Privacy Policy
Effective date: TBD — this policy is a working draft for the external TestFlight learning build and takes effect once the founder approves it for release to testers. Last updated: 2026-07-28 Applies to: the external TestFlight essentials learning build of Shade Diary (iOS). A future version with an account, a paywall, or a different feature set gets its own review of this document before it ships. Privacy contact: support@shadediary.com
This policy describes what Shade Diary does with your data today. Where a decision has not been made yet, that is stated plainly below instead of guessed at, and the app does not ship to external testers until every TBD in this document is resolved.
What happens to your photo
The photo of your hair is the most sensitive thing this app touches, so this section covers it in full before anything else.
You choose or take one photo. When you pick a colour direction and start a preview, the app sends that photo over an encrypted connection to a server we run (the "broker"). The broker strips the photo's metadata (things like the location and device information a camera can attach to a file) and forwards the photo to a third-party image-rendering provider, which generates the colour preview and returns it to the broker, which returns it to your device.
The rendering provider is Google. Your photo is sent to the Google Gemini API, which generates the preview and returns it. We use Google's paid tier, and that distinction matters: on the paid tier Google's terms say it does not use your photo, or the preview it generates, to train or improve its models. On Google's free tier it would, which is why this app does not use the free tier.
The part you should know about, because it is longer than our own deletion window:
- Google keeps a copy of your photo and the generated preview for up to 55 days to check for
misuse of its service. That is Google's policy, not ours, and we cannot switch it off or shorten it. It is separate from — and outlives — the 24-hour deletion on our own server described below.
- A Google employee may view a photo if their automated systems flag it as possibly violating
Google's usage rules. We are not told when this happens and cannot audit it.
- Google does not give us a deletion receipt. We can ask Google to delete a specific photo and
Google's system accepts the request, but it returns no confirmation we could show you as proof, and Google does not document whether that deletion also reaches the 55-day misuse-check copy.
- Google processes photos on its global infrastructure. It does not commit to a specific country
for this API, so your photo may be processed outside the country you are in.
- You own the preview. Google's terms do not claim ownership of the image it generates for you.
Google's own terms for this service are at ai.google.dev/gemini-api/terms and its privacy policy is at policies.google.com/privacy.
If the 55-day window is not acceptable to you, do not send a photo. Everything else in the app works without one.
What is true regardless of the provider:
- Your photo is sent only to generate the one preview you asked for. It is not sold, and it is not
shared with anyone for advertising.
- The copy of your photo on our server is deleted as soon as the provider has finished handling it,
and no later than 24 hours after you sent it, whichever comes first.
- The generated preview on our server is deleted after your device receives it, and no later than 24
hours after it was created, whichever comes first.
- Your photo and the generated preview never reach our analytics tool. No image, thumbnail, file
name, or image-derived value is ever included in an analytics event.
- If you save a preview, that saved copy lives only on your device, encrypted at rest, and is
excluded from iCloud backup for this build. We do not have a copy of it once the server-side deletion above has happened.
- Deleting a preview, or using Delete all local data, asks our server to delete any copy of your
photo that might still exist there. See Retention And Deletion below.
No account required
Shade Diary does not ask for your name, email address, phone number, or a password, and there is no account to create or log into. The app identifies your installation with a random ID it generates on your device. That ID is not your Apple ID, not an advertising identifier, and not tied to your identity in any way we can see. Reinstalling the app creates a new, unconnected ID.
Data Inventory
| What | Where it lives | Sent anywhere? | Why |
|---|---|---|---|
| --- | --- | --- | --- |
| Your photo (the one you choose for a preview) | Your device, then briefly our server and the rendering provider | Yes, once per preview you request | To generate the colour preview |
| The colour direction you pick | Your device, then our server | Yes, with the photo | To generate the right preview |
| Installation ID | Your device (random, not the Keychain, not an ad ID) | A hashed version, only when you submit a preview request | Rate limiting and abuse prevention on our server, not identification |
| Saved previews (original and result images you chose to keep) | Your device only, encrypted | No | You control what you keep |
| Check-back state (went for it, chose another direction, still deciding) | Your device only | No — deliberately excluded from analytics | This is yours; we do not need to know it |
| Reminder date and time | Your device only, as a local notification | No, never the exact date. If analytics is on, a coarse bucket showing roughly how far off the reminder was set may be sent | Understand whether reminders help without knowing your schedule |
| App-usage events (for example, that a preview finished, or that you found a comparison helpful) | Our analytics provider, PostHog, if analytics is turned on for your build | Anonymous, no account attached | Understand whether the app works and helps |
| Device-integrity check (Apple's App Attest) | Our server, as a hashed key reference | Yes, to confirm requests come from a genuine, unmodified copy of the app | Stops abuse of the rendering provider |
Analytics is off by default for this build and only turns on for a given build after we confirm the event list matches what this table says. When it is on, it never includes photos, signed image links, free text, precise dates, or your IP address. The full event and property list lives in ANALYTICS.md, which this policy is required to match.
Not in this build: a free-text note on the check-back step, and a screen that resurfaces your own past notes for a colour direction you have tried before, are both designed and documented (see ONBOARDING.md) for a future full release. Neither exists in the external TestFlight learning build this policy covers. This policy is updated before either ships.
