Travel Art.

YOUR MEMORIES. YOUR INFORMATION.

Privacy Policy

Effective date: 23 September 2026

1. Who is responsible for your information?

This policy covers the Travel Art website and mobile app, which help you turn photographs into personalised travel posters.

Data controller: Simon Hopkin, trading as Travel Art
Privacy contact: support@travelart.app

You can email us or use our contact form. Teemill's responsibility for print checkout and order information is described below.

2. Information we process

Most information comes from you or your use of the service. Our providers return information such as generated images, authentication status, notification delivery status and print handoff results. Checkout providers collect the contact, delivery and payment details you provide during checkout.

3. How we use information

We use information to create and secure your account; upload and save your projects; generate artwork; prepare previews and print files; arrange your requested checkout; send enabled service notifications; answer support requests; enforce usage limits; and investigate technical or security problems.

You need an account and a selected photo to use the documented generation workflow. If you do not provide the information needed for a feature, we may not be able to provide it. You can browse the marketing website without creating an account.

We rely on the following lawful bases:

4. Your photos and artwork generation

When you ask us to create artwork, our backend sends the selected source photo and style instructions to OpenAI through its image-editing API. A variation may use an earlier generated image. The app stores the returned artwork with your project. The backend normalises uploaded images and removes metadata from the processed source; that does not remove personal details visible within a photo.

Under our current standard API configuration, OpenAI does not use API inputs or outputs to train its models. OpenAI may retain inputs, outputs and associated information in abuse-monitoring logs for up to 30 days, unless it must keep them longer for legal reasons. We have not enabled OpenAI Zero Data Retention, Modified Abuse Monitoring or regional data residency. OpenAI processes this information for us under its business data-processing terms.

Only upload images you are entitled to use, and consider the privacy of anyone shown in them. The purpose of this processing is to create your artwork; it is not used to make decisions about your eligibility for employment, credit or similar services.

5. Who receives information?

Access by people operating the service is limited to what their role requires. Information may also be disclosed where necessary to comply with law or establish, exercise or defend legal claims.

Print-file visibility: preparing checkout creates a temporary artwork copy that anyone with its unguessable public link can access. The link is supplied to Teemill for import. Cleanup follows confirmation of import, and unresolved transfers may retain the copy longer. Artwork imported into Teemill is separate from your private Travel Art project and is not removed by deleting that temporary copy.

6. Where information is processed

Travel Art's initial launch is limited to the UK. Our core Firestore, Cloud Storage and Cloud Functions resources are configured in London. However, using a London backend does not mean that every part of the service is processed only in the UK.

Where personal information is transferred outside the UK, we use providers whose terms include an applicable safeguard, such as UK adequacy regulations or approved contractual protections. OpenAI's data-processing addendum incorporates the UK Addendum to the EU Standard Contractual Clauses for UK API data, and Google's applicable processing terms provide contractual safeguards for restricted transfers. Contact support@travelart.app if you would like more information about the safeguard used for a particular transfer.

We record and periodically review the roles, locations and transfer safeguards of our providers. Before offering Travel Art in the EU, we will review this notice, EU representative requirements, EU transfer mechanisms and local rights rather than relying on this UK-launch wording.

7. How long we keep information

We retain your account, saved photographs, artwork and designs while the account remains active. An account becomes inactive when there has been no sign-in, project change, generation request or print-preparation activity for 90 days. We intend to warn you by email before inactivity deletion where reasonably possible. You can delete an individual creative project or request account deletion sooner.

The documented account deletion process removes authentication access first, then schedules private data cleanup after a minimum fifteen-minute delay so accepted work can finish. Failed cleanup is retried; the delay is not a guarantee that every copy is erased within fifteen minutes. A minimal deleted-account security marker is retained for 24 hours to prevent old sign-in tokens recreating data.

Deleting an account does not cancel an order or erase artwork or customer information already transferred to Teemill. Website enquiries are stored separately from app accounts, so deleting an app account does not automatically remove a website enquiry; you can request its deletion using the email address or contact form below. Provider backups may take additional time to expire through their normal backup cycles.

8. Your choices and rights

You can choose which photographs to upload, delete creative projects, and request account deletion in Account Settings. Account deletion requires recent sign-in and may be blocked while generation, rendering or an unresolved print transfer is active. You can change notification permission in your device settings.

Depending on the law and lawful basis that applies, you may have rights to access, correct or erase information; restrict processing; receive or transfer certain information; and withdraw consent for future processing where consent is the basis. These rights have conditions and exceptions. Withdrawing consent does not invalidate earlier lawful processing.

Send a privacy request to support@travelart.app. We log the request through the support mailbox, acknowledge it, and may ask only for proportionate information needed to verify your identity. We respond without undue delay and normally within one calendar month. If a request is complex or you make several requests, the law may allow up to two additional months; if so, we will explain the delay within the first month.

You may complain to the UK Information Commissioner’s Office. You do not have to contact us before approaching the ICO.

9. Website cookies and tracking

The current marketing website does not set application cookies, run advertising or analytics scripts, load third-party fonts, or include mailing-list forms. Its contact form collects your name, email and message to handle your enquiry through Firestore and the support email queue. Website email addresses are self-reported and are not verified against app accounts. Submission references prevent duplicate processing, while derived IP-address and email identifiers support enquiry rate limits; these are not anonymous data. Hosting infrastructure may also retain request logs. Firebase Hosting still processes requests to serve the website. These statements concern this website and do not describe cookies or tracking on an app store or third-party checkout you visit.

10. Protecting information and policy updates

The app’s documented protections include authenticated access to private projects, ownership checks and backend-only provider credentials. The temporary print-delivery links described above are an exception to private image access. No service can promise absolute security.

We will update this page when the service or its privacy practices change. Material changes should also be communicated through an appropriate in-app or direct notice where required.

Read the Terms & Conditions for the conditions of using Travel Art.