Privacy Policy
- Introduction
- Plain-English Summary
- App Store Privacy Label (Apple Disclosure)
- App Tracking Transparency (ATT)
- Information We Collect
- How We Use Your Information
- Legal Basis for Processing (GDPR)
- Third-Party SDKs & Service Providers
- Data Retention
- Your Rights
- Account & Data Deletion
- Children's Privacy
- Face & Body Data (Photos and Videos of People)
- AI Processing Disclosure (EU AI Act)
- In-App Consent & Transparency
- International Data Transfers
- Security
- Changes to This Policy
- Contact Us
1. Introduction
This Privacy Policy describes how the Bob Haircut Filter iOS application ("Bob Haircut Filter", the "App", "we", "us", "our") collects, uses, and shares information when you use the App. The App is published by TRY2APP LTD, the data controller for the purposes of this Policy.
We've designed the App to collect as little personal information as possible. You do not need to create an account. We do not ask for your name, email, phone number, or any other personally identifying information.
2. Plain-English Summary
In one paragraph: We don't know who you are. When you tap Generate, the photo you pick — and the funny AI haircut-prank video generated from it — are sent to and from our AI provider over an encrypted connection, and then dropped. We keep an anonymous ID on our backend so the App remembers your video credits and subscription status. We do not use your photos or videos to train AI, we do not sell data, and we do not track you across other apps or websites.
3. App Store Privacy Label (Apple Disclosure)
Apple requires every app on the App Store to disclose its data collection practices in the "App Privacy" label shown on each app's App Store listing. The table below mirrors the exact disclosures we make to Apple under its three required categories.
Category A — Data Used to Track You
None.
Bob Haircut Filter does not link any data collected from this app with data from third-party apps or websites for advertising or tracking purposes. We do not share any data with data brokers.
Category B — Data Linked to You
The following data types are linked to your anonymous App installation (not to your real identity):
- Identifiers — User ID. A random anonymous ID generated by Firebase Authentication. Used for App Functionality (to remember your video credit balance and subscription state).
- Purchases — Purchase History. The product identifiers and subscription/consumable status of purchases made through Apple. Used for App Functionality (to unlock video generations).
- User Content — Photos and Videos. The photo you explicitly pick for the haircut prank, and the resulting AI-generated video URL. Used for App Functionality only (to produce the video you asked for).
Category C — Data Not Linked to You
- Diagnostics — Crash Data, Performance Data. Aggregated crash logs and performance metrics used for App Functionality and Analytics. These are anonymized and not tied to your identity.
What we do NOT collect
For full transparency, the following data categories Apple asks about are not collected by Bob Haircut Filter at all:
- Contact Info (email, name, phone number, physical address, other contact info)
- Health & Fitness
- Financial Info (payment, credit, other financial info)
- Location (precise or coarse)
- Sensitive Info (race, sexual orientation, religion, politics, etc.)
- Contacts
- Browsing History
- Search History
- Identifiers — Device ID (IDFA or similar advertising identifier)
- Usage Data — Product Interaction, Advertising Data, Other Usage Data
- Other Data Types (Customer Support messages you email us are stored by our mail provider for support purposes only)
4. App Tracking Transparency (ATT)
Apple's App Tracking Transparency framework requires apps to request user permission before tracking them across other apps and websites owned by different companies.
Bob Haircut Filter does not track you across other apps or websites. Because we do not engage in cross-app tracking, we do not present the ATT permission prompt. We do not access or use your Identifier for Advertisers (IDFA), and we do not share any data with advertisers or data brokers.
5. Information We Collect (Detailed)
Anonymous Identifier (Firebase Auth)
When you first open the App, our backend (Google Firebase Authentication) generates a random anonymous user ID for your installation. This ID is not linked to your real identity, your Apple ID, your email, or any other personal information you've shared with Apple. The ID exists so the App can sync your video credit balance and subscription state across sessions on the same device.
Photos You Upload
When you tap Select Photo, you choose a single photo from your iOS Photo Library via Apple's standard photo picker, which only hands the App the single photo you explicitly select — we never get broader access to your Photo Library. That photo is held in memory on your device only. Before it is ever sent anywhere, the App shows you a dedicated, explicit consent screen — separate from this Privacy Policy — that names the third party (fal.ai), states exactly what is sent (the one photo you selected), and explains why. Nothing is transmitted unless you tap "Agree & Continue" on that screen; tapping "Not Now" or closing it sends nothing. Once you agree, that one photo is uploaded to our AI provider (fal.ai) over an encrypted TLS connection so the AI video model can generate your haircut-prank transformation video. The photo is used solely to generate the output video you asked for.
- We do not store the original photo on our own servers.
