1. General Provisions
This Privacy Policy explains how the Aestory mobile application and related Aestory backend services process personal data.
Aestory is intended for specialists who keep work records in the Application and use Aestory services for account access, authentication, installation registration, subscription and entitlement checks, catalog/configuration delivery, and support communication.
The Aestory backend does not store patient cards, patient notes, patient photos, videos, 3D materials, before/after materials, or local backups by default. These working materials are intended to remain in the Application's local storage on the user's device unless the user intentionally exports, shares, uploads, or sends them to another service or to support.
If a specialist uses Aestory to process patient data, that specialist or the organization on whose behalf they act is responsible for having a lawful basis for processing patients' personal data, including patient consent, professional or medical confidentiality, records management, and other applicable legal requirements.
2. Data That May Be Processed
The Aestory backend may process the following categories of account, access, and technical data:
- installation data: installation identifier, platform, app version, installation status, creation time, last seen time, and installation credential state;
- account data: internal account identifier, account status, linked installation history, and timestamps;
- email authentication data: email address, email verification state, verification email send records, send status, and timestamps;
- Yandex sign-in data, when the user chooses Yandex authentication: Yandex account identifier, client identifier, display name, first name, last name, and default email address if provided by Yandex;
- session and token data: server session binding, access token claims, refresh token digest, expiry, rotation, revocation, and replacement timestamps;
- subscription and entitlement data: access tier, feature limits, entitlement status, validity period, transfer availability, installation binding history, and signed lease claims;
- commercial catalog data shown to the client, such as plans, store offer identifiers, prices, currencies, and catalog revisions;
- administrative and audit data: staff/admin account data, administrative actions, target identifiers, before/after state, reasons, metadata, request identifiers, and timestamps;
- server request logs: request identifier, HTTP method, matched route, response status, and processing duration;
- reverse proxy access logs and infrastructure logs, which may include IP address, request URL, user agent, timestamp, response status, and similar technical metadata.
The Application may also process specialist workspace data locally on the user's device, depending on how the user uses the Application: specialist profile data, patient records, visit notes, procedures, photos, videos, 3D files, reminders, local analysis results, exports, and backups.
Aestory does not ask users to enter passport details or bank card details into the Aestory backend. Payments, subscriptions, and app-store purchases may be processed by the relevant app store or payment provider under their own rules.
3. Purposes of Processing
Aestory processes data to provide and protect the Application and backend services:
- registering and recognizing an Application installation;
- creating accounts and authenticating users by email or Yandex sign-in;
- sending email verification codes and service emails;
- issuing, refreshing, rotating, and revoking access sessions and tokens;
- linking accounts to installations and protecting account access;
- checking subscription status, issuing signed entitlement leases, and supporting device transfer rules;
- providing catalog, pricing, feature, and configuration information;
- operating the administration interface and recording audit events;
- monitoring service health, diagnosing errors, preventing abuse, and securing the service;
- responding to support and legal requests.
Aestory does not use account, installation, patient, or entitlement data for advertising, sale to third parties, third-party ad targeting, or tracking the user across other applications and websites.
4. Legal Bases and Special Categories of Data
If Aestory is used in the Russian Federation, personal data processing must comply with Federal Law No. 152-FZ "On Personal Data" and other applicable requirements. If Aestory is used in the European Economic Area or in relation to persons covered by the GDPR, processing must have an applicable legal basis and be accompanied by the required information notices to data subjects.
For account, authentication, installation, subscription, and support data, the legal basis may include the user's consent, performance of a contract, legitimate interests in operating and securing the service, and compliance with legal obligations.
Patient data entered into the specialist workspace may include special categories of personal data, including health, appearance, procedures, and photo or video materials. The specialist or organization using Aestory determines the legal basis for such processing and is responsible for obtaining necessary consents and complying with applicable professional, medical, storage, and deletion requirements.
This Policy describes how Aestory works as an application and backend service. It does not replace the personal data processing policy of a clinic, office, sole proprietor, or other operator providing services to patients.
5. Local Storage and Data Sharing
Patient cards, photos, videos, notes, 3D materials, reminders, and backups are intended to be stored locally in the Application's storage and file area on the user's device.
The Aestory backend stores account, installation, authentication, session, entitlement, catalog, audit, and service log data needed to operate the service. The backend does not automatically receive local patient workspace materials.
When the user starts a 3D creation function, such as photo_3D_fl or OrbitHead, the Application may upload user-selected photographs or videos directly to private S3-compatible storage to create 3D images or related 3D result files. A separate processing component reads those materials only for the processing job and writes the resulting 3D output, such as a PLY or GLB result file. Neither the input materials nor the result files are public.
Data may leave the user's device when the user performs an action, for example:
- registers an installation or signs in to an account;
- uses email verification or Yandex sign-in;
- checks subscription status or requests an entitlement lease;
- imports, exports, shares, or saves files through operating system tools;
- creates a backup and shares it through the system share sheet;
- sends a file, screenshot, backup, log, or issue description to support.
When the user shares data through a third-party application, cloud storage, messenger, email, operating system service, or app store, that sharing is governed by the terms and privacy policies of the selected service.
6. Device Permissions
The Application requests permissions only when they are needed for specific features:
- camera: to take photos and videos;
- microphone: to record videos with audio or dictate notes, if this feature is used;
- speech recognition: to convert speech into note text, if this feature is used;
- media library/files: to add materials to records and save selected materials;
- notifications: for local reminders;
- run after device restart on Android: to restore scheduled local notifications;
- internet access: to communicate with Aestory backend services and external services used for authentication, email, subscriptions, updates, or support.
