Privacy Policy

Last updated: 22 August 2026

Airpinner (ABN 49 725 755 315) ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services (the "Service").

For the purposes of applicable data protection laws, Airpinner acts as the data controller of your personal information.

We comply with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth).

Where applicable, this Privacy Policy is intended to comply with the General Data Protection Regulation (EU) 2016/679 (GDPR), including its extraterritorial application under Article 3.

By using our Service, you acknowledge that we collect and use personal information as described in this Privacy Policy, subject to applicable legal bases under Australian Privacy Law and, where applicable, the GDPR.

Quick Summary

Your photosProcessed on your device. Two explicit exceptions: AI editing (per photo, at your request; results deleted within one day) and saved-project preview thumbnails (deleted with the project or your account)
Your dataStored securely, not sold to third parties
MarketingOnly with your consent, easy unsubscribe
Your rightsAccess, correct, delete your data anytime
SecurityIndustry-standard encryption and protection

1. Information We Collect

We collect and process personal information based on one or more of the following legal grounds: contractual necessity, legal obligation, legitimate interests, or your consent, depending on the nature of the data and the purpose of processing.

1.1 Information You Provide

Account Information:

  • Email address
  • Password (encrypted)
  • Name (optional)

Payment Information:

  • Billing details (processed securely by Stripe)
  • Transaction history

User Input:

  • Property addresses you enter
  • Custom labels and settings

1.2 Information Collected Automatically

Image Metadata: When you upload photographs, we may extract:

  • GPS coordinates (location where photo was taken)
  • Camera model and settings
  • Date and time of capture

Usage Data:

  • Features you use
  • Actions performed (searches, exports)
  • Credit consumption
  • Error logs

Device Information:

  • Browser type and version
  • Operating system
  • Screen resolution
  • IP address (anonymised)

We do not store raw IP addresses in our database. IP addresses are processed transiently — for example, our rate limiting stores only one-way hashes, and at sign-up we derive a country-level code (never a precise location) from the network connection. Our analytics and advertising providers (PostHog, Meta) may process your IP address to derive approximate location as part of their services, as described in Section 8.

1.3 Information Shared with Third Parties at Your Request

Google Maps Platform (Places, Geocoding, Routes): When you search for POIs, set a property address, or request distances and travel times, we query Google's services using the relevant location data (your photo's GPS coordinates and/or the property address you entered).

Google Gemini API (AI editing): When you run an AI edit (Enhance, Blue Sky, Golden Hour, Day to Dusk), a working copy of that photograph is sent through our servers to Google's Gemini API to generate the edited version. See Section 3 for exactly how this works.

2. How We Use Your Information

Where applicable, we also align our data handling practices with international privacy standards such as GDPR, although our primary compliance framework is the Australian Privacy Act 1988.

Where processing is based on legitimate interests, we have balanced those interests against your rights and freedoms and determined that such processing is necessary and proportionate.

We use your information to:

  • Provide and maintain the Service
  • Process transactions and manage subscriptions
  • Send transactional emails (receipts, account updates)
  • Detect and label Points of Interest
  • Improve and optimise the Service
  • Respond to customer support requests
  • Send marketing communications (with your consent)
  • Comply with legal obligations
  • Prevent fraud and abuse

3. How We Handle Your Images

3.1 Labelling, cropping and exporting — on your device

By default, your photographs are processed locally — in your browser (web app) or on your computer (desktop app). For these features we:

  • Extract GPS coordinates to find nearby POIs
  • Read camera metadata (including any location data embedded by your drone) for processing
  • Generate previews cached temporarily on your device

For these features we do not upload or store your photographs on our servers, with one small exception: if you save a project in the web app, a low-resolution preview thumbnail is stored with it so your project list can show it. It is deleted when you delete the project, and all of your stored thumbnails are deleted when you delete your account.

