Virtual Staging AI Real Estate — Privacy Policy
Effective Date: September 8, 2026
Virtual Staging AI Real Estate ("the App") is developed by Mobile Card Games & Travel Apps LLC. On your device the App appears as "Virtual Staging" on iOS and "Staging AI" on Android. This Privacy Policy explains what data the App collects, how it is used, and how your privacy is protected.
This policy covers both the iOS version, distributed through the Apple App Store, and the Android version, distributed through Google Play. The two versions behave the same way from your point of view, but they reach the AI staging service by different routes, so a few sections below distinguish between them. Where a section does not say otherwise, it applies to both.
1. Data We Collect
The App handles the following data that you provide directly:
- Room photos: Photos of rooms you want to stage, taken with your camera or selected from your photo library. To generate the staged image, your photo is uploaded to OpenAI's service (see section 2).
- Staging choices: The room type, style, color palette, furniture density, lighting, decor options, and any additional placement instructions you type when staging a room.
- Purchase information: Transaction records for in-app credit purchases, managed by Apple or Google Play together with RevenueCat.
- Anonymous account identifier (Android only): A randomly generated account ID, created without any sign-in, that holds your staging credit balance. It is not linked to your name, email, or Google account.
- Device integrity and abuse-prevention signals: See section 3.
The App does not collect your name, email address, location, or device advertising identifiers, and it contains no analytics SDKs, no advertising SDKs, and no tracking of any kind. On iOS it does not use Apple's App Tracking Transparency framework because it does not track you. On Android the advertising-ID permissions are explicitly removed from the App's manifest.
2. How We Use Your Data
Your room photo and staging choices are used solely to generate an AI-staged version of your room. Each staging job involves two steps, both performed by OpenAI (openai.com):
- Layout analysis: Your photo is first sent to an OpenAI language model that analyzes the room's layout and identifies where furniture can safely be placed, so that doors, windows, closets and walkways are not obstructed. This request is sent with storage disabled (OpenAI's "store: false" setting).
- Staging: Your photo is then sent to OpenAI's image editing API, together with a text description of your staging choices and the layout analysis, to generate the staged image with AI furniture and decor.
In both versions of the App these requests travel over encrypted HTTPS connections, and in neither version is the API key stored in the app itself.
On iOS
The requests are relayed through AIProxy (aiproxy.com), a secure API relay service that holds the API key.
On Android
The requests are relayed through our own backend, running on Google Cloud Functions in the United States, which holds the API key in Google Secret Manager and forwards the requests to OpenAI. The backend also checks and updates your staging credit balance. Your photo passes through this backend in memory only, for the duration of the request; it is never written to disk or to any storage bucket we operate.
The App is designed for photos of rooms, not people. If a photo you upload happens to include a person, it is handled exactly the same way: sent to OpenAI only to produce the staging, never analyzed for identity, and never stored on any server we operate. Per OpenAI's API data-usage policy, data sent through the API is not used to train their models. Your photos are used for nothing else — no advertising, no profiling, no model training by us.
3. Third-Party Data Sharing
- OpenAI (openai.com): Receives your room photo and staging description solely to perform the layout analysis and generate the staged image, over encrypted HTTPS.
- RevenueCat (revenuecat.com): Manages in-app credit purchases. RevenueCat receives purchase transaction tokens from Apple or Google Play and a random anonymous app-user ID — never your name, email, or photos. Payments themselves are processed by Apple or Google; we never see your payment card details.
- Google (firebase.google.com, Android only): Firebase provides the anonymous account, the credit ledger, and the abuse-prevention checks described below. Google Play processes purchases and confirms them to our backend, which also periodically asks Google Play which purchases have been refunded or charged back, so the corresponding credits can be removed.
We do not sell, rent, or share your data with any other third parties.
Abuse prevention
Generating a staged image costs us money on every request, so both versions verify that requests come from a genuine installation of the App rather than a script.
- On iOS: each AI request includes your device's Apple identifier-for-vendor and an Apple DeviceCheck token.
