This Privacy Policy describes what data the **Restora** photo-restoration mobile app collects, how it is used, and your choices. It applies to the Restora iOS and Android apps. If you do not agree with it, please don't use the app.
## 1. Face Data Collection, Use & Sharing
**This section is written specifically to address Apple App Store Review Guideline 2.1 questions about face data.** Restora is a photo-restoration app; the photos users upload may contain faces. Everything the app does with that face data is disclosed below.
### 1.1 What face data the app collects
The only "face data" the app ever handles is the ordinary photo pixels of the image the user chose to upload from their gallery or captured with the camera — nothing more. When that image happens to include a face, the face is part of those photo pixels.
The app does **not** compute, derive, extract, or store any face-specific data from the photo. Specifically, the app does **not** collect:
- Facial landmarks or geometric measurements
- Biometric templates or "face prints"
- Face-recognition embeddings or descriptors
- Identity signatures or face-based identifiers
- Age, gender, ethnicity, or emotion inference from the face
### 1.2 All planned uses of the collected face data
The photo (which may contain a face) is used for exactly one purpose: **generating a restored version of that photo using the AI tool the user selected** — Enhance, Colorize, De-scratch, Enlighten, Recreate, or Animate.
The face inside the photo is **never** used to:
- Identify or authenticate the user
- Personalise the experience
- Target advertising
- Train third-party AI models
- Build any profile
- Perform facial recognition or biometric identification
### 1.3 Who face data is shared with, and where it is stored
Because face data in Restora is just the photo pixels containing a face, it is shared with the same recipients as the photo itself and no others. All three recipients are under contract as data processors and none of them process the face for biometric or identification purposes.
- **Restora AI** — our own backend AI service. Receives the photo + selected tool, calls fal.ai, returns the restored image. **Stored on Restora AI infrastructure in the United States for the 30-day processing window only.**
- **fal.ai** — sub-processor under contract with Restora AI. Runs the underlying AI image-to-image model on the photo. **Stored on fal.ai infrastructure in the United States for the 30-day processing window only.**
- **Backend** — our own backend platform. Stores the original photo + result under the user's account so they appear in the History tab. **Stored on Backend managed infrastructure in the United States, encrypted at rest (AES-256), with HTTPS/TLS in transit.** Kept until the user deletes the creation or their account.
Restora does **not** share face data (or any photo data) with ad networks, analytics vendors, crash reporters, attribution vendors, social-media SDKs, or any other third party.
### 1.4 How long face data is retained
- **On Restora AI:** deleted within **30 days**.
- **On fal.ai (sub-processor):** deleted within **30 days**.
- **On Backend:** retained under the user's account until the user deletes the creation (trash icon on the result detail screen) or deletes the account (Settings → Delete Account, or email `devinfo2026@gmail.com`; deleted within 30 days of the request).
- **Diagnostic logs** (which contain no face data): 30 days.
### 1.5 Consent before face data leaves the device
Before any photo — including a photo that contains a face — leaves the device, the app presents an in-app consent screen that:
- States what is sent: the photo the user selected (which may contain a face).
- States the single purpose: generating a restored version of that photo.
- Names the recipient: Restora AI, and its sub-processor fal.ai.
- States the retention policy: 30-day deletion window on Restora AI and fal.ai.
- Requires the user to tick a checkbox before the upload button is enabled.
If the user does not agree, no photo is uploaded and no API call is made. All other parts of the app (sign-in, viewing past creations on the device, managing subscription) continue to work without sending photos to Restora AI. The user can withdraw consent at any later time by not tapping Restore on future photos, and by deleting past creations from the History tab.
### 1.6 Security of face data in transit and at rest
- All uploads happen over HTTPS / TLS.
- Backend encrypts stored photos at rest with AES-256.
- Restora AI and fal.ai run in US infrastructure with vendor-standard access controls.
- No employee at Restora, Restora AI, or fal.ai routinely accesses individual user photos.
### 1.7 User rights specific to face data
Users can, at any time:
- Delete an individual creation (which deletes the source photo + restored result from Backend) via the trash icon on the result detail screen.
- Delete their entire account (which deletes all photos, results, and associated data) via **Settings → Delete Account** or by emailing `devinfo2026@gmail.com`. Deletion is completed within 30 days.
- Request a copy of all their data, correction of data, or withdrawal of consent by emailing `devinfo2026@gmail.com` (see § 9 Your rights).
