TogetherLens Privacy Policy
Last updated: August 20, 2026
This Privacy Policy explains how TogetherLens ("we", "us", or "our") processes information when you use our mobile app and website (together, the "Service"). It is a privacy notice, not a request to waive any privacy right.
What TogetherLens Does
TogetherLens creates a new AI-generated group portrait from separate face photos. Our application servers run on infrastructure hosted by Hetzner in Germany, API traffic passes through Cloudflare's reverse proxy and security services, and pseudonymous service records are stored in a Turso/libSQL database. Image requests are routed through fal.ai to the applicable model provider, currently Google for portrait generation/editing and Topaz Labs for upscaling. RevenueCat helps validate in-app purchases and subscriptions.
Data We Process
Photos and generation content
- Portraits you or an invited participant choose to upload. We do not create faceprints, facial-geometry templates, or TrueDepth/ARKit maps.
- If you install TogetherLens as an Android PWA and choose it from the system share sheet, the selected JPG, PNG, or WebP files are held only in that browser's IndexedDB long enough to open the local Portrait Readiness Checker (at most 15 minutes). The service worker does not upload them, send them to analytics, or forward them to TogetherLens servers; the one-shot local record is deleted when it is consumed or expires.
- The scenes, styles, and generation settings you choose.
- Generated images and protected trial previews.
- An unguessable invite token and contribution status when you use a participant invite.
- When you start or join an optional guest group draft, an unguessable public draft token, selected public style IDs, portrait count, expiry, and keyed hashes of the separate starter, host, contributor-deletion, and one-use claim capabilities. The raw host and deletion capabilities stay in your browser storage; the raw ten-minute claim capability stays in that browser tab's session until the app uses it or it expires.
- When you intentionally open a group room from Canva, TogetherLens receives only a verified pseudonymous Canva owner mapping and the room data needed to operate that room. Canva receives no uploaded portraits, participant names, contact details, or private room capabilities from TogetherLens.
- When an organizer uses the optional Google Calendar integration, TogetherLens receives the Google authorization and selected calendar-event data needed to list their rooms and attach a participant link. The event attachment contains no host, deletion, or claim capability. Google Calendar receives no uploaded portrait or participant name from the room.
- When an organizer starts the optional Google Meet Photo Room, our backend briefly receives the short-lived Google Identity Services ID credential to verify its signature, audience, issuer, and expiry. We do not persist or log that credential, and we do not use its email or name claims. We retain only a server-keyed hash of the verified Google subject plus the room data needed to operate and recover the organizer's active rooms. Google Meet receives no uploaded portrait, participant name, meeting identifier, meeting code, roster, camera feed, audio, or private room capability from TogetherLens.
- When you create an optional Vibe Vote, we store the two selected public style IDs, an unguessable poll-token hash, the creator's pseudonymous app session, vote totals, status, and creation, update, expiry, first-vote, and optional revocation times. A voter keeps a random voter token on their device; the Service stores only a poll-specific keyed hash of it, the A/B choice, a finite entry source and client surface, and timestamps. Vibe Votes never contain uploaded portraits, generated results, names, contact details, or Discord, Messages, FaceTime, or social-graph data.
- The optional Vibe Vote App Clip receives only the unguessable poll link needed to display two public styles and submit an A/B choice. If someone chooses to continue in the full app, the App Clip can leave a device-only, one-use attribution record containing only the fixed App Clip source/campaign, share placement, and timestamp. It contains no poll token, selected style, voter token, raw URL, portrait, or user identifier.
- When a creator asks people shown in one generated result to review a specific intended use, we store the finite intended-use category, each reviewer's unguessable review-token hash, practical response, status, and expiry. The private-by-link review page receives only a low-resolution image through our first-party proxy and the minimum review metadata. It sends no website analytics. A response is practical feedback, not legal consent or identity verification.
Purchase and service data
- A server-minted pseudonymous purchaser reference, purchase entitlement, token balance, and app-store receipt status. We keep a minimal keyed device-to-purchaser mapping so non-expiring tokens remain recoverable after an app session expires; Delete My Data removes that mapping.
- A random app installation/session identifier. We do not use an advertising identifier for lifecycle analytics.