- Nothing is sent anywhere until you have explicitly agreed on the in-app consent screen — no photo is ever uploaded before you've agreed, and this consent is asked for once, before your very first generation.
- We do not use your photos or generated videos to train any AI model, our own or a third party's.
Generated Videos
The AI-generated video URL returned by our provider is shown back to you inside the App, in the My Videos tab. When you tap "Save", iOS writes the video to your own Photo Library (with your permission) — we never store a permanent copy on our own servers. We keep a reference to the video URL and its generation status tied to your anonymous user ID so you can revisit it in My Videos.
Subscription and Credit Purchase Data
When you purchase a subscription or a credit pack, Apple processes the transaction entirely. We use RevenueCat to verify and sync your purchase status. The data we receive is limited to:
- The anonymous user ID we associate with the purchase
- The product identifier you purchased (e.g.
bobweekly,bobyearly,bob50) - Purchase status (active, expired, refunded), expiration date, and remaining video credit balance
We never see your Apple ID, credit card number, billing address, or any other payment information. That data stays with Apple.
Account Creation Timestamp
We store the date your anonymous user ID was first created in our Firestore database, tied to that identifier only.
Diagnostic & Performance Data
To keep the App stable we may receive aggregated crash logs and performance metrics (such as load times and error rates). This data is not linked to your identity and is used to diagnose issues and improve stability.
Device Signals
For debugging we may log non-identifying signals such as iOS version, device model (e.g. "iPhone 15"), and app version. We do not use the IDFA and we do not run any advertising trackers in the App.
6. How We Use Your Information
We use the limited information we collect for the following purposes only:
- To provide the AI haircut-prank video generation service you requested
- To sync your video credit balance and subscription state across sessions on your device
- To validate and track in-app purchases through Apple's StoreKit
- To prevent fraud, abuse, and violations of our Terms of Service
- To comply with legal obligations
- To improve App stability through aggregated, anonymous diagnostics
We do not sell your personal information. We do not share it with advertisers. We do not use your photos or generated videos to train AI models.
7. Legal Basis for Processing (GDPR)
If you are in the European Union, United Kingdom, or another jurisdiction with comparable law, we process your personal data under the following legal bases:
- Performance of a contract (Art. 6(1)(b) GDPR) — processing necessary to provide the App and fulfill purchases (anonymous ID, purchase data, photos you submit, generated videos).
- Legitimate interests (Art. 6(1)(f) GDPR) — processing for App stability, fraud prevention, and security, balanced against your rights and freedoms.
- Legal obligation (Art. 6(1)(c) GDPR) — retention of purchase records for tax and accounting.
- Consent (Art. 6(1)(a) GDPR) — for any processing that requires consent, such as optional future integrations. You can withdraw consent at any time.
8. Third-Party SDKs & Service Providers
The App includes the SDKs listed below. Each publishes a privacy manifest (PrivacyInfo.xcprivacy) as required by Apple, and is bound to the purpose for which we use it.
fal.ai (AI Generation)
Purpose: AI reference-to-video generation to create your haircut-prank transformation. Model: bytedance/seedance-2.0/fast/reference-to-video. Data sent: the photo you selected, and generation parameters (prompt, duration, resolution). Sent only after you explicitly agree on the in-app consent screen described above, and only for the single request you initiated.
fal.ai is contractually and technically required to protect your data to a standard consistent with this Privacy Policy: it does not use your photo to train AI models, does not sell or share it with further third parties, transmits it only over encrypted connections, and retains it only for the limited time technically necessary to serve your request.
Privacy policy: https://fal.ai/legal/privacy-policy
Google Firebase (Authentication + Firestore)
Purpose: anonymous authentication and storage of your user document containing account creation timestamp, video credit balance, subscription state, and My Videos history. Operator: Google LLC.
Privacy policy: https://firebase.google.com/support/privacy · Google Privacy Policy
RevenueCat
Purpose: subscription and consumable purchase validation, linking Apple transactions to your anonymous user ID. Data: anonymous user ID, Apple transaction identifier, purchase state.
Privacy policy: https://www.revenuecat.com/privacy
Apple
Purpose: App Store distribution, StoreKit billing, and system services. Apple processes all payments directly; we never see your payment instrument.
Privacy policy: https://www.apple.com/legal/privacy/
9. Data Retention
- Photos you upload: Not stored by us. Transmitted to our AI provider for the duration of generation only. Our provider's retention is governed by their own policy linked above.
- Generated videos: Not permanently stored on our own servers. The URL returned by the AI provider is displayed to you in the App and saved to your private My Videos entry, tied to your anonymous user ID, until you delete it or request account deletion.