---
## 2. Photo Data Collection, Use & Sharing (context around § 1)
This section describes the broader photo-data flow, of which the face-data flow above is a subset. Everything that applies to face data also applies here.
### What photo data we collect
- The photo you select from the device gallery, or capture with the device camera.
- The photo may contain faces, people, or family scenes.
### What we DO NOT do
- We do **not** extract or store biometric templates, facial-recognition embeddings, or "face print" identifiers.
- We do **not** perform facial recognition, identity matching, or biometric authentication.
- We do **not** use photos for advertising, analytics, profiling, behaviour tracking, AI model training, identity verification, or any other purpose besides delivering the restoration you requested.
### How we use photo data
The photo is sent to **Restora AI** (our backend AI service) for the single purpose of generating a restored version using the tool you chose (Enhance / Colorize / De-scratch / Enlighten / Recreate / Animate). Restora AI uses **fal.ai** as a sub-processor to run the underlying AI image-to-image models; fal.ai acts as a data processor on our behalf under contract.
### Who photo data is shared with
- **Restora AI** (our backend service) — receives the photo + chosen tool, calls fal.ai, returns the restored result. Stored on Restora AI cloud servers; deleted within 30 days.
- **fal.ai** (sub-processor under contract with Restora AI) — runs the AI image-to-image model and returns the generated image. Stored on fal.ai cloud servers; deleted within 30 days.
- **Backend** (our backend platform) — stores the photo + result inside your account so they appear in the History tab. Stored on Backend managed infrastructure (encrypted at rest, HTTPS in transit); kept until you delete the creation or delete your account.
We do **not** share photo data with any other third party — no ad networks, no analytics SDKs, no crash reporters, no attribution vendors, no social-media SDKs.
### Where photo data is stored
- On your device — temporarily, until you tap **Restore**.
- On Restora AI — during the 30-day processing window.
- On fal.ai (sub-processor) — during the 30-day processing window.
- On Backend — under your account, until you delete the creation or your account.
All transfers happen over HTTPS / TLS. Backend encrypts data at rest.
### How long photo data is retained
- Uploaded photo on device — until app close or new photo.
- Uploaded photo on Restora AI — deleted within 30 days.
- Uploaded photo on fal.ai — deleted within 30 days.
- Uploaded photo on Backend — until you delete the creation or your account.
- Restored result on Backend — until you delete the creation or your account.
- Diagnostic logs (no photo data) — 30 days.
### Consent before photo data leaves the device
Before any photo leaves your device, the app shows a dedicated in-app consent screen that:
- States what is sent: the photo you selected (which may contain faces / people).
- States the single purpose: generating a restored version of that photo.
- Names the recipient: Restora AI (and its sub-processor fal.ai).
- States the retention policy: deletion within 30 days.
- Requires you to tick a checkbox before the upload button is enabled.
If you do not agree, no photo is uploaded and no API call is made. All other parts of the app (sign-in, viewing past creations on your device, managing your subscription) continue to work without sending photos to Restora AI.
## 3. What we collect
### Information you give us
- **Email + password** (password is hashed, never stored in plaintext) for your account, or your Google / Apple OAuth identifier if you sign in with one of those providers.
- **Photos** you choose to upload from your gallery or camera (see Photo Data section above).
- **The tool** you pick (Enhance / Colorize / De-scratch / Enlighten / Recreate / Animate).
- **Your restored result images.**
- **Purchase receipts** (Apple App Store / Google Play original transaction id, subscription status, credit balance) — needed to unlock Restora Pro and restore purchases across devices.
### Information collected automatically
- Device model, OS version, app version (attached to error reports you choose to send via Settings → Send feedback).
- Anonymous error logs for failed restorations.
### We do not collect
- Your contacts, location, microphone, browsing history.
- Advertising identifier (IDFA / AAID).
- Biometric templates, face prints, or facial-recognition embeddings.
- Analytics events, screen views, button taps, session timing.
- Any social-media data.
## 4. How we use it
- To restore photos using AI (see Face Data section § 1 and Photo Data section § 2 above).
- To show your creation history inside the app.
- To unlock Restora Pro features after purchase and restore purchases across devices.
- To diagnose crashes and improve the app.
- To respond to support requests.
We do **not** use your data for advertising, tracking, profile-building, or training third-party AI models.
