Privacy Policy
Effective July 31, 2026
This policy explains what AutoFocus collects, why, and what you can do about it.
1. What we collect
On your device (never sent to us)
- Photos you take, including camera settings, poses, and finish styles
- Your preferences and settings
- Your session shot count and fastest lock time. These stay on the device unless you claim a public handle, which is what puts them on your profile page
- Camera permissions and photo library access
Sent to our servers
- Anonymous product events from inside the app (e.g. a replay exported, a shot published) for product improvement, but only if you switch on "Share anonymous usage data" in Settings. This is off when you install the app, and nothing is sent until you turn it on. An event is the name of the thing that happened and a timestamp, sometimes with whether you were subscribed at the time or which app you shared to. They carry no name, email, handle, referral code, account identifier, device identifier, or photo, and there is nothing in them that lets us tell one person's events from another's.
- If you claim a public handle: your handle, lifetime shots, fastest lock time, and streak days, displayed at
autofocus.cam/u/yourhandle, together with the shots you have published most recently, each one linking through to its own page
- When you open one of our links on the web, we count the visit: which kind of page it was, whether you are on an iPhone or an Android, whether it opened inside another app's browser, and the campaign tag the link was built with. This is counted on our side from the request itself, so there is no cookie and nothing is stored in your browser, and the row keeps neither your address nor which particular link you opened, so there is nothing in it that can be tied back to you or joined up across visits. It is how we tell whether a post on one platform is reaching people better than a post on another.
- Referral codes and associated App Store transaction IDs for trial extension and fraud prevention
- Standard server logs (IP address, user-agent) retained for up to 30 days for security and abuse prevention
- When you open a shot, invite, or referral link on an iPhone that does not have the app yet, a salted one-way hash of your IP address alongside that link, so that installing the app takes you to the thing you tapped rather than a blank camera. The address itself is never written down, the hash is deleted the moment the app collects the link or after one hour if it does not, and where two different links are waiting behind the same address we hand over neither. It is used for this and nothing else: it is not joined to your account, not used to recognise you later, and not shared.
If you create an account
- Your email address, and your name if the provider shares it
- A provider-issued identifier so we can recognise you on return
- Session records: a cryptographic hash of your sign-in token (not the token itself), timestamps, and device user-agent
- For email sign-in: a hash of the six-digit code and a failed-attempt counter, both deleted on use or expiry
2. How we use your data
- To provide and maintain the Service
- To process your subscription and manage your account
- To render your public profile page if you opt in
- To detect, prevent, and address fraud, abuse, and technical issues
- To improve the app through aggregated, anonymised analytics, where you have opted in to sharing usage data
- To count visits to our web links, so we can tell which channels are reaching people
- To communicate with you about your account (e.g. sign-in codes)
We do not sell, rent, or trade personal information. We do not use third-party ad networks. We do not build behavioral profiles.
3. Data retention
We retain your account data for as long as your account exists. Server logs are retained for up to 30 days. Product events are kept indefinitely, which we can do because they were never tied to you in the first place; deleting your account cannot remove them for the same reason. The hashed address behind a pending install link lives an hour at most, and usually far less, because collecting the link deletes it.
Deleting your account removes your email address, your name, the provider identifier behind your sign-in, every live session, your public profile page, and your waitlist entry if you had one. Where a referral has already been redeemed we keep the App Store transaction ID, unlinked from you, purely so the same transaction cannot claim a second trial extension. Residual copies in encrypted backups are overwritten within 30 days.
4. Third-party services
We use the following third-party services, each of which processes data under their own privacy policies:
- Apple StoreKit for purchases and subscriptions. Payment information is handled entirely by Apple.
- Cloudflare (Workers) for backend hosting. Privacy Policy
- Turso for database hosting. Privacy Policy
- Apple and Google for identity verification when you sign in. Apple / Google
- Resend for delivering sign-in codes. Privacy Policy
We require these processors to handle data solely as needed to provide their services to us, and we do not authorise them to use your data for their own purposes.
5. Your rights and choices
- Control usage analytics: open Settings › Privacy in the app and switch "Share anonymous usage data" on or off. It starts off, and turning it off stops all sending straight away.
- Delete your account: tap Delete Account in the app. This is immediate and irreversible.
- Sign out: revokes your session on our servers, not just your device.
- Delete your profile: email hello@autofocus.cam with your handle if you want the profile removed without deleting the account.
- Delete the app: removes all on-device data. Delete your account first if you have one.
- Request your data: email us for a copy of the personal data we hold about you.
6. Security
We use industry-standard security measures including encrypted connections (TLS), hashed session tokens, and rate-limited authentication. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security, but we take reasonable steps to protect your data.
7. Children
AutoFocus is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If we learn that we have collected data from a child under 13, we will delete it promptly.
8. International transfers
Our servers operate on Cloudflare's global edge network. By using AutoFocus, you consent to the transfer and processing of your data in jurisdictions that may have different data protection laws than your own. If you are located in the EU, UK, or EEA, you have rights under GDPR including access, rectification, erasure, restriction, portability, and objection. Contact us to exercise these rights. Our legal basis for processing is legitimate interest (Service operation) and, where applicable, your consent.
9. Changes
We may update this policy. Material changes will be notified in-app or by email. Continued use after the effective date of changes constitutes acceptance.
10. Contact
SCMLC Group
hello@autofocus.cam