Privacy Policy: ColorPhoto
Last Updated: October 10, 2026
Your privacy is a core priority. This policy outlines what data ColorPhoto collects, how it is processed, and your rights under applicable law. It covers ColorPhoto on iPhone and on Android; where the two differ, it says so.
1. Data Collection
- No Sign-In: ColorPhoto doesn't ask you to sign in or create an account. The app creates an anonymous account for your phone, identified only by a random identifier, to keep track of your credits and jobs. We don't receive your name or email address.
- Photos: Images are uploaded for processing and are automatically purged from our temporary processing cache once the AI cycle is complete.
- AI Inference: We utilize the OpenAI API for image processing. Your photos are used for inference only; they are not used by OpenAI or ColorPhoto to train models. OpenAI may retain API inputs and outputs for up to 30 days solely to provide the service and monitor for abuse, after which they are deleted.
- Metadata: We maintain a record of each job (status, timestamps, and processing details such as the AI model used and output size) and a credit ledger to ensure account accuracy and handle automatic refunds.
- App Platform: We store whether you use iOS or Android with your account to support the app and understand usage. This information is deleted when you delete your data.
- Issue Reports: If you choose to include photos when submitting an in-app issue report, the selected original and restored images are uploaded to our servers and retained so our team can reproduce and debug the problem. Attaching photos is optional and only happens when you explicitly select them in the report flow.
- Your Email Address: If you add your email address to a message or issue report, we use it only to reply to you. It is kept with that report.
2. Data Retention
| Data Type | Retention Period |
|---|---|
| Original Photos | Purged promptly after AI inference. |
| Processed Results | Deleted upon app confirmation (Max 24-hour buffer). |
| Photos Attached to Issue Reports | Retained until the report is resolved, then deleted (max 90 days). Email addresses you send us with a report are deleted with it. |
| Job Metadata | Retained until you delete your data. |
| Credit & Purchase Records | Retained after you delete your data, for accounting, with no link to your identity. |
| Account Data | Retained until you delete your data. |
| Device Identifier Hash (Android) | Retained after you delete your data, with no link to your account, so free credits are given once per device. |
3. Data Sharing and Third Parties
We do not sell your data. We share data only with essential service providers:
- Cloud Infrastructure: For hosting and database services.
- AI Inference Providers: Specifically the OpenAI API for image processing.
- Apple and Google Play: For payment processing (Apple on iPhone, Google Play on Android). We receive the purchase details needed to credit your account, never your payment card.
- Crash Reporting: Firebase Crashlytics (Google) receives crash diagnostics along with your account's internal identifier so we can fix bugs.
- Usage Analytics: Google Analytics for Firebase records how the app is used (such as sessions, screens viewed, and in-app purchases) along with a random identifier for your app installation and an approximate location derived from your IP address. It is not linked to your account and is not used for advertising.
- Apple Refund Decisioning (iPhone): When Apple evaluates a refund request you submit for a ColorPhoto credit purchase, Apple's servers may ask us for information about that specific transaction so they can decide whether to grant the refund. In response, we share aggregated, non-identifying signals tied only to the purchase in question — how many of the purchased credits you have used, whether we successfully delivered them, and our recommendation on the refund. We never share your photos, account identity, or contact information for this purpose. By purchasing credits, you consent to this limited disclosure to Apple.
4. Security
We implement industry-standard security protocols to protect your data:
- Encryption: All data in transit uses HTTPS/TLS.
- Integrity: We use Firebase App Check with Apple DeviceCheck on iPhone and Google Play Integrity on Android to verify that requests to our APIs come from the genuine ColorPhoto app.
- Free Credits (Android): To give free credits only once per device, we keep a one-way hash of the identifier Android assigns ColorPhoto on your device. It isn't linked to your account and is kept after you delete your data, so deleting your data doesn't renew the free credits.
5. Your Rights
- Data Deletion: You may delete your data at any time with Delete My Data (Menu → Additional Resources). This deletes your anonymous account, credits, job history, the photos in the app on your phone, and any issue reports you submitted, including their attached photos and email address. Records of credit purchases, refunds, and processing costs are kept for accounting, with no link to your identity. On Android, the device identifier hash used for free credits is also kept, with no link to your account.
- Right to Review: You have the right to review the data held about you in our database.
- Access: You may request a copy of your data via in-app support or by emailing colorphoto.support@gmail.com.
- Complaints: If you live in the EU or the UK, you may also complain to the data protection authority where you live.
6. International Data Transfers
Data is processed on secure servers located in the United States. Where your data is transferred across borders, we rely on appropriate safeguards to protect it.
7. Governing Law
This policy is governed by the laws of the State of Israel. Any disputes regarding data privacy shall be handled in the competent courts of the Tel Aviv District. If you live in the EU or the UK, this does not take away the protection of the data protection laws where you live, or your right to bring a claim there.
8. Contact
Questions about this policy or your data: colorphoto.support@gmail.com