Face Still

Face Still — Privacy Policy

Last updated September 4, 2026

This Privacy Policy explains how Face Still (“the app”), provided by Cheng Kam To, collects, uses, and protects your information. By using the app you agree to this policy.

Information We Collect

We collect none of your content. The app has no account and no sign-in, and no server of ours ever receives a scan, a photograph, a 3D model, a note or a tag. That is the promise this app is built around, and the rest of this page is written so you can check it.

Your scans — the photograph and the 3D model saved beside it — along with any notes, tags and settings, are written into the app’s own container on your iPhone, under iOS file protection, and are read by nothing else.

We do collect statistics about how the app is used, and send them to Google through Firebase Analytics: which screens you open, and whether things like a scan or a video export finished. They carry nothing you created and nothing you typed, and they are tied to no name and no account, because the app has neither. They are sent only if you allow tracking when the app asks on first launch; decline, and none are sent. What they contain is described under Usage Analytics below.

The app also shows advertising, supplied by Google. We send Google nothing about you in order to show an ad — no scan, no photograph, no 3D model, no note, no tag, and no targeting of ours. Google’s advertising library does collect information of its own when it fetches an ad, and that is set out under Advertising and Tracking below.

Your scans leave your iPhone in exactly three ways, and you perform all three yourself: you share an exported video through the iOS share sheet, you save an exported video to your Photos library, or you turn on iCloud Sync. There is no fourth way, and usage analytics is not one — it sends short events, never files.

How We Use Your Information

Your scans are used on your device, to show them to you, to compare any two of them, and to assemble them into a video when you ask for one. They are never uploaded to us, never sold, and never shared.

The app does not alter your photographs. What is saved is the file the camera produced.

We use the usage statistics for one thing: to decide what to work on. They tell us which screens people actually reach and which ones they never find. They are not used to build a profile of you, they are not sold, and they are not shared with anyone beyond Google as our analytics provider.

Camera and Face Data

Face Still uses ARKit face tracking through the TrueDepth camera for one purpose: to decide when your pose, distance and expression match the fixed reference, and to save a 3D model of your own face for your own comparison.

It is not Face ID. It identifies nobody, it matches against nothing, and the geometry is never sent to us or to any third party: it exists only on your iPhone, in your own backup, and — only if you turn iCloud Sync on — in your own iCloud.

What is collected. While the capture screen is open, the app reads — in memory, frame by frame — the position and angle of your face, its distance from the camera, the position of your eyes, and ARKit’s expression coefficients: the numbers that describe how open your eyes are and whether you are smiling. They decide when the conditions match, and they are discarded as each frame passes. Only at the moment the photo is taken are three things saved: the photograph itself, ARKit’s face mesh — 1,220 points in space, with no colour and no texture — and the pose, distance and expression numbers for that one frame. The app never reads a depth map, or any depth or infrared output from the TrueDepth sensor. The only image it reads is the ordinary front-camera picture, which is the photograph.

What is not created. No face template, faceprint, signature or biometric identifier of any kind. Nothing is matched against any database, ours or anyone else’s. The app identifies nobody and authenticates nobody, and it cannot tell one person’s face from another’s. It measures one thing: whether the face in front of the camera is where it was last time.

What it is used for. One purpose — making today’s photograph comparable with the one you took last week. The measurements decide when your pose, distance and expression match the fixed reference, so the app can take the photo itself; the saved mesh lets you hold one of your own scans against another. None of it is used for advertising, profiling or personalisation, and nothing is inferred from it about your identity or your health.

Where it is stored. In the app’s own container on your iPhone, under iOS file protection at its strongest setting, where no other app can read it. It is not placed in the Files app and it is not shared with other apps. It is included in your own iPhone backup, deliberately: losing a phone should not cost you the record. If you turn on iCloud Sync it is also copied into the app’s iCloud container under your own Apple ID — a copy, never a move, described in the next section.

Who it is disclosed or shared with: nobody. It is never sent to us: we run no server, hold no account, and receive no scan, photograph, 3D model or measurement at any point. It is never sent to an advertising network, an analytics service or an AI service. The usage measurement described below cannot carry it: those events are fixed names with numeric and yes-or-no values, and there is no field in them that a photograph, a model, a note, a tag or a date could occupy.

