Privacy Policy
1. Data Controller
The controller responsible for data processing on this website is:
Foth Group GmbH
Email:
2. Data We Collect
We collect the following personal data:
- Name and email address upon registration
- Reference photos you upload for image generation
- Generated images and prompt text
- Payment data (processed via Stripe — we do not store card details)
3. Purpose of Processing
Your data is used exclusively to provide the letsgoo.io service: delivering the AI image generation service, account management, and billing.
4. Reference Photos and Generated Images
Your uploaded reference photos and generated images are visible to you only. There is no public gallery. Your data is not shared with third parties or used for AI model training.
5. Data Sharing and Third-Country Transfers
We share your data only to the extent necessary to provide the service.
5.1 ByteDance / Seedream ("Letsgoo MAX", default image engine)
For AI-based image generation, your reference photos (the facial features of your AI model character) and your text prompts are transmitted to the Seedream API service operated by ByteDance Ltd.
ByteDance is a company headquartered in the People's Republic of China. No adequacy decision exists for China under Art. 45 GDPR. The transfer is based on Art. 49(1)(b) GDPR (necessity for contract performance): without this transfer, the core service — AI image generation — cannot be provided.
We explicitly draw attention to the following risks:
- Companies based in China may be required to disclose data to Chinese authorities under the Chinese National Security Law.
- The level of data protection in China does not meet EU standards.
- There are no enforcement rights for data subjects against Chinese authorities comparable to those in the EU.
By using the service you consent to this transfer. If you wish to object, you may not use the service and should delete your account.
5.2 kie.ai / Google ("Letsgoo ULTRA", optional image engine)
You can choose a second image engine in the generator. If you select Letsgoo ULTRA, your text prompt and your reference photos are processed by kie.ai, an API provider that runs Google's Gemini 3.0 Pro Image model ("Nano Banana Pro"). Google acts as a sub-processor.
Your reference photos are not uploaded to kie.ai by us — they are passed as links, and kie.ai retrieves them from letsgoo.io directly.
Retention at kie.ai, according to their own documentation:
- Generated images: stored for 14 days, then deleted automatically.
- Log records, including the input parameters you submitted (your prompts): stored for 2 months.
This engine is optional. The default engine ("Letsgoo MAX") does not involve kie.ai or Google — if you do not select Letsgoo ULTRA, none of your data reaches them.
5.3 Stripe, Inc. (Payment Processing & Age Verification)
Payment processing and age verification (Stripe Identity) are handled by Stripe, Inc., USA. Stripe is certified under the EU–US Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023). letsgoo.io receives from Stripe Identity only a confirmation of your verification status — never your identity documents or biometric raw data. A data processing agreement pursuant to Art. 28 GDPR is in place with Stripe.
5.4 Hetzner Online GmbH (Hosting)
Our servers and databases are operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. All user data — including reference photos, generated images, and account data — is stored on Hetzner servers in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner.
5.5 Resend (Email Delivery)
For the delivery of transactional emails (registration, notifications) we use Resend, Inc., USA. Your email address and message content are transmitted in this process. Resend is SOC 2 Type II certified. A data processing agreement pursuant to Art. 28 GDPR is in place with Resend.
6. Retention Periods
Your data is stored for as long as your account is active. Upon account deletion:
- Reference photos and generated images: Immediate permanent deletion
- Name and password: Immediate deletion upon account deletion
- Email address: Retained for 10 years pursuant to § 257 HGB / § 147 AO in connection with the billing relationship, and on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in fraud prevention, chargeback handling, and enforcement of our terms of service. The email is stored separately from the active account record and is only accessible to administrators.
- Payment and billing data (Stripe): Retained for 10 years pursuant to § 257 HGB and § 147 AO (statutory retention obligation). We store only the Stripe customer ID; full payment records remain with Stripe.
- Referral commissions and token redemptions: Retained for 10 years pursuant to § 257 HGB and § 147 AO — commissions and their settlement are accounting records. Your referral code and the click counter are deleted with the account.
- Moderation logs: 3 years (statutory documentation obligation, § 184b StGB)
- Usage events (see section 8): Deleted automatically after 90 days; deleted immediately upon account deletion
The right to erasure (Art. 17 GDPR) applies subject to the statutory retention obligations listed above.
7. Referral Program
Every account receives a personal referral code. If someone registers through your link, that registration is stored against your code so purchases can be attributed to you. For each commission we store the purchase reference, the amount, the rate and the resulting commission; for each redemption the amount, the number of tokens and the date. The legal basis is Art. 6(1)(b) GDPR (performance of the contract with you as a participant) and, for the accounting records, Art. 6(1)(c) GDPR in conjunction with § 147 AO / § 257 HGB.
Because commission is settled in tokens rather than money, no payment details are collected for it, and no data is transferred to a payment service provider for this purpose.
Two points of data minimisation: as a participant you only ever see counts and amounts — never who registered or who bought. And clicks on referral links are counted per code and day only, without any personal reference: no IP address, no user agent, no time of day, nothing that could identify a visitor.
8. Product Analytics (First-Party)
To improve the application, we record how the logged-in app is used: which pages are opened, which buttons are clicked, and where errors occur. These events are linked to your account, processed exclusively on our own server, and automatically deleted after 90 days. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in improving and debugging the product).
Data minimisation: we deliberately do not record your IP address, browser or device information, location, or any content you enter — no prompts, no text, no images. No third-party analytics service is involved, nothing is stored on or read from your device for this purpose, and the data is never shared.
9. Your Rights
You have the right to access, rectification, erasure, and restriction of processing of your data. You may also object to processing based on legitimate interest (Art. 21 GDPR), including the usage analysis described in section 8. Please contact:
10. Cookies
This website uses only technically necessary storage (localStorage) for authentication. No tracking cookies and no third-party analytics tools are used; usage analysis is performed first-party only, as described in section 8.