Privacy Policy

Effective Date: July 14, 2026. This Privacy Policy outlines how Refini collects, uses, and protects your personal information. By using our services, you agree to the practices described in this policy.

Overview

Refini provides AI-powered photo enhancement and old photo restoration services, including image sharpening, quality improvement, and restoration of vintage photographs. Our technology is not used to identify or verify individuals in photos, and you retain full ownership of your content.

Information We Collect

We collect the following types of information to provide and improve our services:

Personal Information

  • User identifiers (for account management)
  • Device information (browser type, operating system)
  • Subscription details (for service provision)
  • Facial data (facial feature position/shape information for performing enhancements)
  • Contact information (for customer support)
  • Payment information, including transaction amount, payment status, and receipts. Full payment card data is processed exclusively by Waffo Pancake and other PCI-DSS compliant authorized payment providers when available, and is not stored on our servers.

Usage Data

  • Usage patterns and metadata (for product development)
  • System performance data (for troubleshooting)
  • Analytics data and cookies used for language preferences, session security, anonymous usage statistics, and product improvement

User Content

Images and photos you upload are processed to provide AI image enhancement and generation services. Refini is image-only; supported uploads and outputs are image files only. You retain control and ownership of your content.

How We Use Your Information

  • Service Delivery: Personal data enables core functionality, processing user identifiers, device information, subscription details, and facial data to perform enhancements. The legal basis is performance of our contract with you.
  • Customer Support: Contact information and communication content are retained to address user inquiries, billing questions, refunds, and account requests. The legal basis is contract performance and legitimate interests.
  • Service Improvement: Usage patterns, cookies, and metadata inform product development through statistical analysis. Where required, optional analytics or marketing communications are based on consent.
  • Troubleshooting: System performance data, error logs, and security audit logs help identify and resolve technical issues, abuse, and fraud.
  • Personalized Profiling: User behavior informs personalized experiences and feature recommendations
  • Legal Compliance & Defense: Data may be disclosed to authorities, used for tax and financial recordkeeping, or used to protect legal rights when required by law or legitimate interests.

Data Sharing

We never sell your data. We only share data with third parties when users authorize these connections:

  • Payment Processors: Waffo Pancake and other authorized payment providers when available. Payment card data is handled exclusively by the PCI-DSS compliant payment processor and is not stored on our servers.
  • Authentication Providers: Google, Github (only when users authorize these connections)
  • No Data Sale: We will never sell your personal data to third parties

Data Retention

We keep each category of personal data only for the period stated below, unless a shorter period is appropriate or applicable law requires a longer one.

Data category
Account email and profile
How long we keep it
While the account is active; after a verified deletion request, normally within 1 hour and generally within 24 hours
What happens afterward
Delete from active systems
Data category
Inactive free accounts
How long we keep it
24 consecutive months without activity, only when there is no subscription, purchased-credit balance, pending transaction, refund, or dispute
What happens afterward
Delete automatically without a separate notice
Data category
Images, prompts, and reference files
How long we keep it
Free use: 1 day; paid use: 30 days; after account deletion: generally within 24 hours
What happens afterward
Permanently delete files and related content
Data category
Temporary and failed uploads
How long we keep it
Up to 24 hours
What happens afterward
Permanently delete
Data category
Transaction, payment, and refund records
How long we keep it
3 years after the relevant transaction, or longer where applicable law requires
What happens afterward
Delete or irreversibly anonymize; legally required archives remain access-restricted
Data category
Customer support records
How long we keep it
2 years after the support case is closed
What happens afterward
Delete attachments and delete or irreversibly anonymize the remaining record
Data category
Operational and error logs
How long we keep it
90 days
What happens afterward
Securely delete
Data category
Security audit and anti-abuse logs
How long we keep it
12 months
What happens afterward
Securely delete or irreversibly anonymize
Data category
Serious fraud, security incident, or dispute evidence
How long we keep it
Up to 3 years after the matter is closed, or longer where legally required
What happens afterward
Securely delete or archive under restricted access where legally required
Data category
Identifiable analytics data
How long we keep it
14 months
What happens afterward
Delete identifiers; retain only anonymous aggregate statistics
Data category
Account-deletion request record
How long we keep it
3 years after completion, limited to request ID, dates, status, and outcome
What happens afterward
Securely delete
Data category
Data held by service providers
How long we keep it
Normally within 7 days after a verified account-deletion request
What happens afterward
Request deletion or irreversible anonymization
Data category
Backup copies
How long we keep it
Up to 35 days after deletion from active systems
What happens afterward
Permanently remove through secure backup rotation

A verified account-deletion request overrides the ordinary retention periods for account data and user content. Account access, sessions, and API keys are disabled immediately. Only the minimum records that must be retained for a transaction, security matter, dispute, tax, accounting, or other legal obligation remain subject to their separate periods above.

Deleted data is not restored to active service from a backup except where required for disaster recovery. If a backup is restored, the deletion request is reapplied before ordinary service resumes.

Your Rights

Individuals may request access, correction, deletion, portability, objection to processing, withdrawal of consent where processing is based on consent, or processing restrictions.

  • Access your personal data
  • Correct inaccurate information
  • Request deletion of your data
  • Request data portability
  • Request processing restrictions or object to processing based on legitimate interests or marketing

Requests should be made through the feedback page or [email protected]. Verified account-deletion requests normally begin processing immediately; the 30-calendar-day response period is an outer response timeframe, not a default waiting period before deletion. If you believe your request was not handled properly, you may contact your local data protection authority or consumer protection regulator.

Data Security

We use industry-standard encryption and security measures to protect your data, including HTTPS/TLS in transit, access controls, credential protection, and operational monitoring. If a security incident materially affects your rights or data, we will notify affected users and relevant regulators within the timeframe required by applicable law, with a target of 72 hours after confirmation where legally required. However, no transmission or storage method is 100% secure.

Children's Safety

This platform is intended for users who are at least 18 years old. We do not knowingly collect data from users under 18 years of age. If we discover such information has been collected, we will delete it immediately.

Third-Party Services

The service shares data with payment processors (including Waffo Pancake), authentication providers (Google, Github), AI processing and moderation providers (OpenAI, Replicate), analytics and product improvement tools when used, and hosting/storage infrastructure providers (Cloudflare R2) only as needed to provide, secure, moderate, and support the image-only service. These providers may process data in regions outside your country, including China, the United States, or other regions where our providers operate. Where required, we rely on contractual safeguards and provider security commitments for cross-border transfers.

Automated Processing

This platform may provide recommendations through automated processes based on user data and information from other users. AI outputs may be inaccurate or incomplete, and users remain responsible for reviewing generated results before relying on them.

Policy Changes

We may update this Privacy Policy from time to time. We will post any changes on this page and update the effective date. Significant changes will be communicated via email, service notifications, or platform notice at least 15 days before they take effect when reasonably required.

Contact Us

Privacy, support, billing, refund, legal, and security requests may be sent to [email protected]. You may also contact [email protected] for general business inquiries. Service hours are 10:00-24:00 UTC+8.

Email: [email protected]