This notice separates processing needed for the free enhancement, optional Meta advertising measurement, and optional marketing-email consent.
Effective: 2026-07-25
Controller, company details, and contact
Data controller and DeepBlue AI operator: DIVEROID LTD. Company No.: 16343651. Incorporated and registered in England and Wales. Current registered office: D39 Mexborough Resource Centre, Dolcliffe Road, Mexborough, England, S64 9AZ. Access, correction, and deletion requests: help@diveroid.com. DeepBlue AI is a service brand operated by DIVEROID LTD.
Information we process
We process the email you enter; optional marketing request, email-ownership confirmation, and withdrawal times; notice version and server-generated notice hash; client IP and IP-derived location; User-Agent and parsed device, OS, and browser; locale and its detection source; attribution; the upload file received by our server and image-processing metadata; size-bounded before-and-after JPEG email copies with metadata removed by the server from the actual processed upload JPEG and enhanced result; delivery and suppression status; and result-download activity. For optional Meta advertising measurement, the browser stores the allow or decline choice, consent-notice language and version, notice hash, and decision time. When the first free-enhancement request for an external, non-test email is successfully processed and its result email is accepted, our server database creates a first-email deduplication record containing pseudonymous user and request identifiers and consent status, but no raw email, whether or not measurement was allowed. If you opt in, we also process the advertising-event evidence described below. A supported browser converts every selected JPG, PNG or WebP up to 50MB and HEIC or HEIF up to 15MB into a metadata-free normalized JPEG no larger than 1MB before upload. The selected original and its EXIF or GPS are not sent to or stored by our server; only the converted JPEG is processed. The server makes the before-email copy in request memory by stripping metadata from the actual upload JPEG and does not store it as a separate file in the database or private storage. Our database stores only SHA-256 hashes of confirmation and unsubscribe tokens, not the raw tokens. To deliver email, URLs containing the raw tokens and size-bounded before-and-after email copies are processed by Resend within the scope and retention period disclosed below.
Anonymous daily aggregates for service improvement
To identify friction in the free-enhancement flow, we retain only daily counts by fixed event type (landing_view, photo_selected, submit_attempted), fixed display locale (ko, ja, en), and fixed route group, grouped by Korea Standard Time (KST) calendar date. We do not write cookies or browser/device storage or create or use a persistent identifier for this aggregate. The daily aggregate in the DeepBlue AI application database contains no IP address, User-Agent, email, photo or photo metadata, referrer, UTM parameter, advertising click ID, or separate funnel event record. However, hosting and security provider Cloudflare separately generates operational invocation logs that may contain request time, URL and method, request ID, and routing or security metadata. Under the current setting, Cloudflare retains those logs for up to seven days and then deletes them. We do not use those operational logs to produce the funnel aggregate, target or personalize advertising, or select marketing audiences. We use the application database's daily totals only to improve service usability and reliability, retain only the most recent 90 KST calendar days, and delete older totals through the daily automated retention cleanup.
Notion operational records
After a result email for any user submitted under this notice is accepted, we copy the following information to a US-hosted Notion database for request operations, incident review, user support, and deletion reconciliation: the email address entered; client IP and IP-derived country, city, region and timezone; received User-Agent after control-character and repeated-whitespace cleanup, capped at 1,024 characters; parsed device type, OS and version, and browser and version; the metadata-free normalized upload JPEG generated by the browser and received by the server; the enhanced-result JPEG; the private result URL containing the raw download token; random request ID; request, completion and result-expiry times; request and email states; display locale; a reduced route group; a strictly allowlisted known referring domain; fixed allowlist acquisition tokens issued by the service itself (UTM source, medium, campaign and content); and a marketing-request state. Requests submitted before this notice took effect are not copied to Notion retroactively. Anyone who has the private result URL can access the result while the URL remains valid. The original file selected on the device and its EXIF or GPS are not sent to our server or Notion. The marketing-request state is "not requested" or "requested before confirmation — do not use for marketing"; an email without separately confirmed marketing consent is not used to select a marketing audience or send marketing. The private result URL expires and becomes unusable 168 hours after creation, but its URL string and the Notion photo copies remain until the operational row is cleaned up. The active Notion row and attachments are moved to Notion trash no later than 30 days after collection. Moving a page to trash is not immediate permanent deletion. Under Notion's default settings, a page remains in trash for 30 days before permanent removal from trash and then remains in provider retention for another 30 days before becoming inaccessible to all users. Notion also operates database backups that can restore snapshots from the preceding 30 days. The actual period may differ where Enterprise retention settings, security or recovery needs, or legal-retention obligations apply.
