Shade Diary

Privacy Policy

Effective date: TBD — this policy is a working draft for the external TestFlight learning build and takes effect once the founder approves it for release to testers. Last updated: 2026-07-28 Applies to: the external TestFlight essentials learning build of Shade Diary (iOS). A future version with an account, a paywall, or a different feature set gets its own review of this document before it ships. Privacy contact: support@shadediary.com

This policy describes what Shade Diary does with your data today. Where a decision has not been made yet, that is stated plainly below instead of guessed at, and the app does not ship to external testers until every TBD in this document is resolved.

What happens to your photo

The photo of your hair is the most sensitive thing this app touches, so this section covers it in full before anything else.

You choose or take one photo. When you pick a colour direction and start a preview, the app sends that photo over an encrypted connection to a server we run (the "broker"). The broker strips the photo's metadata (things like the location and device information a camera can attach to a file) and forwards the photo to a third-party image-rendering provider, which generates the colour preview and returns it to the broker, which returns it to your device.

The rendering provider is Google. Your photo is sent to the Google Gemini API, which generates the preview and returns it. We use Google's paid tier, and that distinction matters: on the paid tier Google's terms say it does not use your photo, or the preview it generates, to train or improve its models. On Google's free tier it would, which is why this app does not use the free tier.

The part you should know about, because it is longer than our own deletion window:

misuse of its service. That is Google's policy, not ours, and we cannot switch it off or shorten it. It is separate from — and outlives — the 24-hour deletion on our own server described below.

Google's usage rules. We are not told when this happens and cannot audit it.

Google's system accepts the request, but it returns no confirmation we could show you as proof, and Google does not document whether that deletion also reaches the 55-day misuse-check copy.

for this API, so your photo may be processed outside the country you are in.

Google's own terms for this service are at ai.google.dev/gemini-api/terms and its privacy policy is at policies.google.com/privacy.

If the 55-day window is not acceptable to you, do not send a photo. Everything else in the app works without one.

What is true regardless of the provider:

shared with anyone for advertising.

and no later than 24 hours after you sent it, whichever comes first.

hours after it was created, whichever comes first.

name, or image-derived value is ever included in an analytics event.

excluded from iCloud backup for this build. We do not have a copy of it once the server-side deletion above has happened.

photo that might still exist there. See Retention And Deletion below.

No account required

Shade Diary does not ask for your name, email address, phone number, or a password, and there is no account to create or log into. The app identifies your installation with a random ID it generates on your device. That ID is not your Apple ID, not an advertising identifier, and not tied to your identity in any way we can see. Reinstalling the app creates a new, unconnected ID.

Data Inventory

WhatWhere it livesSent anywhere?Why
------------
Your photo (the one you choose for a preview)Your device, then briefly our server and the rendering providerYes, once per preview you requestTo generate the colour preview
The colour direction you pickYour device, then our serverYes, with the photoTo generate the right preview
Installation IDYour device (random, not the Keychain, not an ad ID)A hashed version, only when you submit a preview requestRate limiting and abuse prevention on our server, not identification
Saved previews (original and result images you chose to keep)Your device only, encryptedNoYou control what you keep
Check-back state (went for it, chose another direction, still deciding)Your device onlyNo — deliberately excluded from analyticsThis is yours; we do not need to know it
Reminder date and timeYour device only, as a local notificationNo, never the exact date. If analytics is on, a coarse bucket showing roughly how far off the reminder was set may be sentUnderstand whether reminders help without knowing your schedule
App-usage events (for example, that a preview finished, or that you found a comparison helpful)Our analytics provider, PostHog, if analytics is turned on for your buildAnonymous, no account attachedUnderstand whether the app works and helps
Device-integrity check (Apple's App Attest)Our server, as a hashed key referenceYes, to confirm requests come from a genuine, unmodified copy of the appStops abuse of the rendering provider

Analytics is off by default for this build and only turns on for a given build after we confirm the event list matches what this table says. When it is on, it never includes photos, signed image links, free text, precise dates, or your IP address. The full event and property list lives in ANALYTICS.md, which this policy is required to match.

Not in this build: a free-text note on the check-back step, and a screen that resurfaces your own past notes for a colour direction you have tried before, are both designed and documented (see ONBOARDING.md) for a future full release. Neither exists in the external TestFlight learning build this policy covers. This policy is updated before either ships.

