Privacy Policy
Effective Date: July 14, 2026. This Privacy Policy outlines how Refini collects, uses, and protects your personal information. By using our services, you agree to the practices described in this policy.
Overview
Refini provides AI-powered photo enhancement and old photo restoration services, including image sharpening, quality improvement, and restoration of vintage photographs. Our technology is not used to identify or verify individuals in photos, and you retain full ownership of your content.
Information We Collect
We collect the following types of information to provide and improve our services:
Personal Information
- User identifiers (for account management)
- Device information (browser type, operating system)
- Subscription details (for service provision)
- Facial data (facial feature position/shape information for performing enhancements)
- Contact information (for customer support)
- Payment information, including transaction amount, payment status, and receipts. Full payment card data is processed exclusively by Waffo Pancake and other PCI-DSS compliant authorized payment providers when available, and is not stored on our servers.
Usage Data
- Usage patterns and metadata (for product development)
- System performance data (for troubleshooting)
- Analytics data and cookies used for language preferences, session security, anonymous usage statistics, and product improvement
User Content
Images and photos you upload are processed to provide AI image enhancement and generation services. Refini is image-only; supported uploads and outputs are image files only. You retain control and ownership of your content.
How We Use Your Information
- Service Delivery: Personal data enables core functionality, processing user identifiers, device information, subscription details, and facial data to perform enhancements. The legal basis is performance of our contract with you.
- Customer Support: Contact information and communication content are retained to address user inquiries, billing questions, refunds, and account requests. The legal basis is contract performance and legitimate interests.
- Service Improvement: Usage patterns, cookies, and metadata inform product development through statistical analysis. Where required, optional analytics or marketing communications are based on consent.
- Troubleshooting: System performance data, error logs, and security audit logs help identify and resolve technical issues, abuse, and fraud.
- Personalized Profiling: User behavior informs personalized experiences and feature recommendations
- Legal Compliance & Defense: Data may be disclosed to authorities, used for tax and financial recordkeeping, or used to protect legal rights when required by law or legitimate interests.
Data Sharing
We never sell your data. We only share data with third parties when users authorize these connections:
- Payment Processors: Waffo Pancake and other authorized payment providers when available. Payment card data is handled exclusively by the PCI-DSS compliant payment processor and is not stored on our servers.
- Authentication Providers: Google, Github (only when users authorize these connections)
- No Data Sale: We will never sell your personal data to third parties
Data Retention
We keep each category of personal data only for the period stated below, unless a shorter period is appropriate or applicable law requires a longer one.
| Data category | How long we keep it | What happens afterward |
|---|---|---|
| Account email and profile | While the account is active; after a verified deletion request, normally within 1 hour and generally within 24 hours | Delete from active systems |
| Inactive free accounts | 24 consecutive months without activity, only when there is no subscription, purchased-credit balance, pending transaction, refund, or dispute | Delete automatically without a separate notice |
| Images, prompts, and reference files | Free use: 1 day; paid use: 30 days; after account deletion: generally within 24 hours | Permanently delete files and related content |
| Temporary and failed uploads | Up to 24 hours | Permanently delete |
| Transaction, payment, and refund records | 3 years after the relevant transaction, or longer where applicable law requires | Delete or irreversibly anonymize; legally required archives remain access-restricted |
| Customer support records | 2 years after the support case is closed | Delete attachments and delete or irreversibly anonymize the remaining record |
| Operational and error logs | 90 days | Securely delete |
| Security audit and anti-abuse logs | 12 months | Securely delete or irreversibly anonymize |
| Serious fraud, security incident, or dispute evidence | Up to 3 years after the matter is closed, or longer where legally required | Securely delete or archive under restricted access where legally required |
| Identifiable analytics data | 14 months | Delete identifiers; retain only anonymous aggregate statistics |
| Account-deletion request record | 3 years after completion, limited to request ID, dates, status, and outcome | Securely delete |
| Data held by service providers | Normally within 7 days after a verified account-deletion request | Request deletion or irreversible anonymization |
| Backup copies | Up to 35 days after deletion from active systems | Permanently remove through secure backup rotation |
- Data category
- Account email and profile
- How long we keep it
- While the account is active; after a verified deletion request, normally within 1 hour and generally within 24 hours
- What happens afterward
- Delete from active systems
- Data category
- Inactive free accounts
- How long we keep it
- 24 consecutive months without activity, only when there is no subscription, purchased-credit balance, pending transaction, refund, or dispute
