Privacy Policy
Rah is an AI portrait camera. You take a short guided burst of photos of yourself, and Rah turns them into a small set of styled portraits. This policy explains what we collect, why, who we share it with, how long we keep it, and the choices you have. By using Rah, you agree to this policy.
We do not sell your personal information, and we do not use your photos to train AI models.
1. Information at a glance
| Category | Examples | Why |
|---|---|---|
| Photos & images | The portrait burst you capture; the generated portraits | To create and deliver your styled photos |
| Profile & preferences | First name (optional), onboarding answers | To personalize the experience and results |
| Purchases | Subscription / in-app purchase status | To unlock and manage paid features |
| Identifiers & device | A random app ID, device type, OS, app version, locale | To run the app, link purchases, and debug |
| Usage analytics | Screens viewed, taps, funnel events | To understand and improve the app |
| Diagnostics | Crash and error logs | To detect and fix problems |
We do not require an account, and we do not collect your email, phone number, contacts, or precise location.
2. Information we collect
Photos and images. When you take a capture, the app records a short burst of photos on your device, scores them locally, and uploads the best frames to our backend for processing. The backend generates your styled portraits and stores the inputs and outputs so the app can retrieve them. You can save the generated portraits to your device's photo library.
Information you provide. During onboarding you may enter a first name (optional) and answer questions about your goals, use cases, and style preferences. These personalize your experience and results.
Purchases and subscriptions. Purchases are processed by Apple. We receive your purchase and subscription status and related events to unlock features and manage access. We do not receive your full payment card details.
Identifiers and device information. On first launch the app generates a random identifier (a UUID) stored securely on your device. It is not derived from you and is not an account or government ID. It links your purchases and lets our services recognize the same install. We also process basic device information such as model, OS, app version, and locale.
Usage analytics. We measure how the app is used (screens viewed, key taps, onboarding and generation progress), associated with the random identifier above, not your real-world identity.
Diagnostics. When something goes wrong we record error details (messages, stack traces, severity, affected job, limited technical context) to diagnose and fix it. Error logs are not intended to contain your photos.
Device permissions. Rah asks for Camera (to capture), Photo Library (to save results), and Motion & orientation (used on your device to guide you through capture angles; this sensor data is used locally and is not collected by us). You can change these anytime in Settings.
3. How your photos are processed (AI)
Creating your portraits is automated. Your uploaded frames are analyzed to select the best frame and locate your face, then sent to AI image providers that generate the styled portraits. To do this we share the relevant images with the third-party AI and infrastructure providers listed below (currently OpenAI, Google models accessed via OpenRouter, and Cloudflare).
We do not use your photos to train our own models, and we instruct our providers to process your content solely to provide the service. We share your photos only with providers that are contractually bound to protect your data to the same or an equivalent standard as described in this policy, to use it solely to perform the service on our behalf, and not for their own purposes. Your onboarding preferences (not your photos) may be sent to an AI provider to personalize on-screen copy.
3a. Face data
Rah is a portrait camera, so the photos you capture contain your face. We want to be specific about this face data:
- What we collect. The portrait photos you choose to capture (which contain images of your face) and, derived from them, an automatically detected face region — a rectangular bounding box — that we use to crop and center your face before generation. We do not create a facial-recognition template or “faceprint,” we do not use this data to identify or verify who you are, and we do not use Face ID or any biometric authentication.
- How we use it. Solely to detect and crop your face, generate your styled portraits, deliver them to you, and store them so you can access your results in the app. We do not use face data to train AI models and do not use it for advertising.
- Face geometry is not retained. The detected face region is a set of bounding-box coordinates computed in the moment to crop and center your face. We do not save it as a face template or “faceprint,” we never use it to recognize or identify you, and it is not retained after your portraits are generated.
- How long we keep it. We keep your uploaded photos and the cropped face image only for as long as it takes to create your portraits. We delete them from our servers as soon as your portraits are generated, and in every case within 24 hours. We chose this short window because your source photos are only needed to create your portraits (and briefly to recover from transient processing errors); we have no reason to keep them longer, and we never store this face data indefinitely. Your generated portraits are your own content: we store them so you can access your results, hosted by Cloudflare in the United States and also saved on your device, and you can delete them at any time from within the app or by emailing contact.rah.app@gmail.com.
- Who we share it with, and whether they keep it. To create
your portraits we send the relevant images to the providers in Section 5, and
we describe how each handles your face data:
- Cloudflare stores the images on our behalf (it hosts our backend, in the United States) and only for us; it does not use them for its own purposes, and they are removed on the schedule above.
