Privacy Policy

1. Who we are

The data controller responsible for this Privacy Policy is:

"Picstreak", "we", "us", or "our" refers to the above. "You" means the person using the Picstreak iOS app or visiting picstreak.app.

2. Plain-English summary

3. Data stored on your device

Picstreak stores the following on your iPhone using Apple's SwiftData and UserDefaults, protected by iOS file-level encryption:

This data never leaves your device unless your iCloud backup is enabled, in which case Apple may include it in your encrypted backup. We do not have access to your iCloud backup.

Uninstalling the app removes all of this data.

iCloud Key-Value Storage (reinstall recovery — Pro only)

iCloud Key-Value Storage sync is a Pro feature. On the free tier nothing is written to or read from iCloud, and a reinstall starts from a clean slate. For Pro subscribers, Picstreak uses Apple's iCloud Key-Value Storage (NSUbiquitousKeyValueStore) to preserve a small slice of state across reinstalls of the app on the same device under the same Apple ID. This is not cross-device sync: we do not maintain a server-side copy of your data, and we do not push your library between devices. The store is provided by Apple, tied to your Apple ID, and accessible only to Picstreak on your devices.

For Pro subscribers, the following items are written to iCloud KVS:

No photo content, raw EXIF, or location data is written to iCloud KVS — only photo identifiers, your display name, and small settings. Pro subscribers can disable iCloud sync for Picstreak in the app's settings; doing so prevents further writes and reads from the KVS store.

3-bis. Referral programme

If you choose to share a Picstreak invite link, redeem one you received, or redeem a promotional code we publish as part of a campaign (see Terms §5-bis), a small amount of data is processed by a Picstreak-operated server (the "Referral Service"). Campaign codes are redeemed through the same endpoint and involve exactly the same data described below — the only difference is that no other user stands behind the code. Once you have taken part, the app also checks in with that server automatically on later launches to keep your Promo access up to date — see "Automatic status check" below. The Referral Service is the only Picstreak-operated server that processes any data about you; outside of this opt-in flow, no Picstreak-operated server processes data about you.

Clipboard (one-time, on-device)

When you first reach the invite screen during onboarding, Picstreak checks your clipboard once to see whether you have copied a Picstreak invite code (an 8-character string matching the pattern [A-Z0-9]{8}). iOS may show a system paste notification when this happens. If a matching code is found it is saved locally on your device so you can redeem it with one tap; no other clipboard content is read or retained, and nothing from your clipboard is sent to the Referral Service unless you explicitly tap "Redeem".

Automatic status check (after you participate)

Once your device has taken part in the referral programme — you created an invite code, or you redeemed one — Picstreak asks the Referral Service for the current expiry date of your Promo access each time the app starts. This happens quietly, without any action from you. It is how a reward reaches the person who sent an invite: that person does nothing at the moment their friend redeems, so without this check the app would never learn that their Promo access had been extended.

The check sends the same data as any other referral request — the signed request from your device (its salted device-identifier hash, key identifier, and anonymous RevenueCat ID) — and receives back only the current expiry date of your Promo access together with the number of people who have redeemed your invite (the counter shown on the invite screen). No new categories of data are collected, and nothing about your photos, library, or app usage is included. The check runs only on devices that have already participated: if you have never shared or redeemed an invite, the app makes no request to the Referral Service at all. If the device is offline or the request fails, it is skipped silently and the app keeps using the expiry date it already stored locally.

What we receive

What we do not receive

The Referral Service does not receive your name, email address, Apple ID, phone number, raw device identifier (we receive only the salted hash), raw IP address (we receive only a short-lived salted hash), private key material, photos, photo metadata, location, contacts, or any data about how you use the app outside of the referral flow itself. Beyond the rate-limit hash described above, we do not retain Vercel edge request logs containing your IP address beyond 72 hours; after that window, request logs are deleted by Vercel.

Legal basis (GDPR Art. 6)

Processing the referral code, the salted device hash, the device public key, the RevenueCat app user ID, and the related timestamps is necessary for the performance of a contract you initiate by sharing or redeeming an invite — Art. 6(1)(b). The 7-day Promo access grant is the consideration; we cannot deliver it without verifying that the request comes from your device and that you have not already redeemed. The same basis covers the automatic status check described above: it is the only channel through which the Promo access you earn when someone redeems your invite can reach your device. Processing the salted, short-lived hash of your IP address for rate-limiting rests on our legitimate interest in preventing abuse and protecting the Referral Service — Art. 6(1)(f). The interest is narrow (throttling) and the data is short-lived (~24 hours) and not linked to any identifier we can use to contact you. The indefinitely-retained anti-fraud device hash likewise rests on our legitimate interest in fraud prevention — Art. 6(1)(f) and Recital 47, which names fraud prevention as a legitimate interest. We keep it after a deletion request under the erasure exception in Art. 17(1)(c)/(3): it is the minimum data needed (a single one-way hash, no contact identifier) to enforce the one-redemption-per-device limit, and that interest overrides erasure for this one value. We treat this hash as pseudonymous (Art. 4(5)) rather than anonymous — because we hold the salt it is not irreversibly anonymous — but it is never linked to your name, email, Apple ID, or any contact identifier.

Retention

Subprocessors

The Referral Service runs on Vercel (serverless functions, US/EU edge regions) and stores data in Vercel Postgres (operated by Neon, EU region — eu-central-1 / Frankfurt). Both are configured as data processors under written agreements; you can request a copy of the safeguards by emailing privacy@picstreak.app.

Russian Federation (ФЗ-152)

Все идентификаторы, которые Picstreak Referral Service сохраняет в собственной базе данных (хеш идентификатора устройства, бессрочный анти-фрод-хеш устройства, хеш IP-адреса для rate-limit), вычисляются как одностороннее SHA-256 от исходного значения и серверной "соли", которая хранится отдельно как секрет и не может быть восстановлена из базы. Публичный ключ устройства (EC P-256), используемый для проверки JWT-подписи запросов, не содержит сведений, позволяющих идентифицировать субъекта персональных данных без обращения к самому устройству. На этом основании мы рассматриваем перечисленные данные как обезличенные в значении ст. 3 ФЗ-152. Если вы являетесь резидентом Российской Федерации и не согласны с этой квалификацией, не используйте функцию рефералов; альтернативно вы можете запросить удаление вашей записи по адресу privacy@picstreak.app. Исключение — анти-фрод-хеш устройства: он хранится бессрочно исключительно для предотвращения повторной активации промокода и не удаляется по запросу (в отличие от остальных записей). Полная переустановка приложения сбрасывает идентификатор устройства для будущих установок, но не удаляет уже сохранённый хеш.

Your rights and how to opt out

Using the referral feature is optional — if you don't share or redeem an invite, and don't redeem a campaign code, no data ever reaches the Referral Service. If you have participated, you can erase your referral data at any time directly in the app: Settings → Delete all data. This wipes everything on your device and your iCloud sync data, and removes your invite codes, redemptions, and device public key from the Referral Service; the request is authenticated by your device, so no account or manual identification is needed. You are then returned to the start of onboarding. You can also email privacy@picstreak.app and we will delete your record within one month (GDPR Art. 12(3)). The one exception is the anti-fraud device hash described above, which we retain indefinitely to enforce the one-redemption-per-device limit and do not delete on request — a full app uninstall only resets your device identity for future installs, it does not delete the stored hash; everything else is deleted. Deleting your data also clears the referral state held on your device, so the automatic status check described above stops as well: from that point the app makes no further requests to the Referral Service unless you choose to share or redeem an invite again. Deleting the app has the same effect.

4. Data processed by third parties

This section covers third-party services that process data on our behalf. The Picstreak-operated Referral Service is described separately in §3-bis (it is first-party, opt-in, and the only Picstreak-operated server). Picstreak relies on three external services in addition; each has its own privacy practices:

Apple — App Store & StoreKit

When you start a subscription (Picstreak Pro Monthly or Yearly) or buy the one-time Picstreak Lifetime purchase, Apple processes payment through the App Store and manages renewals where applicable. We receive a purchase receipt from StoreKit to unlock paid features. We do not receive your name, billing address, or card details.

