1 Introduction & scope
The application “Sima” (technical identifier
ir.sima.aiphotostudio) is an AI-powered image studio
developed and operated by the Sima team (hereinafter “we”).
This Privacy Policy applies equally to every channel through which the product is delivered:
- The Android build published on Cafebazaar.
- The Android build published on Myket.
- The direct-install (Direct APK) build downloaded from our official website.
- The web version at
sima-app.irand its sub-domains.
By installing, opening, or using Sima you confirm that you have read, understood, and unconditionally agree to this document. If you do not agree, you are not permitted to use the service and must uninstall the app and stop using the website.
2 Data we collect
To deliver the service, we collect and process — strictly to the extent necessary — the following data:
2.1 Mobile number
At sign-up or sign-in, we collect your Iranian mobile number to send a one-time password (OTP) and authenticate the session. The number is stored in international format and serves as the primary identifier of your account.
2.2 Photos you upload
Photos you submit for processing are stored temporarily on the server. Before storage, EXIF metadata (location coordinates, camera model, timestamps, and other fields) is automatically stripped, and the image is optimized.
2.3 Generated outputs
Images produced by the AI models are retained on the server so that you can access them from your private gallery, share them, or save them locally.
2.4 Device information
For service stability, device identification, and abuse prevention, we collect:
- A device-unique identifier (Device ID — generated by the operating system).
- Android version and device model.
- App version and flavor (Cafebazaar / Myket / direct).
- IP address at the time of each request to the server.
- Device language and time zone.
2.5 Transaction and diamond-wallet data
Every purchase, top-up, spend, or refund of diamonds is recorded with its timestamp, amount, and payment channel, so we can show it in your transaction history and so it remains traceable in case of dispute.
2.6 Interaction with the app
Logs of each job (selected filter, quality tier, start/end time, final status: success / fail / refund) are stored for reliability and debugging.
2.7 Feedback & support communications
Whenever you submit feedback or open a support ticket, its contents are stored together with your mobile number, the app version, and the timestamp.
3 Data we do not collect
We explicitly state that we do not collect:
- First name, last name, national ID, date of birth, or gender.
- Physical address or postal code.
- Phone contacts, SMS messages, or call history.
- Gallery contents beyond the specific image you choose to process.
- Bank-account details, card numbers, or CVV — payments flow only through store / gateway environments and never reach our servers.
- Social-network accounts or third-party OAuth identities.
- Microphone, camera (unless you open it from inside the app to take a photo), or GPS location.
4 Purpose of processing
The data we collect is used only for:
- Delivering the AI image-processing service.
- Authentication and account security.
- Calculating and managing the diamond wallet and financial transactions.
- Support, incident handling, and response to feedback.
- Preventing abuse, fraud, and suspicious purchases.
- Improving the service based on reported issues.
We will never use your data for targeted advertising, resale to third parties, or building advertising profiles.
5 Legal basis for processing
The processing of your data rests on one of the following bases:
- Consent: by installing the app, accepting this policy, and uploading an image for processing, you give clear consent.
- Performance of a contract: processing is necessary to deliver the services you requested (generations, diamond purchases, …).
- Legitimate interest: technical data such as IP and Device ID is processed for security, stability, and abuse prevention.
- Legal obligation: when Iranian law requires us to retain or disclose information to lawful authorities.
6 AI processing
To generate images, your input photo is sent to AI models. These models are accessed through reputable Iranian provider services that, in turn, may act as relays to global model providers.
Important: AI model providers may have their own, independent privacy, retention, and security policies. We take every reasonable measure to share your data with them only through short-lived, scoped signed URLs, but ultimate responsibility for their behavior is outside our direct control.
If a model fails to process your photo, the system may automatically fall back to an alternative model so that you still receive a result.
7 Retention periods
Different categories of data have different retention windows:
- Input photos: automatically deleted 7 days after upload.
- Output photos: automatically deleted 30 days after generation.
- Account and diamond wallet: retained while the account is active, or until you request deletion.
- Financial transaction logs: retained for at least 5 years (as required by law).
- Technical and error logs: at most 90 days.
- Backups: rotated on a 90-day cycle, overwritten thereafter.
8 Security & encryption
We apply reasonable technical and organizational measures to protect your data:
- All app↔server traffic uses HTTPS with TLS 1.2 or higher.
- Authentication tokens rotate regularly.