- OpenAI receives a cropped image to generate your portrait. Under its API data-usage policy, OpenAI does not use your images to train its models and retains API data only temporarily — up to 30 days — solely to monitor for abuse and misuse, after which it deletes them.
- Google models (accessed via OpenRouter) receive images to analyze your photos and help generate your portraits. Under their API terms they do not use your images to train their models, and any retention is short-term and only for operational and abuse-prevention purposes before deletion. OpenRouter routes the request and does not retain your images for its own purposes.
4. How we use information
- Capture, generate, deliver, and store your styled portraits;
- Personalize your experience and results;
- Provide, maintain, and secure the app;
- Process and manage subscriptions and purchases;
- Measure and improve performance and features;
- Detect, prevent, and debug errors, fraud, and abuse;
- Comply with legal obligations.
Where GDPR/UK GDPR applies, our legal bases are performance of a contract, legitimate interests (improving and securing the app), consent (device permissions), and legal obligation.
4a. Advertising and attribution
We work with advertising and measurement partners to understand how people discover Rah and to measure the performance of our marketing. To do this we use a mobile measurement partner and may share limited device and event information (such as app installs, in-app events, and advertising identifiers) with these partners and the ad networks below.
On iOS, we only access the advertising identifier (IDFA) for cross-app tracking if you grant permission through Apple's App Tracking Transparency prompt. You can change this anytime in your device Settings.
| Partner | Purpose |
|---|---|
| AppsFlyer | Mobile measurement & attribution |
| Meta (Facebook/Instagram) | Ad attribution & measurement |
| TikTok | Ad attribution & measurement |
| Apple Search Ads | Ad attribution & measurement |
5. Who we share information with
We share information with service providers that help us run Rah. We require these providers, by contract, to protect your information to the same or an equivalent standard as this policy and to use it only to provide their service to us.
| Provider | Purpose | Region |
|---|---|---|
| Apple | App distribution, in-app purchases & subscriptions | Global |
| Cloudflare | Backend hosting, image storage, processing, databases | US |
| OpenAI | AI image generation | US |
| OpenRouter | Routing requests to AI models | US |
| AI models (via OpenRouter) for analysis & personalization | US | |
| Mixpanel | Product analytics | EU |
| Superwall | Paywall presentation & subscription management | US |
We may also disclose information if required by law, to enforce our terms, to protect users or us, or in connection with a merger or acquisition (with notice where required). We do not sell your personal information for money. With your permission — granted through Apple's App Tracking Transparency prompt — we share limited device identifiers and app-event data with the advertising and measurement partners described in Section 4a; you can withdraw permission anytime in device Settings.
6. Data retention
We keep information only as long as needed for the purposes described here. Your uploaded photos and the cropped face image are deleted as soon as your portraits are generated, and in every case within 24 hours (see Section 3a); we do not retain this face data indefinitely. Generated portraits are your own content, retained so you can access your results, and you can delete them at any time in the app or on request. Purchase status is retained to manage entitlements and meet legal requirements. Analytics and diagnostics are retained for a limited period. When information is no longer needed, we delete or de-identify it.
7. Your choices and rights
Delete your data. Request deletion of your photos and associated data by emailing contact.rah.app@gmail.com. Because Rah has no accounts, please contact us from the device or include any in-app identifier we ask for so we can locate your data.
Permissions. Grant or revoke Camera, Photo Library, and Motion permissions anytime in device Settings.
Access, correction, portability, objection, restriction. Depending on where you live (e.g. EU/UK/California), you may have these rights over your information. To exercise them, email contact.rah.app@gmail.com; we respond as required by law.
California. We do not sell your personal information for money. We may "share" identifiers for advertising measurement, as defined under California law, only when you opt in through App Tracking Transparency; disable tracking in device Settings to opt out. California residents may exercise the rights above without discrimination.
Complaints. EU/UK users may complain to their local data protection authority.
8. Security
We use reasonable technical and organizational measures, including encryption in transit (HTTPS), secure on-device storage for identifiers, and access controls on our backend. No method of transmission or storage is 100% secure.
9. Children's privacy
Rah is not directed to children under 13 (or the minimum age required in your country, such as 16 in parts of the EU). We do not knowingly collect personal information from children under that age. If you believe a child has provided us information, contact us and we will delete it.
10. International data transfers
We operate globally. Your information may be processed in the United States, the European Union, and other countries where we or our providers operate. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
11. Changes to this policy
We may update this policy from time to time. We will revise the effective date above and, for material changes, provide additional notice where required. Continued use of the app after an update means you accept the revised policy.
12. Contact us
DREAMPRESS LTD
Email: contact.rah.app@gmail.com