Privacy Policy

Last updated: March 28, 2026

This Privacy Policy explains how CarEditor ("we", "us", or "our") collects, uses, and protects your personal data when you use our web application at car-editor.com (the "Service"). We are committed to protecting your privacy and handling your data transparently.

1. Data Controller

The data controller responsible for your personal data is:

CarEditor

Sole trader, Republic of Serbia

Email: team@car-editor.com

2. Data We Collect

Account Data

When you use our Service, we collect the following account information:

  • Email address (when you upgrade from an anonymous account)
  • Firebase user ID (automatically generated)
  • Authentication provider (Google or email)
  • Display name (if provided by your auth provider)

Image Data

When you use our photo editing features, we store:

  • Original uploaded car photos (stored in Firebase Storage)
  • AI-processed result images
  • Images are retained for your future use until you delete them or your account is deleted

Usage Data

We automatically collect usage information including:

  • Pages visited and features used
  • Session duration and frequency
  • Browser type and version
  • Device type and screen resolution
  • Referring website
  • General geographic location (country/region level)

Payment Data

Subscription payments are processed by RevenueCat and Stripe. We do not directly store your credit card numbers or payment method details. We receive transaction confirmations, subscription status, and billing history from these payment processors.

3. How We Use Your Data

We use the data we collect for the following purposes:

  • Service delivery: Authenticating your account, processing your images with AI, managing your subscription, and storing your editing history
  • Analytics and improvement: Understanding how the Service is used so we can improve features and performance
  • Communication: Sending transactional emails related to your account and subscription
  • Legal compliance: Meeting our legal obligations and protecting our rights

The legal bases for processing your data include: performance of our contract with you (providing the Service), your consent (where applicable), and our legitimate interests in operating and improving the Service.

4. AI Image Processing

When you use our AI-powered editing features, your uploaded images are transmitted to third-party AI processing services for transformation. Specifically:

  • Images are sent to Replicate (replicate.com) for AI processing via their API
  • CarEditor does not use your uploaded images to train AI models
  • Replicate's own data retention and privacy policies apply to images processed through their service. We encourage you to review Replicate's Privacy Policy
  • Both original and AI-processed images are stored in your account on Firebase Storage for your future use

5. Third-Party Services

We use the following third-party services that may receive your data:

Firebase / Google Cloud

Authentication, file storage (images), database (Firestore), cloud functions

Privacy Policy →

Replicate

AI image processing

Privacy Policy →

RevenueCat

Subscription management and billing

Privacy Policy →

Stripe

Payment processing (via RevenueCat)

Privacy Policy →

PostHog

Product analytics and usage tracking (with consent)

Privacy Policy →

TikTok Pixel

Advertising conversion tracking (with consent)

Privacy Policy →

6. Cookies & Browser Storage

Essential Cookies

These are required for the Service to function and cannot be disabled:

  • Firebase authentication tokens (session management)
  • Firebase local storage entries (auth state persistence)

Analytics Cookies (consent required)

We use PostHog for product analytics. These cookies are only activated after you provide explicit consent via our cookie consent banner:

  • PostHog analytics cookies (usage tracking, session data)

Marketing Cookies (consent required)

We use advertising pixels to measure the effectiveness of our ads. These are only activated after you provide explicit consent:

  • TikTok Pixel (advertising conversion tracking)

You can withdraw your consent at any time by clearing your browser's local storage, which will reset the cookie consent banner on your next visit.

7. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate personal data
  • Right to erasure: Request deletion of your personal data, including all stored images
  • Right to restriction: Request that we limit processing of your data
  • Right to data portability: Request your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, please email us at team@car-editor.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

8. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to know: You may request details about the categories and specific pieces of personal information we have collected
  • Right to delete: You may request deletion of your personal information
  • Right to opt-out: You may opt out of the sale of your personal information
  • Non-discrimination: We will not discriminate against you for exercising your rights

CarEditor does not sell your personal information. To exercise your CCPA rights, contact us at team@car-editor.com.

9. Brazil Privacy Rights (LGPD)

If you are located in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD), including:

  • Confirmation of data processing and access to your data
  • Correction of incomplete or inaccurate data
  • Anonymization, blocking, or deletion of unnecessary or excessive data
  • Data portability to another service provider
  • Information about public and private entities with which your data has been shared
  • Review of decisions made solely based on automated processing

To exercise your LGPD rights, contact us at team@car-editor.com. You may also file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).

10. Data Retention

We retain your data for the following periods:

Data TypeRetention Period
Account dataUntil account deletion
Uploaded & processed imagesUntil you delete them or account deletion
Payment recordsAs required by applicable law

11. International Data Transfers

Your data is processed on servers located in the United States through our use of Google Cloud (Firebase) and other third-party services. If you are located outside the United States, your data will be transferred internationally. We rely on the data processing agreements and standard contractual clauses provided by our third-party service providers to ensure appropriate safeguards are in place for these transfers.

12. Children's Privacy

Our Service is not intended for children under the age of 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at team@car-editor.com and we will delete such data.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page. We encourage you to review this page periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have any questions about this Privacy Policy, your data, or wish to exercise your privacy rights, please contact us:

We use cookies to analyze traffic and measure ads. Privacy Policy