3.2 AI editing — an explicit, per-photo action

AI editing (Enhance, Blue Sky, Golden Hour, Day to Dusk) works differently, and only runs when you trigger it on a specific photo:

  • A working copy of that photograph is sent to our servers and passed to Google's Gemini API, which generates the edited version.
  • We do not retain the photo you submitted. The edited result may be stored briefly in private storage so your app can download it (access-controlled, per-account, time-limited links); these files are automatically deleted within one day.
  • We use Google's paid API services, which under Google's API terms are not used to train or improve Google's models.
  • Each AI edit consumes credits; we keep a record of the transaction (not the image) for billing.

3.3 In all cases

We do not use your images or their metadata to train machine-learning or artificial intelligence models, and we do not share them with third parties except as described in Section 3.2 (Google Gemini, at your request) — never for advertising.

While we implement robust security measures, no technical system can be guaranteed to be completely secure or free from risk.

You retain full ownership of all photographs and exported images.

4. Data Storage and Security

4.1 Where We Store Data

Your data is stored on:

  • Supabase (database and file storage) - servers in Australia/Singapore
  • Clerk (authentication) - servers in the United States
  • Vercel (application hosting) - global CDN with Australian edge locations

We may change or replace our infrastructure and service providers from time to time, provided that equivalent data protection and security standards are maintained.

4.2 Security Measures

We implement industry-standard security measures including:

  • Encryption in transit (HTTPS/TLS)
  • Encryption at rest for sensitive data
  • Secure password hashing
  • Regular security updates
  • Access controls and authentication

4.3 Data Retention

Data TypeRetention Period
Account informationUntil account deletion + 30 days
Transaction records7 years (legal requirement)
Usage analyticsPer our analytics provider's schedule (typically up to 12 months)
Export history (enables free re-exports)Life of the account
Support communications24 months
Saved-project preview thumbnailsUntil you delete the project or your account
Photos submitted for AI editingProcessed transiently, not retained
AI edit results (delivery storage)Automatically deleted within one day

4.4 Data Breach Notification

In the event of a data breach likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme under the Privacy Act 1988.

Where applicable, we will also comply with data breach notification obligations under Articles 33 and 34 of the GDPR.

5. Third-Party Services

We use the following third-party services that may collect and process your data:

ServicePurpose
SupabaseDatabase, temporary edit-result storage, saved-project preview thumbnails
ClerkAuthentication and account management
Google Maps PlatformPOI search, geocoding, distances & travel times
Google Gemini APIAI photo editing (at your request, per photo)
StripePayment processing
VercelHosting
ResendEmail delivery
PostHogProduct analytics & advertising measurement
Meta PlatformsAdvertising measurement & conversion tracking

We carefully select third-party providers that maintain appropriate privacy and security standards.

6. Sharing Your Information

We do NOT sell your personal information.

We may share your information only in these circumstances:

  • Service Providers: Third parties that help us operate the Service (listed above)
  • Legal Requirements: When required by law, court order, or government request
  • Safety: To protect the rights, safety, or property of Airpinner or others
  • Business Transfer: In connection with a merger, acquisition, or sale of assets (you will be notified)
  • With Your Consent: When you explicitly agree to share information

We may disclose personal information as part of a corporate transaction, such as a merger, acquisition, or asset sale, subject to appropriate confidentiality and data protection safeguards.

We may disclose personal information to regulatory or law enforcement authorities in foreign jurisdictions where required by applicable law.

We do not sell your personal data. To measure and improve our advertising, we share limited, hashed identifiers (such as a hashed email address) and conversion events with advertising partners, including Meta. We do not otherwise share personal data for advertising, and we do not sell it.

7. Your Rights

Under Australian Privacy Law and GDPR (if applicable), you have the right to:

7.1 Access

Request a copy of the personal information we hold about you.

7.2 Correction

Request correction of inaccurate or incomplete information.

7.3 Deletion

Request deletion of your personal information (subject to legal retention requirements).

7.4 Data Portability

Receive your data in a structured, machine-readable format.

7.5 Withdraw Consent

Withdraw consent for marketing communications at any time.

7.6 Right to Object

Where applicable under the GDPR, you have the right to object to the processing of your personal information in accordance with Article 21.