- Event name, event time, platform, app version, device language/locale, and a small allowlisted set of sanitized properties needed to understand the product flow.
- Technical result, duration, error category, and approximate generation cost for operations and debugging.
Optional client lifecycle analytics never includes uploaded photos, generated photos, prompts, filenames, raw IP addresses, or advertising IDs.
Integrity and abuse-prevention data
- Apple App Attest or Google Play Integrity proof associated with a one-time challenge and the specific bootstrap or trial request.
- For Apple App Attest, the attested key identifier, public key, counter, and attestation receipt while the app session remains active and until the next daily cleanup after it becomes inactive. Google Play Integrity verdict contents are checked but not retained.
- Keyed HMAC signals derived from the device/install and network address, trial-redemption state, and a pseudonymous purchaser reference. A keyed HMAC is designed to let us detect repeat redemption without storing the raw installation identifier or raw IP address.
Website analytics
If you choose “Allow analytics” on our website, our first-party analytics records a random browser visitor/session identifier, page URL and path, referrer, screen size, language, campaign parameters, scroll depth, time on page, and store-link platform/placement. Store destinations can receive static campaign information encoded in their destination link so sources and placements can be distinguished at store level; creating that link does not store or report an analytics event. The website does not send photos or app-generation content to analytics. If you decline, analytics storage and store-click event reporting remain disabled.
Essential operational and security records
Your analytics choice applies to optional client analytics, not records required to provide and protect the Service. When you call the API or use a protected feature, our servers always record the relevant subset of: a pseudonymous session or purchaser reference, keyed network signal, request path and time, app version or user agent, response status, duration, error category, billing/idempotency state, provider request identifier, and essential server-side events such as a trial result or invite creation/completion. These records are used for delivery, token reconciliation, replay protection, fraud prevention, security, and debugging, not advertising or behavioral profiling. They do not contain uploaded photos, prompts, or filenames.
Your Analytics Choice
In the app, optional client lifecycle events are neither stored nor sent until you explicitly opt in. If you decline or later opt out, the local lifecycle queue and consent-gated campaign attribution are cleared. You can change the setting later in the app. Essential server-side operational, billing, integrity, abuse-prevention, and security records described above continue regardless of this choice.
On the website, analytics is disabled until you choose “Allow analytics.” Your website choice is stored in your browser. Clearing TogetherLens website data resets that choice.
Why We Process Data
- Provide the Service and purchases: process portraits, create results, operate participant invites, validate one-time consumables or subscriptions, and restore access (performance of a contract).
- Protect the trial and Service: verify app integrity, prevent repeated free-trial redemption, secure infrastructure, reconcile failed generations, and investigate misuse (legitimate interests in fraud prevention and service security).
- Improve the product: analyze the opted-in, pseudonymous lifecycle described above (consent where required).
- Meet legal duties: retain limited billing or transaction records where tax, accounting, or consumer law requires it.
Trial Preview
An eligible new person/device can request one no-charge 0.5K trial output. The server resizes that output to a maximum dimension of 512 pixels and applies a visible center and bottom watermark reading “TogetherLens Preview - Upgrade for HD.” Only the protected result URL is returned. The trial preview URL has a maximum seven-day lifecycle.
We monitor trial redemption for abuse. Operational Telegram alerts about a trial contain no photos, image URLs, prompts, filenames, raw IP addresses, or full purchaser identifiers. They contain only the event/result, UTC time, a shortened attempt identifier, salted hash prefixes, platform/app version, reason, counters, duration, and estimated cost.
Participant Invites
A creator can share an unguessable invite link so another person can contribute their own portrait. Invite links expire after seven days. Contributions are uploaded to unguessable but technically public fal.ai CDN URLs with a forced seven-day expiry; anyone who obtains such a URL during that window could access it. Share invite links only with intended participants.
Authenticated deletion removes the corresponding invite/contribution references immediately. After ordinary expiry, a daily cleanup scrubs contribution URLs; expired invite metadata is removed within 180 days. The contributed portrait is used only to fulfill the requested group-photo flow and related security operations.
