Privacy Policy
Manage Ink App Privacy Policy
Effective Date: September 15, 2026 Last Updated: September 15, 2026
Manage Ink, LLC ("Manage Ink," "we," "us," or "our") is a Delaware limited liability company. This Privacy Policy explains what information the Manage Ink mobile app (iOS and Android) and the connected web application at app.manageink.com collect, how we use and share it, and the choices you have. We refer to the app and the web application together as the "Services."
The Services help tattoo and piercing artists photograph their finished work, generate caption and hashtag suggestions from that photograph using artificial intelligence, and publish the result to their own social media accounts.
The separate privacy policy at manageink.com/privacy covers our marketing website. This Policy governs the Services.
The Services are for adults, 18 and over, operating a tattoo or body-art business in the United States. If you do not agree with this Policy, do not use the Services.
1. The Short Version
- We collect your account details, the photographs and content you put into the app, and basic technical data needed to run it.
- Your photographs are sent to third-party AI providers for analysis. We name them in §6. They are contractually prohibited from training their models on your images.
- We do not run facial recognition or any other biometric analysis on your photographs, and we do not build profiles of the people in them.
- We do not sell your information, we do not share it for advertising, and there is no advertising or tracking SDK in the app.
- You can delete your account and everything in it from inside the app, or from manageink.com/delete-account.
- Questions: info@manageink.com.
2. Who You Are Under This Policy
You — the artist or studio. You create the account, you pay for it, and you decide what goes into it. We are the "controller" (or "business") for your information, and everything in this Policy applies to it directly.
The people in your photographs. A photograph of finished tattoo or piercing work often shows an identifiable person: your client. We never have a relationship with that person, we do not contact them, and we do not identify them. You are responsible for having their permission before you photograph, upload, or publish their likeness — see §8. If someone believes their image is in the Services without their permission, they should contact you first; if they contact us at info@manageink.com we will work with you to resolve it.
3. Age Requirement
The Services are not offered to anyone under 18. You must be 18 or older to create an account, and every Authorized User on your account must be 18 or older.
You must not upload a photograph of anyone under 18, in whole or in part, whether or not their face is visible. This is a condition of using the Services, not a suggestion. If we learn that an account holder is under 18, or that images of a minor are stored in an account, we will remove the content and may terminate the account.
We do not knowingly collect personal information from anyone under 18. If you believe a minor's information is in our systems, write to info@manageink.com and we will delete it.
4. Information We Collect
4.1 Information you give us
| Category | What it includes |
|---|---|
| Account | Your name, email address, password (stored hashed and salted, never in readable form), studio or business name, artist display name, profile photo, and time zone |
| Subscription | Your plan, subscription status, billing history, invoices, and the brand and last four digits of your payment card. We never receive or store your full card number — it goes directly to Stripe (see §6) |
| Photographs and content | Photographs of finished tattoo and piercing work that you capture in the app or select from your photo library, any edits or filters you apply, and any caption, hashtag, or note text you write or approve |
| AI analysis results | The descriptive output the AI analysis returns for each photograph — style, technique, color palette, subject matter, composition, placement — and the caption and hashtag suggestions generated from it |
| Social account connections | For each social platform you connect: the platform account ID and handle, and an OAuth access token stored encrypted at rest (see §7) |
| Publishing records | What you published, where, when, whether it succeeded, and the post identifier the platform returned |
| Support | Emails you send to info@manageink.com and anything you volunteer in them |
4.2 Information we collect automatically
- Device and connection data: IP address, device model, operating system and version, app version and build number, language, and time zone.
- Server logs: requests to our servers, timestamps, response codes, and error traces generated when something fails.
- Usage records: which features you used and when, held in your account record so the Services work — for example, how many analyses you have run in a billing period.
4.2a Approximate location
When you analyze a photograph, the app may ask permission to read your approximate location. This is optional. If you decline, everything in the Services continues to work exactly as before, and we will not ask again during that session.
What we do with it, precisely:
- The app requests the lowest accuracy the device offers — roughly one to three kilometres. We never request, and the device never gives us, a precise position.
- That approximate reading is sent to our server, converted into a city, state and country name, and the underlying coordinates are then discarded. They are not stored, not written to logs, and not sent to any third party.