- What happens afterward
- Delete automatically without a separate notice
- Data category
- Images, prompts, and reference files
- How long we keep it
- Free use: 1 day; paid use: 30 days; after account deletion: generally within 24 hours
- What happens afterward
- Permanently delete files and related content
- Data category
- Temporary and failed uploads
- How long we keep it
- Up to 24 hours
- What happens afterward
- Permanently delete
- Data category
- Transaction, payment, and refund records
- How long we keep it
- 3 years after the relevant transaction, or longer where applicable law requires
- What happens afterward
- Delete or irreversibly anonymize; legally required archives remain access-restricted
- Data category
- Customer support records
- How long we keep it
- 2 years after the support case is closed
- What happens afterward
- Delete attachments and delete or irreversibly anonymize the remaining record
- Data category
- Operational and error logs
- How long we keep it
- 90 days
- What happens afterward
- Securely delete
- Data category
- Security audit and anti-abuse logs
- How long we keep it
- 12 months
- What happens afterward
- Securely delete or irreversibly anonymize
- Data category
- Serious fraud, security incident, or dispute evidence
- How long we keep it
- Up to 3 years after the matter is closed, or longer where legally required
- What happens afterward
- Securely delete or archive under restricted access where legally required
- Data category
- Identifiable analytics data
- How long we keep it
- 14 months
- What happens afterward
- Delete identifiers; retain only anonymous aggregate statistics
- Data category
- Account-deletion request record
- How long we keep it
- 3 years after completion, limited to request ID, dates, status, and outcome
- What happens afterward
- Securely delete
- Data category
- Data held by service providers
- How long we keep it
- Normally within 7 days after a verified account-deletion request
- What happens afterward
- Request deletion or irreversible anonymization
- Data category
- Backup copies
- How long we keep it
- Up to 35 days after deletion from active systems
- What happens afterward
- Permanently remove through secure backup rotation
A verified account-deletion request overrides the ordinary retention periods for account data and user content. Account access, sessions, and API keys are disabled immediately. Only the minimum records that must be retained for a transaction, security matter, dispute, tax, accounting, or other legal obligation remain subject to their separate periods above.
Deleted data is not restored to active service from a backup except where required for disaster recovery. If a backup is restored, the deletion request is reapplied before ordinary service resumes.
Your Rights
Individuals may request access, correction, deletion, portability, objection to processing, withdrawal of consent where processing is based on consent, or processing restrictions.
- Access your personal data
- Correct inaccurate information
- Request deletion of your data
- Request data portability
- Request processing restrictions or object to processing based on legitimate interests or marketing
Requests should be made through the feedback page or [email protected]. Verified account-deletion requests normally begin processing immediately; the 30-calendar-day response period is an outer response timeframe, not a default waiting period before deletion. If you believe your request was not handled properly, you may contact your local data protection authority or consumer protection regulator.
Data Security
We use industry-standard encryption and security measures to protect your data, including HTTPS/TLS in transit, access controls, credential protection, and operational monitoring. If a security incident materially affects your rights or data, we will notify affected users and relevant regulators within the timeframe required by applicable law, with a target of 72 hours after confirmation where legally required. However, no transmission or storage method is 100% secure.
Children's Safety
This platform is intended for users who are at least 18 years old. We do not knowingly collect data from users under 18 years of age. If we discover such information has been collected, we will delete it immediately.
Third-Party Services
The service shares data with payment processors (including Waffo Pancake), authentication providers (Google, Github), AI processing and moderation providers (OpenAI, Replicate), analytics and product improvement tools when used, and hosting/storage infrastructure providers (Cloudflare R2) only as needed to provide, secure, moderate, and support the image-only service. These providers may process data in regions outside your country, including China, the United States, or other regions where our providers operate. Where required, we rely on contractual safeguards and provider security commitments for cross-border transfers.
Automated Processing
This platform may provide recommendations through automated processes based on user data and information from other users. AI outputs may be inaccurate or incomplete, and users remain responsible for reviewing generated results before relying on them.
Policy Changes
We may update this Privacy Policy from time to time. We will post any changes on this page and update the effective date. Significant changes will be communicated via email, service notifications, or platform notice at least 15 days before they take effect when reasonably required.
Contact Us
Privacy, support, billing, refund, legal, and security requests may be sent to [email protected]. You may also contact [email protected] for general business inquiries. Service hours are 10:00-24:00 UTC+8.
Email: [email protected]