child has supplied personal information so we can investigate and take appropriate action.
We will update this policy when our practices change and provide notice of material changes through the app or another appropriate channel. Where a change requires consent, we will obtain it before the new processing. The updated date identifies the current version.
Contact for privacy requests
Person in charge of the protection of personal information — 10951811 Canada Inc.
1502 Rue Noel Lareau, Chambly, Quebec J3L 5M7, Canada
Email: floral.studio@outlook.com. Include "Floral Studio privacy" in your subject line.