Privacy Policy
Last updated: July 29, 2026
InkEthos ("we," "us," or "the app") is an independently operated tattoo studio management app maintained by the app owner, located in California, United States. This Privacy Policy explains what information we collect, how we use it, and the choices you have. This page is maintained by the app owner and is not an independent audit or certification.
1. Who this policy covers
It covers two groups: Artists — the tattoo professionals who create an account and use InkEthos to run their business — and Guests — the artist's clients who fill out digital consent forms on the artist's tablet.
2. Information we collect
From Artists (account holders):
- Email address and display name (for sign-in via Supabase authentication).
- Business data you enter: clients, bookings, portfolio images, notes, deposits, and tax entries.
- Basic device/usage information such as browser type and app version.
From Guests (through the tablet consent flow):
- Name, date of birth, and expiration date extracted from a government-issued photo ID.
- Answers to the medical/health questionnaire.
- The digital signature you draw on the consent form.
- The image of the ID is processed by an AI vision service to extract text, then discarded unless the artist saves it to the client's profile.
3. How we use information
- To provide the app's features (accounts, bookings, consent records, portfolio, tax estimates).
- To secure your account and prevent abuse.
- To improve the app based on aggregated, non-identifying usage patterns.
We do not sell your data. We do not run advertising networks inside the app.
4. Where your data is stored
Artist and guest data is stored in a Supabase-hosted PostgreSQL database, protected by row-level security so each artist can only read and write their own data. Authentication is handled by Supabase Auth. ID-scan text extraction uses an AI vision provider (Lovable AI Gateway); the ID image is transmitted for extraction and is not persisted by the provider beyond the immediate request.
5. Government ID handling
Guest IDs are scanned solely to verify identity and pre-fill the consent form. The extracted text (name, DOB, expiration) is stored on the guest's consent record. The raw ID image is not kept in the database unless the artist explicitly attaches it to the client profile. Consent records are retained for as long as the artist's account is active, or as required by state record-keeping rules for tattoo professionals.
6. Sharing
We share information only with service providers that make the app work: Supabase (database & auth), our hosting provider, and the AI vision service used for ID extraction. We may disclose information if required by law (subpoena, court order) or to protect safety.
7. Your choices & rights (including California residents)
Under the California Consumer Privacy Act (CCPA/CPRA) and similar laws, you may request to access, correct, or delete your personal information, or opt out of any sale/sharing (we do not sell). To make a request, email behindblueeyes927@gmail.com. Guests who submitted a consent form should contact the artist who took their information, or email us and we will help route the request.
8. Account deletion
Artists can delete their account by emailing us. Deletion removes your account and associated business records within 30 days, except where retention is legally required.
9. Security
Data is transmitted over HTTPS. Row-level security in the database restricts each artist to their own records. No system is perfectly secure — please use a strong, unique password.
10. Children
InkEthos is not intended for use by anyone under 18. Guests receiving tattoos must meet the artist's local legal age requirements.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with a new "Last updated" date.
12. Contact
Questions? Email behindblueeyes927@gmail.com.