Privacy Policy — MomoCap
Last updated: 2026-08-31
MomoCap ("we", "the app") is built by an independent developer. The app's core feature is AI photo styling: photos you submit are uploaded to the cloud and sent to an AI model for generation. This policy describes honestly where each type of data goes.
TL;DR
| What | Where |
|---|---|
| Account info (UID, nickname, email, avatar) | Our backend account system, for sign-in and identity |
| Original & cropped photos | Uploaded to cloud object storage, for AI generation |
| AI generation requests | Cropped photos sent to Volcengine's Doubao-Seedream AI image model for styling |
| Generated images | Cloud object storage, kept under your account |
| Purchase records | Apple / Google billing; backend records orders to deliver credits |
| Usage statistics & crash reports | Firebase Analytics / Crashlytics (linked to your UID) |
| Image & login caches | On-device only, clearable in the app |
What we collect
Account information. Using the app requires signing in — Google and Apple sign-in are currently supported. After you sign in, we receive: a system-generated user ID (UID), your nickname/name, email, and avatar (whatever the sign-in provider actually returns), plus which provider your account is bound to. This is stored in our backend; a sign-in session is cached on your device so you don't have to log in every time.
Photos you submit (including face content). Photos you take or pick (and crop) are uploaded to a private directory under your account in cloud object storage (access requires your account's access token). To generate your styled image, our backend then sends only the cropped image file to Volcengine (Beijing Volcano Engine Technology Co., Ltd.) — the third-party provider of the Doubao-Seedream AI image model we use for photo styling. No account information (your name, email, or user ID) is sent along with the photo, and the photo is used solely to complete the generation task you request. Because MomoCap photos are typically portraits, photos may contain faces; face content is transmitted only to generate your requested image, and is never used for facial recognition, identification, or profiling. Before your first submission, the app presents an in-app notice that explains what data is sent and to whom, and requires your explicit consent before any photo is shared — you can decline and no photo will be sent. The generated result is transferred back and stored under your account. Volcengine processes data under its own privacy policy and service terms.
Usage statistics. The app uses Google Firebase Analytics to record product-interaction events (e.g. app open, sign-in, task submission, purchase). Events are linked to your UID and are used to understand how features are used and to improve the product. Statistics never include photo content or the notes you type.
Crash reports. The app uses Firebase Crashlytics to automatically report crash stacks and device information (OS version, device model, app version, build environment) when the app crashes, so we can find and fix problems.
Purchase information. Quota pack purchases are processed by the Apple App Store (iOS) or Google Play (Android); your payment details only ever pass through the store — we never see them. Our backend records the order number, the quota pack tier, and the order status, to deliver credits and show you your purchase history in the app.
What we do NOT collect
- No contacts, messages, or call logs — we don't request those permissions at all;
- No live location — we don't use location services;
- No advertising identifiers — no ad SDKs, no cross-app tracking, no user profiling;
- Analytics describe actions, not content — your photos and text are never uploaded as analytics data.
Permissions we request
| Permission | What it's for |
|---|---|
| Camera (optional) | Take a new photo for AI generation |
| Photo Library (read) | Read the photo you pick for AI generation |
| Photo Library (add) | Save generated images back to Photos |
Declining the camera permission is fine — you can still pick from your library. You can change these any time in system settings.
Data storage and retention
- Cloud: Photos you submit and images you generate are kept in a directory under your account in cloud object storage (hosted on Tencent Cloud); purchase and usage records are kept in our backend database. Photos (which may contain face content) have no fixed retention period — they are kept only until you delete them from within the app or delete your account, and are never used for any purpose other than the generation tasks you request. You can delete generated content from within the app, and the corresponding cloud data is deleted with it.
- AI generation service: The cropped photo is transmitted to Volcengine solely to produce your requested image. We do not send any account information with the photo, and we do not use the AI service for any other purpose. How Volcengine handles and retains inputs is governed by its privacy policy and service terms.
- On-device: Your device caches your sign-in session and loaded images — clear them any time with Settings → Clear Cache; uninstalling the app removes all local data.
- Account deletion: You can delete your account and all associated data (account info, photos, generated images, purchase and usage records) any time from within the app: Profile → Account Settings → Delete Account. After deletion the account can no longer sign in, and any unused generation credits expire with it.
Third-party services
Your photos and data are processed by the following third parties, each under their own privacy policy:
- Cloud hosting & storage providers (Tencent CloudBase) — object storage, database, and backend compute, storing photos and generated images under your account;
- Volcengine (Beijing Volcano Engine Technology Co., Ltd., Doubao-Seedream AI image models) — receives the cropped photo solely to generate your styled image, under its privacy policy and service terms. Volcengine provides data protection under its own privacy policy that is equivalent to the protections described in this policy;
- Google Firebase — usage statistics (Analytics) and crash reports (Crashlytics);
- Google / Apple account services — sign-in authentication;
- Apple App Store / Google Play — in-app purchase billing.
Children
MomoCap is rated 4+. We do not knowingly collect personal information from children; if you believe a child has submitted data to us, contact us and we will delete it.
Changes
If this policy materially changes — for example, if a new data flow is added — the date at the top will update and the change will be called out in a release note.
Contact
Questions or concerns: momocap1@icloud.com