Privacy Policy
Your prompts and images stay on your device. The website keeps beta addresses you submit, first-party analytics we host ourselves, and scrubbed error reports.
Effective 28 September 2026.
Who we are
Numen Technologies Limited makes Private Diffusion and is the data controller for the processing described here.
Numen Technologies Limited
Work Hub, 77 Camden Street
Dublin D02XE80
Ireland
Registered in Ireland with CRO number 677823.
For any privacy question or request, write to us at [email protected].
What this policy covers
This policy covers the privatediffusion.ai website and the Private Diffusion app for iPhone, iPad, and Mac.
The app and website are separate systems and are described below. The app collects nothing. The website keeps first-party analytics we host ourselves and scrubbed error reports, plus your email address if you join the TestFlight beta.
This policy does not cover other companies. When your device downloads a model, saves an image to your photo library, or syncs your gallery to your iCloud, you are dealing with Apple under Apple's own privacy policy, and we are not responsible for what it does with your data.
We publish this policy in several languages. The English version is the one that controls. If a translation and the English text disagree, the English text applies.
The Private Diffusion app
The app collects no personal data, and neither does the extension that downloads models. Neither collects data types of any kind, tracks you, or contacts tracking domains. There is no account, no sign-up, no analytics SDK, no advertising SDK, and no crash-reporting service in either of them.
Generation happens on your device. The model runs on your device's own silicon, and your prompt, your settings, and the image that comes out of them stay there. There is no Numen server in that loop to send them to.
- Your prompts and your images: they live in the app's gallery on your device. We hold no copy and have no way to get one.
- Gallery sync to iCloud: the gallery syncs through CloudKit into your own private iCloud database, and each synced record carries the prompt that produced the image alongside the image itself. That database is yours: it sits in your Apple account, not in ours, and we cannot read it. If CloudKit is unavailable, the app falls back to a local-only store on the device and the gallery simply stops syncing.
- Model downloads: we convert, quantize, and publish every model ourselves, and you download it inside the app. Delivery runs through Apple's Managed Background Assets, so the request goes to Apple, not to us. We receive no download history, and nothing about your prompts or your images travels with it.
- Saving to your photo library: the app can add an image you chose to save to your photo library. Its access is add-only. It cannot read, search, or browse the photos already there.
- Locking the gallery: you can put hidden images behind Face ID, Touch ID, or your device passcode. Apple's system authentication performs the check and tells the app only whether it succeeded. No biometric data reaches the app, and none reaches us.
- Sensitive-content checks: the app uses Apple's Sensitive Content Analysis framework, which runs on your device. Nothing is uploaded to be checked, and no result is reported to us.
- Exports: the app keeps a bounded cache of watermarked export files in its own storage on the device, so sharing the same image twice does not re-render it. The system can clear that cache at any time.
- Purchases: Apple handles payment on the App Store through StoreKit. The app holds no payment data.
- API server mode on the Mac: the Mac app can start a local image-generation server on your own machine. It stays off until you start it. Requests come from the clients you point at it, and every image it returns is generated on that Mac. We are not in that exchange and see none of it.
The app is distributed through the App Store, and during the beta through TestFlight. Apple sees a download the way it sees any other and gives us anonymous sales and territory reports that do not identify you. That is between you and Apple, and Apple describes it in its own privacy policy.
The models are published by other people, and we prepare the builds the app ships. Once a model is on your device it runs there and reports to nobody.
The privatediffusion.ai website
The website is a different surface from the app. It is a marketing site: a landing page in thirteen locales, a model catalog, a form for joining the TestFlight beta, and a support page where you can write to us.
The website generates no images and has no way to reach the app on your device or the gallery inside it.
Those two forms are the only places where you intentionally submit personal data. The site also retains the limited analytics and scrubbed error records described below.
The beta signup
The signup form asks for your email address and for an explicit tick saying you want the invite. It records the language you were reading in, so the confirmation link brings you back to the site in that language and we can use it to localize later beta communications. It asks for nothing else: no name, no company, no phone number.
We store that in our own database on our own server. Signing up generates a confirmation link, which our email delivery provider delivers to you. If you do not confirm your address, the link expires and we delete the unconfirmed address - sign up again if you still want an invite.
