Privacy Policy — Fotofresh: Photo Cleaner AI
Effective date: [September 25, 2026] Developer: Lamoki Studio Contact: [[email protected]]
This Privacy Policy explains how Fotofresh (“the App”, “we”, “us”) handles your information when you use the App on Android. We built Fotofresh to work on your device first: your photos and videos are analyzed locally and are never uploaded to our servers.
1. Summary
Your photos stay on your phone. Duplicate, similar, blurry and burst detection and Smart Albums run entirely on your device.
We do not sell your personal data.
Vault is local and encrypted (AES-256). The optional Google Drive backup (Pro) is encrypted with a key derived from your PIN before it leaves your device.
Ads in the free version are served by Google AdMob, which may collect device identifiers as described below. You can manage ad consent in Settings → Ad privacy options.
2. Information processed on your device only
Data Why Leaves the device?
Photos and videos (via the media permission you grant) Find duplicates, similar/blurry/burst shots, large files, screenshots; build Smart Albums No
Image fingerprints, categories, scan results Speed up future scans and show results No (stored in the App’s private database)
Vault photos Hide photos behind your PIN, encrypted with AES-256-GCM No, unless you turn on Drive backup
Vault PIN Unlock the Vault; derive the backup encryption key No
App preferences (language, theme, scan progress, swipe position) Remember your settings No
Biometric unlock (fingerprint / face) is handled by the Android system. The App only receives a success or failure result and never accesses your biometric data.
3. Information that is sent off your device
3.1 Anonymous app account (Firebase Authentication)
When the App starts, it creates an anonymous Firebase account. It does not ask for your name, email or phone number. We use the random user ID it generates to:
keep track of your Pro subscription status, and
keep a usage counter for free-tier limits.
These records are stored in Google Cloud Firestore and can only be read by your own anonymous account.
3.2 Purchases (Google Play Billing)
Payments are processed by Google Play. We never see your card or payment details. To activate Pro, the App sends the purchase token and product ID to our server (Firebase Cloud Functions), which verifies it with Google Play and stores your subscription status and expiry time against your anonymous user ID.
3.3 App configuration (Firebase Remote Config)
The App downloads configuration values (for example feature flags and ad settings) from Firebase Remote Config. To do this, Firebase uses a Firebase installation identifier and basic device information such as app version, OS version and locale.
3.4 Advertising (Google AdMob)
The free version shows ads served by Google AdMob. AdMob may collect and use:
the Android Advertising ID,
IP address, device model, OS version and app information,
ad interaction data (impressions, clicks).
These are used to deliver, measure and — where you have consented — personalize ads. In the European Economic Area, the United Kingdom and Switzerland, and where otherwise required, the App asks for your consent through Google’s User Messaging Platform before personalized ads are shown. You can change your choice anytime in Settings → Ad privacy options, and you can reset or delete your Advertising ID in your Android settings.
Learn more: https://policies.google.com/technologies/partner-sites
3.5 Google Drive backup (optional, Pro)
If you choose to back up your Vault, you sign in with your Google account and grant access only to the App’s private Drive folder (drive.appdata scope). The App cannot see or modify any other files in your Drive.
Each Vault photo is encrypted on your device with a key derived from your PIN before upload. Without your PIN, the backup cannot be decrypted — not by us, and not by Google.
A small backup manifest (album names, file references, creation time and encryption parameters) is stored alongside the encrypted files.
Your Google account email is shown in the App so you know which account is connected. We do not store it on our servers.
Backups are stored in your own Google Drive and are subject to Google’s Privacy Policy.
4. What we do not do
We do not upload your photos or videos to our servers.
We do not collect your name, email, contacts, location or phone number.
We do not sell or rent your personal data.
We do not use your photos to train AI models.
5. Permissions
Permission Purpose
Photos and videos / storage Scan and clean your media library
Manage media Move items to Trash and delete with fewer system prompts
Internet, network state Ads, subscription verification, configuration, Drive backup
Notifications Show scan progress and occasional cleanup reminders
Foreground service Keep long scans running reliably in the background
Biometric Optional fingerprint / face unlock for the Vault
You can revoke any permission in Android settings. Some features will stop working without the related permission.
6. Third-party services
The App relies on the following services, each governed by its own privacy policy:
Google Firebase (Authentication, Firestore, Cloud Functions, Remote Config) — https://firebase.google.com/support/privacy
Google AdMob and User Messaging Platform — https://policies.google.com/privacy
Google Play Billing — https://policies.google.com/privacy
Google Drive API (optional backup) — https://policies.google.com/privacy
7. Data retention and deletion
On-device data (scan results, Vault, preferences) stays until you delete it in the App or uninstall the App. Uninstalling removes all local data, including the Vault — back it up first if you want to keep it.
Trash: photos you remove stay in Trash for 30 days, then are permanently deleted.
Drive backup: you can delete it at any time in Google Drive → Settings → Manage apps → Fotofresh → Delete hidden app data.
Anonymous account records (subscription status, usage counter) are kept while your subscription is active or needed for billing and legal purposes. To request deletion, email us at [[email protected]]. Because the account is anonymous, please include the order ID from your Google Play receipt so we can find the record.
8. Security
We use industry-standard safeguards: AES-256-GCM encryption for the Vault, PIN-derived encryption for backups, HTTPS for all network traffic, and Firestore security rules that let each anonymous user read only their own records. No method of storage or transmission is 100% secure, but we work to protect your information.
9. Children’s privacy
The App is not directed to children under 13 (or the minimum age in your country). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
10. Your rights
Depending on where you live (for example under the GDPR in the EU/UK or the CCPA/CPRA in California), you may have the right to access, correct, delete or port your personal data, to object to or restrict processing, and to withdraw consent. Because almost all data stays on your device, you can exercise most of these rights directly in the App. For anything else, contact us at [[email protected]]. We do not sell or share personal information for cross-context behavioral advertising except through AdMob as described in section 3.4, which you can control via the consent settings.
11. International transfers
Our service providers (Google) may process data on servers outside your country. Where required, these transfers are protected by appropriate safeguards such as Standard Contractual Clauses.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the new version at this URL and update the effective date above. Significant changes will be announced in the App.
13. Contact
Questions or requests about this Privacy Policy: Lamoki Studio — [[email protected]]