Sima
Features Filters Pricing FAQ
FA EN Back to site
Legal document

Privacy Policy

This document explains what information the “Sima” application collects, why, for how long, and how. It applies uniformly to every distribution channel of the product — the Android builds on Cafebazaar and Myket, the direct-APK build downloaded from our website, and the web version at sima-app.ir.

Last updated: 2026-05-24 Version: 1.0 Applies to: ir.sima.aiphotostudio + sima-app.ir

Contents

  1. Introduction & scope
  2. Data we collect
  3. Data we do not collect
  4. Purpose of processing
  5. Legal basis
  6. AI processing
  7. Retention periods
  8. Security & encryption
  9. Sharing with third parties
  10. Cookies & similar tech
  11. Your rights
  12. Account deletion
  13. Minors
  14. Payments & store channels
  15. International data transfers
  16. Changes to this policy
  17. Contact
  18. Guest mode
  19. Technical & analytics data
  20. Backup & recovery
  21. Data breach notification
  22. Automated decision-making
  23. Data portability
  24. Lawful access by authorities
  25. Security of the user's device

1 Introduction & scope

The application “Sima” (technical identifier ir.sima.aiphotostudio) is an AI-powered image studio developed and operated by the Sima team (hereinafter “we”).

This Privacy Policy applies equally to every channel through which the product is delivered:

  • The Android build published on Cafebazaar.
  • The Android build published on Myket.
  • The direct-install (Direct APK) build downloaded from our official website.
  • The web version at sima-app.ir and its sub-domains.

By installing, opening, or using Sima you confirm that you have read, understood, and unconditionally agree to this document. If you do not agree, you are not permitted to use the service and must uninstall the app and stop using the website.

2 Data we collect

To deliver the service, we collect and process — strictly to the extent necessary — the following data:

2.1 Mobile number

At sign-up or sign-in, we collect your Iranian mobile number to send a one-time password (OTP) and authenticate the session. The number is stored in international format and serves as the primary identifier of your account.

2.2 Photos you upload

Photos you submit for processing are stored temporarily on the server. Before storage, EXIF metadata (location coordinates, camera model, timestamps, and other fields) is automatically stripped, and the image is optimized.

2.3 Generated outputs

Images produced by the AI models are retained on the server so that you can access them from your private gallery, share them, or save them locally.

2.4 Device information

For service stability, device identification, and abuse prevention, we collect:

  • A device-unique identifier (Device ID — generated by the operating system).
  • Android version and device model.
  • App version and flavor (Cafebazaar / Myket / direct).
  • IP address at the time of each request to the server.
  • Device language and time zone.

2.5 Transaction and diamond-wallet data

Every purchase, top-up, spend, or refund of diamonds is recorded with its timestamp, amount, and payment channel, so we can show it in your transaction history and so it remains traceable in case of dispute.

2.6 Interaction with the app

Logs of each job (selected filter, quality tier, start/end time, final status: success / fail / refund) are stored for reliability and debugging.

2.7 Feedback & support communications

Whenever you submit feedback or open a support ticket, its contents are stored together with your mobile number, the app version, and the timestamp.

3 Data we do not collect

We explicitly state that we do not collect:

  • First name, last name, national ID, date of birth, or gender.
  • Physical address or postal code.
  • Phone contacts, SMS messages, or call history.
  • Gallery contents beyond the specific image you choose to process.
  • Bank-account details, card numbers, or CVV — payments flow only through store / gateway environments and never reach our servers.
  • Social-network accounts or third-party OAuth identities.
  • Microphone, camera (unless you open it from inside the app to take a photo), or GPS location.

4 Purpose of processing

The data we collect is used only for:

  1. Delivering the AI image-processing service.
  2. Authentication and account security.
  3. Calculating and managing the diamond wallet and financial transactions.
  4. Support, incident handling, and response to feedback.
  5. Preventing abuse, fraud, and suspicious purchases.
  6. Improving the service based on reported issues.

We will never use your data for targeted advertising, resale to third parties, or building advertising profiles.

5 Legal basis for processing

The processing of your data rests on one of the following bases:

  • Consent: by installing the app, accepting this policy, and uploading an image for processing, you give clear consent.
  • Performance of a contract: processing is necessary to deliver the services you requested (generations, diamond purchases, …).
  • Legitimate interest: technical data such as IP and Device ID is processed for security, stability, and abuse prevention.
  • Legal obligation: when Iranian law requires us to retain or disclose information to lawful authorities.

6 AI processing

To generate images, your input photo is sent to AI models. These models are accessed through reputable Iranian provider services that, in turn, may act as relays to global model providers.

Important: AI model providers may have their own, independent privacy, retention, and security policies. We take every reasonable measure to share your data with them only through short-lived, scoped signed URLs, but ultimate responsibility for their behavior is outside our direct control.

If a model fails to process your photo, the system may automatically fall back to an alternative model so that you still receive a result.

