Privacy Policy

Privacy Policy

Last Updated: September 11, 2026

1 Our Privacy-First Architecture

At Photo Cartoonizer (developed and operated by Cloudspirit Ltd.), we believe your personal memories, face portraits, and photos belong exclusively to you.

🔒 Zero Photo Upload Guarantee:
Photo Cartoonizer uses a 100% on-device AI pipeline. All image transformations, face analysis, and cartoon artistic generation run entirely on your phone's processor (NPU, GPU, and CPU).

Your photos, images, and text prompts are NEVER uploaded to any cloud server, external API, or third-party database.

2 Information We Do NOT Collect

3 Face Data Policy

Photo Cartoonizer processes photographs that may contain human faces in order to generate cartoon-style portraits. This section describes how face data is handled in compliance with Apple's Developer Program License Agreement (Sections 3.3.3(C) and 3.3.3(K)) and App Store Review Guideline 5.1.1(i).

A. Collection, Use & Disclosure of Face Data

When you select or capture a photo, the App loads the image into your device's local memory (RAM and/or GPU VRAM) for on-device AI processing. The on-device diffusion model analyzes the visual features of the image — including any facial features present — solely to generate a cartoon-style rendition of the photo. Face data is used exclusively for this single artistic transformation purpose. No facial geometry maps, facial recognition templates, faceprints, or biometric identifiers are extracted, computed, or stored at any point during this process. Face data is never disclosed to Cloudspirit Ltd., any cloud server, external API, analytics service, or any third party.

B. Sharing & Retention of Face Data

Sharing: Face data is never shared with any third party, including Cloudspirit Ltd. itself. All AI inference occurs entirely on the user's device using locally-stored model weights. No face data, facial features, or derivative facial representations are transmitted off the device via any network connection.

Retention: Face data exists in device memory (RAM/VRAM) only for the duration of the active generation session. Once the cartoon image has been generated and returned to the user, the source image data — including any facial features — is immediately released from processing memory. The App does not write face data to any persistent database, cache, log file, or cloud storage. The only persistent artifact is the final cartoon output image, which the user may choose to save to their device's photo library.

C. Deletion & Revocation of Consent

Because face data is held only transiently in device RAM during an active generation and is never persisted to disk or transmitted to any server, there is no stored face data that requires manual deletion. Face data is automatically purged from memory when:

Revoking consent: You may revoke the App's access to your camera or photo library at any time through your device's Settings → Privacy & Security → Photos / Camera. Once permissions are revoked, the App can no longer access any photos containing face data. You may also uninstall the App entirely, which removes all locally-stored AI models and any cached data from your device.

D. Third-Party Face Data Obligations

Photo Cartoonizer does not share face data with any third party. No third-party SDK, service, or library integrated in the App (including Google AdMob and Firebase Crashlytics) receives, processes, or has access to your photos or face data. AdMob and Crashlytics only receive non-identifying device telemetry and crash diagnostics as described in Section 4 below.

E. Optional Local HTTP API Server & Face Data

Photo Cartoonizer includes an optional premium feature that hosts a local HTTP API server on the user's own device, accessible only within the user's local Wi-Fi network (LAN). Other devices on the same network may send photos — which may contain face data — to this server for on-device cartoon generation.

Face data received through the local server is subject to the same protections described above:

The local server is disabled by default and must be explicitly activated by the user. The user can stop the server at any time from within the App, which immediately terminates all listening connections and prevents further photo reception.

Summary: Face data is processed on-device only, never leaves your device, is never shared with any third party, is retained only in volatile memory for the duration of a single generation session, and is automatically purged upon completion. No face data deletion request is necessary because no face data is ever stored persistently.

4 Limited Information Processed

To deliver, maintain, and support the App, certain non-identifying operational data may be processed through standard mobile service providers:

A. Advertising (Google AdMob):

For non-VIP users, the App displays ads served by Google AdMob (App Open, Interstitial, and Rewarded video ads). AdMob may collect pseudonymous identifiers such as your device's Advertising ID (IDFA on iOS, Google Advertising ID on Android), general location (country/city), and ad interaction telemetry to serve relevant ads. You can opt out of personalized ads via your device operating system settings.

B. In-App Purchases & Subscriptions:

Purchases of Premium VIP subscriptions are handled securely through Apple App Store (In-App Purchases) or Google Play Billing. Cloudspirit Ltd. does not collect, receive, or store your credit card numbers or billing addresses. We only receive anonymous confirmation receipts indicating active subscriber status.

C. Anonymous Crash & Performance Logs:

We may collect anonymous crash stack traces (via Google Firebase Crashlytics) to diagnose memory leaks, app crashes, and device hardware incompatibilities. These reports contain device technical specs (e.g., OS version, RAM capacity) and contain no personal content or photos.

5 Device Permissions Requested

The App requests only the permissions necessary for its core offline features:

6 Children's Privacy

Photo Cartoonizer does not knowingly collect or solicit any personal information from children under the age of 13 (or under 16 in the European Union). Because no personal user profiles or photos are collected on external servers, the App complies with the Children's Online Privacy Protection Act (COPPA) and GDPR regulations.

7 Your Rights (GDPR, UK DPA & CCPA)

Under privacy laws such as the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), individuals have rights to access, delete, or restrict processing of their personal data.

Because Photo Cartoonizer operates on a strict zero-server-storage policy for photos and user accounts, we do not maintain any personal data records, profiles, or galleries to access, disclose, or delete. All data remains under your absolute control on your personal mobile hardware.

8 Updates to this Policy

We may occasionally update this Privacy Policy to reflect changes in our app features or regulatory requirements. Any updates will be posted here with a revised "Last Updated" timestamp.

9 Contact Us

If you have questions, concerns, or feedback about our privacy practices, please reach out to us: