Brickium Privacy Policy

Effective date: 19 September 2026

Brickium (the "App") is operated by Zhang Liu (刘章), an individual developer ("we", "us"). Contact for anything in this policy: [email protected].

1. Summary

2. What we process, and why

Information What it is Why Kept
Account When you sign in with Apple or with Google: the account identifier that provider issues for you, and the name and email address it shares with us. With Apple you may hide your email, and we then receive only Apple's relay address. We never receive your Apple or Google password. To create your account and recognise you when you return. Until you delete your account.
Sessions A sign-in token kept in your device's keychain. Our server stores only a one-way hash of it. To keep you signed in. Until you sign out or delete your account.
Inventory Part numbers, colours and quantities you add by photo, by set number or by hand. To design models that use only the bricks you have. Until you delete it or your account.
Scan photographs Photographs you take of your own bricks. To suggest which parts are in the picture. Nothing is added to your inventory until you confirm it. Not stored by us. See section 3.
Design requests and results What you type, the design that is generated, its building instructions and your build progress. To generate, check and show you your designs. Until you delete your account.
Purchases The pack you bought, Apple's transaction identifier and the number of creations credited. Apple takes the payment; we never receive your card number or billing address. To credit what you paid for, once, and to take it back if Apple refunds it. Kept after account deletion, attached only to the deleted account's random identifier, so that the same purchase cannot be credited twice and so that we hold the transaction records the law requires.
Free-creation marker A one-way hash of your Apple or Google account identifier. So that the free creation given to a new account is given once per person. Kept after account deletion. It cannot be reversed and does not identify you.
Usage counters Your balance of creations and how many scans you made today. To apply the limits described in the Terms. Until you delete your account.
Technical data IP address, time, the address requested and the result. To deliver the service and protect it from abuse. Processed by our server and by Cloudflare, which carries the traffic. Only as long as needed to operate and secure the service.
Crash reports Diagnostics provided by Apple, only if you have chosen to share them with developers. To fix defects. As provided by Apple.

Where the GDPR applies, we process account, inventory, design and purchase information to perform our contract with you (Article 6(1)(b)); technical data, the free-design marker and the retained purchase record for our legitimate interest in securing the service and preventing fraud (Article 6(1)(f)); and transaction records where the law requires them (Article 6(1)(c)).

We do not collect your contacts, your precise location or biometric information. Recognition works on pictures of plastic bricks; we do not use photographs to identify anyone. Please frame your photographs so that people are not in them.

3. How a photograph is handled

  1. You take or choose a photograph in the App. It is sent to our server over an encrypted connection.
  2. Our server passes it to Google's Gemini API, which returns a list of candidate parts.
  3. We show you that list. You correct it and confirm it, or discard it.
  4. Our server does not write the photograph to disk and keeps no copy, thumbnail or derivative of it. What is kept is only what you confirmed: part numbers, colours and quantities.

4. Who receives information

Recipient What they receive Purpose Location
Google LLC (Gemini API) Scan photographs Part recognition United States
OpenAI, L.L.C. (API) The text of your design request and a list of your available parts Design generation United States
Tencent Cloud Everything our server stores Hosting Santa Clara, California, United States
Cloudflare, Inc. Network traffic, including your IP address Delivery and protection of the service Global network
Apple Sign in with Apple; purchases Authentication; payment. Apple is the seller of record and handles your payment under its own privacy policy. Global
Google Sign in with Google, if you choose it Authentication Global

Your account identifier, name and email address are not sent to the AI providers. These providers may keep what they receive for a limited period to monitor for abuse, under their own policies: OpenAI and Google.

We disclose information to authorities only where the law requires it.

5. Where information is processed

Our server is in the United States, and the providers above process information in the United States and other countries. If you use the App from elsewhere, your information is transferred to the United States.

6. Deleting your account

Me → your account → Delete account deletes, immediately: the account record with your name, email address and provider identifier; every session; your balance of creations, including creations you bought and have not used; your scan counters; and your inventory, designs and builds. What remains is described in the Purchases and Free-creation marker rows of section 2. If you signed in with Apple, you can also stop using Apple ID with Brickium in your Apple Account settings.

7. Your rights

Wherever you live, you may ask us for a copy of the information we hold about you, ask us to correct it, ask us to delete it, ask for it in a portable format, or object to processing based on our legitimate interests. Write to [email protected]; we answer within 30 days and do not charge a fee. You can revoke camera and photo access at any time in iOS Settings; the App keeps working with set import and manual entry. If you are in the European Economic Area or the United Kingdom you may also complain to your data protection authority.

California and Nevada. We do not sell or share personal information as those terms are defined in California and Nevada law. We do not let third parties collect information about your activity over time and across other services, so we do not respond differently to a Do Not Track signal.

8. Children

The App is intended for people aged 16 and over and is not directed to children under 13. Before the App offers any way to create an account, it asks for your date of birth. The date is checked on your device and is not sent to us. Only the outcome is kept, on your device: that you are old enough, or the day on which you will be. Someone who is not old enough is not shown the sign-in options. We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, write to us and we will delete it together with the account. A parent or guardian who lets a child use their account remains responsible for it; see the safety section of the Terms of Use.

9. Artificial intelligence

Part recognition and design generation are performed by AI systems. Every design and every set of instructions is generated by such a system and then checked by deterministic software; a recognition result is a suggestion that you confirm. Before the first photograph and before the first design request, the App tells you which provider will receive what and asks for your permission; where the GDPR applies, that permission is your consent to this sharing, and withdrawing it in Me → AI and your data stops that feature from sending anything. This processing decides only which design you are shown. It has no legal or similarly significant effect on you.

10. Security

Connections are encrypted with TLS. Session tokens are stored only as hashes. Access to the server is limited to the developer. No system is perfectly secure; if a breach affects your information we will tell you and the authorities as the law requires.

11. Changes

If we change this policy we will change the date above, and for material changes we will tell you in the App before they take effect.

12. Contact

Zhang Liu (刘章) · [email protected]