7 Retention periods

Different categories of data have different retention windows:

  • Input photos: automatically deleted 7 days after upload.
  • Output photos: automatically deleted 30 days after generation.
  • Account and diamond wallet: retained while the account is active, or until you request deletion.
  • Financial transaction logs: retained for at least 5 years (as required by law).
  • Technical and error logs: at most 90 days.
  • Backups: rotated on a 90-day cycle, overwritten thereafter.

8 Security & encryption

We apply reasonable technical and organizational measures to protect your data:

  • All app↔server traffic uses HTTPS with TLS 1.2 or higher.
  • Authentication tokens rotate regularly.
  • Output images are reachable only through short-lived signed URLs.
  • Servers are hosted in Iranian data centers (primarily ArvanCloud).
  • Anti-abuse and rate-limit protocols are continuously enforced.

Explicit disclosure: no system is 100% secure. Despite all our measures, we offer no guarantee against intrusions, human error, data leaks resulting from attack, or infrastructure-level failure. Using Sima implies acceptance of this baseline risk. In the event of a security incident, we will follow lawful procedures and notify users where appropriate.

9 Sharing with third parties

We share your data with third parties only in the following limited cases:

  • Cloud-infrastructure providers for hosting and storage (such as ArvanCloud).
  • Payment and store gateways: Cafebazaar, Myket, and banking gateways (on the web version) — solely to verify a purchase.
  • SMS / OTP provider to deliver the one-time password to your number (mobile number and SMS body only).
  • AI model providers — only your input image at processing time, via a short-lived signed URL.
  • Judicial and law-enforcement authorities when disclosure is required by lawful order.

We never transfer your data to third parties for advertising, market analysis, or sale.

10 Cookies & similar technologies

In the mobile app: no cookies are used; authentication is managed by secure in-app tokens.

On the web: we may use strictly-functional cookies to preserve sessions, user preferences, and security context. These cookies are essential for baseline functionality and do not include advertising trackers.

11 Your rights

As a user, you have the following rights:

  • Right of access: ask what data we hold about you.
  • Right to rectification: request correction of inaccurate account information.
  • Right to deletion: request full deletion of your account and associated data (see §12).
  • Right to opt out of processing: processing stops once you uninstall the app and revoke access.
  • Right to object: in case of dispute, you may contact us.

Exercise of these rights may be restricted in certain cases — for example, financial transaction logs are retained even after account deletion to meet legal obligations.

12 Account deletion

To permanently delete your account, choose one of the following routes:

  1. From inside the app → Profile → Delete account (when available).
  2. Send an email from the registered mobile number to legal@sima-app.ir with the subject “Account deletion request”.

After identity verification, within at most 30 working days:

  • All your input and output images will be deleted.
  • The account will be deactivated and your mobile number will be detached from it.
  • Any remaining diamonds are not refundable and not convertible to cash; deletion of the account constitutes waiver of those diamonds.
  • Financial transaction logs are retained as required by law (without personally-identifying fields, for auditing only).

13 Minors

Use of Sima by individuals under 13 years of age is prohibited. Individuals between 13 and 18 must use the service only with the permission and active supervision of a legal guardian.

We do not knowingly collect data from children under 13. If we discover an account belongs to a person below the legal age, we will deactivate it and delete the data.

14 Payments & store channels

Diamond top-ups flow through the channels below. Payment happens directly in their secure environments, and your bank-card details never reach our servers:

  • Cafebazaar (Poolakey) for the Cafebazaar build.
  • Myket (IAB) for the Myket build.
  • Banking gateways (on the web): ZarinPal or Zibal may be enabled in a future phase.

In the direct-APK build, top-ups are processed through web gateways; store-level in-app purchases are not available.

Any refund or dispute at the store level follows that store's own policy and lies outside our control. If a store approves a refund, the corresponding diamonds will be deducted from your wallet, and if already spent we reserve the right to pursue the matter independently.

15 International data transfers

Our primary infrastructure is hosted inside Iran, and your data does not cross the border by default. The only exception arises at the time of AI processing, when the file is temporarily forwarded to the model provider; these providers are Iranian companies, but they may themselves act as relays to global models.

By using the service, you accept this short-lived transfer for the purpose of processing.

16 Changes to this policy

We reserve the right to change, amend, or update this policy at any time. Material changes will be communicated via one or more of:

  • An in-app message on your next launch.
  • An update to the “Last updated” date at the top of this document.
  • For significant changes, an announcement on the sima-app.ir homepage.

Continued use of the service after a new version is published constitutes acceptance of the updated terms.

17 Contact

For questions, exercise of your rights, or to report a security incident:

  • Legal: legal@sima-app.ir
  • General support: support@sima-app.ir
  • In-app: Profile → Support → New ticket (each ticket has a tracking number and you will be notified in-app when the support team replies).

Official website: sima-app.ir

18 Guest mode

In the mobile builds, you can use one free generation as a guest without signing up. In that mode we store:

  • A device-unique identifier (Device ID) — to prevent abuse of the free quota.
  • The input and output images, identical to a signed-in user.
  • Technical device information and the app version.

