Bebelu Privacy Policy
Last updated: 22 September 2026
Purpose and data controller
Bebelu is for parents and legal guardians to create photos, keep memories and maintain personal records. Contact: Oğuz Kağan Yatağan — fethiyewebtasarimi@gmail.com.
Data sent to the AI
After you give consent, the photos you select, the generation prompt and the options are sent to Google Gemini via the Bebelu server hosted on Hostinger. In chat, the last 20 messages, the type of the selected profile and the approximate age/pregnancy week are shared. The profile name, exact birth date/last menstrual period date and measurements are not sent automatically. Any personal information you type into a message yourself is also transmitted as part of that message. Do not enter unnecessary personal or health information.
Retention
- Uploaded photos are used only during processing; no permanent archive of input photos is kept. During processing, the hosting provider's temporary upload area is used.
- The generated photo is stored for at most 24 hours in an area that is not directly accessible from the web, so that you can retrieve it if the connection is lost. Once the app confirms the local save, the server copy is deleted. Records exceeding this period are cleared by a maintenance task.
- Photos, chat history, profiles, measurements and preferences are stored on your device until you delete them. Your operating system's backup settings apply separately.
- The wallet ID, hashes of the session and the recovery code, credit transactions and verified purchase identifiers are stored for balance management and to prevent duplicate processing. Apple processes your card details; Bebelu does not receive your card details.
- To limit abuse, a short-lived counter is kept using a one-way hash of your IP address. Raw photos, chat text and recovery codes are not written to the app's error logs. The hosting provider's access logs may additionally contain IP/request information.
Google and other service providers
Google processes Gemini data under its own terms of service, billing tier and abuse monitoring. Bebelu does not guarantee zero retention or non-use for training on Google's side. The Gemini API terms and Google's retention statement apply. Because of the Hostinger and Google infrastructure, data may be transferred outside the country. The live service's data-processing and region settings are managed by the publisher.
Permissions and security
Selecting a photo does not grant access to your entire library. Camera and photo-adding permissions are requested during the relevant action. You can withdraw AI sharing consent in Settings; this stops future transfers. Jobs that have already started cannot be reversed. The wallet session is stored in the device's Keychain. Do not share your recovery code. DeviceCheck is used for device verification with Apple and to reduce abuse of the one-time starter allowance. No ad tracking or third-party advertising SDKs are used.
Deletion, recovery and requests
Settings > Delete content on this device deletes the local gallery, profiles, measurements and chats; it does not delete your server balance or Apple subscription. In the Wallet and recovery section, you can close wallet access and delete pending content on the server. After the wallet is closed, financial transaction and uniqueness records are retained to the extent required for legal obligations or payment disputes; other data requests are assessed via the support address. You must also cancel your Apple subscription from your Apple account. The recovery code is for the wallet only; it does not back up photos or profiles.
Children's photos
A child's photo should be uploaded only by a parent/legal guardian or a person with the necessary permission. You must also be authorised to share photos of other people. The app is not a standalone social network aimed at children.