Place-name lookup. When a photo you are reviewing carries location metadata, the app uses Apple's geocoding service (CLGeocoder) to turn those coordinates into a place name shown on the card. The request goes to Apple and is governed by Apple's Privacy Policy. We do not receive, store, or transmit the coordinates or the place name ourselves, and nothing about your location reaches a Picstreak server (see also §2).

See Apple's Privacy Policy.

RevenueCat — purchase management

We use RevenueCat to verify your purchase status and manage entitlements across re-installs. RevenueCat assigns an anonymous app user ID generated on your device. It is not linked to your name, email, Apple ID, or any other identifier we hold. RevenueCat receives the purchase receipt from Apple and basic device/OS data needed to validate purchases.

Purchase history is processed solely to determine your subscription tier (Free or Pro). It is not linked to your real-world identity and is not used for tracking, profiling, or advertising.

See RevenueCat's Privacy Policy.

Sentry — crash & performance reports

We use Sentry as a data processor to capture anonymous crash, performance, and diagnostic data so we can fix bugs and improve stability. Reports may include: device model, iOS version, app version, a stack trace, a non-identifying installation identifier, your IP address (used by Sentry to identify network errors and discarded after processing), and "breadcrumbs" / transaction spans (a short trail of in-app technical events such as screens visited, API calls, and errors, with no photo content or personal identifiers). Sentry is configured as a diagnostic tool, not as an advertising or analytics product, and the data is not linked to your real-world identity and is not used for tracking.

See Sentry's Privacy Policy and Data Processing Addendum.

What we do not use

The Picstreak iOS app does not use Google Analytics, Meta Pixel, Firebase, advertising SDKs, attribution SDKs, or any cross-app tracking technology. We do not run an AI/ML backend; classification (if any) happens on-device. (This website, picstreak.app, uses Google Analytics for visit statistics on a consent basis — that is a separate, opt-in website tool described in §4-ter, and it never touches the app or your photos.)

4-bis. In-app support requests

The app has a Profile → "Help & feedback" option. Tapping it opens your device's standard mail composer (Apple's MFMailComposeViewController) with a message addressed to support@picstreak.app, pre-filled with the diagnostics described below. Nothing is sent automatically. You choose whether to send the email; you can edit the body, remove the attachment, or cancel entirely before sending. There is no background collection or silent transmission — the data only reaches us if you tap Send in your own mail app.

What the email is pre-filled with

To help us diagnose your issue, the draft includes:

How we use it and who receives it

Recipient: the diagnostics you send reach support@picstreak.app, a mailbox operated by the controller named in §1. We use this data solely to handle and respond to your support request — we do not use it for tracking, profiling, or advertising, and we do not share it with third parties beyond our email provider acting as a processor. Because you compose and send the email yourself through your own mail account, the transmission is initiated by you. We retain support correspondence only as long as needed to resolve your request and any follow-up, then delete it.

4-ter. Website analytics (picstreak.app)

This section is about the website at picstreak.app — not the iOS app. The app ships no analytics SDK (see §4). On the website we use Google Analytics 4 (provided by Google Ireland Limited) to understand, in aggregate, how many people visit, which pages they read, and roughly where visits come from, so we can improve the site.

Consent first — nothing runs until you accept

Google Analytics is off by default for every visitor. When you first arrive, a banner asks whether you accept analytics cookies. Until you tap Accept, the Google Analytics script is not loaded at all: no cookie is written, no identifier is created, and no request — not even a cookieless one — is sent to Google. If you tap Decline, analytics stays off and we remember that choice so you are not asked again. This is your legal basis under GDPR Art. 6(1)(a) (consent), and it is the only processing on this site that relies on consent. You can change your mind at any time (see "How to withdraw" below).

What Google Analytics receives if you accept

What it is not used for

We run Analytics in an analytics-only configuration: Google Signals and ad-personalisation signals are disabled, no advertising cookies are set, and the data is not used for advertising, ad targeting, or building a cross-site profile of you. We do not sell this data and do not combine it with the app data described elsewhere in this policy. The pseudonymous analytics identifier is not linked to your name, email, Apple ID, the RevenueCat ID, or any referral record.