How long it is kept, and how to delete it. For as long as you keep it, and no longer. Nothing expires and nothing is deleted on your behalf. Because we never receive it, there is no copy of it for us to hold and no retention period of ours that applies to it. You can remove it in three ways, all permanent, with no trash and no recovery period: delete a single scan in History; use Settings > Data > Delete All Data, which erases every scan on the device and, if you ever turned iCloud Sync on, the iCloud copy as well; or delete the app, which takes its container with it.

The app also asks permission to add to your photo library, so it can save a video you export. It never asks to read your library, and it never reads your music library: a music file for an export is one you choose yourself through the system file picker, and the export is written out, never in.

iCloud Sync

iCloud Sync is off until you turn it on. When you do, scans are copied into the app’s iCloud container under your own Apple ID, and iOS replicates them between devices you already own. We have no access to that container and no account with which to obtain one.

It is a copy, not a move: the files on your phone are never moved or deleted.

Usage Analytics

Face Still uses Google Firebase Analytics to count how the app is used. Whether anything is sent at all depends on the tracking permission described under Advertising and Tracking below: allow it, and the statistics go to Google; decline it, and iOS blocks them before they leave your phone.

What the app chooses to send. A short, fixed set of events, each recording only that something happened — a scan finished, the compare screen or the 3D viewer was opened, a video export started, finished, or was saved to your Photos library, the iCloud Sync switch was changed — and, in two cases, one detail about it: which of the two compare views you used, and which way you moved the iCloud Sync switch. Alongside them the app records which of its main screens you are on, from a fixed list of names built into the app. iOS apps can be set to report every screen automatically; this one is not, so that the list stays short and fixed.

Where an event describes a video export, the number of scans that export covers is sent as a size band — fewer than ten, ten to twenty-nine, or thirty or more — and never as an exact number, because how many scans your archive holds is a fact about you rather than about the app.

What the app cannot send. No event above carries text. Not a note, not a tag, not a file name, not a date from your own scans, not a search term. This is enforced in the app’s own source code, where an event is only permitted to carry a whole number, a true/false value, or one of a fixed set of words — a photograph or a note cannot be handed to the analytics system at all.

What Firebase collects that we do not choose. Any app using Firebase Analytics also sends, automatically:

  • an app-instance identifier — a random value created when you install the app, tied to no account, and shared with no other app;
  • automatic events such as first open, session start, app update and OS update;
  • your device model, iOS version, app version and language;
  • an approximate location, worked out from your IP address, at roughly city-or-region level;
  • and, if you allowed tracking when the app asked, your device’s advertising identifier, described in the next section.

We do not receive your name, your email address, your phone number or your precise location, and we have no way to connect an app instance to a person.

The app’s configuration switches off Google’s advertising-personalisation signals and the collection of your device’s vendor identifier. We link no crash reporter and receive no crash reports; Google’s advertising library collects operational diagnostics about its own code, which is described in the next section.

Google’s own description of how it handles data from apps that use its services is at policies.google.com/technologies/partner-sites, and Firebase’s privacy documentation is at firebase.google.com/support/privacy.

Advertising and Tracking

Face Still shows ads supplied by Google AdMob. They appear as a band at the bottom of some screens, and occasionally as a full-screen ad between one part of the app and the next. There is no advertising on the capture screen, and none while a video export is running.

The ads are never personalised. The app tells Google’s advertising library to serve only non-personalised advertising, before it asks for the first ad, and that setting does not change with anything you do. Ads are also limited to content suitable for a general audience.

We tell Google nothing about you. An ad request from this app carries no keywords, no interests, no custom targeting and nothing of ours about you. Your photographs, 3D models, face measurements, notes and tags are never shared with AdMob, are never used to select an ad, and never leave your device for any advertising purpose. What Google’s own library sends with the request is the next paragraph.

What Google collects when an ad is fetched. Requesting an ad is a connection to Google, and Google’s advertising library sends its own information with it: your device model and operating system, your IP address — from which Google derives an approximate location, at roughly city-or-region level — which app is asking, how you interacted with the ad, and, only if you allowed tracking, your device’s advertising identifier. It also collects operational diagnostics about its own code, including crashes and performance. That is Google’s collection rather than ours: we receive none of it, hold none of it, and cannot connect any of it to you. It is governed by Google’s privacy policy and Google’s advertising policies.

The app asks for tracking permission. On first launch, after explaining in its own words what it is about to ask, the app shows Apple’s App Tracking Transparency prompt, once per install. The question is whether Google may use this device’s advertising identifier: to measure how the app is used, and — because the app shows advertising — for advertising and the measurement of it.

