# Privacy Policy — Selfie Camera
Policy version: PP-2026-09-12 (current)
Scope: Effective from Selfie Camera 1.0.2 and continuing for later versions whose data practices are not materially changed, until this Policy is replaced
Effective date: September 12, 2026
## Version history
- **PP-2026-09-12 (current):** Effective from Selfie Camera 1.0.2 and covering cloud AI, Firebase, advertising, subscriptions, and one-time AI uses. This Policy continues to apply to later releases while their data practices remain materially unchanged.
- **Earlier key data practices:** Selfie Camera 1.0.1 was an offline release. It did not request internet access or include advertising, analytics, billing, subscriptions, cloud storage, or remote AI. This summary explains the historical difference and does not extend the scope of this Policy.
Selfie Camera is provided by Beauty Dream Studio ("we," "us," or "our"). This Policy explains how Selfie Camera currently processes information. Please read it before using the app. When a feature requires a photo to be uploaded, the app also presents a prominent notice and requires an explicit action before submission.
## 1. Scope
This Policy applies to the Selfie Camera Android app from version 1.0.2 onward while it uses the data practices described here, and to the cloud services directly supporting it. A change to the app version number does not by itself create a new Privacy Policy version. We update the Policy version when there is a material change to data types, purposes, providers, retention, or user rights. Google Play, advertising providers, payment providers, and AI processing providers may also process information under their own privacy policies.
## 2. Information we process
### 2.1 Photos, masks, and creations
- Local editing, collages, cropping, AI Filter style application and previews, and camera capture are primarily performed on your device. The app uses the Android system photo picker and can access only photos you select. Camera permission is requested only when you use the camera feature.
- When you explicitly submit Photo Enhance, Background Removal, Object Removal, Makeup Looks, or another feature clearly identified as cloud processing, the app sends the selected photo, any required mask, processing parameters, and request identifiers to our secure gateway and the processing providers required to complete that feature.
- A photo may contain a face, but we do not use photos to identify a person, create face templates, or verify a real-world identity. On-device face detection is used only to provide the editing effect you request.
- Submit only images you are authorized to process. If an image depicts another person, you are responsible for obtaining appropriate permission and for not submitting prohibited content.
### 2.2 App, security, and device information
To create an anonymous session, protect cloud APIs, prevent abuse, and diagnose failures, we may process a Firebase anonymous user ID, Firebase Installation ID, app package and version, device model and operating system, language and approximate country/region, IP address, network state, request time, App Check tokens, and app/device integrity attestations returned by Play Integrity. You do not need to provide a name, phone number, or password to use the basic features.
### 2.3 Usage, analytics, and remote configuration
We use Firebase Analytics and Firebase Remote Config to understand whether features work, measure app and feature usage, control safety switches, and improve the experience. Information may include a random or pseudonymous identifier; an analytics identifier derived by applying SHA-256 to the app package and Android ID; install-source classification; session, screen, and feature events; ad request, impression, and revenue events; purchase-result status; error category; app version; language; and approximate country/region. Analytics events must not include photo content, payment-card details, authentication tokens, or provider secrets.
### 2.4 Advertising and consent choices
The app uses Google Mobile Ads (AdMob) to display ads and Google User Messaging Platform (UMP) to manage advertising consent and privacy choices where applicable. Depending on your region, consent choices, and device settings, Google Mobile Ads may process IP address (which can indicate approximate location), advertising ID, App Set ID, device or account-related identifiers, app launches and ad interactions, and diagnostic or performance information for ad delivery, frequency capping, measurement, attribution, and fraud prevention. Personalized ads are requested only when permitted by applicable rules and consent status. If you do not consent, non-personalized ads, limited ads, or technical ad delivery may still occur.
### 2.5 Purchase, subscription, and AI-use information
Payments are processed by Google Play. We do not receive your full payment-card number. To display products, confirm and restore eligible purchases, and manage Pro access and AI uses, we and RevenueCat may process your Firebase anonymous user ID (used as a RevenueCat App User ID); Google Play order and product identifiers; package, price, and currency; purchase tokens; transaction and pending status; subscription status and expiration; entitlements; AI-use balances; and related grant, reservation, deduction, and revocation records. One-time AI uses are consumable digital products. Subscription and one-time purchases have different renewal, validity, and restoration rules, as explained in the Subscription and Purchase Terms.
### 2.6 Local data
Drafts, previews, edit parameters, imported source files, and temporary working files are stored in the app's private storage. Exported creations are saved to the Android public media library and may remain after the app is uninstalled. App settings, language, disclosure acceptance, advertising consent state, and the most recently confirmed entitlement state are stored on the device.