The user may revoke permissions in device settings. After permissions are revoked, some features may become unavailable or work with limitations.
7. Backups, Exports, and Support Materials
The user may create local backups or exports. A backup or export may include specialist profiles, patient records, notes, media files, and other local workspace materials.
The user independently chooses where to store backups and exported files and with whom to share them. Aestory does not automatically receive these files and cannot control copies saved outside the Application.
If the user sends a backup, export, screenshot, log, or other file to support, Aestory may process the supplied material to diagnose the issue, answer the request, and protect the service. Do not send patient data to support unless there is a lawful basis and the data is necessary for the request.
8. Security
Aestory uses technical and organizational safeguards appropriate to the current service architecture. Installation credentials and refresh tokens are stored on the backend as cryptographic digests rather than as plain tokens. Entitlement leases are signed with server-side keys. Production traffic is served through HTTPS.
Server-side authentication includes access tokens, refresh token rotation, installation credential checks, session binding, rate limits for sensitive authentication routes, and account/session revocation mechanisms.
Local Application protections, such as a workspace PIN or protected backup, do not replace device-level security. The user is responsible for securing the phone or tablet, including device passcode, biometrics, screen lock, operating system updates, backup protection, and access control.
9. Retention and Deletion
Local workspace data is stored on the user's device until the user deletes it in the Application, deletes the Application, clears Application data through the operating system, or deletes externally saved copies.
Backend account, installation, authentication, entitlement, audit, and log data is retained for as long as needed to provide the service, secure accounts, maintain subscription and access records, comply with legal obligations, resolve disputes, and enforce agreements.
For 3D creation functions such as photo_3D_fl or OrbitHead, input photographs or videos are retained only for as long as technically required to perform the selected processing job and are deleted as soon as processing is complete or otherwise reaches a final status. A successful PLY or GLB result is kept for no more than two hours, or is scheduled for deletion earlier after the Application confirms receipt. Physical deletion may take longer while automatic cleanup retries a temporary storage error. Technical job metadata may remain for security and audit purposes.
When the user deletes an account from an authenticated app session, Aestory closes the backend account, revokes its active sessions and refresh tokens, removes or de-identifies email and Yandex sign-in identifiers stored by Aestory, and revokes active account entitlements. Limited installation, session, entitlement, audit, and log records may be retained without direct sign-in identifiers where needed for security, accounting, dispute resolution, legal compliance, or proof that deletion was handled.
Access tokens and refresh tokens have limited lifetimes. Refresh token records may be retained as digests with rotation, expiry, and revocation timestamps for security and replay protection. Audit and infrastructure logs may be retained for security, diagnostics, and accountability.
Backups, exported files, and materials shared through other applications are stored wherever the user saved or sent them. Such copies must be deleted separately.
10. User and Data Subject Rights
The user may view, edit, export, and delete local workspace data using the Application and operating system tools where the relevant feature is available.
If the user's app version supports account deletion, the user may delete the backend account from the authenticated account or settings area. After deletion, the previous account tokens stop working and the same email address or provider identity may be used to create a new account.
For backend account, authentication, installation, subscription, or support data, the user may contact Aestory to request access, correction, deletion, restriction, or other actions available under applicable law.
If you are a patient and your data has been entered into Aestory by a specialist, please contact that specialist or the organization providing services to you. They determine the purposes and legal bases for processing patient data.
For questions related to the Application, backend services, or this Policy, contact: privacy@aestory.space.
11. Children
Aestory is not intended for independent use by children and is not directed at children as an audience. If data of minor patients is entered into the Application, the user must ensure that there is a lawful basis and the required consent from the child's representatives in accordance with applicable law.
12. Third Parties and Processors
Aestory may use third-party services and infrastructure providers to operate the Application and backend services. In the current backend configuration, this includes Yandex OAuth for Yandex sign-in and Yandex Postbox for sending email verification and service emails.
The Application also uses iOS and Android platform capabilities and technical libraries required for features such as camera, media library, local notifications, video playback, file handling, speech recognition, local image analysis, networking, and backups.
App stores, payment providers, cloud storage providers, messengers, email services, operating systems, and other third-party services selected by the user may process data independently under their own terms and privacy policies.
In the current version, Aestory does not use advertising SDKs, analytics SDKs, or third-party SDKs for user tracking.
13. Cross-Border Transfers
Aestory backend services, infrastructure providers, email providers, authentication providers, app stores, and support tools may process data in jurisdictions different from the user's location.
Patient workspace materials are not automatically uploaded to the Aestory backend. A cross-border transfer of such materials may occur if the user intentionally sends, exports, backs up, or shares them through third-party services, cloud storage, messengers, email, support channels, or other applications.
14. Changes to This Policy
This Policy may be updated when Application features, backend behavior, data processing practices, third-party providers, or legal requirements change. The English version is published at https://dev.aestory.space/privacy-policy and https://dev.aestory.space/privacy-policy/en. The Russian version is published at https://dev.aestory.space/privacy-policy/ru.
If changes materially affect data processing, the user will be notified in a reasonable way, for example through an updated policy page, release notes, or an in-app notice if such a feature is available.
15. Contacts
Operator/developer: Fiks Ilya Iosifovich
Email: privacy@aestory.space