Deletion limits for Notion photo files
In the Notion row-and-attachment cleanup described above, "deleting an attachment" means clearing the file reference displayed in the database property. Cleanup removes the result-URL property and displayed reference to the enhanced photo when the result expires. It clears the displayed reference to the before photo and the remaining sensitive properties no later than 30 days after collection, then moves the page to trash. However, Notion's official File Upload API makes a file permanent and reusable in the workspace after its first attachment and states that the File Upload ID remains valid even when the original page or property is deleted. The current public API provides no way to delete or revoke an attached File Upload. The displayed references to the before and after photos are removed on the schedule above, but we cannot guarantee deletion of the underlying file objects, which may be retained by Notion indefinitely.
Required service processing and optional marketing
Your photo and email are needed to create and deliver the result you request. Marketing consent is optional. Declining it does not prevent you from enhancing one photo at a time for free. A checkbox request becomes active only after you explicitly complete the confirmation page linked from the result email.
Optional Meta advertising measurement
Meta advertising-measurement consent is a separate optional choice from both processing required for free enhancement and marketing-email consent. The browser stores your allow or decline choice, consent-notice language (ko, ja, or en), version, notice hash, and decision time in localStorage so it can remember your choice on later visits. Only when you allow measurement do we register on our server an approval receipt containing a unique receipt ID, status, notice language, version, hash, and decision time; when withdrawal reaches our server, we update that receipt's status. Server-registered approval and withdrawal receipts are retained for up to 90 days. Before you allow it, we do not load Meta Pixel or transmit through Conversions API. After you allow it, Meta Pixel sends PageView and may use _fbp and _fbc cookies. When the first free-enhancement request for an external, non-test email is successfully processed and its result email is accepted, our server database retains for up to 90 days a first-email deduplication ledger containing pseudonymous user and request identifiers and consent status, but no raw email. Only where measurement was allowed does this ledger also store the notice language, version, hash, and decision time. If you decline, this record is still created with a not-consented status but is never sent to Meta. Only after you allow measurement do we record Lead once; Browser Pixel and server Conversions API use the same event ID for deduplication. Meta may receive the page URL and referrer, event name, time and ID, _fbp and _fbc, IP, User-Agent, Meta click identifier, and a SHA-256 hash of the email normalized server-side. We never send Meta the raw email, uploaded photo, enhanced result, result-download URL, or token. If a Conversions API transmission fails transiently, a server-only retry record retains the already SHA-256-hashed email, event time and source URL, IP, User-Agent, and optional _fbp and _fbc, and retries with the same event ID for up to 48 hours. Including daily deletion cleanup, the server-retention limit for that record is 72 hours after creation. The retry record never contains the raw email, photo, enhanced result, result URL, or token and is deleted on delivery, final failure, or retention expiry. When withdrawal reaches our server, we delete any retry record whose transmission has not started and stop future transmission, but a transmission already in progress may complete. We also attempt to delete _fbp and _fbc cookies set by DeepBlue AI. Declining or withdrawing has no effect on free photo enhancement. The anonymous daily service-improvement aggregate described above is separate from this advertising measurement and continues to use no cookies, browser storage, or persistent identifier.
