Privacy Policy
How we handle your data
Last updated: July 14, 2026
Data Collection
When you use Draw My Life, we collect the following information:
- Uploaded image files: Children's drawings or hand-drawn images you upload, used for AI scoring and image enhancement.
- Contact form information: Name, email address, and message content submitted via the "Contact Us" form.
- Login email information: When you sign in with an email verification code, we collect the email address you provide to send the code, create or identify your account, show account status, and calculate your daily usage quota.
- Browser local data: Language preference plus sanitized first-touch, last-touch, and current-tab campaign/referrer-host attribution. Attribution stays in browser storage and is not added to service records.
- Website analytics data: We use Google Analytics for a fixed, minimized conversion funnel using allowlisted event names and low-risk context such as language, user type, fixed placement, and sanitized campaign fields.
Other than the information needed for the features above and website analytics, we do not collect personal information unrelated to the service.
How We Use Your Data
Your data is used only for the following explicit purposes:
- Image files: Used solely for AI scoring and image enhancement. After processing, they are not used to train models, nor shared or sold.
- Contact form information: Used only to reply to your inquiry, never for marketing, advertising, or third-party outreach.
- Website analytics data: Used only to understand where the product journey succeeds or stops. Events exclude drawings, filenames, report text, scores, contact form content, complete URLs, raw errors, and account or artwork identifiers.
We promise never to sell your personal information to third parties, nor disclose your data without authorization.
AI and Third-party Processing
To perform scoring and enhancement, we may send your uploaded images to a configured AI service provider for processing.
- Scope of processing: The AI provider is used only to generate this session's scores, feedback, and a clearly labelled AI reference when generation succeeds.
- Provider configuration: The service calls models through a backend-configured AI interface; public production deployments should use explicitly authorized provider accounts and keys.
- Training use: This product does not proactively use uploaded images to train its own models.
- Cross-border and third-party rules: If the operator chooses an overseas or third-party AI service, disclosure must follow that provider's data processing terms and applicable laws.
- Google Analytics: We use Google Analytics for minimized page and conversion measurement. It does not receive uploaded drawings, filenames, report text, scores, contact form content, complete URLs, raw errors, or internal IDs. Blocking Analytics does not block product features.
- Content safety moderation: Before scoring, uploaded images are sent to a third-party content safety provider (Aliyun Content Moderation) to detect non-compliant content. Only the image needed for this check is transmitted, and no contact form content is shared.
- Email verification delivery: When you sign in with email, we use Aliyun DirectMail to send a one-time verification code to the email address you provide. This service is used only for sign-in verification emails, not marketing emails.
- Verified-email account linking: If you use Google and Email login with the same verified email address, we may link them to the same local account so your artwork, quota, and account data stay consistent.
Data Retention
We set clear retention periods for different types of data:
- Artwork assets: Guest artworks are temporary and periodically removed. Signed-in artworks remain in account history until permanent deletion; local working copies may expire independently.
- Contact form records: Retained for no more than 90 days for follow-up communication, then deleted.
- Browser storage data: Language preference remains until cleared. Sanitized first-touch attribution expires after 90 days, last-touch after 30 days, and current-tab attribution when the tab session ends. You can clear this data in browser settings.
- Email verification records: Verification codes are valid only for a short period. The server stores only secure hashes of codes and necessary sending, verification, and rate-limit records to complete sign-in and prevent abuse.
- Password records: If you set a local password, we store only a secure password hash and necessary security metadata. We do not store your plaintext password.
Permanent artwork deletion removes the original, enhancement, report, task state and related metadata. External-storage failures are retried and may take up to 24 hours.
Deletion Requests
You can delete or request deletion of your data in the following ways:
- Signed-in artworks: Use Permanent Delete in My Center. The work is hidden immediately while original and enhanced images, report/task state and related metadata are removed; retry status is retained if external storage is temporarily unavailable.
- Contact form records: Submit a deletion request via the Landing Page contact form, providing the email or submission ID used at submission.
- Browser local data: Clear localStorage and cache through your browser settings.