- Anonymous user ID and account creation timestamp: Retained while your installation is active. Deleted on request (see Section 11).
- Subscription, credit, and purchase records: Retained for the duration of your subscription/credit balance plus the period required by tax, accounting, and consumer-protection law (typically up to 7 years depending on jurisdiction).
- Crash/diagnostic data: Retained in aggregated form for up to 90 days.
10. Your Rights
European Union and United Kingdom (GDPR / UK GDPR)
- Right to access the personal data we hold about you
- Right to rectification of inaccurate data
- Right to erasure (the "right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right not to be subject to solely automated decision-making
- Right to withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal
- Right to lodge a complaint with a supervisory authority (e.g. ICO in the UK, your national DPA in the EU)
California, USA (CCPA / CPRA)
- Right to know what personal information is collected
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information (we do not sell or share)
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your privacy rights
Other Jurisdictions
Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), and other jurisdictions provide similar rights. You may exercise them through the contact address in Section 19.
How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected] with the subject line "Privacy Request — Bob Haircut Filter". Because we use anonymous identifiers, please include your anonymous user ID so we can locate your data. We will respond within the timeframe required by applicable law (typically within 30 days under GDPR/CCPA).
11. Account and Data Deletion
You can delete your anonymous account and all associated data at any time. Because the App does not require an email or real-name account, deletion is handled via email:
- Email [email protected] with the subject "Bob Haircut Filter — Delete my data".
- We confirm receipt within 2 business days and complete deletion within 30 days.
- If you have purchased items, we may retain the minimal purchase-history records required by tax and consumer-protection law, in anonymized form.
Deleted data includes your Firestore user document, My Videos history, credit balance, and subscription sync state. Apple retains purchase records it is legally required to keep; these are outside our control.
Uninstalling the App alone does not delete server-side data. To have everything removed from our backend, you must email us.
12. Children's Privacy
The App is not intended for children under 13 years of age (or under the minimum digital consent age in your jurisdiction, which may be 14 or 16 in some EU member states). We do not knowingly collect personal information from children.
If you are a parent or guardian and believe a child has provided personal information to us, please contact us at [email protected] and we will delete it promptly.
The App's content rating in the App Store is set in accordance with Apple's age rating guidelines.
13. Face & Body Data (Photos and Videos of People)
Bob Haircut Filter's core purpose is to turn a photo of a person into a funny haircut-prank reveal video — so nearly every photo processed by the App contains a face. This section explains in detail how we treat images and videos that include people.
What face and body data we collect
The App processes your photo and the resulting video as pixels — a collection of visual data. It does not perform any of the following on faces or bodies in your photo:
- No facial recognition or face identification
- No biometric face data, face embeddings, or faceprints
- No attempts to link a face to a real-world identity
- No extraction of demographic, emotion, age, or identity signals from faces
- No creation or storage of face templates
The AI model we use (bytedance/seedance-2.0/fast/reference-to-video at fal.ai) treats your photo holistically as an image to animate, using a separate bundled reference clip purely for motion/action guidance. It does not output biometric data, does not cross-match faces, and does not maintain any face database. The model is instructed to preserve the photographed person's identity, facial features, and likeness while applying the haircut transformation for comedic effect — it does not replace the person or generate a different face.
All planned uses of face and body data
The only purpose for which a photo containing a face is processed is to produce the haircut-prank video you explicitly requested by picking a photo and tapping Generate. No other use is made of the pixels — not for training, not for analytics, not for advertising, not for demographic profiling.
Sharing with third parties
The photo — which will typically contain a face — is transmitted once, over an encrypted TLS connection, to our AI processing provider fal.ai (operated by Features & Labels, Inc.) to generate the video. It is not shared with any other third party. fal.ai is contractually bound not to train on user input and not to retain the photo or video beyond what is technically necessary to serve the request. Our list of subprocessors is in Section 8.
Storage and retention of face and body data
- We do not store the original photo on our own servers.
- fal.ai processes the photo in memory to produce the output video and retains it only for the time technically required to serve that individual request. fal.ai does not use input photos or output videos as training data.
- The generated video URL is displayed to you in the App. If you save the result to your own Photo Library, iOS handles that storage — we do not keep a copy on our servers.
- In our Firestore database we store, for your private My Videos history, only the URL of the finished video and a timestamp, tied to your anonymous user ID. URLs hosted by fal.ai are not guaranteed to remain reachable long-term; that retention is governed by fal.ai's own policy.
- On request (see Section 11) we will delete all data associated with your anonymous user ID within 30 days.
