Axend
Privacy Policy
Effective date: July 3, 2026 · Applies to the Axend mobile application for iOS and Android (com.balkanbit.looxmaxxing)
1. Who we are
The Axend application (“the App”) is published by “Pazaruvai Umno” EOOD (“ПАЗАРУВАЙ УМНО” ЕООД), a company registered in the Republic of Bulgaria with Unified Identification Code (UIC/ЕИК) 206373314, with registered address at Sofia 1343, Lyulin 2, bl. 235, vh. V, et. 2, ap. 81, Republic of Bulgaria (“we”, “us”, “our”). We are the Data Controller under the EU General Data Protection Regulation (GDPR) and the Bulgarian Law on Personal Data Protection (PDPA). The App is developed and operated through the BalkanBit venture studio.
Questions about this policy or your data: manol@balkanbit.app.
2. What the App does with your photos
Axend generates appearance trait scores from two photos of your face (a front photo and a profile photo) that you capture with your camera or select from your photo library. Because your face is sensitive data, we designed the App to handle photos as minimally as possible:
- Photos are stored locally on your device. You can delete them at any time in Profile → Privacy → Delete my photos.
- When you run a scan, your photos are uploaded over encrypted HTTPS connections using single-use, signed upload links to our secure cloud storage.
- Our scoring service analyzes the photos with an AI model to produce your trait scores, and deletes both photos from our servers immediately after scoring. Only the numeric scores are returned to your device.
- If you use the avatar feature, your reference photo is uploaded the same way to generate a stylized image; the generated image is served from a temporary link that expires automatically.
- Your photos are never used to identify you, sold, shared for advertising, or used to train AI models.
3. Categories of data we process
- Face photos — front and profile photos, processed transiently as described in Section 2.
- Scan results and onboarding answers — your trait scores, selected concerns, and goals are stored only on your device. They are removed when you delete the App.
- Anonymous app identifier — a random identifier generated by our subscription provider (RevenueCat). It is sent with scan requests to enforce fair-use limits and to associate your subscription with your device. It is not linked to your name, email, or any account — the App has no user accounts.
- Purchase data — if you subscribe, Apple or Google processes the payment. We and our processor RevenueCat receive the anonymous identifier, product purchased, subscription status, device platform, and locale. We never receive your payment card details.
We do notcollect your name, email address, phone number, contacts, or location. The App contains no advertising and no third-party analytics SDKs, and it does not track you across other companies’ apps or websites.
4. Lawful bases for processing
- Consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) — for capturing and processing your face photos. You grant camera and photo library access through the operating system prompts, and each scan is started only by your explicit action. You may withdraw consent at any time by deleting your photos and not running further scans.
- Performance of a contract (Art. 6(1)(b) GDPR) — to deliver the scoring service and manage your subscription and purchases.
- Legitimate interest (Art. 6(1)(f) GDPR) — to prevent fraud and abuse of the scanning service and to keep the service secure.
- Legal obligation (Art. 6(1)(c) GDPR) — to keep transaction records required by tax and accounting law.
5. Service providers
We use a small number of processors, each bound by data processing agreements and receiving only what is necessary:
- RevenueCat, Inc. — subscription management (anonymous identifier, purchase and entitlement data).
- Cloud hosting and storage providers — host our scoring API and the temporary photo storage described in Section 2.
- AI inference provider — processes photos transiently to compute trait scores; photos are not retained or used for model training.
- Apple App Store / Google Play — payment processing under their own privacy policies.
Where a provider processes data outside the European Economic Area, transfers are protected by the European Commission’s Standard Contractual Clauses or an adequacy decision (including the EU–US Data Privacy Framework where applicable).
6. Retention
- Photos on our servers — deleted immediately after scoring; generated avatar images expire automatically.
- Photos, scores, and answers on your device — kept until you delete them in the App or uninstall the App.
- Purchase records — kept for the duration of your subscription and thereafter up to 10 years where required by Bulgarian tax and accounting law.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy in a portable format;
- rectify inaccurate data and restrict or object to processing;
- withdraw consent at any time, without affecting prior processing;
- erasure (“right to be forgotten”), subject to legal retention duties.
Because we hold no account data about you, most data lives only on your device: deleting your photos in Profile → Privacy or uninstalling the App removes it. For anything else — including deletion of purchase records associated with your anonymous identifier — email manol@balkanbit.app and we will respond within one month.
8. Children
The App is intended for users aged 17 and over and includes an age gate at onboarding. We do not knowingly process personal data of children. Under the Bulgarian PDPA, consent of a person under 14 is valid only if given by a parent or guardian; if we learn we have processed a child’s data without valid consent, we will delete it immediately.
9. Security
All data in transit is encrypted with HTTPS/TLS. Photo uploads use single-use signed URLs, server-side photo storage is access-controlled and short-lived, and scan requests are authorized per device. Data on your device is protected by your device’s operating system sandbox.
10. Complaints
You have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP):
- Address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
- Fax: +359 2 915 3525
- Email (qualified electronic signature required): kzld@cpdp.bg
- Web: https://www.cpdp.bg
11. Changes to this policy
We may update this policy as the App evolves. Material changes will be announced in the App before they take effect, and the effective date above will always reflect the current version.