- We keep only the place name — for example "Georgetown, Delaware, US" — attached to the analysis record.
We use this for one purpose: understanding which tattoo styles are popular in which regions, so we can improve the suggestions the Services generate. It is never used to locate you or any individual, is never sold, and is never shared for advertising.
We do not collect location in the background, and we do not track your movements.
4.3 What is deliberately absent
We want to be specific about this, because it is unusual and because it determines what our App Store and Google Play privacy declarations say:
- No third-party analytics or crash-reporting SDK is embedded in the app. We do not use Google Analytics for Firebase, Sentry, Amplitude, Mixpanel, PostHog, or any comparable product inside the app. Diagnostics come from our own server logs.
- No advertising identifiers. We do not collect the IDFA, the Android Advertising ID, or any comparable identifier, and the app does not present an App Tracking Transparency prompt because there is nothing to track.
- No advertising or retargeting pixels anywhere in the Services.
- No precise or background location. We request approximate location only, and only while you are using the app — never in the background. See §4.2a.
- No contacts, calendar, microphone, or health data.
- No cross-app or cross-site tracking of any kind.
4.4 What you must not put into the Services
Do not enter or upload:
- Government identification numbers — Social Security, driver's license, or passport numbers.
- Full payment card or bank account numbers in any free-text field, caption, or note.
- Health or medical information. Studio intake and consent forms often ask about medications, allergies, skin conditions, pregnancy, or bleeding disorders. Do not store that in Manage Ink. The Services are not designed, configured, or contracted as a system of record for health information, and several state laws — including Washington's My Health My Data Act, Nevada SB 370, and consumer-health provisions in California and Connecticut — place separate obligations on anyone who holds it. Keep medical screening in your dedicated consent-form system.
- Photographs of anyone under 18 (see §3).
We are not a HIPAA covered entity or business associate, the Services are not HIPAA-compliant, and we do not sign Business Associate Agreements. If we find prohibited data in an account, we may require you to remove it.
5. Camera, Photo Library, and Notifications
The app asks for these permissions, and only these:
| Permission | Why | When |
|---|---|---|
| Camera | To photograph finished work inside the app | Only while you are actively using the capture screen. We do not access the camera in the background |
| Photo library | To let you choose an existing photograph to analyze | Only the specific images you select. We do not read, scan, or index your library |
| Notifications (optional) | To tell you when an analysis is finished or a scheduled post published or failed | Only if you allow it. Declining does not limit any other feature |
You can change or withdraw any of these at any time in your device's operating system settings. Withdrawing camera access means you can still select photographs from your library; withdrawing both means you cannot create new posts, but your account and existing content remain intact.
We do not access any device data beyond what these permissions cover.
6. Artificial Intelligence — How Your Photographs Are Analyzed
This is the most important disclosure in this Policy. Please read it.
Your photographs leave our servers. When you run an analysis, the image and a text instruction are transmitted over an encrypted connection to a third-party AI provider, which returns a description of the work and suggested captions and hashtags. We use a provider-agnostic layer and may route a given request to any of:
- Anthropic, PBC (Claude)
- OpenAI, L.P. (GPT)
- Google LLC (Gemini)
All three process the request in the United States under enterprise API terms.
What we send. The image itself, and a text instruction describing the kind of output we want. We do not send your name, your email address, your account identifier, your client's name, or any other identifying information about you or the person in the photograph.
What the analysis extracts. Visual and stylistic attributes of the artwork: tattoo or piercing style, technique, line work, shading, color palette, subject matter, composition, and body placement. That is all it is asked for and all we store.
What it does not do. We do not perform facial recognition, faceprinting, face matching, age estimation, or any other biometric identification or classification, and we do not permit our AI providers to perform it on our behalf. We do not extract or store biometric identifiers or biometric templates as those terms are defined by the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, Washington HB 1493, or comparable laws. A photograph is analyzed as an image of artwork, not as a means of identifying a person.
Training. We do not use your photographs, content, or account data to train AI models, and we contract with each provider on terms that prohibit them from training their models on our API inputs and outputs and that require deletion within a limited retention window (each provider's standard abuse-monitoring period, currently up to 30 days, after which the data is deleted).
