Privacy Policy
Aim ("we", "our", or "us") respects your privacy. This Privacy Policy explains what data we collect, how we use it, and what choices you have. By using Aim you agree to the practices described below.
1. What we collect
Account
- Email address — to authenticate you and to send transactional emails (welcome, referral credits).
- Apple / Google identifier — when you choose Sign in with Apple or Google. We receive only the unique account ID and (for Apple, optionally) name and email.
- Display name (optional) — used as your stream label on the local network when you host or join a Stream session.
Device
- Device identifier — a random UUID generated on first launch and stored in your device's secure storage (iOS Keychain, or the Android Keystore-backed equivalent on Android). Used for fraud prevention (one referral per physical device) and single-device session enforcement (signing in on a new phone signs out the old one). It is not Apple's IDFA or Android's advertising ID, and is not shared with advertisers.
- OS version, device model — included in feedback emails you choose to send so we can reproduce bugs.
Location
- Approximate location — used only to power the optional "Today's Vibe" photo-idea suggestions (for example, general area such as coastal, urban, or nature, and time of day). We request reduced-accuracy/coarse location only — on Android this is the coarse-location permission, and precise location is never requested on either platform. This location is processed on your device; it is not stored on or transmitted to our servers.
Photos and projects
- Photos you take or import — stored locally on your device. We do not upload your photos to our servers. The optional "Save to Photos" action writes to your device's photo library only (the Photos app on iOS, or your gallery on Android).
- Project metadata (project names, capture settings, photo arrangements) — stored locally on your device.
- Stream sessions (iOS only, for now) — peer-to-peer over your local Wi-Fi or Bluetooth using Apple's Multipeer Connectivity. Frames go directly from one phone to the other; nothing transits our servers. Stream is not yet available on Android.
Subscriptions
- Subscription status — managed by RevenueCat on our behalf. Apple validates the receipt; we receive only entitlement state ("Aim Unlimited active until …"), never your payment details.
Usage diagnostics
- We keep anonymous, first-party usage statistics — which features are used and how often (for example, a screen was opened or a photo was captured) — so we know what to improve. This data is keyed only to a one-way cryptographic hash of your device identifier (see "Device" above) — the hash cannot be reversed to recover the original identifier or linked to your name, email, or account, and it never includes your photos or their contents. It lives on our own servers; we do not use third-party analytics or advertising SDKs, and we do not share it with data brokers or use it to track you across other apps. You can turn it off at any time in the app under Settings → “Help improve Aim.”
- If you tap the in-app feedback button, the email you send is the only other diagnostic we receive.
2. How we use it
- To run the service (sign-in, save your projects on your device, deliver subscription entitlements).
- To honor referral rewards (linking referrer/referee, granting Unlimited time).
- To power optional location-based suggestions like "Today's Vibe", using only your approximate location.
- To prevent abuse (one referral per device, single-device session).
- To respond to feedback and support requests you send.
- To send transactional email (welcome, "your friend joined" notifications). We do not send marketing email.
3. Third parties we share with
- Supabase — hosts our database and authentication. Your email and account row live here. Supabase Privacy.
- RevenueCat — validates App Store / Google Play receipts and tracks subscription state. RevenueCat Privacy.
- Resend — sends our transactional emails. Resend Privacy.
- Apple — App Store, Sign in with Apple. Subject to Apple's privacy policy.
- Google — Sign in with Google (only if you choose this method). Subject to Google's privacy policy.
We do not sell your data. We do not share your data with advertisers.
4. Permissions
- Camera — to capture reference photos. Required.
- Photos / Media library — read access to import existing photos as references; write access to save captured photos to your library. Both optional. (On Android this covers the photos/videos media permissions; Android 14+ also supports granting access to selected photos only.)
- Microphone — only when Live Photos is enabled (Live Photos record ~1.5s of audio). Optional.
- Motion & Orientation — to drive the on-screen level indicator while framing. On Android this uses standard device sensors and does not require a runtime permission prompt.
- Approximate location — for the optional "Today's Vibe" suggestions. Optional; we only ever request reduced/coarse accuracy, never precise location.
- Local Network (iOS only, for now) — to discover nearby phones for Stream (Multipeer Connectivity). No data leaves your local network.
You can revoke any permission at any time: iOS Settings → Aim, or Android Settings → Apps → Aim → Permissions.
5. Data retention & account deletion
Account data lives in our database for as long as your account exists. Your photos, projects, and captures are never uploaded to our servers — they live only on your device — so uninstalling Aim, or clearing its storage, deletes them locally and we cannot recover them for you.
You can permanently delete your account directly from inside the app at any time: open Settings → Delete Account, confirm twice, and we'll wipe everything tied to you. The action is irreversible. See our Delete Account page for the full walkthrough.
What we delete: on our servers, your account record (email, identity), your subscription/entitlement link, and your referral code together with any pending referral relationship. On your device, when you delete from inside the app, we also wipe your saved projects and captures, your Stream display name, your app preferences (theme, language, dismissed hints), and the cached image thumbnails — everything except for the one technical exception below. Because your photos, projects, and captures were never on our servers to begin with, deleting your account only clears them from the device you delete on — not from any other device, since we hold no server-side copy to erase.
What we retain: a random, non-identifying device token (stored in your device's secure storage — iOS Keychain, or the equivalent on Android) is kept for up to 24 months after account deletion to prevent abuse of our referral system — e.g. deleting an account and re-creating it to redeem the same referral reward on the same device. This token cannot identify you personally or be linked to your previous account; it's a device-level anti-fraud marker only. We also retain your in-app purchase transaction history for up to 10 years to meet accounting and tax record-keeping obligations; this history contains no payment card details, which stay with Apple, Google, and RevenueCat.
If you can't access the app for any reason, email care@aimcamera.info from the address tied to your account and we'll action the deletion of your server-side data within 30 days. We have no way to remotely clear data stored on your device — if you also want your locally-saved projects and photos gone, delete the app (or clear its storage) on each device where you used it.
6. Children
Aim is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us and we will delete it.
7. International transfers
We are based in Vietnam. Our data processors (Supabase, RevenueCat, Resend) operate in the United States and the European Union. By using Aim you consent to your account data being stored and processed in these regions.
8. Your rights
- Access — ask us what we hold about you.
- Correction — ask us to fix inaccurate data.
- Deletion — delete your account anytime via Settings → Delete Account inside the app, or email us if you can't access the app.
- Portability — ask for your account data in a machine-readable format.
- Objection — opt out of any non-essential processing.
Email care@aimcamera.info to exercise any of these rights.
9. Security
Authentication is handled by Supabase Auth (TLS, hashed credentials). Photos and projects are stored only on your device, under your OS's app sandbox protection (iOS app sandbox, or Android scoped app storage). Subscription receipts are validated server-side by Apple, Google Play, and RevenueCat. We do not see or store your payment information.
10. Changes
We may update this Privacy Policy. Material changes will be announced in-app and the "Last updated" date above will change. Continued use of Aim after a change means you accept the updated policy.
11. Contact
Questions about this policy or your data? Email care@aimcamera.info.