Virtual Staging AI Real Estate — Privacy Policy

Effective Date: September 8, 2026

Virtual Staging AI Real Estate ("the App") is developed by Mobile Card Games & Travel Apps LLC. On your device the App appears as "Virtual Staging" on iOS and "Staging AI" on Android. This Privacy Policy explains what data the App collects, how it is used, and how your privacy is protected.

This policy covers both the iOS version, distributed through the Apple App Store, and the Android version, distributed through Google Play. The two versions behave the same way from your point of view, but they reach the AI staging service by different routes, so a few sections below distinguish between them. Where a section does not say otherwise, it applies to both.

1. Data We Collect

The App handles the following data that you provide directly:

The App does not collect your name, email address, location, or device advertising identifiers, and it contains no analytics SDKs, no advertising SDKs, and no tracking of any kind. On iOS it does not use Apple's App Tracking Transparency framework because it does not track you. On Android the advertising-ID permissions are explicitly removed from the App's manifest.

2. How We Use Your Data

Your room photo and staging choices are used solely to generate an AI-staged version of your room. Each staging job involves two steps, both performed by OpenAI (openai.com):

In both versions of the App these requests travel over encrypted HTTPS connections, and in neither version is the API key stored in the app itself.

On iOS

The requests are relayed through AIProxy (aiproxy.com), a secure API relay service that holds the API key.

On Android

The requests are relayed through our own backend, running on Google Cloud Functions in the United States, which holds the API key in Google Secret Manager and forwards the requests to OpenAI. The backend also checks and updates your staging credit balance. Your photo passes through this backend in memory only, for the duration of the request; it is never written to disk or to any storage bucket we operate.

The App is designed for photos of rooms, not people. If a photo you upload happens to include a person, it is handled exactly the same way: sent to OpenAI only to produce the staging, never analyzed for identity, and never stored on any server we operate. Per OpenAI's API data-usage policy, data sent through the API is not used to train their models. Your photos are used for nothing else — no advertising, no profiling, no model training by us.

3. Third-Party Data Sharing

We do not sell, rent, or share your data with any other third parties.

Abuse prevention

Generating a staged image costs us money on every request, so both versions verify that requests come from a genuine installation of the App rather than a script.

These signals are used solely to prevent abuse, restore purchases, and rate-limit AI requests. They are not linked to your name or identity and are not used for advertising or tracking.

4. Data Storage and Retention

5. Data Security

All data leaving your device is transmitted over encrypted HTTPS connections. API keys are never embedded in the App: on iOS they are held by the AIProxy relay service, and on Android they are held in Google Secret Manager and used only by our backend. On Android, the credit balance can only be changed by our backend — the App itself has no write access to it — and every request to that backend must pass a Google Play Integrity check.

6. Your Rights

You have the right to:

Depending on where you live, privacy laws such as the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) give you rights over your personal data, including the rights to know, access, correct, and delete it. On iOS we hold no data on servers we operate, so there is typically nothing for us to access or delete on request — deleting the App deletes your data. On Android, the anonymous account record described in section 4 is data we hold, and you may contact us at the email below to access or delete it. We will respond as required by applicable law.

7. Children's Privacy

The App is not directed at children under 13, and we do not knowingly collect data from children under 13. In some regions, including the European Union, a higher minimum age applies to consent for data processing; the same statement applies there — we do not knowingly collect data from anyone under the applicable age.

8. Data Breach Notification

In the unlikely event of a data breach affecting user data on any system we operate, we will notify affected users as required by applicable law.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Effective Date" at the top of this page.

10. Contact Us

If you have questions about this Privacy Policy or your data, please contact us at:

v5cqpsj4e3u4@opayq.com