- Output images are reachable only through short-lived signed URLs.
- Servers are hosted in Iranian data centers (primarily ArvanCloud).
- Anti-abuse and rate-limit protocols are continuously enforced.
Explicit disclosure: no system is 100% secure. Despite all our measures, we offer no guarantee against intrusions, human error, data leaks resulting from attack, or infrastructure-level failure. Using Sima implies acceptance of this baseline risk. In the event of a security incident, we will follow lawful procedures and notify users where appropriate.
9 Sharing with third parties
We share your data with third parties only in the following limited cases:
- Cloud-infrastructure providers for hosting and storage (such as ArvanCloud).
- Payment and store gateways: Cafebazaar, Myket, and banking gateways (on the web version) — solely to verify a purchase.
- SMS / OTP provider to deliver the one-time password to your number (mobile number and SMS body only).
- AI model providers — only your input image at processing time, via a short-lived signed URL.
- Judicial and law-enforcement authorities when disclosure is required by lawful order.
We never transfer your data to third parties for advertising, market analysis, or sale.
10 Cookies & similar technologies
In the mobile app: no cookies are used; authentication is managed by secure in-app tokens.
On the web: we may use strictly-functional cookies to preserve sessions, user preferences, and security context. These cookies are essential for baseline functionality and do not include advertising trackers.
11 Your rights
As a user, you have the following rights:
- Right of access: ask what data we hold about you.
- Right to rectification: request correction of inaccurate account information.
- Right to deletion: request full deletion of your account and associated data (see §12).
- Right to opt out of processing: processing stops once you uninstall the app and revoke access.
- Right to object: in case of dispute, you may contact us.
Exercise of these rights may be restricted in certain cases — for example, financial transaction logs are retained even after account deletion to meet legal obligations.
12 Account deletion
To permanently delete your account, choose one of the following routes:
- From inside the app → Profile → Delete account (when available).
- Send an email from the registered mobile number to legal@sima-app.ir with the subject “Account deletion request”.
After identity verification, within at most 30 working days:
- All your input and output images will be deleted.
- The account will be deactivated and your mobile number will be detached from it.
- Any remaining diamonds are not refundable and not convertible to cash; deletion of the account constitutes waiver of those diamonds.
- Financial transaction logs are retained as required by law (without personally-identifying fields, for auditing only).
13 Minors
Use of Sima by individuals under 13 years of age is prohibited. Individuals between 13 and 18 must use the service only with the permission and active supervision of a legal guardian.
We do not knowingly collect data from children under 13. If we discover an account belongs to a person below the legal age, we will deactivate it and delete the data.
14 Payments & store channels
Diamond top-ups flow through the channels below. Payment happens directly in their secure environments, and your bank-card details never reach our servers:
- Cafebazaar (Poolakey) for the Cafebazaar build.
- Myket (IAB) for the Myket build.
- Banking gateways (on the web): ZarinPal or Zibal may be enabled in a future phase.
In the direct-APK build, top-ups are processed through web gateways; store-level in-app purchases are not available.
Any refund or dispute at the store level follows that store's own policy and lies outside our control. If a store approves a refund, the corresponding diamonds will be deducted from your wallet, and if already spent we reserve the right to pursue the matter independently.
15 International data transfers
Our primary infrastructure is hosted inside Iran, and your data does not cross the border by default. The only exception arises at the time of AI processing, when the file is temporarily forwarded to the model provider; these providers are Iranian companies, but they may themselves act as relays to global models.
By using the service, you accept this short-lived transfer for the purpose of processing.
16 Changes to this policy
We reserve the right to change, amend, or update this policy at any time. Material changes will be communicated via one or more of:
- An in-app message on your next launch.
- An update to the “Last updated” date at the top of this document.
- For significant changes, an announcement on the
sima-app.irhomepage.
Continued use of the service after a new version is published constitutes acceptance of the updated terms.
17 Contact
For questions, exercise of your rights, or to report a security incident:
- Legal: legal@sima-app.ir
- General support: support@sima-app.ir
- In-app: Profile → Support → New ticket (each ticket has a tracking number and you will be notified in-app when the support team replies).
Official website: sima-app.ir
18 Guest mode
In the mobile builds, you can use one free generation as a guest without signing up. In that mode we store:
- A device-unique identifier (Device ID) — to prevent abuse of the free quota.
- The input and output images, identical to a signed-in user.