If you later sign up on the same device, your guest generation is automatically transferred into the new account. If you never sign up, guest data is purged on the same retention schedule as §7, and the Device ID is dropped after 90 days of inactivity.

19 Technical & analytics data

19.1 Technical logs

For error diagnosis, stability, and bug fixing, we keep logs of:

  • The timestamp and duration of each API request.
  • The response status (success / error) and the error code.
  • The requesting IP address.
  • The flavor name and version (Bazaar / Myket / Direct).
  • The associated job or transaction identifier, when applicable.

Technical logs are auto-deleted after at most 90 days, unless retention is required for a legal or security investigation.

19.2 Device fingerprinting

We do not collect any comprehensive device fingerprint (such as font scanning, Canvas, WebGL, or audio fingerprinting). Only the standard ANDROID_ID or APP_INSTANCE_ID generated by the operating system for apps is used.

19.3 Behavioral analytics

In the current phase, no third-party analytics SDKs (Google Analytics, Firebase Analytics, Yandex, Adjust, AppsFlyer, …) are bundled in the app. If we add one in a future release, this document will be updated and, where required, your clear consent will be requested.

20 Backup & recovery

To protect against data loss caused by hardware failure or attack, the database is periodically backed up. This backup:

  • Is stored on the same Iranian data center (no cross-border transfer).
  • Rotates on a 90-day cycle and is overwritten thereafter.
  • Is encrypted at rest.
  • Is accessible only to the infrastructure team behind two-factor authentication.

Note: even after you delete your account, a backup copy may still contain your data for up to 90 days while the rotation cycle completes. After that period, the data is permanently purged from backups as well.

21 Data breach notification

In the event of a security incident that exposes your personal data, we commit to:

  1. Contain the incident as quickly as possible.
  2. Investigate the scope of the leak and identify affected users.
  3. Notify affected users by email or SMS within at most 72 hours of confirmation, when a material risk exists.
  4. Report to the competent authorities if required by law.
  5. Publish a public explanation on sima-app.ir if the impact is broad.

The notification will describe the nature of the incident, the categories of data affected, the actions taken, and our recommendations to the user. By accepting this policy you agree that this notification process satisfies any other legal obligation we may have regarding breach disclosure.

22 Automated decision-making & profiling

Sima makes two kinds of automated decisions:

  • Content moderation: the AI models may automatically reject your input.
  • Abuse detection: suspicious behavioral patterns (multiple accounts from one IP, bulk request bursts, …) may result in automatic restrictions.

These decisions are fully automated and we do not build advertising or behavioral profiles of you. If an automated decision harms you, you may request manual review by emailing legal@sima-app.ir.

23 Data portability

Upon request, we commit to delivering your account information in a machine-readable format (JSON or CSV). The export contains:

  • Account info: mobile number, creation date, status.
  • Diamond-transaction history.
  • The list of successful generations with timestamps and filter used.

The export does not include the image files themselves (due to size and security considerations); images remain downloadable from your in-app private gallery until their retention window expires.

Send portability requests to legal@sima-app.ir — we respond within at most 30 working days. This service is free of charge unless requests are repetitive or unreasonable, in which case a reasonable fee may apply.

24 Lawful access by authorities

We are bound by the laws of the Islamic Republic of Iran. We will disclose your data to competent authorities in the following cases:

  • A lawful or judicial order from a competent court.
  • A written request from a lawful authority (Cyber Police, Prosecutor's Office, …) citing a case number.
  • A legal obligation in the context of combating cybercrime, financial fraud, or illegal content.

Where lawful, we will endeavor to inform you prior to disclosing data, unless the authority explicitly forbids it or notification would obstruct the investigation.

Any data disclosed to authorities is logged in our internal audit ledger with the date and reference number of the request.

25 Security of the user's device

Responsibility for the security of your personal device, your phone unlock code, your biometric authentication, and access to the SIM card registered to the account rests entirely with you. We recommend:

  • Keep the operating system and the Sima app up to date.
  • Avoid rooting and avoid installing the app from untrusted sources.
  • Don't lose the SIM card registered to the account; if it is lost or stolen, block it immediately with your carrier.
  • Protect the device with a strong PIN or biometric lock.

Damage resulting from a user's failure to secure their device (for example, another person gaining access to your account) is outside the scope of Sima's liability.


This document is published in Persian and English. In case of any discrepancy between language versions, the Persian version is the authoritative reference.

Back to home Read the Terms of Service
Sima

An AI-powered image studio built for the Iranian market.

Product

  • Features
  • Filters
  • Pricing
  • How it works

Support

  • FAQ
  • In-app ticket system
  • support@sima-app.ir

Legal

  • Privacy Policy
  • Terms of Service
  • legal@sima-app.ir
© 2026 Sima — All rights reserved. Made in Iran ❤