TogetherLens Privacy Policy
Last updated: July 20, 2026
This Privacy Policy explains how TogetherLens ("we", "us", or "our") processes information when you use our mobile app and website (together, the "Service"). It is a privacy notice, not a request to waive any privacy right.
What TogetherLens Does
TogetherLens creates a new AI-generated group portrait from separate face photos. Our application servers run on infrastructure hosted by Hetzner in Germany, API traffic passes through Cloudflare's reverse proxy and security services, and pseudonymous service records are stored in a Turso/libSQL database. Image requests are routed through fal.ai to the applicable model provider, currently Google for portrait generation/editing and Topaz Labs for upscaling. RevenueCat helps validate in-app purchases and subscriptions.
Data We Process
Photos and generation content
- Portraits you or an invited participant choose to upload. We do not create faceprints, facial-geometry templates, or TrueDepth/ARKit maps.
- The scenes, styles, and generation settings you choose.
- Generated images and protected trial previews.
- An unguessable invite token and contribution status when you use a participant invite.
Purchase and service data
- A server-minted pseudonymous purchaser reference, purchase entitlement, token balance, and app-store receipt status. We keep a minimal keyed device-to-purchaser mapping so non-expiring tokens remain recoverable after an app session expires; Delete My Data removes that mapping.
- A random app installation/session identifier. We do not use an advertising identifier for lifecycle analytics.
- Event name, event time, platform, app version, device language/locale, and a small allowlisted set of sanitized properties needed to understand the product flow.
- Technical result, duration, error category, and approximate generation cost for operations and debugging.
Optional client lifecycle analytics never includes uploaded photos, generated photos, prompts, filenames, raw IP addresses, or advertising IDs.
Integrity and abuse-prevention data
- Apple App Attest or Google Play Integrity proof associated with a one-time challenge and the specific bootstrap or trial request.
- For Apple App Attest, the attested key identifier, public key, counter, and attestation receipt while the app session remains active and until the next daily cleanup after it becomes inactive. Google Play Integrity verdict contents are checked but not retained.
- Keyed HMAC signals derived from the device/install and network address, trial-redemption state, and a pseudonymous purchaser reference. A keyed HMAC is designed to let us detect repeat redemption without storing the raw installation identifier or raw IP address.
Website analytics
If you choose “Allow analytics” on our website, our first-party analytics records a random browser visitor/session identifier, page URL and path, referrer, screen size, language, campaign parameters, scroll depth, time on page, and store-link platform/placement. Store destinations can receive static campaign information encoded in their destination link so sources and placements can be distinguished at store level; creating that link does not store or report an analytics event. The website does not send photos or app-generation content to analytics. If you decline, analytics storage and store-click event reporting remain disabled.
Essential operational and security records
Your analytics choice applies to optional client analytics, not records required to provide and protect the Service. When you call the API or use a protected feature, our servers always record the relevant subset of: a pseudonymous session or purchaser reference, keyed network signal, request path and time, app version or user agent, response status, duration, error category, billing/idempotency state, provider request identifier, and essential server-side events such as a trial result or invite creation/completion. These records are used for delivery, token reconciliation, replay protection, fraud prevention, security, and debugging, not advertising or behavioral profiling. They do not contain uploaded photos, prompts, or filenames.
Your Analytics Choice
In the app, optional client lifecycle events are neither stored nor sent until you explicitly opt in. If you decline or later opt out, the local lifecycle queue and consent-gated campaign attribution are cleared. You can change the setting later in the app. Essential server-side operational, billing, integrity, abuse-prevention, and security records described above continue regardless of this choice.
On the website, analytics is disabled until you choose “Allow analytics.” Your website choice is stored in your browser. Clearing TogetherLens website data resets that choice.
Why We Process Data
- Provide the Service and purchases: process portraits, create results, operate participant invites, validate one-time consumables or subscriptions, and restore access (performance of a contract).
- Protect the trial and Service: verify app integrity, prevent repeated free-trial redemption, secure infrastructure, reconcile failed generations, and investigate misuse (legitimate interests in fraud prevention and service security).
- Improve the product: analyze the opted-in, pseudonymous lifecycle described above (consent where required).
- Meet legal duties: retain limited billing or transaction records where tax, accounting, or consumer law requires it.
Trial Preview
An eligible new person/device can request one no-charge 0.5K trial output. The server resizes that output to a maximum dimension of 512 pixels and applies a visible center and bottom watermark reading “TogetherLens Preview - Upgrade for HD.” Only the protected result URL is returned. The trial preview URL has a maximum seven-day lifecycle.
We monitor trial redemption for abuse. Operational Telegram alerts about a trial contain no photos, image URLs, prompts, filenames, raw IP addresses, or full purchaser identifiers. They contain only the event/result, UTC time, a shortened attempt identifier, salted hash prefixes, platform/app version, reason, counters, duration, and estimated cost.
Participant Invites
A creator can share an unguessable invite link so another person can contribute their own portrait. Invite links expire after seven days. Contributions are uploaded to unguessable but technically public fal.ai CDN URLs with a forced seven-day expiry; anyone who obtains such a URL during that window could access it. Share invite links only with intended participants.
Authenticated deletion removes the corresponding invite/contribution references immediately. After ordinary expiry, a daily cleanup scrubs contribution URLs; expired invite metadata is removed within 180 days. The contributed portrait is used only to fulfill the requested group-photo flow and related security operations.