Accuracy. AI output is a suggestion, not a fact and not advice. It can be wrong, generic, or unsuitable. You are responsible for reading and editing anything the app generates before you publish it.
No automated decisions about you. We do not use automated processing to make decisions that produce legal or similarly significant effects concerning you.
7. Social Media Connections and Publishing
If you connect a social account, here is exactly what happens.
Connecting. You are sent to the platform's own login and permission screen — Instagram and Facebook via Meta, or TikTok. You authorize Manage Ink there. We never see or receive your social media password. The platform returns an access token to us.
What we store. The access token and any refresh token, encrypted at rest, plus your account ID on that platform, your handle, and your profile image. We store the token on our servers rather than only on your device so that queued and scheduled publishing works when the app is closed.
What we do with it. We use the token only to publish content you have approved, to confirm whether the publish succeeded, and to retrieve engagement metrics for posts you made through Manage Ink. We do not read your inbox or direct messages, post anything you have not approved, follow or unfollow accounts, or access your social data for any purpose other than operating the Services for you.
Disconnecting. You can disconnect any platform from inside the app at any time. Disconnecting deletes the stored token from our systems immediately and revokes our access. Posts already published remain on the platform; removing them is done on the platform.
Their rules, not ours. Once content is published to Instagram, Facebook, or TikTok, it is governed by that platform's terms and privacy policy, not by this one. Their handling of your content and your audience's data is between you and them.
8. Your Photographs and Third-Party Consent
Images are the heart of this product, so we are explicit about them.
You own your photographs. We claim no ownership. We store them, generate resized and web-optimized versions so they display and upload efficiently, transmit them for analysis as described in §6, and publish them where you direct.
You must have permission from the person depicted. Before you upload a photograph showing an identifiable person — including a photograph of a tattoo or piercing on an identifiable person — you must have that person's permission to photograph them, to store the image, and to publish it in the way you intend, including any release your state's right-of-publicity or likeness law requires.
The attestation. The app asks you to confirm this before you publish an image containing an identifiable person. We record that confirmation with a timestamp against the post. That record is evidence of what you told us; it is not a substitute for an actual release from your client, and it does not shift responsibility to us.
Public versus private. An image you publish to a social platform is public by design, and may be copied, indexed, cached, and redistributed beyond anyone's control. An image that stays in your account is visible only to Authorized Users of your account and to our personnel under the limits in §11.
Removal. Delete an image in the app and it is removed from our active systems promptly and purged from backups within our normal rotation (see §10). We cannot remove copies from a social platform once published — do that on the platform.
9. How We Use Information
- To run the Services — create and maintain your account, capture and store your images, run analyses, generate suggestions, publish to the platforms you connect, and return your results.
- To bill you — administer the 7-day free trial, subscriptions, renewals, refunds, and failed payments through Stripe.
- To support you — answer your emails, troubleshoot, and communicate about your account.
- To keep it working — monitor uptime, debug failures, and fix defects using our server logs.
- To keep it secure — authenticate you, detect abuse and fraud, investigate suspected violations of our Terms, and protect our rights and our customers'.
- To tell you about Manage Ink — product announcements, onboarding, tips, and offers. You can unsubscribe from marketing email at any time using the link in the message or by writing to info@manageink.com. Transactional messages — receipts, trial and renewal notices, security alerts, and service changes — are not marketing and continue while you have an account.
- To comply with law — tax, accounting, and lawful requests.
Aggregated and de-identified data. We may derive statistics from usage — for example, which tattoo styles are analyzed most often across all accounts — with all identifiers removed and no reasonable means of re-identification. We use that to improve the Services and may publish it as industry reporting. We commit to keeping it de-identified and to not attempting to re-identify it. Your photographs themselves are never included in or published as part of this.
10. Who We Share Information With
We share information in these situations, and no others.
