Privacy Policy
Last updated: September 25, 2026
This Privacy Policy explains how Trace ("we", "us", or "Trace"), an iOS application developed by Alberto Luján Ruiz, collects, uses, stores, and protects your information. By using Trace, you agree to the practices described here.
Information we collect
Information you provide
- Account: if you sign in with Apple, we receive an opaque user identifier and (optionally, your choice) your name and an email address. If you sign in with email, we store your email and a salted-hashed password handled by Supabase Auth.
- Profile: the first name and (optional) birthday you enter during onboarding. We use the birthday only to surface anniversary-related features inside the app.
- Pairing: the invitation code you generate or accept, so we can link your account to your partner's.
- Photos: the JPEG bytes captured in-app and metadata (the day each photo represents, whether it is a Recovery shot, the time of capture). Photos are stored in private Cloudflare R2 storage; older photos may remain in Supabase Storage.
- Subscription: your subscription status as reported by RevenueCat (active / cancelled / expired), plus the months you have paid for.
Information collected automatically
- Device push token: if you allow notifications, we store your APNs device token so we can send you the daily reminders and the "your partner just shot" cross-notification.
- Diagnostics: we use Sentry for crash reports and performance diagnostics, including stack traces, device and app information, and technical request context. We do not intentionally include photo content in these reports.
- Time zone: derived from the device for accurate "shooting window" and "Reveal Day at 20:00 local" logic.
- Usage analytics: we record first-party usage events (e.g. "onboarding completed", "photo captured", subscription lifecycle events) in our own database to understand how the app is used and fix funnel problems. These events may be associated with your account or device identifiers and do not contain photo content.
- Acquisition answer: the optional "how did you hear about us?" answer you pick during onboarding.
Information we do NOT collect
- We do not access your phone's camera roll or photo library — Trace uses only the in-app camera.
- We do not access your contacts.
- We do not access your precise or coarse location.
- We do not collect your bank or payment details — Apple handles billing.
- We do not sell, rent, or share your data with advertisers.
How we use your data
- To operate the pairing, daily-shooting, Reveal Day, and historical-album features described in the app.
- To send the notifications you opt into.
- To validate your subscription and unlock the months you have paid for.
- To fix bugs and improve stability and loading performance using diagnostics.
How your data is protected
Account data and photo metadata are stored in Supabase. Photos are stored in private Cloudflare R2 storage, with some older photos in Supabase Storage. Access is controlled through authenticated requests and database access rules. You can see your own photos; your paired partner receives access to the full photos after the roll reveals. Before reveal, the app may show small, heavily blurred previews, counts and dates. Media links are time-limited.
Authentication is handled by Supabase Auth (Sign in with Apple via Apple's OAuth flow, or email + password). We never see plaintext passwords.
Third-party services
- Cloudflare R2: private photo storage and delivery. Privacy policy.
- Supabase: database, legacy photo storage, authentication, edge functions. Privacy policy.
- Apple App Store + Apple Push Notification service — purchases and push delivery. Privacy policy.
- RevenueCat — subscription state. Privacy policy.
- Sentry: crash and performance diagnostics. Privacy policy.
Your rights (GDPR Articles 15–22)
Access & export
You can export every one of your own photos in their original JPEG format without added film filters from Settings → Export my photos. You cannot export your partner's photos — those are their data, not yours.
Deletion (Article 17 — Right to be Forgotten)
Use Settings → Delete account to delete your account inside the app, including your authentication record and your associated data and photos. You can also use Settings → Delete all my photos to remove your photos separately. Account deletion ends your pairing but does not delete your partner's account or their own photos. If you have an Apple subscription, cancel it separately in your Apple ID settings; deleting the account does not cancel Apple billing. If you cannot access the app, contact us at the address below for help.
Pair dissolution
Either of you can dissolve the pairing unilaterally. Dissolution stops new photos from being added but does not delete existing history — each of you keeps the rolls you already revealed. The bond can be restored within 60 days; after that, it is permanent.
Withdraw consent / opt out
- Disable notifications from Settings inside the app or from iOS Settings.
- Cancel your subscription from your Apple ID settings.
- Sign out from Settings → Sign out.
Data retention
Photos remain in your account until you delete them or close your account. After bond dissolution, both users keep their own copy of the historical album. Every monthly roll your couple opened stays fully visible to both of you forever; if the subscription lapses, you keep read access to those rolls and simply cannot open new ones.
Widgets
Trace widgets read a small status snapshot stored locally in the app's shared container. The widget itself does not download photos or contact our server.
Children's privacy
Trace is intended for users aged 18 or older. We do not knowingly collect data from users under 18. If you are a parent or guardian and believe your child has provided personal information to us, contact us and we will delete it.
International transfers
Our Supabase project uses EU-region infrastructure. Cloudflare R2 handles photo storage and delivery. Apple, RevenueCat and Sentry also process data to provide their services, and processing may involve infrastructure outside your country. Their privacy policies are linked above.
Changes to this Policy
We may update this Privacy Policy. When we do, we will update the "Last updated" date at the top of this page and, for material changes, notify you in the app.
Contact
For any privacy question, request, or complaint, email [email protected]. We respond to all GDPR requests within 30 days.