Once your address is confirmed, we keep it until the beta ends or until you ask us to delete it, whichever comes first. Write to [email protected] and it goes. We use it to send beta invites and to administer the beta, and for nothing else: beyond the email delivery provider that carries those messages, listed below, we do not share it, we do not sell it, and we do not put it on a marketing list.
The form is protected by Cloudflare Turnstile and by a per-IP rate limit.
The support form
The support page carries a form for writing to us. It asks for your name, your email address, what your message is about, and the message itself. If you tell us you are reporting a technical problem, it also asks which platform you are on and which device you have, because on-device generation behaves differently on different hardware.
The form writes nothing to our database. It sends your message straight to our support inbox through our email delivery provider, so what you write becomes a message in our mailbox, kept for as long as we need it to deal with your request, exactly like an email you had sent us yourself.
Send only what you are willing to share. Your prompts and images stay on your device, and the form carries text alone: it has no attachment field, so nothing you generated reaches us unless you type or paste it into the message yourself.
The form is protected by Cloudflare Turnstile and by a per-IP rate limit.
Analytics
We measure how the website is used with an analytics tool we host ourselves on our own infrastructure and serve from our own domain. There is no Google Analytics, no tag manager, and no advertising pixel anywhere on this site.
It sets no cookies and builds no cross-site profile. It records page paths, the query string an inbound link carries (including campaign tags and advertising click IDs), referrers, your browser, operating system, device type, screen size, browser language, and an approximate location down to city level, derived from your IP address. It also records named events such as a button click. It never records anything you type. Where your browser holds the analytics identifier, these events carry it.
Your IP address is processed transiently to derive that approximate location. It is not stored.
The legal basis is our legitimate interest in understanding how our own site performs.
The app does none of this. It carries no analytics at all.
Analytics identifier
We keep a random identifier in your browser so that your visits to this site are counted as one visitor rather than many. It is issued by servers we run, contains nothing about you, and is sent only to those servers.
To issue it we derive a signature from your browser and its settings. It is computed only when we need to issue you an identifier, and discarded unless we may issue one, so where we ask first and you have not decided yet, nothing is kept from it. Where we do issue one, we hold that signature only in a form we cannot reverse, paired with the identifier, for up to a year after we issue it, and we use it for nothing else. It is also why clearing this site's data removes the identifier from your browser without stopping us from reissuing the same one within that year.
If you are in the European Union, the European Economic Area, the United Kingdom, or Switzerland, we ask first: nothing is stored until you accept, and a decline is remembered until you close the tab. Elsewhere we rely on our legitimate interest. Where we ask first, an Analytics preferences link in the footer lets you withdraw at any time, which deletes the identifier.
Error reports
When something on the website breaks, your browser can send an error report to an error tracker we also host ourselves. The report describes the failure so we can fix it.
Before a browser error report is stored, query strings are stripped from URLs and identifiers are removed. The legal basis is our legitimate interest in keeping the site working.
The same error tracker also receives performance measurements: a sampled share of ordinary page loads and requests is timed and sent there even when nothing breaks, scrubbed the same way. We use those measurements only to keep the site fast and working, on the same legal basis and with the same handling as the error reports.
The app sends us no crash reports and no error reports of any kind.