- Technical device information and the app version.
If you later sign up on the same device, your guest generation is automatically transferred into the new account. If you never sign up, guest data is purged on the same retention schedule as §7, and the Device ID is dropped after 90 days of inactivity.
19 Technical & analytics data
19.1 Technical logs
For error diagnosis, stability, and bug fixing, we keep logs of:
- The timestamp and duration of each API request.
- The response status (success / error) and the error code.
- The requesting IP address.
- The flavor name and version (Bazaar / Myket / Direct).
- The associated job or transaction identifier, when applicable.
Technical logs are auto-deleted after at most 90 days, unless retention is required for a legal or security investigation.
19.2 Device fingerprinting
We do not collect any comprehensive device fingerprint
(such as font scanning, Canvas, WebGL, or audio fingerprinting). Only the
standard ANDROID_ID or APP_INSTANCE_ID generated
by the operating system for apps is used.
19.3 Behavioral analytics
In the current phase, no third-party analytics SDKs (Google Analytics, Firebase Analytics, Yandex, Adjust, AppsFlyer, …) are bundled in the app. If we add one in a future release, this document will be updated and, where required, your clear consent will be requested.
20 Backup & recovery
To protect against data loss caused by hardware failure or attack, the database is periodically backed up. This backup:
- Is stored on the same Iranian data center (no cross-border transfer).
- Rotates on a 90-day cycle and is overwritten thereafter.
- Is encrypted at rest.
- Is accessible only to the infrastructure team behind two-factor authentication.
Note: even after you delete your account, a backup copy may still contain your data for up to 90 days while the rotation cycle completes. After that period, the data is permanently purged from backups as well.
21 Data breach notification
In the event of a security incident that exposes your personal data, we commit to:
- Contain the incident as quickly as possible.
- Investigate the scope of the leak and identify affected users.
- Notify affected users by email or SMS within at most 72 hours of confirmation, when a material risk exists.
- Report to the competent authorities if required by law.
- Publish a public explanation on
sima-app.irif the impact is broad.
The notification will describe the nature of the incident, the categories of data affected, the actions taken, and our recommendations to the user. By accepting this policy you agree that this notification process satisfies any other legal obligation we may have regarding breach disclosure.
22 Automated decision-making & profiling
Sima makes two kinds of automated decisions:
- Content moderation: the AI models may automatically reject your input.
- Abuse detection: suspicious behavioral patterns (multiple accounts from one IP, bulk request bursts, …) may result in automatic restrictions.
These decisions are fully automated and we do not build advertising or behavioral profiles of you. If an automated decision harms you, you may request manual review by emailing legal@sima-app.ir.
23 Data portability
Upon request, we commit to delivering your account information in a machine-readable format (JSON or CSV). The export contains:
- Account info: mobile number, creation date, status.
- Diamond-transaction history.
- The list of successful generations with timestamps and filter used.
The export does not include the image files themselves (due to size and security considerations); images remain downloadable from your in-app private gallery until their retention window expires.
Send portability requests to legal@sima-app.ir — we respond within at most 30 working days. This service is free of charge unless requests are repetitive or unreasonable, in which case a reasonable fee may apply.
24 Lawful access by authorities
We are bound by the laws of the Islamic Republic of Iran. We will disclose your data to competent authorities in the following cases:
- A lawful or judicial order from a competent court.
- A written request from a lawful authority (Cyber Police, Prosecutor's Office, …) citing a case number.
- A legal obligation in the context of combating cybercrime, financial fraud, or illegal content.
Where lawful, we will endeavor to inform you prior to disclosing data, unless the authority explicitly forbids it or notification would obstruct the investigation.
Any data disclosed to authorities is logged in our internal audit ledger with the date and reference number of the request.
25 Security of the user's device
Responsibility for the security of your personal device, your phone unlock code, your biometric authentication, and access to the SIM card registered to the account rests entirely with you. We recommend:
- Keep the operating system and the Sima app up to date.
- Avoid rooting and avoid installing the app from untrusted sources.
- Don't lose the SIM card registered to the account; if it is lost or stolen, block it immediately with your carrier.
- Protect the device with a strong PIN or biometric lock.
Damage resulting from a user's failure to secure their device (for example, another person gaining access to your account) is outside the scope of Sima's liability.
This document is published in Persian and English. In case of any discrepancy between language versions, the Persian version is the authoritative reference.