Premium subscriptions and Stripe payments
The Premium subscription provider and contracting party is DIVEROID LTD (Company No. 16343651, registered in England and Wales). When you start Premium checkout, we process your email, recurring-billing acknowledgement time and terms version, IP, country, locale, User-Agent, Stripe Checkout Session, customer, subscription and price identifiers, payment and subscription status, billing period, scheduled cancellation, monthly 200-image allowance and usage, and webhook-processing records. Card numbers and CVCs are entered directly on Stripe's hosted checkout page; our service database does not store full card numbers or CVCs. Stripe may provide limited payment information such as card brand and last four digits. We use payment data for subscription activation, renewal and cancellation, refunds and disputes, accounting and tax, security, and fraud prevention. Declining Premium payment does not affect one-photo-at-a-time free enhancement.
Purposes
We use data to enhance and deliver photos, prevent abuse and enforce fair-use limits, measure service quality, respond to requests, and provide marketing only where separately authorized. Only where Meta advertising measurement is separately authorized do we use its data for advertising and conversion attribution, Pixel and Conversions API deduplication, and cost-per-first-email-acquisition (CPL) measurement.
Retention and deletion
The enhanced result image and download link are available for 168 hours; at expiry, access is revoked and the result image in DeepBlue AI's private storage is deleted. However, the URL string and photo copies replicated to Notion are not automatically deleted at that time and remain until the active Notion row is cleaned up. The active Notion row and attachments are moved to Notion trash no later than 30 days after collection. Moving a page to trash is not immediate permanent deletion. Under Notion's default settings, a page remains in trash for 30 days before permanent removal from trash and then remains in provider retention for another 30 days before becoming inaccessible to all users. Notion also operates database backups that can restore snapshots from the preceding 30 days. The actual period may differ where Enterprise retention settings, security or recovery needs, or legal-retention obligations apply. The size-bounded before-and-after email copies included in the email are ordinarily retained by Resend for 30 days and may remain longer in the recipient's mailbox according to that mail service and the recipient's deletion settings. Independently of result-link expiry, the upload file received by the server (a browser-generated, metadata-free normalized JPEG no larger than 1MB) and request-environment record remain in private storage until 30 days after collection and are then deleted. They may be deleted earlier after a user deletion request or safe cleanup of a failed request. Server-registered Meta approval and withdrawal receipts and the first-email deduplication ledger are retained for up to 90 days after creation. An approval receipt contains a unique ID, status, notice language, version, hash, and decision time; a not-consented deduplication ledger contains no notice evidence. A transient Conversions API transmission is retried for up to 48 hours, while the server-retention limit for its retry record, including daily deletion cleanup, is 72 hours after creation. That record is deleted on delivery, final failure, retention expiry, or withdrawal received before transmission starts. Active marketing consent may be retained until withdrawal, and legally required evidence until the applicable obligation ends.
Processors and international transfers
DIVEROID LTD (Company No. 16343651, registered in England and Wales), the operator of DeepBlue AI ("we"), transfers personal data abroad for core processing and storage necessary to enter into and perform the photo-enhancement service you request. The Meta advertising-measurement transfer occurs only after a separate optional choice and is distinct from both those required transfers and optional marketing-email consent. Transfers use encrypted channels such as HTTPS.
The United States and the processing countries or regions disclosed for OpenAI subprocessors. ChatGPT Sites currently provides no fixed data residency, and network processing may occur at the Cloudflare data center nearest the visitor.
Data transferred
Email; IP and IP-derived country, city, region and timezone; User-Agent and device, OS and browser; locale; landing URL, host, UTM and ad-click IDs; consent and withdrawal evidence; request, email-delivery and download metadata; the upload file received by the server and result images; hashed security tokens and link tokens processed only when a request is made. A supported browser converts every selected JPG, PNG or WebP up to 50MB and HEIC or HEIF up to 15MB into a metadata-free normalized JPEG no larger than 1MB before transfer. The selected original and its EXIF/GPS are not transferred to the server.
Timing and method
Over encrypted networks when you visit the site or submit, store, process or download a photo, and when you confirm or withdraw consent
Purpose
Site hosting and traffic delivery, database and private-image storage, regional language selection, request processing, security and incident response
Retention
The enhanced result image and link expire after 168 hours, when access is revoked and the result is deleted. Independently, the upload file received by the server (a browser-generated, metadata-free normalized JPEG no larger than 1MB) and the request-environment record remain in private storage until 30 days after collection and are then deleted. Active marketing consent and legally required evidence may remain until withdrawal or the relevant obligation ends. Provider-side operational logs and backups are processed for the periods required by the applicable agreement, security needs and law.