Retention And Deletion

DataKept for
------
Photo sent for a preview, on our serverUntil the provider finishes with it, and no later than 24 hours
Generated preview, on our serverUntil your device receives it, and no later than 24 hours
Photo and preview, on Google's serversUp to 55 days, for Google's misuse checks. Google's policy, outside our control, and longer than every other row here
Job record (an ID, status, and a hashed installation ID; no photo)7 days after the job ends, then deleted
Rate-limit record (a hashed device or network bucket)No more than 24 hours
Device-integrity key reference30 days after its last use
A preview you did not save, on your deviceAutomatically removed after 24 hours
A preview you saved, on your deviceUntil you delete it or delete all local data
Analytics events, if analytics is onThe shortest period that still lets us read the first learning results, reviewed before any wider release

Deletion route

You can delete your data in two ways, both inside the app:

server to delete any copy of it that has not already expired.

your device, cancels any scheduled reminders, and gives your installation a brand-new random ID. Anything already deleted from our server under the schedule above stays deleted; anything not yet expired is asked to delete on the same request.

Because there is no account, there is nothing on our side tied to you to delete beyond what the tables above already describe. If analytics is on for your build and you want your anonymous analytics history cleared, contact us at the address at the top of this page and we will remove it.

Your choices

same way either way.

name. If you can give us your installation ID (visible in Settings) or a job ID from a specific preview, we can tell you what our server still holds for it and delete it on request.

delete, or object to how your data is used, that right applies to Shade Diary too. Write to the contact address above; because the app collects so little identifiable data, most requests resolve by deleting local data on your device and asking us to confirm nothing remains on the server.

Third parties

preview. On the paid tier we use, Google's terms say it does not train its models on your photo or the preview. Google keeps both for up to 55 days for misuse checks, may have an employee review a flagged image, and processes on global infrastructure without committing to a country. Google does not provide a deletion receipt we could show you. See "What happens to your photo" above, and Google's own terms at ai.google.dev/gemini-api/terms.

hosted in the United States. PostHog does not receive your photo, your name, or your email.

This learning build has no subscription, no purchase, and no RevenueCat call in its code, so RevenueCat receives nothing from your use of this build.

the download, update, and crash-reporting infrastructure, and its own privacy terms apply to that part of the relationship. Apple's App Attest, used to confirm requests come from a genuine copy of the app, is part of this.

Children

Shade Diary is not directed at children under 13, and we do not knowingly collect data from anyone under 13. If you believe a child has used the app and you would like their local or server-side data removed, contact us at the address above and we will delete it.

App Store Disclosure Mapping

This section maps Apple's App Privacy categories to what this build does, so filling out the App Store Connect questionnaire is a transcription of this table rather than a fresh decision.

Apple categoryCollected?Linked to you?Used to track you?Notes
---------------
Contact InfoNoNo account, no email, no phone number is ever requested
Health & FitnessNoThe app makes no health, fitness, or medical claim and asks nothing about your health
Financial InfoNoNo payment method in this build
LocationNoNot requested
Sensitive InfoNoThe app does not infer or record race, ethnicity, or any other sensitive attribute; see ANALYTICS.md's banned-property list
ContactsNoNot requested
User Content — Photos or VideosYesNoNoThe photo you choose, sent only to generate your preview; not linked to a name or account, not used to track you across apps or sites
User Content — Other User ContentNoThis build has no free-text field anywhere; the check-back note described in "Not in this build" above ships in a future release
Identifiers — Device IDYesNoNoThe random installation ID, sent hashed, used only for rate limits, not tied to an account
Usage Data — Product InteractionDepends on buildNoNoAnonymous app-usage events, only once analytics is turned on for a given build; no person profile is created
PurchasesNoNo purchase exists in this build
DiagnosticsNoThis build has no crash-reporting SDK. We chose not to add one for this milestone (SECURITY.md's Accepted Risks); Apple's own TestFlight crash reports apply at the platform level, outside what this app collects

Changes to this policy

If what the app collects changes, this document changes first, and the effective date at the top updates. We will not make a material change to how your photo is handled without updating this page before the change ships.