Privacy Policy
- Introduction
- Plain-English Summary
- App Store Privacy Label (Apple Disclosure)
- App Tracking Transparency (ATT)
- Information We Collect
- How We Use Your Information
- Legal Basis for Processing (GDPR)
- Third-Party SDKs & Service Providers
- Data Retention
- Your Rights
- Account & Data Deletion
- Children's Privacy
- Face Data (Photos of People)
- AI Processing Disclosure (EU AI Act)
- In-App Consent & Transparency
- International Data Transfers
- Security
- Changes to This Policy
- Contact Us
1. Introduction
This Privacy Policy describes how the Lofi Dusk Filter iOS application ("Lofi Dusk Filter", the "App", "we", "us", "our") collects, uses, and shares information when you use the App. The App is published by TRY2APP LTD, the data controller for the purposes of this Policy.
We've designed the App to collect as little personal information as possible. You do not need to create an account. We do not ask for your name, email, phone number, or any other personally identifying information.
2. Plain-English Summary
In one paragraph: We don't know who you are. When you tap Create, the photo you pick is sent to our AI provider over an encrypted connection to produce the lofi dusk output, and then it is dropped. We keep an anonymous ID on our backend so the App remembers your credit balance and subscription status. We do not use your photos to train AI, we do not sell data, and we do not track you across other apps or websites.
3. App Store Privacy Label (Apple Disclosure)
Apple requires every app on the App Store to disclose its data collection practices in the "App Privacy" label shown on each app's App Store listing. The table below mirrors the exact disclosures we make to Apple under its three required categories.
Category A — Data Used to Track You
None.
Lofi Dusk Filter does not link any data collected from this app with data from third-party apps or websites for advertising or tracking purposes. We do not share any data with data brokers.
Category B — Data Linked to You
The following data types are linked to your anonymous App installation (not to your real identity):
- Identifiers — User ID. A random anonymous ID generated by Firebase Authentication. Used for App Functionality (to remember your credits and subscription state).
- Purchases — Purchase History. The product identifiers and subscription status of purchases made through Apple. Used for App Functionality (to unlock paid features and replenish credits from active subscriptions).
- User Content — Photos. The photo you explicitly pick to apply the lofi dusk filter to, and the resulting AI-generated image URL. Used for App Functionality only (to produce the lofi dusk photo you asked for).
Category C — Data Not Linked to You
- Diagnostics — Crash Data, Performance Data. Aggregated crash logs and performance metrics used for App Functionality and Analytics. These are anonymized and not tied to your identity.
What we do NOT collect
For full transparency, the following data categories Apple asks about are not collected by Lofi Dusk Filter at all:
- Contact Info (email, name, phone number, physical address, other contact info)
- Health & Fitness
- Financial Info (payment, credit, other financial info)
- Location (precise or coarse)
- Sensitive Info (race, sexual orientation, religion, politics, etc.)
- Contacts
- Browsing History
- Search History
- Identifiers — Device ID (IDFA or similar advertising identifier)
- Usage Data — Product Interaction, Advertising Data, Other Usage Data
- Other Data Types (Customer Support messages you email us are stored by our mail provider for support purposes only)
4. App Tracking Transparency (ATT)
Apple's App Tracking Transparency framework requires apps to request user permission before tracking them across other apps and websites owned by different companies.
Lofi Dusk Filter does not track you across other apps or websites. Because we do not engage in cross-app tracking, we do not present the ATT permission prompt. We do not access or use your Identifier for Advertisers (IDFA), and we do not share any data with advertisers or data brokers.
5. Information We Collect (Detailed)
Anonymous Identifier (Firebase Auth)
When you first open the App, our backend (Google Firebase Authentication) generates a random anonymous user ID for your installation. This ID is not linked to your real identity, your Apple ID, your email, or any other personal information you've shared with Apple. The ID exists so the App can sync your credit balance and subscription state across sessions on the same device.
Photos You Upload for Creation
When you tap Create, you select a single photo from your iOS Photo Library via Apple's standard PHPickerViewController. The selected photo is uploaded to our AI provider (fal.ai) over an encrypted TLS connection so the AI model can apply the lofi dusk restyle you requested. The photo is used solely to generate the output image you asked for.
- We do not store the original photo on our own servers.
