PRIVACY POLICY · VERSION 1.0 · 07 AUG 2026
YOUR WORK.
YOUR DATA.
This privacy notice applies to the iOS app CRT — Curated Remains Tool and its supporting service at crt.artefckd.com.
01 / CONTROLLER
Pretty Lush! GmbH
Heimerichstr. 20
90419 Nürnberg
Germany
Email: privacy@milchglas-media.de
02 / LOCAL MEDIA AND PROJECTS
Imported images and videos, saved projects and recorded atmosphere clips are primarily processed and stored locally on your iPhone. Atmosphere recordings are not uploaded to the CRT AI backend in the current version.
03 / AI CURATION
When you actively request a CURATOR or ANTI-CURATOR analysis and allow AI processing, CRT sends a compressed image/frame and the information required for the selected curation mode to the CRT backend. The backend forwards the material required for the requested AI analysis to OpenAI's API.
CRT does not intentionally store submitted artwork images in its D1 usage database. OpenAI states that API inputs and outputs are not used to train its models by default. API content may be retained by the provider for a limited period for abuse monitoring and service operation according to OpenAI's applicable API data policies.
04 / AI VOICE
When you request an AI-generated curator voice and allow AI processing, the text to be spoken, selected synthetic voice and style settings are sent through the CRT backend to OpenAI's text-to-speech API. The generated audio is returned to the app and can be stored locally as part of your project/export.
LAURA and OTTO are display names for synthetic AI voices. They are not recordings or clones of real people.
05 / APP STORE VERIFICATION AND AI ALLOWANCE
CRT is a paid app. Version 1.0 includes a fixed number of AI requests. To verify legitimate App Store access and enforce that allowance, CRT processes Apple's pseudonymous App Transaction ID, a locally generated installation identifier, the App Store environment/bundle information and usage counters for Curations, AI Voices and server-generated voice previews.
The CRT backend verifies app transaction information with Apple's App Store Server API. It does not receive your Apple Account email address, payment-card details or Apple Account password.
06 / INFRASTRUCTURE
CRT uses Cloudflare infrastructure for its backend and database and OpenAI for requested AI analysis, artist research and synthetic speech generation. Apple provides App Store distribution and app-transaction verification. These providers process technical data as necessary to provide and secure their services.
07 / PURPOSE AND LEGAL BASIS
Processing is performed to provide features you request, verify paid access, enforce the included AI allowance, protect the service against abuse and maintain technical security. Depending on the context, the legal basis is performance of the contract (Art. 6(1)(b) GDPR) and/or legitimate interests in secure and economical service operation (Art. 6(1)(f) GDPR).
08 / RETENTION
Local projects remain on your device until you remove them or the app data. Server-side access and usage records are retained as necessary to provide the fixed AI allowance, prevent repeated claims and operate the service securely. Submitted artwork is not intentionally archived by the CRT usage database. Third-party processing may be subject to the providers' own limited retention and security requirements.
09 / TRACKING AND ADVERTISING
CRT does not use third-party advertising, the advertising identifier or cross-app/cross-site tracking.
10 / YOUR RIGHTS
Where applicable, you have rights including access, rectification, erasure, restriction, portability and objection under the GDPR. AI-processing permission can be withdrawn at any time inside CRT under INFO → REVOKE AI PERMISSION; after withdrawal, CRT will ask again before sending content to OpenAI. For access or deletion requests concerning server-side records, contact privacy@milchglas-media.de. You may also lodge a complaint with a competent data-protection authority.
11 / CHANGES
This notice may be updated when CRT's functionality, providers or legal requirements change.
This page describes CRT 1.0's intended production configuration. App Store privacy disclosures must remain consistent with the deployed app and backend.