App

Privacy policy

Last updated: 14 August 2026

Privacy policy (app)

This policy covers the Hissberto iPhone app. The website hissberto.app has its own policy: hissberto.app/privacy/

1. Who is responsible

Apptheism, Jörg Klausewitz
Fischmarkt 17, 78462 Konstanz, Germany
Email: privacy@hissberto.app

2. What this app does

Hissberto inserts a cat into a photo. To do that, the photo you choose is sent to an AI service operated by Google, edited there, and returned as a new image. That is the only data transfer required for the app to work.

There is no user account, no registration and no sign-in. We do not know who you are and cannot link your usage to a person.

3. Processing of your photos

What happens: When you generate an image, the selected photo is sent together with a fixed text instruction to Google (Firebase AI Logic with the Gemini image models). Google produces the edited image and returns it to your device.

Purpose: Carrying out the image edit you requested.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract. Without this transfer the app cannot deliver its only function.

Storage: We do not store your photos on any server. There is no server and no database of our own; the app talks to Google directly.

The finished image is saved automatically inside the app, on your device only, so that it is not lost if you close the app without sharing it. You can view these images under “Your cats” and delete any of them at any time. They reach your system photo library only if you save them there explicitly. Deleting the app removes them all.

Use by Google: Hissberto uses the paid tier of the Gemini API. For that tier, Google states that submitted content is not used to train its models. Google may retain content briefly for abuse monitoring. Details are governed by the Google terms linked in section 9.

If your photo shows other people: you are transferring their likeness as well. Only upload photos you are entitled to use.

4. Other data leaving your device

Apart from the photo, only technical data is transmitted:

Device attestation (App Attest). So that other software cannot abuse our AI access, your device proves to Apple and Google that the request comes from a genuine, unmodified Hissberto installation. What is transmitted is a cryptographic attestation, not an identifier that identifies you. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in preventing abuse and runaway cost.

Installation identifier. Firebase assigns a random identifier per installation (Firebase Installation ID). It is technically required for the attestation and for loading the app configuration. It contains no personal details and is reset when you delete and reinstall the app.

App configuration. On launch the app loads settings from Google (Firebase Remote Config), for example which AI model to use. No content of yours is transmitted in the process.

Purchases. Credits are bought through the App Store. Payment is handled by Apple; we receive neither your name nor payment details, only the confirmation that a purchase took place.

5. What stays on your device

The images you create are kept in the app’s own directory on your device, see section 3. Your credit balance and the free-image counter are stored locally only, in the device keychain. Your settings (quality tier, watermark switch) are stored in the app's own preferences. None of this is transmitted.

Because the keychain is not erased when an app is removed, both your credit balance and the free-image counter survive deleting and reinstalling the app. Your settings do not — they return to their defaults.

6. No analytics, no tracking

Hissberto contains no analytics, advertising or tracking libraries. No usage profiles are created, no advertising identifier (IDFA) is read, and no data is passed to third parties for advertising. There are no cookies.

7. Permissions

Camera — to take the photo the cat is inserted into.
Photo library (add only) — solely to save a finished image when you ask for it.

You can revoke both at any time in the iOS settings. Without camera access you can still pick photos from your library.

8. Recipients and international transfers

Recipients are Google (image processing, attestation, configuration) and Apple (app distribution, payment processing, attestation).

Data may be transferred to and processed in the United States.

For Google, transfers are covered by the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, under which Google is certified, supplemented by the European Commission's Standard Contractual Clauses where applicable.

For Apple, transfers are covered by the European Commission's Standard Contractual Clauses and Apple's data transfer agreements.

In both cases the providers' data processing terms apply in addition.

9. Providers' privacy information

10. Retention

We do not store personal data ourselves and therefore have no retention periods of our own. Photos are transmitted for processing and are not kept by us. How long Google retains content for abuse monitoring is governed by the Google terms.

11. Your rights

You have the rights of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), as well as the right to lodge a complaint with a supervisory authority.

In practice: because the app works without an account and we store no data, we generally cannot connect a request to a person — there simply is no data about you on our side. You can delete everything stored locally by removing the app. For data held by Google or Apple, please contact those providers.

12. Children

The app is not directed at children and is not intended for them.

13. Changes

We update this policy when the app changes. The version published here is the one that applies.