MythicEcho Privacy Policy

How we handle your photos and personal data.

MythicEcho is operated by Tailor Made Innovations LLC (“MythicEcho,” “we,” “us,” or “our”).

Effective date: June 21, 2026  ·  Last updated: June 21, 2026

ATTORNEY REVIEW REQUIRED. This document is a draft prepared from the application’s actual data flows. It is not legal advice and has not been reviewed by an attorney. It must be reviewed and approved by qualified legal counsel, and all bracketed placeholders completed, before publication.
Contents
  1. Summary
  2. Who we are
  3. What we collect
  4. How we use your information
  5. Third parties who process your data
  6. Legal bases for processing (GDPR/UK GDPR)
  7. Data retention and storage
  8. Deleting your account and data
  9. Anonymous-first sign-in
  10. Children’s privacy
  11. Child-safety screening
  12. Your rights (EEA / UK)
  13. Your rights (California & other U.S. states)
  14. Security
  15. International data transfers
  16. Changes to this policy
  17. Contact us

1. Summary

MythicEcho lets you upload one or two selfies and transform yourself into an imaginative archetype using AI image generation. The app keeps your face and reimagines your clothing and surroundings.

2. Who we are

MythicEcho is a mobile application for iOS and Android, operated by Tailor Made Innovations LLC. For the purposes of the EU/UK General Data Protection Regulation (GDPR) and similar laws, Tailor Made Innovations LLC is the data controller for personal data processed through the app.

Contact: support@mythicecho.app
Mailing address: 6076 Chowchilla Mountain Rd, Mariposa, CA 95338

3. What we collect

CategoryExamplesSource
Photos / images The 1–2 selfies you upload; the AI-generated result image. These images may contain your facial appearance. You provide them.
Generation content The archetype you select, the quality tier, and the text prompt built from your selection. A short, automatically generated text description of the face in your photo (used to improve likeness in the result). Created in-app and on our backend.
Account identifiers An anonymous user ID issued at sign-in. If you later link an Apple or Google account, the identifier associated with that sign-in. Created automatically; see Anonymous-first sign-in.
Purchase / credit data In-app purchase events (which credit pack or subscription you bought), product IDs, a transaction/event ID, and your credit ledger. We do not receive or store your payment card or full billing details — those are handled by Apple and Google. Apple App Store / Google Play, via RevenueCat.
Consent records A record that you accepted the applicable policy version before your photo is sent to a third-party AI, with a timestamp. Created when you consent in-app.
Reports If you report content, the reported item’s request ID and the reason you provide. You provide them.
Basic technical data Information necessary to operate the service (e.g., authentication tokens, request timing for rate-limiting and abuse prevention, and standard server logs). Generated automatically.

What we do not collect: we do not collect your precise location, contacts, health data, or biometric templates for identification; we do not use advertising identifiers; and we do not embed third-party advertising or data-broker analytics SDKs.

A note on facial images. Your selfies depict your face. Some laws (including the GDPR and certain U.S. state laws) treat facial images as sensitive personal data in some contexts. We use your photo solely to generate the image you request and to screen it for safety — not to identify you, build a faceprint, or train AI models. See How we use your information.

4. How we use your information

We do not use your photos to train AI models, we do not sell your personal information, and we do not share it for cross-context behavioral advertising.

5. Third parties who process your data

We rely on a small number of service providers (“processors”) to run MythicEcho. We share only the data each provider needs for its function. Each provider is contractually bound to use the data only to perform services for us. Review each provider’s own privacy terms for details.

ProviderFunctionWhat it receives
fal.ai
(AI image generation + vision)
Generates your archetype image (Flux.2 image editing) and runs a vision step that describes the face in your photo to improve likeness. Your uploaded photo (via a temporary signed link) and the text prompt. This is the core third-party data share required to deliver the product.
Hive
(content moderation, incl. CSAM)
General visual content moderation plus a separate, zero-tolerance child-safety (CSAM) detection lane. Your input photo and the AI-generated output image, for safety screening. See Child-safety screening.
RevenueCat
(purchases)
Validates in-app purchases and reports purchase/refund events to our backend. Purchase events and an app-level user identifier. No photos are sent to RevenueCat.
Supabase
(our backend)
Our own first-party backend infrastructure: authentication, database, private file storage, and server functions. Acts as our hosting/storage provider. Holds your photos, account records, credit ledger, consents, and reports on our behalf. Supabase is our infrastructure vendor, not a consumer-facing data recipient.
AI provider data retention. Media processed by our AI provider (fal.ai) is generally retained on their side for a short period (about 7 days) and then removed in the ordinary course. See Data retention and storage.

If you are in the EEA or UK, we rely on the following legal bases under Article 6 (and, where facial images are treated as special-category data, Article 9):

PurposeLegal basis
Generating your image and sending your photo + prompt to our AI provider Your explicit consent (Art. 6(1)(a); Art. 9(2)(a) for facial images), captured in-app before any third-party send. You can withdraw consent at any time, which stops future processing and lets you delete your data.
Delivering the app, crediting purchases, and providing requested features Performance of a contract (Art. 6(1)(b)).
Content moderation, fraud/abuse prevention, security, and service reliability Legitimate interests (Art. 6(1)(f)) in operating a safe, lawful service.
Child-safety (CSAM) screening and reporting Legal obligation and/or substantial public interest in child protection (Art. 6(1)(c)/(e); Art. 9(2)(g)).

The lawful basis we use can affect which rights are available to you; see Your rights (EEA / UK).

7. Data retention and storage

When you delete your account, we delete your stored photos and result images and remove the associated database records (see Deleting your account and data).

8. Deleting your account and data

You can delete your account and all associated data at any time:

Deleting your account removes your stored source photos and result images from our private storage, and deletes the records tied to your account — including your profile, generation history, credit ledger, purchase records, consent records, and any reports you filed. Deletion is irreversible; any unused credits are forfeited. Backups and logs are purged on our routine cycles. We may retain limited records where required by law (e.g., financial records, or information related to a child-safety report).

9. Anonymous-first sign-in

MythicEcho is anonymous-first. You do not need to provide an email address, name, or other identifying details to use the app. At sign-in we issue an anonymous identifier so the app can store your credits and your generations. You may optionally link an Apple or Google account; if you do, we receive only the identifier provided by that sign-in method (not your password). Because identity is anonymous, you alone control your account through the device(s) on which you are signed in.

10. Children’s privacy

MythicEcho is a face-transformation app and is not directed to children under 13 (or the equivalent minimum age in your jurisdiction) and is not listed in the App Store Kids Category. We do not knowingly collect personal information from children under 13 without verifiable parental consent. While some archetypes are family-friendly in theme, the service is intended for general audiences and minors should only use it with the involvement and consent of a parent or guardian.

If you believe a child under 13 has provided us personal information without the required parental consent, contact support@mythicecho.app and we will delete it.

11. Child-safety screening

We have a zero-tolerance policy toward child sexual abuse material (CSAM) and the sexualization of minors. To enforce this, your uploaded photo and the generated output are screened by Hive’s CSAM Detection (which uses hash-matching against known CSAM databases and an AI classifier, in partnership with Thorn) in addition to general visual moderation.

Where the law requires it, we report apparent child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC) or other competent authorities, and we may preserve related information as legally required even after account deletion. Content that fails safety screening is blocked.

12. Your rights (EEA / UK)

If you are in the EEA or UK, you have the following rights, subject to the conditions in the GDPR / UK GDPR:

To exercise these rights, use in-app deletion or email support@mythicecho.app. We will respond within the timeframes required by law. Because the app is anonymous-first, we may ask you to verify control of the relevant account (for example, from the signed-in device) before acting on a request.

13. Your rights (California & other U.S. states)

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the right to:

We do not “sell” your personal information and we do not “share” it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We disclose personal information to the processors listed in Section 5 only so they can perform services for us. We use facial images (which may be sensitive personal information) only to provide the transformation you request and to screen for safety — not to infer characteristics about you — so no additional “right to limit” action is required for that use.

Residents of other U.S. states with comprehensive privacy laws may have similar rights to access, delete, correct, and opt out. To exercise any of these rights, use in-app deletion or email support@mythicecho.app. You may use an authorized agent where the law permits; we may verify the request and the agent’s authority.

14. Security

We protect your data with measures appropriate to its sensitivity, including private (non-public) storage for photos, per-user access controls so users can only reach their own files, encrypted transport, short-lived signed links, and confining AI provider keys to our backend so they are never shipped in the app. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

15. International data transfers

We and our processors may process your data in the United States and other countries. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism.

16. Changes to this policy

We may update this policy from time to time. When changes are material, we will update the “Effective date” above and, where appropriate, re-prompt you to review and accept the updated terms before your photo is sent to a third-party AI again.

17. Contact us

Questions, requests, or privacy concerns:
Tailor Made Innovations LLC (operator of MythicEcho)
Email: support@mythicecho.app
Mailing address: 6076 Chowchilla Mountain Rd, Mariposa, CA 95338

This policy is governed by the laws of California, without regard to its conflict-of-laws rules, except where mandatory local data-protection law applies.