The United States and the visitor-near Cloudflare data center in its global network
Data transferred
IP address, TLS fingerprint, User-Agent, Sitekey and associated origin, and browser or connection signals used for bot detection. We do not store the Turnstile response token in our database after verification.
Timing and method
Over an encrypted network when the upload form performs and submits its security check
Purpose
Automated-access and bot detection and blocking, and Turnstile improvement
Retention
For the period needed for bot detection, security and legal obligations. Cloudflare determines the period using the purpose, nature and risk of the information and its legal obligations.
The United States and OpenAI's disclosed API-processing infrastructure regions. The service currently uses the non-regional default API endpoint.
Data transferred
The image sent for AI enhancement (a browser-generated, metadata-free normalized JPEG no larger than 1MB made from the selected JPG, PNG, WebP, HEIC or HEIF), the underwater-enhancement instruction, generated result image and API-request metadata. The selected original and its EXIF/GPS, the email you enter and your client IP are not included in the image API request. The before-email copy is not a separate upload: the server makes it from this actual AI-input JPEG in request memory.
Timing and method
Through an encrypted HTTPS API when you request photo enhancement
Purpose
AI image enhancement and result generation, abuse prevention and safety review. API inputs and outputs are not used to train models by default.
Retention
By default, the image-edit endpoint has no application-state retention and abuse-monitoring logs may remain for up to 30 days. Data may remain longer where required by law or needed to protect services or third parties. Images flagged as potential child sexual abuse material may exceptionally be retained for manual review.
Recipient email, localized subject and body, a requested six-digit account email-verification code, a size-bounded before JPEG stripped of metadata from the actual upload and a size-bounded after JPEG stripped of metadata from the enhanced result, result-download URL, marketing confirmation, cancellation and unsubscribe URLs, message ID, and sent, delivered, delayed, bounced, complained and suppressed status
Timing and method
Through an encrypted HTTPS API and email network when a result or consent-related email or a user-requested account email-verification code is sent and when delivery-status webhooks are received
Purpose
Result delivery, email-ownership verification for account connection, optional-marketing confirmation, cancellation and unsubscribe, and delivery, bounce and complaint handling
Retention
Email data and email-sized previews for the standard service are ordinarily retained by Resend for 30 days. The delivered message and previews may remain longer in the recipient's mailbox according to that mail service and the recipient's deletion settings. Under the Resend DPA, customer data is processed while the agreement is active and deleted within 90 days after account termination, subject to legal-retention exceptions.
United States. Because no separate Enterprise data-residency setting is currently confirmed for this workspace, it is treated as US-hosted.
Data transferred
The email address entered; client IP address and IP-derived country, city, region and timezone; received User-Agent after control-character and repeated-whitespace cleanup, capped at 1,024 characters; parsed device type, OS and version, and browser and version; the metadata-free normalized upload JPEG generated by the browser and received by the server; the enhanced-result JPEG; the private result URL containing the raw download token; random request ID; request, completion and result-expiry times; request and email states; two-letter country code; display locale; a reduced route group; a strictly allowlisted known referring domain; fixed allowlist acquisition tokens issued by the service itself (UTM source, medium, campaign and content); and a marketing-request state ("not requested" or "requested before confirmation — do not use for marketing"). Anyone who has the private result URL can access the result while the URL remains valid. The original file selected on the device and its EXIF or GPS are not sent to our server or Notion. We do not treat an unconfirmed request as marketing consent or an audience for sending.
Timing and method
After a result email for any user submitted under this notice is accepted, when the server creates or updates the operational row and attachments through the encrypted HTTPS Notion API and File Upload API. Requests submitted before this notice took effect are not transferred to Notion retroactively.