Providers and Where Processing Occurs
- Hetzner Online GmbH — application hosting in Germany: https://www.hetzner.com/legal/privacy-policy/
- Cloudflare — DNS, website/static delivery, and API reverse proxy, TLS, and security filtering: https://www.cloudflare.com/privacypolicy/
- Turso/libSQL — database hosting for pseudonymous service, security, billing, and retention records (not portrait files): https://turso.tech/privacy-policy
- fal.ai — temporary image storage and routing of AI generation and upscaling requests: https://www.fal.ai/privacy
- Google — current portrait generation/editing model provider through fal.ai, as well as Android distribution, payment, and Play Integrity services: https://policies.google.com/privacy
- Topaz Labs — current image-upscaling model provider through fal.ai: https://www.topazlabs.com/privacy-policy
- RevenueCat — purchase receipt, entitlement, and subscription processing: https://www.revenuecat.com/privacy/
- Convex — first-party website analytics infrastructure: https://www.convex.dev/legal/privacy/
- Telegram — delivery of pseudonymous operational alerts to the Service operator: https://telegram.org/privacy
- Apple — app distribution, payment processing, and App Attest verification under Apple's platform terms: https://www.apple.com/legal/privacy/
Providers process only the categories needed for their role. Provider infrastructure may process data outside your country; where legally required, we rely on adequacy decisions, contractual safeguards, or another lawful transfer mechanism.
Retention
- Original uploads on TogetherLens application servers: used in memory/temporary processing and not persisted by us beyond the request. Every fal.ai upload and output created by TogetherLens is assigned a maximum seven-day lifetime from that object’s creation. Account deletion removes our local references but does not restart the provider expiry clock, because fal.ai does not provide reliable deletion by file URL.
- Trial preview: protected CDN URL expires no later than seven days from creation.
- Participant invite and contributions: invite expires after seven days; contribution CDN URLs have a forced seven-day expiry from upload. Deletion removes pointers immediately; daily expiry cleanup scrubs URLs and expired metadata is removed within 180 days.
- On-device faces and generated history: remain locally until you remove them with Clear Local Data or delete the app’s storage.
- Lifecycle and operational records: opted-in client lifecycle analytics and essential server-side lifecycle/API/usage records are retained for no more than 395 days. Account-linked lifecycle and usage rows are removed immediately when you use Delete My Data.
- Session and purchaser mapping: expired or revoked session credentials are removed after live integrity challenges and session-linked operational work have cleared. A smaller keyed device-to-purchaser mapping remains so non-expiring tokens can be restored after session expiry; it is removed when you use Delete My Data.
- Idempotency records: completed generation, edit, and upscale replay records can retain a provider request identifier and the earlier response's media URL as text for no more than 180 days. The media itself still expires no later than seven days from creation, so a retained URL can be dead and does not extend file availability. Delete My Data removes account-linked idempotency rows immediately.
- Integrity challenges: deleted after expiry plus no more than one additional day. Apple App Attest key material is removed by the next daily cleanup, no later than one additional day after its corresponding session becomes inactive.
- Trial state: deleted with session data except a successful-redemption tombstone containing keyed device, purchaser, network-prefix, and App Attest-key digests where available. It expires no later than 180 days after the original redemption; deletion never restarts that clock.
- Deletion fence: keyed session/device/purchaser digests are retained for up to 395 days to prevent an in-flight request from recreating data after deletion. They cannot be used to recover the original identifiers.
- Billing records: completed transaction and webhook records are pseudonymized and retained for no more than 395 days for reconciliation, fraud, accounting, chargeback, and consumer-law purposes. While RevenueCat deletion is pending, its pseudonymous purchaser reference can remain only in fenced billing/deletion-queue rows until bounded retry succeeds; those rows cannot initiate new purchases.
- Telegram alerts: local delivery records are retained for no more than 180 days. Deletion queues a best-effort removal of an already delivered bot message, but Telegram age or permission rules may prevent removal. If an auto-delete timer is enabled in the private operations chat, that setting supplies the remote retention bound; otherwise an undeletable message remains subject to Telegram’s own retention. Messages contain only the limited pseudonymous fields listed above.
Sharing
We do not sell personal data and do not use portraits for advertising. We share data only with the providers above as needed to run the Service, with app stores/payment processors for purchases, or with authorities when legally required.
We do not use your content to train our own models. fal.ai and the current underlying model providers, Google and Topaz Labs, maintain their own privacy terms; review those policies for their processing commitments.
Security
We use HTTPS in transit, restricted service access, pseudonymous identifiers, one-time integrity challenges, and least-privilege controls. No network or storage method is completely secure, so we cannot promise absolute security.
Your Choices and Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to withdraw consent without affecting earlier lawful processing.
- Clear Local Data removes locally stored generated images, recent faces, custom styles, and local tester authentication from the device.
- Delete My Data sends an authenticated server deletion request that immediately removes the current session, the minimal device-to-purchaser mapping, account-linked lifecycle/usage and idempotency rows, trial attempts, invites/contributions, active Apple App Attest key, local Telegram delivery rows, and local app data, and queues bounded deletion with RevenueCat.
- Deletion does not remove the limited HMAC-only deletion fence, successful-redemption tombstone, pseudonymized transaction records, or already-delivered Telegram message described above. Remaining fal.ai media keeps its original maximum seven-day expiry from creation.
- Because TogetherLens does not require a conventional user account, provide the in-app session information requested by support so we can locate the correct pseudonymous record.
To exercise rights or ask for help, contact [email protected]. We may need to verify that the request belongs to the relevant app session. You may also complain to your local data-protection authority.
Children
TogetherLens is not directed to children under 13, or a higher minimum age required locally. A parent or legal guardian must provide required permission before a child’s portrait is uploaded. We do not knowingly allow children below the applicable age to operate the Service independently.
Changes
We may update this notice when our practices or legal obligations change. We will publish the new date and provide additional notice for material changes where required.
Contact
- Email: [email protected]
- Subject: “Privacy Request – TogetherLens”