Legal
Last updated: 1 May 2026
The TL;DR version:
We don't store your prompts. We don't store your reference photos. We don't store your generated designs after delivery. We don't sell data to advertisers. We don't track you across the web. We genuinely just want you to make a great tattoo design and leave.
TattooDesignr ("Service," "we," "us") operates tattoodesignr.com. We are an AI-powered tattoo design generator. We do not have a corporate parent, advertiser network, or data-broker relationships.
When you purchase a design pack, our payment processor Stripe collects:
Stripe retains transaction records as required by US tax and financial regulations. Their privacy policy applies.
We use Plausible Analytics — a cookieless, privacy-respecting analytics service — to track aggregate site metrics like page visits and conversion rate. Plausible does not use cookies, does not track you across sites, and does not collect personal data. Read about Plausible's approach.
We use one (1) functional cookie: inkpilot_session — a temporary cookie that links your browser to your active checkout session. It expires when you close your browser. It contains no personally identifiable information.
We use no advertising cookies. No tracking pixels. No social-media share buttons that phone home. No fingerprinting.
To deliver the Service, we share minimal data with the following processors:
We have data processing agreements (DPAs) with each of these vendors. We do not share data with anyone else.
Because we don't maintain user accounts or personal records, most data-rights requests don't apply to us in the traditional sense. However:
TattooDesignr is not intended for users under 18. Tattoos require legal consent — most US states require 18+. We do not knowingly collect data from minors. If we learn we've collected data from a minor, we delete it.
TattooDesignr is operated from the United States. By using the Service, you consent to the transfer and processing of your data in the US, subject to the limited collection described above. We are GDPR-compliant for EU users via Standard Contractual Clauses with our processors.
All site traffic is served over HTTPS. Payment data is handled by Stripe (PCI-DSS Level 1 certified). Our infrastructure runs on Netlify with industry-standard access controls. Generated content is deleted, not just hidden — we use ephemeral filesystems.
We may update this policy. Material changes will be reflected by an updated "Last updated" date at the top. We'll never weaken our commitments retroactively.
Privacy questions: hello@tattoodesignr.com. We respond within 48 hours.