Purpose
Operational monitoring of request and email states and acquisition path, incident and support handling, and retention-cleanup reconciliation. An email without separately confirmed marketing consent is not used to select a marketing audience or send marketing.
Retention
The private result URL expires and becomes unusable 168 hours after creation. Daily cleanup removes the expired result-URL property and the displayed reference to the enhanced photo. The remaining active Notion row, sensitive properties, and displayed reference to the before photo are cleared no later than 30 days after collection, and the page is moved to Notion trash. By default, a page remains in trash for 30 days and may then remain in provider retention for another default 30 days; Notion also operates backups capable of restoring snapshots from the preceding 30 days. Separately from that page-and-property lifecycle, Notion's official File Upload API makes a file permanent and reusable in the workspace after its first attachment and states that the File Upload ID remains valid even when the original page or property is deleted. The current public API provides no way to delete or revoke an attached File Upload. The displayed references to the before and after photos are therefore removed on the schedule above, but we cannot guarantee deletion of the underlying file objects, which may be retained by Notion indefinitely. The actual period may differ with Enterprise settings, the provider's security, recovery or deletion procedures, or legal-retention obligations.
The United States, Ireland, and the processing countries or regions of affiliates and processors disclosed in the Meta Privacy Policy
Data transferred
Page URL and referrer; event name, time and unique event ID; Meta Pixel cookie identifiers (_fbp and _fbc); IP address; User-Agent; Meta advertising-click identifier; and the normalized email SHA-256 hashed server-side for Conversions API. We never send Meta the raw email, uploaded photo, enhanced result, result-download URL, or token.
Timing and method
Through the browser Meta Pixel and encrypted HTTPS Conversions API only after separate optional advertising-measurement consent, when a page is viewed or when the first free-enhancement request and result-email acceptance for an external, non-test email produces a Lead event
Purpose
Meta advertising and conversion attribution, deduplication of browser Pixel and server Conversions API events by the same event ID, and cost-per-first-email-acquisition (CPL) measurement
Retention
Under the Meta Business Tools Terms, hashed email as Contact Information is deleted after the matching process and Event Data may be retained for up to two years. The Meta Privacy Policy, security needs, and legal obligations also apply. The browser's advertising-measurement choice remains in localStorage until withdrawal. On withdrawal, we stop future Pixel and Conversions API transmission and attempt to delete _fbp and _fbc cookies set by DeepBlue AI.
Stripe Payments Europe, Limited, Stripe Payments UK Limited, and Stripe affiliates and subprocessors involved based on account and transaction location, including Stripe, LLC
The United States, India, and processing countries or regions disclosed for Stripe affiliates and subprocessors, depending on account, customer location and payment method
Data transferred
Email; billing name and address where requested; payment-method, transaction and subscription information; IP, device, browser and fraud-prevention signals; and Checkout Session, customer, subscription, price and payment identifiers and status. Stripe collects card numbers and CVCs directly; our database does not store the full values. The current payment integration does not send photos, EXIF/GPS or marketing-consent data to Stripe.
Timing and method
Through encrypted HTTPS APIs and payment networks when Premium checkout opens, a payment is attempted, a subscription renews or is canceled, a refund or dispute occurs, or a signed webhook is processed
Purpose
Recurring payment and renewal, subscription and monthly 200-image entitlement administration, receipts, refunds, disputes, accounting, tax, authentication, security, fraud and loss prevention, and legal compliance
Retention
For the subscription term and thereafter as required for legal, accounting, tax, payment-method, fraud and dispute obligations. Stripe determines the actual period under applicable limitation periods and record-retention requirements.
Because ChatGPT Sites does not provide fixed data residency, the actual processing country may vary with connection location and provider infrastructure. We will update this notice if a provider or processing region changes materially.
Withdrawal and rights
You can withdraw marketing consent through the unsubscribe link in result email and separately withdraw Meta advertising-measurement consent through the site's measurement settings. Neither choice affects the free service. Contact help@diveroid.com for access, correction, deletion, or restriction requests. Bounced, complained, suppressed, and unsubscribed addresses are automatically excluded from marketing.