## 3. Purposes and legal bases
We process information only as needed to:
- provide the photo editing, AI processing, saving, and sharing features you request;
- create an anonymous session, verify app integrity, enforce usage limits, and prevent abuse;
- display ads, record consent choices, and comply with advertising rules;
- display products, process and restore purchases, and synchronize Pro access and AI usage;
- diagnose failures, protect the service, measure usage, and improve the app; and
- comply with legal, tax, accounting, platform-policy, and dispute-resolution obligations.
Where applicable law requires a legal basis, we rely on performance of a contract, your consent, our legitimate interests, or compliance with legal obligations. You may decline optional cloud AI processing or personalized advertising. Doing so does not prevent use of basic local features that do not require that processing.
## 4. Service providers and sharing
We disclose information to service providers only as needed to provide features, protect the service, complete purchases, or comply with law:
- Google Firebase / Google Cloud for anonymous authentication, App Check, Play Integrity verification, analytics, remote configuration, and secure gateway infrastructure;
- Google Play Billing for payments, subscriptions, and refunds;
- Google Mobile Ads / UMP for advertising, consent management, measurement, and fraud prevention;
- RevenueCat for products, purchase status, subscription entitlements, hosted paywalls, AI-use balances, and related transactions;
- Tencent Cloud data processing and private COS storage, when enabled for the relevant feature, for photo enhancement, background removal, object removal, and temporary files;
- Perfect Corp, when enabled for the relevant cloud feature, for makeup looks or related visual effects; and
- operations, security, audit, or professional advisers subject to confidentiality and data-protection obligations.
We do not sell personal information for money. The identifiers and advertising data involved in personalized advertising may be considered a "sale" or "sharing" under some regional laws. You can manage those choices through the app's privacy options, where available, and Android or Google advertising settings.
## 5. Retention and deletion
- On-device data remains until you delete it in the app, clear app data, or uninstall the app. Creations exported to the public media library must be deleted by you.
- Cloud AI inputs are retained by our gateway for no more than 24 hours and may be deleted sooner when a task ends or deletion is requested.
- Cloud AI results are retained for download, recovery, and troubleshooting for no more than 7 days. They cannot be downloaded after expiration.
- AI task, idempotency, and security metadata is retained for no more than 8 days. Necessary purchase, AI-use, fraud-prevention, audit, or dispute records that do not contain photo content may be retained for as long as needed to fulfill purchases, restore access, and comply with legal obligations.
- Firebase, Google Ads, Google Play, RevenueCat, Tencent Cloud, and Perfect Corp apply their own retention periods under their service terms, your choices, and applicable law. We use configuration, lifecycle rules, and contractual requirements to limit retention.
You can delete local creations and temporary files. To request deletion of information associated with an anonymous user ID, cloud task, or purchase entitlement, email `contact@yuzhensoftware.com`. We may ask for a non-sensitive identifier visible in the app or proof of purchase so we can locate the record. Do not send full payment-card information, passwords, or authentication tokens. Records required for legal, accounting, fraud-prevention, or dispute purposes may not be deleted immediately.
## 6. Your choices and rights
- If you do not select a photo or tap Generate, the app does not upload a photo for that AI operation.
- You may revoke Camera permission, reset or delete the advertising ID, and modify advertising consent through the app's privacy options where applicable.
- You can manage or cancel a subscription through Google Play. Uninstalling the app does not cancel a subscription. Consumable one-time AI uses have different restoration behavior; review the Subscription and Purchase Terms before clearing app data, uninstalling the app, or changing devices.
- You can clear app data or uninstall the app to remove data from the app's private on-device storage.
- Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; withdraw consent; obtain data portability; and complain to a data-protection authority. Contact us using the address below.
## 7. Security and international processing
The app uses HTTPS for cloud connections. Photos are placed in access-controlled private temporary storage, and server secrets are not embedded in the Android app. We use measures including least-privilege access, short-lived tokens, integrity checks, rate limits, log redaction, and lifecycle deletion. No transmission or storage method can be guaranteed to be completely secure.
Our providers may process information outside your country or region, including regions where Google, RevenueCat, or their service facilities operate and cloud regions needed to complete AI processing. We use contractual, security, and access-control measures required by applicable law for international processing.
## 8. Children
Selfie Camera is not directed to children under 13, or a higher minimum age where required by local law. We do not knowingly collect personal information from children. If you believe a child submitted information without appropriate authorization, contact us and we will take appropriate deletion steps.
## 9. Changes to this Policy
We update the Policy version and effective date when features, providers, data practices, or legal requirements change materially. This Policy may continue to apply to a later app release that only fixes defects, improves performance, or otherwise leaves the data practices described here unchanged. We provide an in-app or other appropriate notice for material changes.
## 10. Contact us
For privacy, access, or deletion requests, contact:
`contact@yuzhensoftware.com`