Google as processor, and international transfer

Google acts as our data processor for Analytics under Google's Ads Data Processing Terms. Data may be transferred to Google LLC in the United States; Google relies on the European Commission's Standard Contractual Clauses and its certification under the EU–US Data Privacy Framework for those transfers. See Google's Privacy Policy and how Google Analytics safeguards data.

Retention

We set the Google Analytics data-retention control to its shortest option — 2 months — for user- and event-level data; Google deletes that data automatically after the window. Aggregated, non-identifying reports may persist longer within Google Analytics. The _ga cookies stored in your browser expire after up to two years, or immediately when you clear them (see below).

How to withdraw or opt out

Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew (GDPR Art. 7(3)).

For users in the European Economic Area, UK, and Switzerland, we process the limited data described above under the following legal bases (Article 6 GDPR):

You can object to processing based on legitimate interests at any time, and withdraw analytics consent at any time (see §8 and §4-ter).

6. Retention

7. International transfers

RevenueCat and Sentry are U.S.-based providers; Google (Analytics, website only, if you accept the cookie banner) may transfer data to the U.S. as well. When data is transferred outside the European Economic Area, transfers rely on the European Commission's Standard Contractual Clauses (SCCs) and the EU–U.S. Data Privacy Framework where applicable. You can request a copy of the safeguards by emailing privacy@picstreak.app.

8. Your rights

Under GDPR (and equivalent laws), you have the right to:

Because we do not collect direct identifiers, in practice the data we can match to you is limited to (a) the anonymous RevenueCat ID tied to your purchase and (b) crash reports linked to a non-identifying installation ID.

How to exercise your rights. Email privacy@picstreak.app and include either:

Either identifier lets us locate the relevant records without you sharing your Apple email. We respond within one month of receiving a verifiable request (GDPR Art. 12(3)), free of charge in normal circumstances (Art. 12(5)). We have not appointed a Data Protection Officer: our processing does not meet the thresholds in GDPR Art. 37 (no large-scale systematic monitoring, no large-scale special-category data). For all data protection matters, contact the controller directly at the address above.

9. California residents (CCPA / CPRA)

This section is the "Notice at Collection" required under the California Consumer Privacy Act, as amended by the CPRA.

Categories of personal information we collect

Sources, purposes, recipients, retention

Sale, sharing, and behavioral advertising

We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding twelve months. We do not use personal information for cross-context behavioral advertising, profiling that produces legal or similarly significant effects, or automated decision-making. Google Analytics on the website is configured as a service provider under Google's Ads Data Processing Terms, with Google Signals and ad-personalisation disabled; it is used only for our own analytics and not for cross-context behavioral advertising, so it does not constitute a "sale" or "share" (see §4-ter).

Your California rights

You have the right to: know the categories and specific pieces of personal information we hold about you; request deletion; request correction of inaccurate information; opt out of any future sale or sharing; and limit the use of sensitive personal information (not applicable here, since we don't collect any).

To exercise these rights, email privacy@picstreak.app using the verification process described in §8. You may also designate an authorised agent in writing. We will not discriminate against you for exercising any of these rights.

10. Children

Picstreak is rated 4+ in the App Store as a general-audience utility. It is not directed at children, does not collect a name, email, or any account information, and does not contain in-app messaging, social features, or behavioural advertising. We do not knowingly collect personal information from a child. If you are a parent or guardian and believe a child has provided personal information through the app, contact privacy@picstreak.app and we will delete it. Apple Media Services Terms and your device's parental controls also apply.

11. Security

On-device data is protected by iOS file-level encryption tied to your device passcode/Face ID/Touch ID. Network traffic to RevenueCat, Sentry, and Apple uses TLS. No system is perfectly secure; we cannot guarantee absolute security but we use industry-standard safeguards.

12. Changes

If we update this policy, we'll change the "Last updated" date at the top. Material changes will also be announced in the app on next launch. Continued use of Picstreak after a change means you accept the updated policy.

13. Contact