Retention And Deletion
| Data | Kept for |
|---|---|
| --- | --- |
| Photo sent for a preview, on our server | Until the provider finishes with it, and no later than 24 hours |
| Generated preview, on our server | Until your device receives it, and no later than 24 hours |
| Photo and preview, on Google's servers | Up to 55 days, for Google's misuse checks. Google's policy, outside our control, and longer than every other row here |
| Job record (an ID, status, and a hashed installation ID; no photo) | 7 days after the job ends, then deleted |
| Rate-limit record (a hashed device or network bucket) | No more than 24 hours |
| Device-integrity key reference | 30 days after its last use |
| A preview you did not save, on your device | Automatically removed after 24 hours |
| A preview you saved, on your device | Until you delete it or delete all local data |
| Analytics events, if analytics is on | The shortest period that still lets us read the first learning results, reviewed before any wider release |
Deletion route
You can delete your data in two ways, both inside the app:
- Delete this preview removes that preview's photos and record from your device, and asks our
server to delete any copy of it that has not already expired.
- Delete all local data, in Settings, removes every saved preview, check-back, and reminder from
your device, cancels any scheduled reminders, and gives your installation a brand-new random ID. Anything already deleted from our server under the schedule above stays deleted; anything not yet expired is asked to delete on the same request.
Because there is no account, there is nothing on our side tied to you to delete beyond what the tables above already describe. If analytics is on for your build and you want your anonymous analytics history cleared, contact us at the address at the top of this page and we will remove it.
Your choices
- Turn off analytics. A setting in the app opts you out of analytics. The app keeps working the
same way either way.
- Ask us what we hold. Because installations are anonymous, we cannot look up "your" data by
name. If you can give us your installation ID (visible in Settings) or a job ID from a specific preview, we can tell you what our server still holds for it and delete it on request.
- Rights where local law grants them. If you are in a place with a legal right to access, correct,
delete, or object to how your data is used, that right applies to Shade Diary too. Write to the contact address above; because the app collects so little identifiable data, most requests resolve by deleting local data on your device and asking us to confirm nothing remains on the server.
Third parties
- Google (Gemini API). Our rendering provider. It receives your photo and returns the generated
preview. On the paid tier we use, Google's terms say it does not train its models on your photo or the preview. Google keeps both for up to 55 days for misuse checks, may have an employee review a flagged image, and processes on global infrastructure without committing to a country. Google does not provide a deletion receipt we could show you. See "What happens to your photo" above, and Google's own terms at ai.google.dev/gemini-api/terms.
- PostHog. Our analytics provider, used only for the anonymous app-usage events described above,
hosted in the United States. PostHog does not receive your photo, your name, or your email.
- RevenueCat. We keep an existing RevenueCat project for a future paid version of the app.
This learning build has no subscription, no purchase, and no RevenueCat call in its code, so RevenueCat receives nothing from your use of this build.
- Apple. Distributing the app through TestFlight and, later, the App Store means Apple provides
the download, update, and crash-reporting infrastructure, and its own privacy terms apply to that part of the relationship. Apple's App Attest, used to confirm requests come from a genuine copy of the app, is part of this.
Children
Shade Diary is not directed at children under 13, and we do not knowingly collect data from anyone under 13. If you believe a child has used the app and you would like their local or server-side data removed, contact us at the address above and we will delete it.
App Store Disclosure Mapping
This section maps Apple's App Privacy categories to what this build does, so filling out the App Store Connect questionnaire is a transcription of this table rather than a fresh decision.
| Apple category | Collected? | Linked to you? | Used to track you? | Notes |
|---|---|---|---|---|
| --- | --- | --- | --- | --- |
| Contact Info | No | — | — | No account, no email, no phone number is ever requested |
| Health & Fitness | No | — | — | The app makes no health, fitness, or medical claim and asks nothing about your health |
| Financial Info | No | — | — | No payment method in this build |
| Location | No | — | — | Not requested |
| Sensitive Info | No | — | — | The app does not infer or record race, ethnicity, or any other sensitive attribute; see ANALYTICS.md's banned-property list |
| Contacts | No | — | — | Not requested |
| User Content — Photos or Videos | Yes | No | No | The photo you choose, sent only to generate your preview; not linked to a name or account, not used to track you across apps or sites |
| User Content — Other User Content | No | — | — | This build has no free-text field anywhere; the check-back note described in "Not in this build" above ships in a future release |
| Identifiers — Device ID | Yes | No | No | The random installation ID, sent hashed, used only for rate limits, not tied to an account |
| Usage Data — Product Interaction | Depends on build | No | No | Anonymous app-usage events, only once analytics is turned on for a given build; no person profile is created |
| Purchases | No | — | — | No purchase exists in this build |
| Diagnostics | No | — | — | This build has no crash-reporting SDK. We chose not to add one for this milestone (SECURITY.md's Accepted Risks); Apple's own TestFlight crash reports apply at the platform level, outside what this app collects |
Changes to this policy
If what the app collects changes, this document changes first, and the effective date at the top updates. We will not make a material change to how your photo is handled without updating this page before the change ships.