Privacy policy

Last updated: 09.10.2026

Draft: this text has not yet been reviewed by a lawyer. Details in square brackets will be added.

This policy explains which personal data Inkmirra processes, for what purpose, on which legal basis, for how long, and what your rights are. In short: your tattoos and scans are private by default. We never sell data, we use no advertising or analytics trackers, and we make no automated decisions about you.

Controller and contact

The controller within the meaning of the GDPR is:

Think3DDD – Jacobi & Lauer GbR
Teutonenstraße 74
12524 Berlin
Deutschland
Represented by: Tino Jacobi und Amar Kumar Myadam (Gesellschafter)
Phone: +49 (0)30 678 05 995

Data protection officer: Memex Consulting GmbH, Stefan Priess, Nördliche Münchner Str. 14 A, 82031 Grünwald, datenschutz@think3ddd.de

For any privacy question or to exercise your rights, contact inkmirra@think3ddd.de.

Which data we process

  • Account data: e-mail address, user name, first and last name (on registration), account type (tattoo owner, artist, studio, platform), language, password (hash only), optional two-factor data.
  • Scans and body images: the uploaded smartphone video, frames extracted from it and the 3D model of a body part with a tattoo, preview images, a crop you set.
  • Tattoo data: title, body part, style, colour, date, artist, visibility, permissions, memorial mode.
  • Diary: phases, notes, skin condition (1–5), care products, photos. Healing details can be health data.
  • Artist and studio profile: profile name, display name, studio, city, styles, bio, links, profile picture, team memberships, statistics (views).
  • Payment and contract data: products and subscriptions bought, credit balance and bookings, billing address and VAT ID (business customers), Stripe customer and payment IDs. We never receive card details; Stripe processes them.
  • Consents and declarations: time and version of your consent to the terms, to the immediate start (right of withdrawal) and to the processing of body images; notices, withdrawals and cancellations sent via our forms.
  • Communication: messages to us, feedback, support chat.
  • Technical data: IP address, time, requested address, browser identifier (server logs); session and security cookies.

Purposes and legal bases

PurposeLegal basis
Creating and running your account, providing Inkmirra (upload, 3D processing, viewer, journey, diary, sharing, widgets, handover, codes, studio teams, platform API)Art. 6(1)(b) GDPR (contract)
Scans of body parts and tattoos, diary with healing details (may reveal health, religious or philosophical beliefs)Art. 9(2)(a) GDPR (explicit consent) in addition to Art. 6(1)(b) GDPR
Sharing by link, sharing your journey, public visibility, gallery, artist portfolio and showcaseYour consent (Art. 6(1)(a), Art. 9(2)(a) GDPR), given with the respective setting and withdrawable at any time by changing it
Payments, invoices, credits, artist creditArt. 6(1)(b) GDPR; retention under Art. 6(1)(c) GDPR with § 147 AO, § 14b UStG
Service e-mails (registration, scan ready, handover, purchase confirmation, reminders you set up)Art. 6(1)(b) GDPR
Proof of consents and declarations (time, version)Art. 6(1)(c) with Art. 7(1) GDPR; Art. 6(1)(f) GDPR (defence of claims)
Security, abuse prevention, troubleshooting (server logs, rate limits, CSRF protection)Art. 6(1)(f) GDPR (legitimate interest in secure operation)
Handling notices of illegal content, withdrawals and cancellationsArt. 6(1)(c) GDPR (Art. 16, 17 DSA; § 312k BGB; right of withdrawal)
Enquiries (e-mail, feedback, chat)Art. 6(1)(b) GDPR where related to a contract, otherwise (f)

We only send marketing e-mails with separate consent (double opt-in). Service e-mails contain no advertising.

Special categories: body images and tattoos

A 3D scan shows a part of the body. Tattoos and diary entries may reveal health (e.g. healing, skin condition), religious or philosophical beliefs or other sensitive traits. We therefore treat this data as special categories under Art. 9 GDPR:

  • Before your first scan we ask for your explicit consent separately (its own checkbox, separate from the terms).
  • Artists and studios who scan clients confirm beforehand that the scanned person has consented. They are responsible for that consent.
  • Scans are private by default. They only become visible if you create a link, change the visibility or allow use in an artist portfolio.
  • With a crop, sharing shows only the motif. The original file stays in your account.
  • Please do not film faces. We do not analyse scans biometrically or use them to identify people.
  • You can withdraw your consent at any time (on the upload page or under Account and data). We then create no new scans; you delete existing scans in your account. Processing before the withdrawal remains lawful.

Hosting, processing and recipients

Servers

Website, database and files run on a server managed by us (Cloudron) at [HOSTING-ANBIETER des Cloudron-Servers], location [SERVERSTANDORT, z. B. Deutschland], under a data processing agreement (Art. 28 GDPR). Sign-in uses this server's user directory.

3D processing

A computer we own and operate (Mac Studio, [STANDORT DES MAC-STUDIO-WORKERS, z. B. Büro in …]) turns your video into the 3D model. It only receives short-lived access keys for each job. No scans are sent to third parties or AI services.

E-mail

Service e-mails are sent through the mail server of our own server [IF AN EXTERNAL SENDING SERVICE IS USED: ADD NAME, SEAT, DPA].

Nextcloud (optional)

With a subscription you can have your scans copied to your Nextcloud space on our server. This only happens if you connect it yourself. You delete copies there yourself.