10.1 Service providers
Each vendor below is bound by contract to use the information only to perform services for us. A current, named list is maintained at manageink.com/subprocessors, and we will post at least 30 days' notice there before adding a new one that processes your content.
| Vendor | Role | What it handles |
|---|---|---|
| Hostinger International Ltd. | Application hosting | The web application and API |
| Cloudflare, Inc. | DNS, CDN, and object storage (R2) | Your photographs and generated image derivatives |
| Stripe, Inc. | Payment processing | Subscriptions, cards, invoices, tax. Stripe is the controller of your payment card data under its own privacy policy |
| Anthropic, PBC | AI vision and text | Photograph analysis and caption generation (see §6) |
| OpenAI, L.P. | AI vision and text | Photograph analysis and caption generation (see §6) |
| Google LLC | AI vision and text | Photograph analysis and caption generation (see §6) |
| Resend, Inc. | Transactional email | Account verification, password resets, trial and renewal notices |
| Expo (650 Industries, Inc.) | Mobile app delivery and updates | Over-the-air app updates and build delivery. Receives app version and device platform, not your content |
10.2 At your direction
When you connect Instagram, Facebook, or TikTok, we exchange data with that platform as you configure. Those platforms operate under their own privacy policies, not this one. See §7.
10.3 Legal and safety
We may disclose information when we believe in good faith it is necessary to comply with a law, regulation, subpoena, warrant, or court order; to enforce our Terms; to detect or address fraud or a security incident; or to protect the rights, property, or safety of Manage Ink, our customers, or the public. Where we are legally permitted to do so, we will notify you before responding to a request for your data, so you have an opportunity to object.
10.4 Business transfers
If Manage Ink is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may transfer as part of that transaction. We will require the recipient to honor this Policy, and we will notify you before your information becomes subject to a materially different one.
10.5 With your consent
Any other sharing happens only with your permission.
10.6 We do not sell your information
We have not sold personal information, and we have not shared personal information for cross-context behavioral advertising, in the preceding twelve months, and we do not do so today. We also do not knowingly sell or share the personal information of anyone under 16. There is no advertising business inside this product.
11. Who at Manage Ink Can See Your Data
Access to production systems is limited to personnel who need it to do their jobs. Access is individually credentialed, protected by multi-factor authentication, and logged. We access the content of your account only (a) when you ask us to look at something, (b) when it is necessary to investigate a security incident or a suspected violation of our Terms, or (c) when required by law. All personnel are bound by confidentiality obligations that survive their engagement.
12. How Long We Keep Information
| Data | Retention |
|---|---|
| Account and profile | For the life of your account |
| Photographs, analysis results, captions, and publishing records | For the life of your account, then 30 days after account closure to allow export, then permanent deletion |
| Individual items you delete | Removed from active systems promptly; purged from backups within the backup rotation below |
| Social access tokens | Until you disconnect the platform or close your account — deleted immediately on disconnect |
| Images held by AI providers | Deleted by the provider within its standard abuse-monitoring window, currently up to 30 days; never used for training |
| Billing and transaction records | 7 years from the transaction, for tax and accounting law |
| Support correspondence | 3 years from resolution |
| Server, access, and security logs | 12 months |
| Marketing contact and suppression records | Until you unsubscribe; suppression entries are kept indefinitely so we do not contact you again |
| Backups | Rolling 35-day cycle; deleted data ages out within that window |
| Aggregated, de-identified statistics | Indefinitely |
We may keep information longer where required to comply with a legal obligation, resolve a dispute, or enforce our agreements — for example, under a litigation hold.
13. Security
We maintain administrative, technical, and physical safeguards designed to protect your information, including: encryption in transit (TLS 1.2 or higher); encryption at rest for stored images and for social access tokens; hashed and salted password storage; role-based access control and multi-factor authentication for administrative access; logging and monitoring; least-privilege vendor access; and regular dependency patching.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your credentials confidential and for the actions of users you invite to your account.
Breach notification. If we determine that a security incident has compromised personal information, we will notify affected customers without undue delay, and will notify regulators and affected individuals where the law requires it, within the timeframes the law requires.
14. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights:
- Know and access — confirm whether we process your personal information and get a copy, including the categories collected, the sources, the purposes, and the categories of recipients.
- Correct — have inaccurate information corrected.
- Delete — have your information deleted, subject to legal exceptions.
- Portability — receive a copy in a portable, machine-readable format.
- Opt out of sale, of sharing for cross-context behavioral advertising, of targeted advertising, and of profiling with legal or similarly significant effects. We do none of these.