Where in this policy face and body data is addressed
Face and body data (as part of the broader category of photos/videos that may contain people) is addressed in:
- Section 3 — "App Store Privacy Label" (disclosed as User Content — Photos and Videos)
- Section 5 — "Photos You Upload" and "Generated Videos"
- This Section 13 — Face & Body Data
- Section 9 — Data Retention
- Section 14 — AI Processing Disclosure
In-app consent before any face-bearing photo is sent
No photo is ever transmitted automatically. Before your very first generation, and before any photo ever leaves your device, the App presents a dedicated consent screen that plainly discloses: what is sent (your selected photo), who it is sent to (fal.ai, our third-party AI provider, named by name), and why (to generate your haircut-prank video). Sending only happens after you tap "Agree & Continue" on that screen — tapping "Not Now" or closing the screen sends nothing. You can withdraw consent at any time by uninstalling the App, which also erases the on-device consent record.
14. AI Processing Disclosure (EU AI Act Compliance)
In compliance with Regulation (EU) 2024/1689 (the "EU AI Act") and global best practices for transparent AI, we disclose:
- The App uses generative artificial intelligence to transform a user-supplied photo into a short comedic video — depicting a playful "haircut prank" (hair being cut on camera, revealing a bob haircut) while preserving the same person's identity, face, and clothing. The output is synthetic content generated by an AI system.
- The AI model is
bytedance/seedance-2.0/fast/reference-to-video, provided by fal.ai. - AI generation is initiated only by your explicit action (picking a photo, explicitly agreeing on the in-app consent screen to send your photo to fal.ai, then tapping "Generate"). The App does not generate content automatically.
- Generated videos may include provenance markers embedded by the AI provider.
- You are responsible for the lawful use of any content generated by the App. Use to deceive, harass, create non-consensual manipulated imagery, or otherwise violate applicable law is prohibited by our Terms.
15. In-App Consent & Transparency
Apple's App Review guidelines (5.1.1(i) and 5.1.2(i)) require that, before any personal data is shared with a third-party AI service, the App disclose what data is sent, identify who the data is sent to, and obtain the user's permission. Bob Haircut Filter complies with these requirements through the following in-app mechanisms:
- First-run AI consent screen. Before any photo is ever sent for AI processing, the App presents a dedicated consent screen — separate from this Privacy Policy — with three explicit disclosure rows matching Apple's required elements: what is sent (the one photo you selected), who it is sent to (named by name: fal.ai, our third-party AI video generation provider), and why (to generate your haircut-prank video, for no other purpose); plus a line confirming the photo is not used to train AI models and is not stored on our servers, and a link to this Privacy Policy. The user must tap Agree & Continue to proceed. Tapping Not Now, or the close button, keeps the App usable but prevents any photo from being sent — no photo is transmitted unless this explicit step is completed.
- Consent tied directly to the data-sending action. The consent screen is not a one-off checkbox buried in onboarding — it sits directly in the path of the action that actually sends data: tapping to pick a photo triggers the consent screen first, and only an explicit "Agree & Continue" unlocks the system photo picker. There is no way to reach photo selection, or the AI provider, without passing through this screen.
- Explicit user action required. The App never transmits a photo automatically. A transmission only occurs when the user has agreed on the consent screen, manually selected a photo through Apple's standard Photo Library picker, and tapped the Generate button.
- Revocability. Consent can be withdrawn by uninstalling the App or by contacting us at [email protected]. On data deletion request we remove all records associated with the user's anonymous identifier within 30 days.
16. International Data Transfers
Our backend services (Google Firebase, RevenueCat, fal.ai) operate from data centers in the United States and the European Union. By using the App, you consent to the transfer of your information to these regions for processing.
For transfers of personal data from the European Union or United Kingdom to countries outside the EEA, we and our processors rely on Standard Contractual Clauses approved by the European Commission and other appropriate safeguards (Art. 46 GDPR).
17. Security
We protect the limited information we collect using industry-standard measures:
- TLS 1.2+ encryption for all data in transit
- Encryption at rest provided by Google Cloud and our other infrastructure providers
- Anonymous identifiers — no real-name linkage
- Firestore security rules that restrict access to each user's own documents
- Limited backend access restricted to authorized personnel
- Regular security review of third-party providers and their privacy manifests
No system is perfectly secure. If you become aware of a security incident affecting your data, please contact us immediately at [email protected]. For incidents that affect personal data of EU/UK users, we will notify the relevant supervisory authority as required by law.
18. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will:
- Update the "Last updated" date at the top of this policy
- Notify users via in-app message where appropriate
- For significant changes, provide a plain-language summary of what changed
Continued use of the App after changes are posted constitutes acceptance of the updated policy.
19. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact us at:
Email: [email protected]
Subject: Bob Haircut Filter — Privacy Inquiry
Data controller: TRY2APP LTD
We typically respond within 7 business days.