7.7 Complaint

Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached your privacy. If you are in the European Union or the United Kingdom, you also have the right to lodge a complaint with your local supervisory authority (GDPR Article 77) or the UK Information Commissioner's Office.

To exercise these rights, contact us at: hello@airpinner.com

We will respond to requests within 30 days.

8. Cookies and Tracking

8.1 Essential Cookies

We use essential cookies to:

  • Maintain your login session
  • Remember your preferences
  • Ensure security

These cookies are necessary for the Service to function and cannot be disabled.

Our analytics are configured to minimise personal data (for example, person profiles are only created for signed-in users). Where the law of your location requires consent for non-essential cookies, you can withhold it by using your browser's cookie controls (Section 8.4) — and you can always contact us to have associated data removed.

8.2 Analytics & Advertising

We use product analytics (via PostHog) to understand how users interact with the Service. Some analytics events are associated with your account so we can measure outcomes such as sign-ups.

We use the Meta Pixel and Meta Conversions API (the latter via our analytics provider, PostHog) to measure the effectiveness of our advertising. These may set or read advertising cookies (such as _fbp and _fbc) and transmit hashed identifiers to Meta. You can manage interest-based advertising through your Meta ad preferences and your browser or operating-system settings.

8.3 First-Party Attribution Cookies

To understand which channel or campaign brought you to Airpinner, we set a small number of first-party cookies on our own domain when you arrive (for example, an acquisition-source token and the campaign parameters from the link you clicked, retained for up to 90 days, plus short-lived cookies used to hand off between our pages). These contain no third-party identifiers, are readable only by Airpinner, and are used solely to attribute sign-ups to marketing channels.

When you create an account or submit your email address to us, we also record an approximate, country-level location derived from your network connection at that moment (a two-letter country code — never your precise location, and we do not store your IP address with it). We use this to understand which markets Airpinner serves.

8.4 Managing Cookies

You can control cookies through your browser settings. Disabling cookies may affect Service functionality.

9. Marketing Communications

9.1 What We Send

If you have an account or have asked to hear from us (for example by joining the waiting list or requesting a download link), we may send — as permitted by applicable law, and always with a working unsubscribe:

  • Product updates and new features
  • Tips and tutorials
  • Special offers and promotions

9.2 Opting Out

You can unsubscribe from marketing emails at any time by:

  • Clicking the "unsubscribe" link in any email
  • Contacting us at hello@airpinner.com

Note: You will still receive transactional emails (receipts, account notifications) as these are necessary for the Service.

10. Children's Privacy

Our Service is not intended for users under 16 years of age. We do not knowingly collect personal information from children under 16.

If we discover that we have collected information from a child under 16, we will delete it immediately. If you believe we have information about a child under 16, please contact us.

Where applicable, we comply with equivalent international laws governing children's data and age-of-consent requirements.

11. International Data Transfers

Your information may be transferred to and processed in countries other than Australia, including:

  • United States (Vercel, Stripe, Clerk, Google, Meta, PostHog, Resend)
  • Singapore (Supabase)

We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.

International data transfers are safeguarded through appropriate mechanisms, including standard contractual clauses, adequacy decisions, or equivalent legal protections.

You may request further information or copies of applicable transfer safeguards by contacting us.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of changes by:

  • Updating the "Last updated" date at the top
  • Posting the new Privacy Policy on our website
  • Sending an email notification for significant changes

Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.

Where required by applicable law, material changes to this Privacy Policy may require your explicit consent.

13. Contact Us

If required under applicable data protection laws, Airpinner will appoint a representative in the European Union. Requests relating to GDPR matters may be directed to hello@airpinner.com.

If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us:

Airpinner
ABN: 49 725 755 315
Email: hello@airpinner.com
Website: https://airpinner.com

Office of the Australian Information Commissioner (OAIC)
For privacy complaints: oaic.gov.au
Phone: 1300 363 992


By using Airpinner, you acknowledge that you have read and understood this Privacy Policy.