Payments: Stripe

Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (card, Apple Pay, Google Pay, SEPA Direct Debit; PayPal via Stripe). You enter payment details directly with Stripe. We receive name, e-mail, billing address, VAT ID where given, amount, payment status and the type or last digits of the payment method. Stripe also processes data as an independent controller (e.g. fraud prevention, legal obligations) and may transfer it to Stripe, Inc. in the USA on the basis of the EU-US Data Privacy Framework adequacy decision or standard contractual clauses. Privacy notice: stripe.com/privacy.

If you pay with PayPal, PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg, is an additional independent controller: paypal.com/legalhub/privacy-full.

Other recipients

  • Artists, studios and platforms you are connected with (e.g. the artist sees whether you accepted a handover; a studio sees its members' work).
  • Anyone with a link you shared sees the shared content (without your name and e-mail address).
  • Tax advisers and authorities where we are legally obliged.

We do not sell personal data or pass it on for advertising.

Artists, studios and platforms as controllers

When an artist or studio scans a client, the artist or studio decides on that processing and is responsible for the client's consent and information. We process these scans on their behalf until the handover. Once the client accepts the tattoo, this policy applies to the client's account.

Platforms that integrate Inkmirra via the API or scan widget are responsible for their artists' and clients' data; we act as their processor under an agreement according to Art. 28 GDPR. Platform scans never appear in the gallery, directory or showcase.

Retention and deletion

DataRetention
Uploaded videos and frames (raw data) in the processing storage7 days after upload, then deleted automatically
Preview and trial scans that were not accepted, were rejected or failed, and were neither paid nor linked to a tattoo30 days, then the 3D files are deleted automatically
Accepted scans (viewer or full quality)until you delete them or your account
Deleted tattoos and scans (trash)restorable for 30 days, then deleted for good
Account after a deletion request30-day grace period (cancellable), then scans, diary, photos, profiles and exports are deleted and the account record is anonymised
Data export (ZIP)downloadable for 7 days, then deleted
Invoices and accounting recordskept under § 147 AO, § 14b UStG (currently 8 years for accounting vouchers, 10 years for books and annual accounts); restricted to this purpose. In your Inkmirra account the details are anonymised when the account is deleted.
Proof of consents, notices, withdrawals and cancellationsuntil the limitation periods expire (usually 3 years from the end of the year)
Server logs[LOG-SPEICHERDAUER, z. B. 14] days
All other dataas long as your account exists or until you delete it

Shared links expire after the period you chose (7, 30 or 90 days, or never for a family link) and go offline at once when you end them or delete your account.

Your rights

  • Access (Art. 15 GDPR) – also as a data export under Profile → Account and data
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR) – you can delete tattoos, scans and your account yourself
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR) – ZIP export with JSON and 3D files
  • Objection to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21 GDPR)
  • Withdrawal of consent at any time with effect for the future (Art. 7(3) GDPR)

You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), e.g. in your country or the authority responsible for us: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin.

Cookies and local storage

We use no analytics, advertising or tracking cookies and no third-party tools that analyse your behaviour. Fonts and flag icons are served by us. That is why there is no cookie banner. We only store on your device what is strictly necessary for the service you asked for (§ 25(2) no. 2 TDDDG):

NameTypePurposeDuration
access_token, refreshTokenCookie (HttpOnly)sign-inuntil sign-out or expiry (hours to days)
__Secure-psifi.x-csrf-tokenCookieprotection against forged requests (CSRF)session
authTokenLocal storagesign-in when the browser blocks cross-site cookies (e.g. Safari); also the restricted device sessionuntil sign-out
last2FAVerifiedLocal storagetime of the last two-factor confirmationuntil sign-out
i18nextLng, language, themeMode, accessibilitySettingsLocal storagelanguage, light/dark mode and accessibility settings you choseuntil you change or clear them
pilotBannerDismissedLocal storagenotice dismissedpermanent
api_version, subscription_updatedLocal storagetechnical check after updates or subscription changespermanent or short
inkmirraClaimToken, inkmirraStudioInvite, inkmirra.qr.*, ink.topUp.return, inkmirraPricingAudience, live_chat_*Session storagethe current process (handover, invitation, QR purchase, return after payment, pricing tab, support chat)until the tab is closed

Campaign parameters in links (utm_source, utm_medium, utm_campaign …) are not stored on your device; they are only part of the requested address and therefore of the server logs.

On Stripe's payment page, Stripe sets its own cookies needed for the payment and fraud prevention (see Stripe's privacy notice).

Restricted device session

If you buy via QR code, accept a tattoo or redeem a code, we create an account with your e-mail address and sign you in on this device only. Until you confirm your e-mail address and set a password, the session is restricted (e.g. no export, no sign-in on other devices). Legal basis: Art. 6(1)(b) GDPR.

Widgets embedded on other websites

Artists, studios and platforms can embed portfolio, tattoo and scan widgets on their own websites. Your browser then loads content from our server, which technically transmits IP address, time and requested address (Art. 6(1)(f) GDPR). Widgets set no tracking cookies. The website operator is responsible for embedding them on their site.

Minimum age

Inkmirra is for people aged 16 and over. Only people aged at least 16 may create an account (see Youth protection).

No automated decision-making, no sale of data

We make no decisions based solely on automated processing that produce legal effects for you (Art. 22 GDPR) and do no profiling for advertising. Technical checks (e.g. scan quality, preview quota, rate limits) do not assess you as a person.

We do not sell personal data.

Obligation to provide data

For an account and purchases we need at least your e-mail address; without it we cannot conclude a contract. For scans we need your consent to the processing of body images. Everything else is voluntary.

Security

Connections are encrypted with TLS. Passwords are stored as hashes only. Two-factor sign-in is available. Access to model files is checked per request; the scan server only receives short-lived keys.

Changes

We update this policy when Inkmirra or the law changes. The version published here applies.