Privacy Policy
Effective date: August 24, 2026
FotoCraft ("we," "our," or "us") is a photography education app that includes camera guidance, photo analysis, and learning content. It is developed and operated by an individual developer from India. This policy explains what data we collect, how we use it, and the choices you have.
Summary
- We process photos you choose to analyze to generate feedback.
- We store analyzed photos and scores on your device so you can view history.
- We keep a server-side summary of your scores (averages and trends, never your photos) so coaching feedback can reference your progress. You can turn this off in Settings.
- Optionally, we back up your learning progress (XP, streaks, missions, badges) so it survives reinstalling the app. You can turn this off in Settings.
- We do not sell your personal information.
- You can delete your photo history at any time in the app.
- Photos you share to the public Discover feed are visible to other users and expire from the feed after about 14 days; you can delete them sooner.
- We use a device identifier and IP address to enforce usage limits and prevent abuse.
- We collect crash reports and anonymous usage analytics through Google Firebase to improve stability and features.
Data We Collect
Photos and Analysis Results
- Photos you analyze: When you take or select a photo for analysis, the image is processed to generate feedback and scores.
- Analysis results: We generate scores and feedback text for composition, lighting, technical quality, and creativity.
- Photo history: We store analyzed photos and results locally on your device so you can view your history and progress.
Usage and App Data
- Subscription status: We store subscription state to determine premium access.
- Usage limits: For free users, we track daily analysis counts.
- App settings: We store settings such as onboarding completion.
- Device identifier: When your device communicates with our servers (for analysis, daily tips, or Discover), we associate the request with an anonymous device identifier to enforce usage limits and link your Discover interactions (such as likes, reports, and blocks).
- Scoring history summary: When your photos are analyzed, our servers keep a compact statistical summary tied to your device identifier — running averages, recent averages, best scores per category, and a bounded list of recent scores (numbers and rules only, no images and no free text). This summary lets the coach reference your progress instead of repeating beginner advice.
- Learning progress backup: If "Back Up My Progress" is on (Settings), we store your XP total, streaks, completed missions with dates, and earned badges, tied to your device identifier, so your progress can be restored if you reinstall the app.
- IP address: We use your IP address to rate-limit requests and prevent abuse. This data is short-lived (typically deleted within 48 hours).
Crash Reports and Usage Analytics
- Crash reports: If the app crashes, we automatically receive a crash report through Firebase Crashlytics to diagnose and fix problems. This collection is always on in the current version and cannot be disabled in the app.
- Usage analytics: We record anonymous usage events (such as which screens and features you use) through Firebase Analytics to understand how the app is used.
- Crash reports are tagged with an anonymous per-install device identifier and your subscription tier to help us reproduce issues. They do not include your photos.
How We Use Data
- To analyze photos and provide personalized feedback.
- To show your analysis history and learning progress.
- To enforce daily usage limits for free users.
- To manage subscriptions and premium features.
- To improve stability and performance, including crash reporting.
- To send you optional notifications (such as practice reminders) if you have enabled them.
How We Share Data
AI Processing
- When AI analysis is used, we send the selected photo and a short prompt to OpenAI to generate feedback. For photos you share to Discover, we also send the image (and any display name you set) to OpenAI's moderation service to screen for prohibited content.
- If "Personalized Coaching" is on (Settings), the prompt may also include aggregate statistics from your scoring history — averages, trends, and your photographer level. These are numbers only; your photos are never part of this summary, and scores are always graded against the same rubric for everyone regardless of history.
- We do not use your photos to train AI models.
Service Providers
- FotoCraft Backend: Photos are sent to our secure backend server, which processes analysis requests on your behalf. The backend is hosted on Vercel and uses Upstash Redis and Vercel Blob storage.
- Google Firebase: Crash reporting (Crashlytics) and usage analytics (Firebase Analytics) are processed by Google as our service provider.
- Apple StoreKit: Used to process subscriptions and purchases.
- Apple Vision: Used for on-device image analysis.
We only share the minimum data required to provide the feature.
Discover Community Feed
The Discover feed displays photos that users have chosen to share publicly. If you share a photo to Discover:
- Public visibility: Your photo becomes visible to other FotoCraft users.
- Moderation: Shared photos are screened by automated moderation for explicit or prohibited content and may be rejected or removed.
- Storage: Shared photos are stored with our hosting provider. Feed entries expire automatically after approximately 14 days, and deleting a photo also deletes its stored image files; cached copies may persist briefly thereafter.
- Interactions: Other users may "like" or report your photo. These interactions are tied to your device identifier, not a public account or profile.
- Your choices: You can remove your shared photo at any time, block other users, and turn off sharing prompts in Settings.
Data Storage and Retention
- Local storage: Analyzed photos and results are stored on your device.
- Retention: Local data remains on your device until you delete it from the app or uninstall the app. Discover feed entries are retained on our servers for up to approximately 14 days.
- Server-side scoring summary and progress backup: These are retained until you delete them or ask us to, and are purged automatically after approximately 12 months of inactivity.
- Transient server data: Rate-limiting data tied to your device identifier or IP address is short-lived (typically up to 48 hours). Crash data is retained by Firebase Crashlytics in line with Google's policies (typically about 90 days).
Your Choices
- Delete history: You can delete individual photos or all analysis history in the app.
- Personalized coaching: You can turn off "Personalized Coaching" in Settings at any time — your feedback then no longer references your scoring history.
- Progress backup: You can turn off "Back Up My Progress" in Settings at any time, and "Delete Server Data" in Settings immediately removes your backup and scoring summary from our servers. You can also request deletion through the contact below.
- Disable AI analysis: The app can use on-device analysis as an alternative to AI-powered analysis.
- Subscription management: You can manage your subscription in Apple account settings.
- Server-side data: To request deletion of data stored on our servers that is tied to your device identifier (such as Discover posts or diagnostics), contact support@fotocraft.pro.
Your Privacy Rights
Depending on where you live — for example in the EU/EEA, the UK, or a US state with a privacy law — you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct inaccurate personal data.
- Delete personal data we hold about you.
- Restrict or object to certain processing.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with your local data protection authority.
Because FotoCraft does not require an account, we identify your data through your device identifier. To exercise these rights, contact support@fotocraft.pro; we will respond within a reasonable period and may ask for details that help us locate the relevant data.
Security
- We use iOS security features (such as file protection) to protect local photo storage.
- We use secure network connections when communicating with external services.
Children's Privacy
FotoCraft is not directed to children under 13, and we do not knowingly collect personal information from children.
International Data Transfers
FotoCraft is developed and operated from India. Our service providers — including OpenAI, Google, Vercel, and Upstash — may process data in the United States and other countries. Where required by law, we rely on safeguards such as the European Commission's standard contractual clauses or comparable protections offered by those providers.
Changes to This Policy
We may update this policy from time to time. We will update the effective date when changes are made.
Contact Us
If you have questions about this policy, contact us at:
support@fotocraft.pro