Guest Group Drafts
After you add a portrait to an ordinary participant invitation, you may separately choose to start your own private group draft. Starting a draft requires a second consent and uploads a separate copy of the portrait still open on your device. We do not silently reuse the earlier provider URL. A draft accepts at most four portraits and expires within 72 hours.
The public-by-link draft page shows only its status, portrait count, expiry, and one or two public style previews. It never displays uploaded portraits, names, contact details, host access, or a portrait gallery. Anyone with the public link can submit one portrait while the draft is open, so share it only with people expected in the photo.
The host capability stays in the browser that created the draft. The Service stores only a keyed hash of that capability. After at least two portraits arrive, the host can create a one-use claim capability that expires after ten minutes. The browser removes it from the visible web address and keeps it in that tab's session for the app handoff. Claiming imports the draft into an authenticated, integrity-checked app session. It does not grant tokens, start a purchase, or include a free generation.
A contributor can delete their own portrait reference with the deletion capability stored in their browser. The host can delete the whole draft. Deletion removes our draft and portrait references immediately. The separate fal.ai upload keeps its original maximum 72-hour expiry because fal.ai does not provide reliable deletion by file URL.
An optional Canva-origin room follows the same private-by-link controls. TogetherLens uses the verified pseudonymous owner mapping only to connect the organizer's user-initiated Canva action to the room; it does not send portraits or participant names back to Canva. The active room and its portrait references expire within 72 hours. Limited expired metadata can remain pseudonymously for the bounded cleanup period described under Retention, but it can no longer be used to open or claim the room.
An optional Google Calendar-origin room follows the same controls. The organizer chooses the Calendar action that creates or attaches the room. The event receives only the participant room URL; organizer, deletion, and one-use claim capabilities stay out of the event. The public room shows a count and public style previews, not portraits, attendee names, or contact details. A Calendar attendee contribution is recorded as a finite source only when the room itself has an authoritative Google Calendar origin and the attachment carries the complete TogetherLens-owned campaign tuple.
An optional Google Meet-origin room also follows the same controls. Starting the activity shares only one opaque public room token with meeting participants. TogetherLens does not request Meet media, roster, meeting information, or participant identity. Each participant explicitly chooses and consents to their own portrait upload. The organizer's host capability and later one-use app claim remain separate from the activity state. A Meet contribution or app claim is attributed to this channel only when the backend room has the authoritative Google Meet origin.
Vibe Vote and App Clip
A Vibe Vote is private by its unguessable link, remains open for no more than 72 hours, and accepts at most 50 distinct voter tokens. It shows exactly two current public TogetherLens styles. It never shows or transfers anyone's portrait, generated result, prompt, name, contact details, or purchaser information. Anyone with the link can vote, so share it only with the intended group.
The random voter token remains on the voter's device. The Service derives a poll-specific keyed hash, so the stored value cannot be used to link the same browser across different polls. A voter can change their choice while the poll is open. The creator can close the vote early. Closing or expiry removes the individual vote rows; limited creator-linked poll metadata can remain for the bounded operational-retention period below. Delete My Data removes a creator's polls and their vote rows immediately.
The App Clip is a smaller Apple-provided Vibe Vote surface. It has no photo-library, camera, contact, advertising-identifier, purchase, or generation access. Its random voter token remains device-only. The optional full-app handoff record is consumed once or discarded, is accepted for no more than seven days, and cannot overwrite an earlier acquisition source.
Private Group Review
A creator can make an unlisted review request for one generated result and one finite intended use: private sharing, a social post, a profile or team image, or a print or gift. The request must be created while the original short-lived result source is still available, before that capability is used to publish a Result Remix page. Each reviewer receives a separate unguessable link. The page shows only a low-resolution, first-party-proxied preview, the intended use, the expiry, and that reviewer's saved practical response. It does not show names, contact details, other reviewers, their responses, an original-resolution file, or a result-download control.
The reviewer can answer "Okay for this use" or "Please don't use it." Repeating the same response is safe. A conflicting later response is rejected. This response helps the creator make a practical decision. It is not legal consent, identity verification, a release, or a waiver of rights. The review set and links expire within 72 hours, and the creator can revoke them sooner.
