TinyLapse is built so your photos and albums stay with you. This policy explains what stays on your device, the small set of records our own servers keep, and exactly what happens when you ask us to make an AI keepsake from one photo you choose.

1. What Stays on Your Device

Your album content lives on your device and in your own iCloud account. We never receive it, with the single exception of the AI keepsake flow described in Section 3.

  • Photos & Videos: Stored locally on your device and synced to YOUR personal iCloud account. We cannot see them.
  • Album Data: Album names, dates, reminder settings, and preferences are stored on your device and in your private iCloud database.
  • Baby Information (Optional): If you add a baby name and birth date, they stay on your device and in your iCloud account. We have no access to them.
  • Time-lapse Videos: Rendered on your device from your own photos. They are never uploaded to us.

2. What Our Servers Hold

TinyLapse has a small backend: one Cloudflare Worker serving tinylapse.app and api.tinylapse.app, with a Cloudflare D1 database, R2 object storage, and KV. It exists to carry AI credits, subscription status, announcements, and promotion codes. It never receives your albums, your photos, or your baby information - except for the one photo you pick for an AI keepsake (Section 3).

  • Anonymous Device Record: A random install identifier created by the app, plus platform, app version, operating system version, locale, and the time we last saw the device. No account, name, or email is needed; this record is what carries your credit balance.
  • App Session Token: A token the app uses to call our API. We store only a hash of it, never the token itself.
  • Optional Sign-In: Signing in with Apple or Google is optional and only needed for AI credits, announcements, and promotion codes. We store the subject identifier the provider gives us for you and your email address - the email only when the provider marks it verified. With Sign in with Apple we also keep Apple's credential, encrypted, for one purpose: revoking it when you delete your account.
  • Subscriptions: Managed by RevenueCat, as before. We also store the webhook events RevenueCat sends us: subscription status and purchase history. No album content is involved, and Apple handles all payments.
  • Credits: Your credit balance and an append-only ledger of grants, purchases, holds, refunds, and corrections we make by hand, so any balance can be explained and a failed creation can be refunded.
  • Free Credit Check: When Apple's DeviceCheck is enabled, the app sends Apple a device token so Apple can tell us whether this hardware already received its one free credit. Apple receives nothing else from us, and we never learn a hardware identifier.
  • Contact Form: Your name, email address, subject and message, the category you picked, and anything you attach, a photo or a short video. A message written in the app also carries the account it came from and the app and iOS version you were on, so an answer does not have to start by asking. Plus a hashed form of your IP address, used only to rate-limit the form; the raw address is never stored.
  • Your Name and Photo (Optional): If you type a name or pick a profile photo on the account screen, they are kept with your account so we know how to address you when you write in. They are never shown to another user and never sent to an image model. You can change or remove either of them in the app at any time, and both go when you delete your account.

3. AI Keepsakes

AI keepsakes are optional. Before the first photo upload, the app explains which photos are shared with fal.ai and its image models, why they are processed, and how long they are kept. You must explicitly allow this processing. Your choice and the notice version are saved on your account, so the same notice is not asked for before every card. A changed notice requires fresh permission.

  • What Is Sent: The photos you pick - one to six, depending on the template. Each is uploaded to our private storage (a Cloudflare R2 bucket that is not publicly reachable) and sent from our server to fal.ai, the processor that runs the image model. The generated image is written back to the same private storage.
  • Other People in the Photos: Some templates ask for a photo of a mum, a dad or a sibling alongside the baby. Our Terms state that by using the feature you confirm you have permission to share the photos of everyone in them; those photos are handled exactly like the baby's, deleted from our storage when the job ends and never used for training.
  • Models: Google's Nano Banana Pro and ByteDance's Seedream, both reached through fal.ai. The second is used only as a fallback when the first cannot finish the card.
  • Prompts: Fixed presets written and versioned by us. You never type a prompt, and no free text of yours reaches a model.
  • At fal.ai: The photo is sent inline with the request, with request-history storage switched off and a one-hour expiry on anything fal.ai holds while the job runs. fal.ai acts as our processor under its data processing agreement: your photo is used to produce your keepsake and for nothing else - not for training.
  • Deletion: The photo you sent is deleted from our storage as soon as the job ends, whether it succeeded or failed. The generated keepsake is kept for 90 days, or until you delete it or delete your account, whichever comes first.
  • About the Job: We keep which preset and model ran, the status, timestamps, our cost estimate, and the provider's request id - enough to return your credit when a creation fails.

4. Information We Do NOT Collect

This has not changed, and the backend did not add anything to it:

  • Location or GPS data
  • Contacts or address book
  • Health or biometric data
  • Browsing history
  • Advertising identifiers
  • Analytics or usage tracking data
  • Any data from other apps on your device
  • No ads, no sale of your data, and no tracking across apps or websites
  • Crash reports or diagnostic logs from your device

5. How Your Information is Stored

On your device: photos, albums, and settings are stored with iOS file system encryption. In your iCloud: if you are signed in, your data syncs to Apple’s CloudKit service in YOUR private database, protected by Apple’s security and your Apple ID, and not accessible to us or any third party. On our servers: the records in Section 2 live in a Cloudflare D1 database; keepsake images, your profile photo, and anything you attach to a message live in a private R2 bucket that is not publicly reachable and is served only through an authenticated request. Short-lived counters such as rate limits live in Cloudflare KV and expire on their own. Everything travels over HTTPS/TLS. Your albums, your photos, and your baby information are not stored on our servers.