- On Android: each request includes a Google Play Integrity attestation, obtained through Firebase App Check, which confirms the request comes from an unmodified copy of the App. Separately, when the App first contacts our backend it sends two one-way cryptographic hashes: one of the Android device identifier, and one of a random value stored in Google Block Store so it can follow your Google backup to a new phone. These let us restore your credit balance after a reinstall or a device change and grant the one free staging only once per person. We receive only the hashes, never the underlying values, and we hash them again with a secret key before storing them.
These signals are used solely to prevent abuse, restore purchases, and rate-limit AI requests. They are not linked to your name or identity and are not used for advertising or tracking.
4. Data Storage and Retention
- On your device: Your original photos, staged results, and the options you chose are stored locally in the App's own storage for the in-app gallery, until you delete them from the gallery or uninstall the App. If you choose to save a staged photo, it is also written to your device's photo library.
- In your iCloud (iOS only): Your remaining credit balance is synced across your devices via Apple's iCloud key-value storage, tied to your Apple ID. We cannot access this data. Your photos are never synced to iCloud by the App.
- In your Google account backup (Android only): If you have Android backup enabled, your in-app gallery (staged images and their settings) is included in your device's backup to your own Google account, in the same way as other app data. That backup belongs to you and we cannot access it. You can exclude it by turning off backup for the App in Android Settings.
- On our servers (Android only): Because Android has no equivalent of Apple's iCloud key-value storage, the Android version keeps your credit balance on a server we operate, so that a reinstall or a new phone does not cost you credits you paid for. We store an anonymous account record containing your credit balance, the number of stagings you have generated, the hashed identifiers described above, and a record of each purchase and refund. We also keep a record of each staging request — its anonymous account ID, timestamp, output size, and whether it succeeded — for 30 days, so that a failed staging can be refunded and abuse can be detected. These records never include your photos, your staging choices, or the generated images. Your gallery on Android stays on your device and in your own Google backup only.
- Photos: On neither platform do we operate any server that stores your photos. Photos exist in transit only, for the duration of the API request.
5. Data Security
All data leaving your device is transmitted over encrypted HTTPS connections. API keys are never embedded in the App: on iOS they are held by the AIProxy relay service, and on Android they are held in Google Secret Manager and used only by our backend. On Android, the credit balance can only be changed by our backend — the App itself has no write access to it — and every request to that backend must pass a Google Play Integrity check.
6. Your Rights
You have the right to:
- Delete individual staged results from the App's gallery at any time.
- Remove all app data stored on your device by uninstalling the App.
- Deny camera or photo library permissions in iOS Settings, which prevents the App from accessing your photos. On Android the App requests no camera or photo-library permission: photos are chosen through the Android photo picker or captured by your own camera app, so only the single photo you pick is ever shared with the App. (On Android 9 and older, saving a finished image to your gallery still uses the system storage permission, which you can deny in Android Settings.)
- Request deletion of your anonymous account (Android): Because the Android account is anonymous, we cannot look it up by name or email. Email us at the address below from the device in question and we will tell you how to supply the account identifier, then delete the account record and its associated data. Deleting the account also forfeits any unused staging credits on it.
Depending on where you live, privacy laws such as the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) give you rights over your personal data, including the rights to know, access, correct, and delete it. On iOS we hold no data on servers we operate, so there is typically nothing for us to access or delete on request — deleting the App deletes your data. On Android, the anonymous account record described in section 4 is data we hold, and you may contact us at the email below to access or delete it. We will respond as required by applicable law.
7. Children's Privacy
The App is not directed at children under 13, and we do not knowingly collect data from children under 13. In some regions, including the European Union, a higher minimum age applies to consent for data processing; the same statement applies there — we do not knowingly collect data from anyone under the applicable age.
8. Data Breach Notification
In the unlikely event of a data breach affecting user data on any system we operate, we will notify affected users as required by applicable law.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Effective Date" at the top of this page.
10. Contact Us
If you have questions about this Privacy Policy or your data, please contact us at:
v5cqpsj4e3u4@opayq.com