Providers and Where Processing Occurs
- Hetzner Online GmbH — application hosting in Germany: https://www.hetzner.com/legal/privacy-policy/
- Cloudflare — DNS, website/static delivery, and API reverse proxy, TLS, and security filtering: https://www.cloudflare.com/privacypolicy/
- Turso/libSQL — database hosting for pseudonymous service, security, billing, and retention records (not portrait files): https://turso.tech/privacy-policy
- fal.ai — temporary image storage and routing of AI generation and upscaling requests: https://www.fal.ai/privacy
- Google — current portrait generation/editing model provider through fal.ai, as well as Android distribution, payment, and Play Integrity services: https://policies.google.com/privacy
- Topaz Labs — current image-upscaling model provider through fal.ai: https://www.topazlabs.com/privacy-policy
- RevenueCat — purchase receipt, entitlement, and subscription processing: https://www.revenuecat.com/privacy/
- Convex — first-party website analytics infrastructure: https://www.convex.dev/legal/privacy/
- Canva — optional organizer-initiated group-room integration and pseudonymous owner verification; Canva receives no portraits or participant names from TogetherLens: https://www.canva.com/policies/privacy-policy/
- Google Calendar — optional organizer-initiated event attachment and room management; Calendar receives no uploaded portraits, participant names, or private room capabilities from TogetherLens: https://policies.google.com/privacy
- Google Meet — optional organizer-initiated collaborative photo room; Meet receives only the opaque public activity token and no uploaded portraits, participant names, meeting identifiers, or private room capabilities from TogetherLens: https://policies.google.com/privacy
- Telegram — delivery of pseudonymous operational alerts to the Service operator: https://telegram.org/privacy
- Apple — app distribution, payment processing, and App Attest verification under Apple's platform terms: https://www.apple.com/legal/privacy/
Providers process only the categories needed for their role. Provider infrastructure may process data outside your country; where legally required, we rely on adequacy decisions, contractual safeguards, or another lawful transfer mechanism.
Retention
- Original uploads on TogetherLens application servers: used in memory/temporary processing and not persisted by us beyond the request. Every fal.ai upload and output created by TogetherLens is assigned a maximum seven-day lifetime from that object’s creation. Account deletion removes our local references but does not restart the provider expiry clock, because fal.ai does not provide reliable deletion by file URL.
- Trial preview: protected CDN URL expires no later than seven days from creation.
- Participant invite and contributions: invite expires after seven days; contribution CDN URLs have a forced seven-day expiry from upload. Deletion removes pointers immediately; daily expiry cleanup scrubs URLs and expired metadata is removed within 180 days.
- Guest group drafts and contributions, including Canva-origin, Google Calendar-origin, and Google Meet-origin rooms: each separately consented portrait upload has a maximum 72-hour provider lifetime from its creation. The active room expires within 72 hours. Raw host, starter, contributor-deletion, and claim capabilities are never stored by us; only keyed authorization hashes are stored. Deletion or expiry makes the room and its capabilities unusable and scrubs portrait URLs, owner mapping, and active claim state as applicable. Those keyed hashes and other limited, pseudonymous expired metadata can remain until the draft rows are removed within 180 days. A claim capability expires after ten minutes, issuing a new one revokes the earlier one, and a consumed claim can be replayed only by the same app session until the room expires.
- Vibe Votes and App Clip handoff: a poll remains active for no more than 72 hours. Individual vote rows are removed when the poll expires or is revoked. Revoked or expired poll metadata is removed within 180 days. A device-only App Clip handoff record is consumed once or rejected after no more than seven days.
- Private Group Review: the review set and first-party image proxy remain available for no more than 72 hours and can be revoked sooner. Review links cannot open or accept responses after expiry or revocation. The Service stores only keyed hashes of raw reviewer tokens. Limited pseudonymous review metadata can remain until the review-set rows are removed within 180 days. The underlying generated result keeps its existing maximum seven-day provider expiry; creating a review does not extend it.
- On-device faces and generated history: remain locally until you remove them with Clear Local Data or delete the app’s storage.
- Lifecycle and operational records: opted-in client lifecycle analytics and essential server-side lifecycle/API/usage records are retained for no more than 395 days. Account-linked lifecycle and usage rows are removed immediately when you use Delete My Data.
