Draw For Me privacy policy
Effective date: September 11, 2026
Draw For Me is operated by Pocket Dusk (pocketdusk.com). Our app website is drawforme.app. Contact us about privacy at support@drawforme.app. The app is designed for adults to draw, receive an AI-generated spoken reaction, and keep drawings in a local collection.
Drawing locally and choosing to send
You can draw and save on your device without an account or sending a drawing for an AI reaction. Before your first upload, we explain processing and ask you to agree. Declining keeps the drawing on your device. When the in-app notice changes, we ask you to review it again before sending another drawing.
Your optional first name is stored in the app's local settings. You can change or remove it in Settings. Removing it affects future reactions; it does not change the words in previous recordings.
How a spoken reaction is made
When you choose to show a drawing, these services process it:
| Service | What it receives and does |
|---|---|
| Our backend, hosted on an OVHcloud VPS in Beauharnois (BHS), Canada | Receives the drawing, optional first name and chosen personality; coordinates the reaction and delivers results to your device. |
| OpenRouter and Google Gemini through Google AI Studio or Vertex AI | Receive the drawing and optional first name with reaction instructions. Gemini produces the spoken text, speech directions and bounding boxes used to move around the drawing during speech. OpenRouter routes the requests and responses. |
| Breeze Blue | Receives the reaction text, speech directions and selected voice settings, and generates speech. The text and directions may contain your name and details about your drawing. We do not send the drawing image to Breeze Blue. |
| OpenRouter and Microsoft MAI Transcribe 2 through Azure | Receive the generated speech to produce a transcript and word timings that synchronize the picture with speech. This audio can contain your name and details about your drawing. It is synthetic speech, not a microphone recording of you. |
Audio-only retries send existing reaction text and speech directions back to our service to regenerate audio. These pass through the same speech and timing services.
We do not attach your installation identifier or client IP address to AI generation or transcription requests. This does not make the content anonymous: your optional name, details written or drawn in the picture, and the resulting reaction may contain personal information. Providers receive requests using our service accounts and see our server's network connection.
What our service keeps
Our production backend does not write drawings, optional names, reaction text, speech directions, bounding boxes, audio or transcripts to its database or content logs. It processes them in memory. Completed reaction results normally remain in a temporary memory cache for up to 10 minutes after completion to support delivery and reconnection, and can be removed sooner.
We keep operational records to provide reactions, manage fair usage, prevent abuse, understand personality usage, diagnose failures and track service costs:
- An app installation identifier, hashed authentication credential, creation and last-seen times, verification status and usage-limit settings. This is an app installation identity, not a claim that we collect a hardware serial number or advertising ID. These records currently have no automatic expiry.
- Request identifiers and checksums, chosen personality, app version, request status and times, provider/model/voice identifiers, usage quantities, audio duration, costs, latency and sanitized error codes. Closed-job records are normally deleted 90 days after closure. Unresolved jobs remain until settled, after which that retention period applies.
- Raw IP addresses in the backend database, normally removed after 7 days, and derived network keys used to enforce rate limits. Network keys associated with jobs follow the job-record retention period.
- Reaction reports containing a reaction identifier and selected reason. The report does not upload the drawing, reaction text or audio. Reports follow the associated closed-job retention period.
Automatic backups of stored backend data rotate out after 7 days. They contain only data already stored by the backend; they do not add copies of drawings, reaction text, audio or transcripts that the production backend does not save. A record deleted from the live database may remain in an older backup for up to 7 additional days before that backup rotates out.
Our backend and websites are hosted on the same OVHcloud VPS in Beauharnois, Canada. This hosting location does not establish where the separate AI providers process or retain content.
Our Apache web server also keeps standard access and error logs for operation, troubleshooting and security. Depending on the configured log format, these may include IP addresses, request times, requested paths, response status, browser/app information and referrers. These logs are separate from the backend database, so removing an IP address from that database does not remove it from web-server logs.
Apache logs rotate daily. We retain 14 rotated copies alongside the current log; the oldest rotated copy is deleted as a new one is added. Older copies are compressed to save space. Compression does not delete their contents or extend this rotation schedule.
Android releases use Google Play Integrity to verify the app, installation licensing and device integrity for abuse prevention. This is separate from Google's processing of drawings for AI reactions.
Local development tests can explicitly capture prompts, responses and audio on the development computer. This mode is rejected by the production backend and must not be used to serve public users.
Provider retention and model training
Our server's storage rules do not control provider storage.
The OpenRouter endpoint descriptions supplied for this release state that Google AI Studio may retain prompts but does not train on them, while Vertex AI and Azure MAI Transcribe 2 do not retain prompt data or train on prompts. We do not promise a deletion deadline for AI Studio where one has not been confirmed. These statements concern content, not an absence of provider billing or operational metadata. See OpenRouter's provider policy guidance.
OpenRouter keeps operational request metadata, such as the model used, request time and usage measurements. Content logging is disabled for our account, so these logs do not contain drawings, names, reaction text or audio. We do not send app installation identifiers or client IP addresses with these requests. See OpenRouter data collection. OpenRouter's separate setting allowing use of inputs and outputs to improve its products is also disabled for our account.
Breeze Blue's policy permits retention of submitted content, generated outputs and related metadata while the service account is active and generally for up to one year after its last activity. This includes the text and speech directions we submit and the generated audio, not just the audio. Because we use an account that serves the app, its wording does not guarantee deletion within one year of your individual reaction. Continued activity on our account may extend that period. Deleting a drawing in Draw For Me does not delete provider copies. See Breeze Blue's privacy policy.
We have opted out of Breeze Blue's use of content for general model training or improvement. This opt-out does not shorten its stated retention period or promise deletion of content previously retained.
Your choices and deletion
You can keep drawings local, decline upload, remove your optional name, delete saved pictures and reactions, or clear the app's local data. Uninstalling or clearing app data removes local copies, not server records or provider copies. Delete exported copies separately wherever you saved them.
To request deletion of server-held information associated with your app installation, email support@drawforme.app. We may ask for limited information to locate the relevant records and verify the request. Please do not send passwords, authentication credentials or copies of your drawings.
We will review your request and delete information we can identify as yours, except where limited retention is necessary and permitted by applicable law for security, preventing abuse, enforcing fair-use limits, or meeting legal obligations. We will explain any information retained, the reason and the applicable retention period. A deletion request does not automatically reset reaction allowances. These exceptions are not a reason to keep all usage history indefinitely.
Deleted records may remain in rotating backups for up to 7 additional days. We will account for completed deletion requests if a backup is restored. For content retained by an AI provider, we will help pursue deletion where we can identify the relevant request and the provider supports it; we cannot promise immediate removal of all provider copies.
Deletion requests are handled manually by Pocket Dusk using the relevant app installation identifier; the app does not provide automatic server-data deletion.
Security and changes
Access to stored backend data is restricted using service accounts and file permissions. Our backend and administration services are not directly exposed to the public network. Production content logging is disabled as described above.
We update this notice when our practices change. The in-app notice version is 3. A change to the website alone does not trigger a new in-app agreement; the updated notice is delivered with an app update.