- We do not access your Photo Library without you explicitly picking a photo — we rely on Apple's picker, which sandboxes selection.
- We do not use your photos to train any AI model, our own or a third party's.
Generated Images
The AI-generated image URL returned by our provider is shown back to you inside the App. When you tap "Save to Photos", iOS writes the image to your own Photo Library (with your permission) — we never store it on our own servers. We do not keep long-term copies of your generated images.
Subscription and Purchase Data
When you purchase a subscription or credit pack, Apple processes the transaction entirely. We use RevenueCat to verify and sync your purchase status. The data we receive is limited to:
- The anonymous user ID we associate with the purchase
- The product identifier you purchased (e.g.
weeklylofi,yearlylofi,10lofi,50lofi) - Purchase status (active, expired, refunded) and expiration date
We never see your Apple ID, credit card number, billing address, or any other payment information. That data stays with Apple.
Credit and Subscription State
We store the following minimal data against your anonymous user ID in our Firestore database:
- Your current credit balance (an integer)
- Timestamps of the last weekly and monthly subscription credit grants, so we know when to replenish your allowance
- Timestamp of account creation
Diagnostic & Performance Data
To keep the App stable we may receive aggregated crash logs and performance metrics (such as load times and error rates). This data is not linked to your identity and is used to diagnose issues and improve stability.
Device Signals
For debugging we may log non-identifying signals such as iOS version, device model (e.g. "iPhone 15"), and app version. We do not use the IDFA and we do not run any advertising trackers in the App.
6. How We Use Your Information
We use the limited information we collect for the following purposes only:
- To provide the photo-to-lofi-dusk AI service you requested
- To sync your credits and subscription state across sessions on your device
- To validate and track in-app purchases through Apple's StoreKit
- To replenish credit allowances for active weekly or yearly subscribers
- To prevent fraud, abuse, and violations of our Terms of Service
- To comply with legal obligations
- To improve App stability through aggregated, anonymous diagnostics
We do not sell your personal information. We do not share it with advertisers. We do not use your photos or generated images to train AI models.
7. Legal Basis for Processing (GDPR)
If you are in the European Union, United Kingdom, or another jurisdiction with comparable law, we process your personal data under the following legal bases:
- Performance of a contract (Art. 6(1)(b) GDPR) — processing necessary to provide the App and fulfill purchases (anonymous ID, purchase data, photos you submit, generated images).
- Legitimate interests (Art. 6(1)(f) GDPR) — processing for App stability, fraud prevention, and security, balanced against your rights and freedoms.
- Legal obligation (Art. 6(1)(c) GDPR) — retention of purchase records for tax and accounting.
- Consent (Art. 6(1)(a) GDPR) — for any processing that requires consent, such as optional future integrations. You can withdraw consent at any time.
8. Third-Party SDKs & Service Providers
The App includes the SDKs listed below. Each publishes a privacy manifest (PrivacyInfo.xcprivacy) as required by Apple, and is bound to the purpose for which we use it.
fal.ai (AI Generation)
Purpose: AI image editing to apply the lofi dusk aesthetic. Model: fal-ai/nano-banana-2/edit. Data sent: your uploaded photo and generation parameters (prompt, resolution, output format).
Privacy policy: https://fal.ai/legal/privacy-policy
Google Firebase (Authentication + Firestore)
Purpose: anonymous authentication and storage of your user document containing credit balance, subscription refill timestamps, and creation count. Operator: Google LLC.
Privacy policy: https://firebase.google.com/support/privacy · Google Privacy Policy
RevenueCat
Purpose: subscription and consumable purchase validation, linking Apple transactions to your anonymous user ID. Data: anonymous user ID, Apple transaction identifier, subscription state.
Privacy policy: https://www.revenuecat.com/privacy
Apple
Purpose: App Store distribution, StoreKit billing, and system services. Apple processes all payments directly; we never see your payment instrument.
Privacy policy: https://www.apple.com/legal/privacy/
9. Data Retention
- Photos you upload: Not stored by us. Transmitted to our AI provider for the duration of generation only. Our provider's retention is governed by their own policy linked above.
- Generated images: Not stored on our own servers. The URL returned by the AI provider is displayed to you in the App and discarded when you close the screen. You can save the image to your own Photo Library.