- Session and purchaser mapping: expired or revoked session credentials are removed after live integrity challenges and session-linked operational work have cleared. A smaller keyed device-to-purchaser mapping remains so non-expiring tokens can be restored after session expiry; it is removed when you use Delete My Data.
- Idempotency records: completed generation, edit, and upscale replay records can retain a provider request identifier and the earlier response's media URL as text for no more than 180 days. The media itself still expires no later than seven days from creation, so a retained URL can be dead and does not extend file availability. Delete My Data removes account-linked idempotency rows immediately.
- Integrity challenges: deleted after expiry plus no more than one additional day. Apple App Attest key material is removed by the next daily cleanup, no later than one additional day after its corresponding session becomes inactive.
- Trial state: deleted with session data except a successful-redemption tombstone containing keyed device, purchaser, network-prefix, and App Attest-key digests where available. It expires no later than 180 days after the original redemption; deletion never restarts that clock.
- Deletion fence: keyed session/device/purchaser digests are retained for up to 395 days to prevent an in-flight request from recreating data after deletion. They cannot be used to recover the original identifiers.
- Billing records: completed transaction and webhook records are pseudonymized and retained for no more than 395 days for reconciliation, fraud, accounting, chargeback, and consumer-law purposes. While RevenueCat deletion is pending, its pseudonymous purchaser reference can remain only in fenced billing/deletion-queue rows until bounded retry succeeds; those rows cannot initiate new purchases.
- Telegram alerts: local delivery records are retained for no more than 180 days. Deletion queues a best-effort removal of an already delivered bot message, but Telegram age or permission rules may prevent removal. If an auto-delete timer is enabled in the private operations chat, that setting supplies the remote retention bound; otherwise an undeletable message remains subject to Telegram’s own retention. Messages contain only the limited pseudonymous fields listed above.
Sharing
We do not sell personal data and do not use portraits for advertising. We share data only with the providers above as needed to run the Service, with app stores/payment processors for purchases, or with authorities when legally required.
We do not use your content to train our own models. fal.ai and the current underlying model providers, Google and Topaz Labs, maintain their own privacy terms; review those policies for their processing commitments.
Security
We use HTTPS in transit, restricted service access, pseudonymous identifiers, one-time integrity challenges, and least-privilege controls. No network or storage method is completely secure, so we cannot promise absolute security.
Your Choices and Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to withdraw consent without affecting earlier lawful processing.
- Clear Local Data removes locally stored generated images, recent faces, custom styles, and local tester authentication from the device.
- Delete My Data sends an authenticated server deletion request that immediately removes the current session, the minimal device-to-purchaser mapping, account-linked lifecycle/usage and idempotency rows, trial attempts, invites/contributions, active Apple App Attest key, local Telegram delivery rows, and local app data, and queues bounded deletion with RevenueCat.
- A guest-draft contributor can use Delete my portrait in the same browser. A guest host can use Delete this group draft there. After a draft is claimed by the app, Delete My Data also removes its account-linked draft and contribution references.
- A Vibe Vote creator can close the vote early. Delete My Data removes that creator's polls and their vote rows. Public voter rows are also removed automatically when the poll closes or expires.
- A Private Group Review creator can revoke the review set early. Delete My Data removes that creator's review sets and responses. A reviewer can ask the creator to revoke the set or contact privacy support with the review link while it remains active.
- Deletion does not remove the limited HMAC-only deletion fence, successful-redemption tombstone, pseudonymized transaction records, or already-delivered Telegram message described above. Remaining fal.ai media keeps its original maximum seven-day expiry from creation.
- Because TogetherLens does not require a conventional user account, provide the in-app session information requested by support so we can locate the correct pseudonymous record.
To exercise rights or ask for help, contact [email protected]. We may need to verify that the request belongs to the relevant app session. You may also complain to your local data-protection authority.
Children
TogetherLens is not directed to children under 13, or a higher minimum age required locally. A parent or legal guardian must provide required permission before a child’s portrait is uploaded. We do not knowingly allow children below the applicable age to operate the Service independently.
Changes
We may update this notice when our practices or legal obligations change. We will publish the new date and provide additional notice for material changes where required.
Contact
- Email: [email protected]
- Subject: “Privacy Request – TogetherLens”