Privacy Policy
Last updated: August 2026
The short version: no accounts, no names, no emails. Photos you choose are uploaded only to be processed and are automatically deleted from our servers within 72 hours. They are never used to train AI models, never sold, and never shared beyond the processing described below.
Who we are
It Was Never You (“the app,” “we,” “us”) is an iOS app that replaces one person with another in photos you select from your library (“reCasting”). Contact: support@itwasneveryou.app.
What we collect, and why
- Photos you select. The photos you explicitly choose — the reference photos for the two identities and the photos to be reCast — are uploaded to our servers solely to generate your results. We never access your photo library beyond what you select. Photos flagged by on-device screening are excluded and stay on your device unless you explicitly choose to include one.
- An anonymous device identifier. On first launch the app registers an anonymous, randomly generated device ID used to authenticate requests and track your credit balance. It is not linked to your name, email, phone number, or Apple ID, and we have no way to connect it to you.
- Credit and purchase records. Purchases are processed entirely by Apple. We receive a transaction identifier and the product purchased so we can add credits to your anonymous device ID. We never see your payment details.
- A push notification token, if you allow notifications, used only to tell you when your reCast is ready.
- Operational logs and metrics (request timing, error rates, queue depths) that contain no photo content and no personal information, kept to run the service reliably.
- Face data is derived on your device and stays there. The app computes face positions and on-device face feature prints to find the person you chose within your own photos. We never receive them — see Face data below.
How photos are processed
Photos are processed on our servers using Google’s Gemini API to generate the reCast results. Photo data is sent to Google for that processing under Google’s API terms, which for paid API usage exclude the use of your data to train Google’s models. No other third parties receive your photos.
Face data
Because reCasting means finding one particular person in your photos, the app works with face data. Here is exactly what that means, what stays on your device, and what does not.
- What is derived, and where. On your device only, the app detects faces in the photos you select and computes two things: the position of each face in the image (a bounding box and basic landmark points such as eyes and mouth, used to confirm a detection is really a face), and a face feature print — a numeric similarity vector produced by Apple’s on-device Vision framework from a crop of the face.
- What it is used for. The feature print is used for exactly one purpose: to recognise that a face in one of your photos is the same person as the identity you chose, so the app can find that person across the photos you selected. It is a similarity score between your own photos. It is never used to determine who a person is.
- Face feature prints never leave your device. Feature prints, bounding boxes, and landmark points are not transmitted to our servers, are not sent to Google, and are not shared with anyone. They are stored only in the app’s private storage on your device so a timeline can be resumed, and they are removed when you delete that timeline or uninstall the app. We never receive, store, or have any access to face feature prints or any other biometric template.
- What is sent to our servers. The photographs themselves, which of course contain faces: the reference image for each of the two identities (cropped around the face you selected) and the photos you chose to reCast. These are ordinary images. They are processed as described above and deleted within 72 hours. No face template is ever created or stored on our servers.
- Third parties. The only third party that receives these images is Google, as the AI processor generating your results, under Google’s API terms, which for paid API usage exclude using your data to train Google’s models. No face data is shared with anyone else, and none is sold, disclosed, or used for advertising or profiling.
- What we do not do. We do not perform facial recognition to identify individuals, do not match faces against any external database or watchlist, do not compare faces between different users, do not build face profiles, and do not use face data to train any model. The app does not use Face ID or any TrueDepth camera data.
- Retention, restated plainly. On-device face data: kept until you delete the timeline or the app. On our servers: no face templates, ever; the photos containing faces are deleted within 72 hours. You can request deletion of your device record at any time via Settings → Support in the app, or by emailing support@itwasneveryou.app.
Retention and deletion
- Uploaded photos, generated results, and related artifacts are automatically deleted from our servers within 72 hours of upload.
- Face feature prints are never uploaded — they exist only on your device and are deleted with the timeline or the app (see Face data above).
- Delivered results live in your own photo library, under your control. Edits made by the app are reversible — each edited photo preserves its original underneath, and you can revert any time in the app or in Apple Photos.
- Anonymous device records and credit ledgers are retained while the service operates, since they hold your remaining credit balance.
On-device safety screening
Before upload, every selected photo is screened on your device for nudity and sensitive content, using Apple’s Sensitive Content Analysis and a bundled on-device classifier. Flagged photos are excluded by default and stay on your phone; if you explicitly choose to include one anyway, it remains subject to the same server-side safety checks during processing. Additionally, our processing refuses requests where the person being replaced appears to be a young child (under 13).
Your responsibilities
Only reCast photos of yourself or people who have agreed. You are responsible for the content you process and for how you use the results.
What we don’t do
- No selling or sharing of your data for advertising.
- No training of AI models on your photos.
- No facial recognition to identify people, no face matching against any external database, and no face profiles. Face feature prints stay on your device and are never sent to us or to anyone else.
- No tracking across other apps or websites; the app contains no third-party analytics or advertising SDKs.
- No accounts, and no collection of names, emails, or contact details.
Your rights
Because we hold no identifying information, most data requests are satisfied automatically by the 72-hour deletion cycle. If you want your anonymous device record and credit ledger deleted, email support@itwasneveryou.app from within the app’s Settings → Support (which includes your anonymous device ID) and we will delete them. Depending on where you live (e.g. the EU/EEA, UK, or California), you may have additional statutory rights to access, correct, or delete personal data.
Children
The app is not directed at children and is rated for adult audiences. Processing refuses requests that appear to involve minors as the replaced person.
Security
All transfers use TLS. Server-side data is stored on infrastructure in the EU with access limited to the operator. Photos are stored only transiently, as described above.
Changes
We’ll post any changes to this policy on this page and update the date above. Material changes will be noted in the app.