- Limit the use of sensitive personal information — we do not collect sensitive personal information for purposes that trigger this right.
- Non-discrimination — we will not deny service, charge you differently, or degrade your service because you exercised a right.
- Appeal — if we decline a request, you may appeal.
These rights exist under laws including the California Consumer Privacy Act as amended (CCPA/CPRA), the Virginia CDPA, the Colorado Privacy Act, the Connecticut CTDPA, the Utah UCPA, the Texas DPSA, and the Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, and Rhode Island privacy acts, among others as they take effect. As a matter of policy we extend the core rights above to every U.S. resident, whether or not a law in your state requires it.
14.1 Deleting your account
You have two ways, and neither requires you to talk to anyone:
- In the app: Settings → Account → Delete Account. You will be asked to confirm. This deletes your account, your photographs, your analysis results, your publishing records, and your social connections.
- On the web: manageink.com/delete-account — use this if you have uninstalled the app or cannot sign in.
Deletion is permanent. Content is removed from active systems immediately and ages out of backups within 35 days. We retain only what §12 says we must — principally billing records we are required to keep for tax law, which we isolate from your account content.
14.2 Exercising other rights
Email info@manageink.com with "Privacy Request" in the subject line, or write to the address in §18. Tell us what you want and the email address on your account.
Verification. We verify requests before acting. For account holders we verify by confirming control of the account email. For others we may ask for enough information to match you to our records. We will not create new records about you solely to verify a request.
Authorized agents. You may designate an agent. We will require written authorization signed by you, or a valid power of attorney, and we may still contact you to confirm.
Timing. We respond within 45 days. If we need more time we will tell you within that period and may take up to 45 additional days (90 total). There is no charge for a reasonable number of requests; we may charge a reasonable fee or decline a request that is manifestly unfounded, excessive, or repetitive, and we will tell you why.
Appeals. If we deny a request, our response will explain why and how to appeal. Reply with "Appeal" in the subject line. We will respond within 45 days (or 60 where your state requires it) in writing. If we deny the appeal we will give you a way to complain to your state attorney general.
14.3 California
- The categories of personal information we collected in the past 12 months, the sources, business purposes, and categories of recipients are set out in §§4, 9, and 10.
- We have not sold or shared personal information in the past 12 months.
- We have no actual knowledge of selling or sharing the personal information of consumers under 16.
- Under California's "Shine the Light" law (Civ. Code §1798.83): we do not disclose personal information to third parties for their own direct marketing purposes.
14.4 Nevada
Nevada residents may submit a verified request that we not sell covered information. We do not sell covered information; you may still submit a request to info@manageink.com.
15. Cookies and Tracking
The mobile app does not use cookies and contains no tracking technology.
The web application at app.manageink.com uses only:
- Strictly necessary cookies — session management, authentication, and security. These cannot be disabled without breaking sign-in.
- Functional cookies — remembering preferences such as your dashboard layout.
There are no analytics cookies, advertising cookies, or third-party pixels in the Services.
Global Privacy Control. We honor the Global Privacy Control and other recognized universal opt-out signals as an opt-out of sale, sharing, and targeted advertising in the states that require it. Because we do not sell or share personal information, honoring it changes nothing in practice, but we recognize it. We do not respond to legacy "Do Not Track" headers, which have no agreed standard.
16. Where We Operate
The Services are offered only in the United States. Our App Store and Google Play listings are restricted to the U.S. storefronts, and all information we collect is stored and processed in the United States.
We do not offer the Services in the European Economic Area, the United Kingdom, or Switzerland, and this Policy is not written to satisfy the GDPR or the UK GDPR. If we expand to those markets we will publish an updated policy first.
17. Changes to This Policy
We may update this Policy. When we do we will change the "Last Updated" date. If a change is material — a new category of data use, a new category of recipient, a new AI provider, or a change to your rights — we will give at least 30 days' advance notice by email to account holders and by notice in the app before it takes effect. Continued use after the effective date is acceptance. Prior versions are available on request.
18. Contact Us
Manage Ink, LLC 20451 State Forest Road Georgetown, DE 19947
We are the entity responsible for the personal information described in this Policy. If you have a concern we have not resolved, you may contact your state attorney general's consumer protection office.