Magicly

Privacy Policy

Effective as of 2026-07-19

Magicly is an app for generating images and video with AI and publishing them to a shared feed. It is operated by Retomagic (“we”, “us”). This page describes what we collect, where it goes, and what you can ask us to do about it. It covers the Magicly app on iOS and Android and the website at magicly.ai.

What we collect

Your account. You sign in with Google or with Apple. Authentication is handled by Google Firebase Authentication, which holds your email address and issues us an account identifier. On our own servers we store that identifier together with the profile you create: nickname, display name, description, avatar, and the counters shown on your profile. We do not store your password — we never see one.

What you make. Prompts and negative prompts, any reference image you upload, the images and video generated from them, and anything you publish: posts, remixes, comments, likes, follows, bookmarks and albums.

How you use the app. A per-installation device identifier, the notification token for your device if you allow notifications, your credit balance and its transaction history, your subscription status, and a record of which posts have already been shown to you so the feed does not repeat itself.

Technical data. Our servers log requests in the normal way, including IP address, approximate time, and the app version and device type that made the request.

Prompts and images are sent to AI providers

We do not run the AI models ourselves. To produce a result, the prompt you wrote and any reference image you uploaded are transmitted to the third-party provider that operates the model you selected, and are processed there under that provider’s own terms and privacy policy. Which providers we use changes as the catalog changes; we will tell you who they are at any given time if you ask us at the address at the bottom of this page.

This is worth stating plainly: do not put anything in a prompt or a reference image that you would not want a third-party AI provider to receive.

What is public, and what is not

Generations are private when they are created. They stay in your gallery until you choose to publish, and when you publish you choose the audience: everyone, your followers, or nobody.

A published post can be remixed: another user can start a new generation from it, and their result appears as a reply under your post. You can switch remixing off for an individual post. Your nickname, display name, avatar, description and public posts are visible to anyone, including people who are not signed in.

Third parties we use

Google Firebase — sign-in and push notifications. Apple — Sign in with Apple. AppLovin MAX — advertising in the mobile app. Adapty — subscription management on mobile. Stripe — payments on the web. Third-party AI model providers — generation, as described above.

Generated media and uploaded images are stored on our own infrastructure, not on a third-party image host.

Advertising

The mobile app shows a rewarded video ad in exchange for a generation when you are not a Pro subscriber. Ads are served by AppLovin MAX. On iOS you are asked first whether apps may track you; if you decline, you still see ads, but they are not personalised. There is no advertising on the website.

Payments

Subscriptions bought in the mobile app are processed by Apple or Google and managed through Adapty. Payments on the website are processed by Stripe. Card numbers never reach our servers; we receive only the fact that a payment succeeded, the plan, and an identifier that lets us attribute it to your account.

Moderation

Prompts are checked against a list of forbidden terms before a generation runs, and a generation may be marked as adult content by the system that produces it. Users can report a post or an account; a report is recorded against it and may lead to content being hidden or an account being restricted. Reports and moderation decisions are retained with the account they concern.

How long we keep things, and deletion

Content is kept for as long as your account exists. You can delete individual generations and posts at any time, and you can delete your account from Settings.

Deleting your account starts a 30-day pause. During it the account is hidden — you are signed out and it disappears from the app — and you can change your mind by signing in again and confirming. Nothing is lost until the 30 days are up.

After that it is erased for real: profile, posts, remixes, comments, likes, follows, bookmarks, albums, styles, the generated images and video themselves, your devices and notification tokens, and the Firebase sign-in record that holds your email address. This is irreversible — we cannot bring it back for you afterwards.

Two things outlive it, because the law requires them to. Records of payments and credit transactions are retained so purchases and refunds stay reconstructable for accounting and tax purposes. Reports you filed about other people are retained, because they are records about that other person’s conduct. Both are stripped of anything that identifies you.

Your rights

You can ask us for a copy of the data we hold about you, ask us to correct it, or ask us to erase it. Write to contact@retomagic.com and we will respond. Depending on where you live you may also have the right to complain to a data-protection authority.

Children

Magicly is not intended for children under 13, and we do not knowingly collect information from them. The feed contains user-generated content, including material intended for adults, so the app is rated accordingly in both app stores. If you believe a child has given us personal information, contact us and we will remove it.

Changes

We may update this policy. When we do, we will change the effective date at the top of this page, and for a significant change we will say so in the app.

Contact

Questions about this policy, or a request about your data: contact@retomagic.com.

Questions about this document? contact@retomagic.com