Cookies and browser storage
There is very little here, and none of it is an advertising cookie. The table below is the complete list.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| NEXT_LOCALE | First-party cookie | Remembers the language you are reading the site in, so later visits land in the same one. Strictly necessary for delivering the site in that language. | Until you close the browser |
| Theme preference | First-party local storage | Remembers whether you chose the light or the dark theme. | Until you clear it |
| Analytics identifier | First-party local storage | A random value issued by our servers so that your visits are counted as one visitor. Not strictly necessary. Where the law requires, we ask before storing it; elsewhere we rely on our legitimate interest. | Where we ask first, until you withdraw through the Analytics preferences link or clear your browser's site data. Elsewhere there is no set end: clearing your site data removes it, but the same identifier can be reissued on a later visit within a year of when we last issued it |
| Analytics choice | First-party session storage | Remembers that you declined the analytics identifier, so the banner does not reappear in this tab. | Until you close the tab |
| Campaign label | First-party session storage | When you arrive through a link that names one of our marketing campaigns, remembers that campaign name so that a download you start from the App Store during this visit is counted towards it. | Until you close the tab |
| Logo animation flag | First-party session storage | Records that the animated logo has already played its entrance, so it does not replay on every page. Not personal data. | Until you close the tab |
| Cloudflare Turnstile | Third-party security challenge | Tells a person from a bot on the beta signup form and on the support form. | Per challenge, set by Cloudflare |
| cf_clearance | Cookie, set by Cloudflare | Appears only if Cloudflare has to challenge suspicious traffic, so that a visitor who passes the challenge is not asked again. It protects the site; it does not track you. On an ordinary visit it is never set. | Short-lived, set by Cloudflare |
One thing on this site can ask for your consent, and the banner exists for it alone: the analytics identifier described above. Everything else here needs none: the locale cookie only remembers which language to serve you, the analytics themselves set no cookies and stay on this one site, and Turnstile on the signup and support forms and Cloudflare's cf_clearance challenge cookie are security measures that protect the site rather than track you.
This site embeds nothing from X, YouTube, or any other third-party service. If that ever changes, the embed will not load until you click it, and this policy will say so.
Why we process data, and on what legal basis
Every purpose we process data for needs a legal basis under the GDPR. The table below is the complete list.
| What we do | Data involved | Legal basis (GDPR) |
|---|---|---|
| Put you on the beta list and send you the confirmation and invitation emails | Your email address, the language you signed up in, and the record of the consent tick | Article 6(1)(a), your consent, given by the checkbox. You can withdraw it at any time by writing to us |
| Answer a message you sent us | Your name, your email address, what your message is about, and whatever you write. For a technical report, also the platform and device model you select | Article 6(1)(b) and Article 6(1)(f), answering your request |
| Block bots and keep the signup and support forms available | Connection data processed by Cloudflare Turnstile, and a per-IP rate limit | Article 6(1)(f), our legitimate interest in forms that survive abuse |
| Measure how the site is used | First-party page and event data, carrying the analytics identifier where your browser holds one | Article 6(1)(f), our legitimate interest in improving our own site |
| Count return visits to this site | A random analytics identifier held in your browser, and a signature of your browser held on our servers in a form we cannot reverse | Article 6(1)(a), your consent, where we ask first; Article 6(1)(f), our legitimate interest, elsewhere |
| Diagnose errors | Error reports and performance measurements with query strings stripped from URLs and identifiers removed | Article 6(1)(f), our legitimate interest in a working service |
| Meet legal obligations, including accounting and tax | Records Apple and our accountants require | Article 6(1)(c), legal obligation |
Who else is involved
We keep as much as possible in our own hands. Our analytics, our error tracking, and our database are all operated by us, not bought as a service, so they are not third parties receiving your data.
These providers process data on our behalf:
- Our hosting provider - runs our servers.
- Cloudflare - DNS, TLS, content delivery, Turnstile, the country code that tells us which consent rules apply to your connection, and encrypted off-site backup storage (R2).
- Our email delivery provider - delivery of the beta confirmation and invitation emails, and carrying support-form messages to our inbox.
- Apple - the App Store and TestFlight, and the delivery of model downloads.
Your iCloud is not on that list, because it is not ours. Gallery sync uses CloudKit's private database, which means the records sit in your own Apple account under Apple's terms; Apple is not processing them for us, and we cannot read them.
We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not use it to train AI models. We disclose data to a public authority only where the law requires it.
How long we keep things
We keep little:
- Your prompts and images: never held by us at all. They are files on your device, and in your own iCloud if you turned sync on.
- Beta signup: your email address, the language you signed up in, and the record of your consent. If you never confirm, the link stops working after seven days and the unconfirmed address is deleted automatically. Once confirmed, they are kept until the beta ends or you ask us to delete them, and the confirmation record stays until the address is deleted.
- Messages you email us: kept in our mailbox for as long as we need them to deal with your request.
- Analytics: kept indefinitely as event records. Where your browser holds the analytics identifier, events from that browser carry it, and where we ask first, withdrawing stops that. The signature that lets us reissue the same identifier to your browser is kept for up to a year after we issue it. The IP address behind a visit is not stored. Where an inbound link carried an advertising click ID, that ID stays part of the recorded URL.
