Privacy Policy
Published 3 October 2026. This policy mirrors the current app’s disclosures.
Purchases and account credentials
Apple processes App Store payments; Aphrodite does not receive card or bank details. RevenueCat validates purchases using your Firebase account ID and store transaction information. The server stores purchase claims and a Credit ledger in Firebase to prevent duplicate grants and reconcile balances. Firebase login credentials are stored in the device protected credential store, not ordinary app preferences.
What we process
When you submit a link, we process its public metadata, captions and selected frames. When captions are missing, we may send temporary extracted audio through OpenRouter for speech-to-text to inform product and routine notes. When you submit a photo, the app resizes it for analysis. We process your input, derived product candidates and routine, account ID if signed in, and technical request data needed to operate the service.
Why and with whom
We use submitted media to return the analysis you requested. Selected media and context may be sent to the configured AI provider through OpenRouter. We do not intentionally use your content to train our own models. Product reference data may be obtained from public catalogs, including Open Beauty Facts.
Glow-up makeup previews
If you choose a makeup reference, we send a resized selfie and reference to OpenRouter for editing, and the reference to OpenRouter for makeup analysis. Aphrodite stores these images and the generated preview in private backend storage for reopening and preview regeneration, with a configured 30-day lifecycle. Requests use inline image data rather than public photo URLs. Provider retention and processing follow the provider terms; inline image output is not a guarantee of zero provider retention. Deleting backend history or your account also deletes the owned preview images.
Storage
The production queue temporarily stores resized analysis photos in server-only Firestore documents. The worker deletes them after completion or failure; unprocessed payloads expire after 15 minutes and physical TTL deletion is asynchronous. Firestore recovery copies may persist for the configured backup or point-in-time recovery window. Successful video transcripts are cached privately for reuse, expire from cache reads after 24 hours, and are removed by server-history or account deletion. Physical expired-cache deletion requires the configured Firestore TTL policy and is asynchronous. Temporary extracted audio is removed after source processing. Derived analysis is retained for up to 30 days. We do not intentionally retain full source videos or original-resolution photos. For signed-in accounts, saved looks and named collections sync through Firebase Firestore. Small look thumbnails stay on this device. Preview-guest collections stay on this device only.
Your choices
You may decline analysis, use the app without an account, remove saved looks, and delete backend analysis history below. Clearing app data removes device-only thumbnails and preview-guest saves, but not signed-in Firestore data. Signed-in users can request account deletion from Profile. This deletes saved cloud data and derived history; minimal purchase/anti-replay records are retained. Deleting your account does not cancel your Apple subscription.
Security and third parties
We restrict backend requests to supported source hosts and verify generated shopping destinations separately. External retailer and content sites have their own privacy practices. No third-party analytics SDK is enabled in this preview.
Changes
We may update this policy when storage, providers or features change. Material changes should be described before a new data use begins.
Contact
Questions about privacy: support@aphroditeapp.site.