If you allow it, Google may read your device’s advertising identifier and attach it to the usage statistics described above. Apple counts this as tracking, and the app’s App Store privacy label says so, because the advertising identifier is the same one every other app on your device that reads it sees. It does not make the ads personalised — they stay non-personalised either way — and it is also what lets Google use the identifier on the advertising side. Google’s handling of the identifier is governed by Google’s privacy policy and Google’s advertising policies, not by us.

If you decline, no usage statistics are sent at all. The app declares Google’s measurement service to iOS as a tracking domain, and iOS then refuses the app’s connections to it, so those events never leave your phone. Google is not given the advertising identifier, and any advertising you do see is the same non-personalised advertising as before. Every feature of the app works exactly the same either way, and nothing is withheld from you for declining.

You can change your answer at any time in Settings → Privacy & Security → Tracking on your iPhone. If Allow Apps to Request to Track is switched off there, the app never asks, and is treated as declined.

If you are in the European Economic Area or the United Kingdom, Google’s own consent message is shown before any ad is requested, and the app’s Settings screen has a row that reopens it so you can change that answer later.

A Premium subscription removes advertising from the app entirely. Nothing else about this policy changes if you subscribe: the same statistics, the same tracking question, and the same promises about your scans. Advertising authorisation for our apps is published at /app-ads.txt.

Your Choices About Usage Analytics

The usage measurement described above carries nothing you create, is tied to no account, and is never combined with your scans, photographs, notes or tags.

The tracking permission is the switch. Face Still has no separate setting for usage analytics; whether they are sent is decided by the App Tracking Transparency prompt described above. Allow it, and the statistics — together with your advertising identifier — go to Google. Decline it, and iOS blocks them, and no usage statistics are sent. You can change the answer at any time in Settings → Privacy & Security → Tracking.

The Share iPhone Analytics switch in your iPhone’s privacy settings is a different thing: it governs what your device sends to Apple, and has no effect on the analytics inside this app.

Deleting the app removes every scan it holds on the device and discards the app-instance identifier, so a later reinstall counts as a new, unconnected install. You can also write to us through the contact route at the bottom of this page and ask that the data associated with your app instance be deleted; tell us roughly when you installed the app and on what device model, because those are the only handles that exist — we cannot look you up by name.

If a future version adds a switch of its own for this, it will be described here.

Third-Party Services

Apple, for the App Store, the camera, iCloud and subscriptions; Google Firebase Analytics, for the usage measurement described above; and Google AdMob, for the advertising described above.

There are no others — no cloud database holding your scans, no crash reporter and no AI service. Nothing you create is sent to any of them.

Data Retention

We keep none of your content, because we never receive it. Your scans stay on your device — and, if you turned it on, in your own iCloud — for as long as you keep them. Deleting a scan in the app deletes it on that device.

The usage statistics, and the advertising identifier if you allowed it, are different. Google holds those events for a limited retention window configured on our Firebase property, and keeps aggregate totals after that. Google describes how this retention works at support.google.com/analytics/answer/7667196. Google processes this data as our processor under the Firebase Data Processing and Security Terms, firebase.google.com/terms/data-processing-terms, which may involve storage and processing on servers outside your country. Data that AdMob collects in order to serve and measure advertising is held by Google under its own terms, not by us — we receive no advertising data about you and hold none of it.

Your Choices and Deletion

Delete individual scans in the app, or use Settings > Data > Delete All Data to erase every scan on the device — and, if you ever turned iCloud Sync on, the iCloud copy as well. Deleting the app removes everything it holds on that device. If you turned on iCloud Sync, you can also remove the app’s data from iCloud in Settings → [your name] → iCloud.

Deleting the app also discards the app-instance identifier used for usage measurement; a later reinstall is a new, unconnected install.

Tracking permission for Face Still — which is also what turns usage analytics on or off — can be changed at any time in Settings → Privacy & Security → Tracking. A Premium subscription removes advertising from the app.

Depending on where you live, you may have rights to access, correct, delete or object to the processing of personal data about you. We hold no account and no content of yours to give you, which makes most of these straightforward; for the usage statistics, write to us using the contact route below and we will do what we can with the handles described above.

Children’s Privacy

Face Still is not directed to children under 13, and we do not knowingly collect personal information from them.

The advertising the app shows is limited to content suitable for a general audience, and is never personalised for anyone.

Changes to This Policy

We may update this policy from time to time. The date at the top of this page reflects the latest version.

Contact

Questions about this policy, or a deletion request? Send them through our feedback form.