- Anonymous user ID, credit balance, subscription refill timestamps: Retained while your installation is active. Deleted on request (see Section 11).
- Subscription and purchase records: Retained for the duration of your subscription plus the period required by tax, accounting, and consumer-protection law (typically up to 7 years depending on jurisdiction).
- Crash/diagnostic data: Retained in aggregated form for up to 90 days.
10. Your Rights
European Union and United Kingdom (GDPR / UK GDPR)
- Right to access the personal data we hold about you
- Right to rectification of inaccurate data
- Right to erasure (the "right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right not to be subject to solely automated decision-making
- Right to withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal
- Right to lodge a complaint with a supervisory authority (e.g. ICO in the UK, your national DPA in the EU)
California, USA (CCPA / CPRA)
- Right to know what personal information is collected
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information (we do not sell or share)
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your privacy rights
Other Jurisdictions
Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), and other jurisdictions provide similar rights. You may exercise them through the contact address in Section 19.
How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected] with the subject line "Privacy Request — Lofi Dusk Filter". Because we use anonymous identifiers, please include your anonymous user ID so we can locate your data. We will respond within the timeframe required by applicable law (typically within 30 days under GDPR/CCPA).
11. Account and Data Deletion
You can delete your anonymous account and all associated data at any time. Because the App does not require an email or real-name account, deletion is handled via email:
- Email [email protected] with the subject "Lofi Dusk Filter — Delete my data".
- We confirm receipt within 2 business days and complete deletion within 30 days.
- If you have purchased items, we may retain the minimal purchase-history records required by tax and consumer-protection law, in anonymized form.
Deleted data includes your Firestore user document, credit balance, and subscription refill timestamps. Apple retains purchase records it is legally required to keep; these are outside our control.
Uninstalling the App alone does not delete server-side data. To have everything removed from our backend, you must email us.
12. Children's Privacy
The App is not intended for children under 13 years of age (or under the minimum digital consent age in your jurisdiction, which may be 14 or 16 in some EU member states). We do not knowingly collect personal information from children.
If you are a parent or guardian and believe a child has provided personal information to us, please contact us at [email protected] and we will delete it promptly.
The App's content rating in the App Store is set in accordance with Apple's age rating guidelines.
13. Face Data (Photos of People)
Photos you choose to process with Lofi Dusk Filter may contain faces (yours or other people's). This section explains in detail how we treat images that include faces.
What face data we collect
The App processes your photo as a single image — a collection of pixels. It does not perform any of the following on faces in your photo:
- No facial recognition or face identification
- No biometric face data, face embeddings, or faceprints
- No attempts to link a face to a real-world identity
- No extraction of demographic, emotion, age, or identity signals from faces
- No creation or storage of face templates
The AI model we use (fal-ai/nano-banana-2/edit at fal.ai) treats your photo holistically as an image to restyle. It does not output biometric data, does not cross-match faces, and does not maintain any face database.
All planned uses of face data
The only purpose for which a photo containing a face is processed is to produce the lofi dusk restyled version you explicitly requested by tapping Create. No other use is made of the face pixels — not for training, not for analytics, not for advertising, not for demographic profiling.
Sharing with third parties
The photo — which may contain faces — is transmitted once, over an encrypted TLS connection, to our AI processing provider fal.ai (operated by Features & Labels, Inc.) to run the restyle. It is not shared with any other third party. fal.ai is contractually bound not to train on user input and not to retain the photo beyond what is technically necessary to serve the request. Our list of subprocessors is in Section 8.
Storage and retention of face data
- We do not store the original photo on our own servers.
- fal.ai processes the photo in memory to produce the output and retains it only for the time technically required to serve that individual request (typically seconds to minutes). fal.ai does not use input photos as training data.
- The generated result URL is displayed to you in the App. If you save the result to your own Photo Library, iOS handles that storage — we do not keep a copy on our servers.
- In our Firestore database we store, for history, only the URL of the finished result and a timestamp, tied to your anonymous user ID. You may delete history entries at any time from the Gallery screen in the App, and they are permanently removed from our database. URLs hosted by fal.ai are not guaranteed to remain reachable long-term; that retention is governed by fal.ai's own policy.
- On request (see Section 11) we will delete all data associated with your anonymous user ID within 30 days.