6. How We Use Your Information

We use information solely to:

  • Provide TinyLapse app functionality on your device
  • Sync your albums across your Apple devices via iCloud
  • Send reminder notifications you configure
  • Process your subscription status and unlock what you paid for
  • Keep your credit balance correct and explainable
  • Create the AI keepsake you asked for
  • Show announcements and honour promotion codes
  • Answer the message you send us
  • Keep the service working and resistant to abuse (rate limiting)

7. Service Providers

This is the complete list of companies involved and what each one does. Nothing else receives your data.

  • Apple - iCloud & CloudKit: Stores your albums and photos in your own private iCloud database, under Apple's privacy policy and your Apple ID. We cannot read it.
  • Apple - Sign in with Apple & DeviceCheck: Identity provider for optional sign-in; DeviceCheck confirms whether a device already used its one free credit.
  • Apple - App Store: Handles every payment. We never see card details.
  • Google - Sign in with Google: Identity provider for optional sign-in. Receives nothing from us beyond the sign-in request.
  • RevenueCat (processor): Subscription and purchase management. Receives an anonymous user identifier, subscription status, and purchase history. No photos, albums or baby information. Processes data in the United States.
  • Cloudflare (processor): Hosts our Worker, the D1 database, R2 storage, and KV on its global network.
  • fal.ai (processor): Runs the image models for AI keepsakes. Receives only the photos you chose and our fixed preset prompt, under its data processing agreement. Processes data in the United States.

8. How Long We Keep Things

A job runs once a day and removes whatever is past its window:

  • Keepsake input photo: Deleted as soon as the job ends
  • Successful keepsakes and their images: 90 days
  • Failed keepsake jobs: 30 days
  • Subscription events from RevenueCat: 90 days
  • Expired or revoked session tokens: 30 days
  • Closed contact messages: 180 days
  • Our internal audit log of changes made by hand: 365 days
  • Account, devices, and credit ledger: Kept while your account exists, so a balance and a purchase stay explainable; removed or zeroed when you delete your account
  • Photos or videos attached to a message: Deleted together with the message
  • Your name and profile photo: Kept while your account exists; removed the moment you delete them or delete your account

9. Device Permissions

TinyLapse requests the following permissions:

  • Camera: To capture photos for your time-lapse albums, and a profile photo if you want one. Album photos are saved only to your device and your iCloud.
  • Photo Library: To export generated videos to your camera roll, and to let you pick the photos you want: for an AI keepsake, for a profile photo, or to attach to a message. We do not read your library otherwise.
  • Notifications: To send reminder alerts you configure. Completely optional.

10. Children's Privacy

TinyLapse is made for parents and guardians documenting a baby's growth. The app is NOT designed for children to use, and we do not knowingly collect personal information from children. A baby name and birth date, if you add them, stay on your device and in your iCloud, and you can delete them anytime in album settings. When you create an AI keepsake, the photo of your child is processed only to produce the keepsake you asked for and never for training or any other purpose; it is deleted as soon as the card is ready. As the parent or guardian, you decide whether to use this at all.

11. Your Rights and Choices

You stay in control of your data:

  • Access: View your albums and photos in the app; your credits and keepsakes are shown there too
  • Export: Save any photo or video to your device
  • Delete a Keepsake: Remove any single creation; the image is deleted from our storage
  • Delete Your Account: In-app account deletion removes the server-side account, detaches Apple and Google sign-in, revokes Apple's credential, zeroes your credit ledger, and deletes your generated images. Your local albums and your iCloud data are untouched and remain yours.
  • Stop AI Features: Stop using keepsakes at any time; nothing is sent unless you start a card yourself
  • Disable Sync: Turn off iCloud sync in device settings
  • Notifications: Disable reminders in the app or in iOS settings
  • Complete Deletion: Delete your account, uninstall the app, and clear its iCloud data
  • Write to Us: Depending on where you live you may have further rights under laws such as the GDPR, the UK GDPR, Turkey's KVKK, or the CCPA: access, correction, deletion, objection and portability. Email us and we will honour them.
  • Your Name and Photo: Change or remove either of them on the account screen at any time

12. Data Security

Your data is protected by several layers:

  • Data on your device is encrypted using iOS file system encryption
  • iCloud data is protected by Apple's security infrastructure
  • All transmission uses industry-standard encryption (HTTPS/TLS)
  • Keepsake images sit in private storage, reachable only through an authenticated request for your own account
  • Session tokens are stored only as hashes; Apple's credential is stored encrypted
  • IP addresses are used only in hashed form, for rate limiting
  • Provider keys are held as server secrets and never shipped in the app

13. Where Your Data is Processed

Your albums stay on your device and in your iCloud account, wherever Apple stores it for you, under Apple's privacy policy. Our backend runs on Cloudflare's global network, so requests are served close to you. fal.ai and RevenueCat process data in the United States. Where data leaves your region, it travels under the contractual safeguards those providers offer, including standard contractual clauses for the EU and the UK.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes update the "Last updated" date above, and a change to how AI keepsakes work also raises the version of the notice recorded against every card, so we can always say which text applied when a given card was made. Continued use of TinyLapse after changes constitutes acceptance.

15. Contact Us

If you have questions about this Privacy Policy, or you want to exercise any of the rights above, please contact us:

Email: hello@tinylapse.app