- Error reports and performance measurements: kept while they are still useful for fixing the fault or keeping the site fast, with query strings stripped from URLs and identifiers removed before they are stored.
Our servers are backed up nightly to encrypted off-site storage, and those backups are kept for up to about six months. The beta signup table is part of the database, so it is in those backups: deleting your address removes it from the live system at once, but a copy can remain inside an encrypted snapshot until that snapshot ages out.
International transfers
We are an Irish company. The cloud servers that run this site and its APIs are hosted in the European Union. Some of the providers listed above are established in the United States and may process data there or in other countries.
The safeguard for each transfer depends on that provider's arrangement: either an adequacy decision or the European Commission's standard contractual clauses, as required by Chapter V of the GDPR. Contact us if you need the current details for a particular provider.
A model download goes to Apple, and gallery sync goes to your iCloud, wherever Apple operates those services. That processing is Apple's own, and Apple's privacy policy describes it.
Security
Traffic to the site is encrypted in transit. Backups are encrypted. Access to production systems is limited to the people who need it.
If we ever suffer a breach that puts your rights at risk, we will notify the Irish Data Protection Commission and, where the law requires it, you.
Children
Private Diffusion is a general-audience creative tool. It is not directed at children, and we do not knowingly collect personal data from children. If you think a child gave us an email address through the beta form, write to [email protected] and we will delete it.
Changes to this policy
We update this policy when what we do changes. The effective date at the top always tells you which version you are reading. We keep a full revision history of this page, and we will share the relevant changes on request.
We do not ask you to click a box accepting it.
Your rights
Which rights you have depends on where you live. To exercise any of them, write to [email protected]. We answer within the time the applicable law allows, and there is no charge. We may ask you for enough information to be sure the request is really yours, and no more.
One limitation: we cannot reach your prompts or images. We may hold a beta signup, support correspondence you sent us, first-party analytics records, and scrubbed website error reports. If your browser holds the analytics identifier, you can send us that value and we can find the analytics events recorded against it. If we cannot find data that identifies you, we will tell you so rather than invent a match.
European Union and European Economic Area (GDPR)
You have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent at any time where we rely on consent. Withdrawing consent does not affect processing that already happened.
Where we rely on legitimate interests, you can object on grounds relating to your particular situation, and we will stop unless we have compelling grounds that override yours.
Our lead supervisory authority is the Irish Data Protection Commission. You can complain to it, or to the authority in the country where you live. The list of national authorities is published by the European Data Protection Board.
United Kingdom (UK GDPR and Data Protection Act 2018)
You have the same set of rights described above. You can complain to the Information Commissioner's Office at ico.org.uk.
United States state privacy rights
If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you may have the right to know what personal information we collect, to get a copy of it, to have it deleted, to correct it, and not to be treated worse for exercising those rights. Not every right exists in every state.
We do not sell personal information and we do not share it for cross-context behavioral advertising, in any state, for any price. There is therefore no sale or sharing for a Global Privacy Control signal to stop, and we do not act on that signal. We do not use sensitive personal information to infer characteristics about you.
To exercise a state right, write to [email protected]. If we cannot verify a request, we will say so and explain why.
Canada (PIPEDA)
You can ask what personal information we hold about you, how we use it, and who we disclose it to, and you can ask us to correct it. You can complain to the Office of the Privacy Commissioner of Canada.
If you are in Quebec, Law 25 gives you further rights, including rights around automated decisions and data portability. We do not make automated decisions that produce legal effects about you.
Brazil (LGPD)
You have the right to confirmation of processing, access, correction, anonymization or deletion of unnecessary data, portability, information about with whom we share data, and revocation of consent. You can complain to the Autoridade Nacional de Proteção de Dados.
India (Digital Personal Data Protection Act 2023)
You have the right to access a summary of your personal data and our processing, to correction and erasure, to nominate someone to exercise your rights if you die or become incapacitated, and to a grievance route. Send grievances to [email protected], which is our contact point for this purpose.
Contact us
Privacy questions, requests, and complaints all go to the same address: [email protected]
The terms that govern your use of this site are in our Terms of Use.