Privacy Policy

Last updated: 30 June 2026

This Privacy Policy explains how the TATUS mobile application and related services (“TATUS”, “we”, “us”) collect, use, store and protect your personal data. TATUS is a productivity tool for tattoo artists: portfolio, scheduling, client management (CRM), a unified client-message inbox and AI assistance.

1. Who we are (Data Controller)

The data controller is Dmytro Kravchuk, an individual developer based in Ukraine, operator of the TATUS application.
Contact: [email protected]

2. Data we collect

CategoryExamplesWhy
AccountEmail address, password (hashed), user IDSign-in, account security
ProfileName, city, studio address, portfolio photos, linksRun your master profile / public page
Business data you enterClient records (CRM), sessions, prices, expenses, notesProvide CRM, scheduling and analytics
Client messagesMessages received via connected channels (Telegram Business)Unified inbox to reply to clients
SubscriptionSubscription status (TATUS Pro), purchase eventsProvide and manage paid features
Usage / diagnosticsScreen views, feature events, crash dataImprove the product (no cross-app tracking)

We do not use advertising trackers, do not sell personal data, and do not share data with data brokers. We do not engage in cross-app/cross-site tracking.

3. Client messages and privacy

If you connect a messaging channel (e.g. Telegram Business), client messages are delivered into your in-app inbox so you can reply from TATUS. Message text is encrypted at rest (AES-256). You are responsible, as the controller of your clients’ data, for handling those conversations lawfully and informing your clients where required.

4. AI assistance

TATUS offers an optional AI assistant for replies, estimates and summaries. AI processing happens on the server. The AI accesses your business data or client conversations only with your explicit opt-in; you can withdraw this at any time in settings. AI output is a suggestion and not professional, legal, medical or financial advice.

5. Legal bases (GDPR)

6. Service providers (processors)

7. International transfers

Primary data is hosted in the European Union. Where a provider processes data outside your country, we rely on appropriate safeguards (e.g. Standard Contractual Clauses).

8. Data retention

We keep personal data while your account is active and as needed to provide the service. When you delete your account, we delete or anonymise your personal data, except records we must keep to meet legal obligations.

9. Your rights

Subject to applicable law (including the GDPR and UK GDPR) you may: access, correct, delete, restrict or object to processing, request portability, and withdraw consent. Contact [email protected].

Delete your account: you can delete your account and associated data in the app (Settings → Account → Delete account), or by emailing [email protected]. Deletion is permanent.

10. Subscriptions and payments

TATUS Pro is an auto-renewable subscription through Apple In-App Purchase. Payment is processed by Apple; we do not receive or store your card details. Manage or cancel in your Apple ID settings. Subscription state is managed via RevenueCat.

11. Security

We use industry-standard measures: encryption in transit (TLS), encryption at rest for sensitive content (AES-256), access controls and least-privilege practices. No method is 100% secure, but we work to protect your data.

12. Children

TATUS is intended for professional tattoo artists and is not directed to children. We do not knowingly collect data from children.

13. Changes

We may update this policy. Material changes will be reflected by the “Last updated” date and, where appropriate, in-app notice.

14. Contact

Questions or requests: [email protected]