## 5. Third-party services
Backend is our own backend platform providing database, authentication, file storage, and account history. It sees your email and hashed password (for email signups) or your OAuth id, your profile, your uploaded photos and restored results, and your purchase metadata.
Restora AI is our AI photo restoration backend. It sees your photo and the chosen tool, for the 30-day processing window only.
fal.ai is a sub-processor used by Restora AI to run the AI image-to-image models. It sees your photo, for the 30-day processing window only, and is bound by contract to act only as a data processor on Restora AI's behalf.
Apple App Store and Google Play handle app distribution and payment processing. They see the payment itself; we never see your credit card number.
No analytics, no ad networks, no crash-reporting SDKs, no attribution trackers.
## 6. Permissions
- **Photos (read)** — when you tap "Choose photo" — pick a photo from your gallery.
- **Photos (save)** — when you tap "Save to gallery" — save your restored image.
- **Camera** — when you tap "Take photo" — capture a new photo for restoration.
## 7. Sharing
- We share data only with the vendors listed above (under contract, for the purposes above), or when required by law.
- We do **not** sell your data.
- When you tap **Share** on a result image, the OS share sheet hands the image to the app you choose — that app's policy then applies to the copy you send.
## 8. Retention
- **Account:** kept until you delete it.
- **Uploaded photos:** see the Face Data section § 1 and Photo Data section § 2 above (30 days on Restora AI + fal.ai; on Backend until you delete the creation or your account).
- **Restored images:** kept until you delete the creation (trash icon on the result detail screen) or delete your account.
- **Purchase metadata:** kept while your account is active so Restora Pro keeps working across devices; removed when you delete your account.
- **Diagnostic logs:** 30 days.
To delete your account, use **Settings → Delete Account** in the app, or email **devinfo2026@gmail.com**. We delete your data within 30 days.
## 9. Your rights
You can request to:
- See the data we hold about you.
- Correct or delete it.
- Receive it in a machine-readable format.
- Withdraw consent at any time (including photo-data consent).
- Object to processing (GDPR).
- Opt out of any "sale" of personal data (CCPA — we do not sell data; this right is satisfied by default).
Email **devinfo2026@gmail.com** with any request. We respond within 30 days.
If you are in the EU/EEA, UK, or California, the rights above apply to you under GDPR / UK GDPR / CCPA respectively.
## 10. Security
- HTTPS / TLS for every connection.
- Encryption at rest on Backend (AES-256 disk encryption).
- Hashed passwords (never plaintext).
- Per-user row-level security on the database.
- We never store payment card numbers — Apple and Google handle that.
No system is perfectly secure. If there's a breach affecting you, we will notify you as required by law.
## 11. Children
- Restora is rated **4+** on the App Store and **Everyone** on Google Play.
- The app is intended for general audiences. We do **not** target children with advertising (we do not show advertising at all). We do not run analytics, profiling, or behavioural tracking on anyone, including children.
- We do not knowingly collect personal data from children under 13 (or the applicable age of digital consent in your jurisdiction). Account creation requires a working email address, and we expect a parent / guardian to be the account holder if the user is under 13.
- If you believe a child has signed up without parental consent, email **devinfo2026@gmail.com** and we will delete the account and any associated data within 30 days.
## 12. AI-generated images
- Result images are produced by AI based on your input photo + the tool you picked (Enhance / Colorize / De-scratch / Enlighten / Recreate / Animate). They are predictions, not perfect renderings — small details (faces, hands, text in the photo) may differ from the original.
- You keep all rights to your original photo.
- **Don't upload photos of other people without their permission.**
- **Don't upload photos of minors** unless you are the parent / guardian of that minor.
- **Don't upload illegal content.** Restora AI screens for clearly illegal content (e.g. CSAM) and will refuse to process and may delete such uploads, plus report them to authorities as required by law.
## 13. International transfers
Restora is operated from servers in the United States (Backend US region, Restora AI US infrastructure, fal.ai US infrastructure). If you use the app from outside the US, your data will be transferred to and processed in the US. We rely on standard contractual clauses (SCCs) where required by EU / UK law.
## 14. Changes to this policy
If we make material changes, we will update the "Effective date" at the top and, where required by law, notify you in the app at next launch. Continued use after the effective date constitutes acceptance.
## 15. Contact
- **Email:** devinfo2026@gmail.com
- **Subject for privacy requests:** "Privacy request — Restora"