Where in this policy face data is addressed
Face data (as part of the broader category of photos that may contain faces) is addressed in:
- Section 3 — "App Store Privacy Label" (disclosed as User Content — Photos)
- Section 5 — "Photos You Upload for Creation" and "Generated Images"
- This Section 13 — Face Data
- Section 9 — Data Retention
- Section 14 — AI Processing Disclosure
In-app consent before any face-bearing photo is sent
Before the App transmits your first photo to fal.ai, the App displays a dedicated in-app consent screen that names fal.ai as the third-party AI processor, explains that photos may contain faces, confirms that no biometric face analysis is performed, and requires you to tap Accept to proceed. You can revoke consent at any time by uninstalling the App. No photo (face-bearing or otherwise) is transmitted before you explicitly tap Create.
14. AI Processing Disclosure (EU AI Act Compliance)
In compliance with Regulation (EU) 2024/1689 (the "EU AI Act") and global best practices for transparent AI, we disclose:
- The App uses generative artificial intelligence to restyle user-supplied photos into a dreamy lofi dusk aesthetic with warm sunset tones, lavender shadows, soft film grain, and a vintage 90s analog vibe. The output is synthetic content generated by an AI system.
- The AI model is
fal-ai/nano-banana-2/edit, provided by fal.ai. - AI generation is initiated only by your explicit action (tapping "Create"). The App does not generate content automatically.
- Generated images may include provenance markers embedded by the AI provider.
- You are responsible for the lawful use of any content generated by the App. Use to deceive, create non-consensual manipulated imagery, or otherwise violate applicable law is prohibited by our Terms.
15. In-App Consent & Transparency
Apple's App Review guidelines (5.1.1(i) and 5.1.2(i)) require that, before any personal data is shared with a third-party AI service, the App disclose what data is sent, identify who the data is sent to, and obtain the user's permission. Lofi Dusk Filter complies with these requirements through the following in-app mechanisms:
- First-run AI consent screen. Before any photo is ever sent for AI processing, the App presents a dedicated consent screen that: (a) names the third party receiving the data — fal.ai (operated by Features & Labels, Inc.); (b) explains that the single photo the user selected, and only that photo, is transmitted; (c) confirms that no facial recognition or biometric analysis is performed; (d) confirms that the photo is not used to train AI models; and (e) links to this Privacy Policy and to our Terms of Service. The user must tap I agree, continue to proceed. Tapping Not now keeps the App usable but prevents any photo from being sent.
- Persistent in-app disclosure. A visible notice on the main creation screen, directly above the Create button, reminds the user that tapping Create sends the selected photo to fal.ai over an encrypted connection.
- Explicit user action required. The App never transmits a photo automatically. A transmission only occurs when the user has (a) manually selected a photo through Apple's standard Photo Library picker and (b) tapped the Create button.
- Revocability. Consent can be withdrawn by uninstalling the App or by contacting us at [email protected]. On data deletion request we remove all records associated with the user's anonymous identifier within 30 days.
16. International Data Transfers
Our backend services (Google Firebase, RevenueCat, fal.ai) operate from data centers in the United States and the European Union. By using the App, you consent to the transfer of your information to these regions for processing.
For transfers of personal data from the European Union or United Kingdom to countries outside the EEA, we and our processors rely on Standard Contractual Clauses approved by the European Commission and other appropriate safeguards (Art. 46 GDPR).
17. Security
We protect the limited information we collect using industry-standard measures:
- TLS 1.2+ encryption for all data in transit
- Encryption at rest provided by Google Cloud and our other infrastructure providers
- Anonymous identifiers — no real-name linkage
- Firestore security rules that restrict access to each user's own documents
- Limited backend access restricted to authorized personnel
- Regular security review of third-party providers and their privacy manifests
No system is perfectly secure. If you become aware of a security incident affecting your data, please contact us immediately at [email protected]. For incidents that affect personal data of EU/UK users, we will notify the relevant supervisory authority as required by law.
18. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will:
- Update the "Last updated" date at the top of this policy
- Notify users via in-app message where appropriate
- For significant changes, provide a plain-language summary of what changed
Continued use of the App after changes are posted constitutes acceptance of the updated policy.
19. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact us at:
Email: [email protected]
Subject: Lofi Dusk Filter — Privacy Inquiry
Data controller: TRY2APP LTD
We typically respond within 7 business days.