Privacy Policy for FaceToon – Cartoon Yourself
Effective date and last updated: July 10, 2026
Vision Labs Yazılım Hizmetleri Anonim Şirketi ("Vision Labs," "we," "us," or "our") operates the FaceToon – Cartoon Yourself mobile application (the "App"). This Privacy Policy explains what information the App collects, how and why it is used, when it is disclosed, how long it is retained, and the choices available to you.
1. Information We Collect
Photos and face data you choose to provide
When you choose a photo from your photo library or take a photo with your camera, the App processes the photo you selected. A selected photo may contain your face or another person's face. For purposes of this policy, "face data" means the visible image pixels and facial appearance contained in that photo and in the AI-generated result.
FaceToon does not use facial recognition, identify a person, verify identity, determine a person's name, create a face geometry template, create a biometric identifier, or compare faces against a database. We do not extract or store biometric templates from your photos.
The App collects a selected photo only after you take an affirmative action to select or capture it and separately consent to the disclosure described in Section 3 before the photo is uploaded.
App and service data
We may collect:
- a randomly generated app user identifier and anonymous authentication identifier;
- editing-session information, such as the selected cartoon style, processing status, source-image and result-image URLs, and timestamps;
- subscription and purchase status supplied by Apple and our subscription-management provider;
- feedback and an email address if you voluntarily submit them; and
- technical and diagnostic information needed to operate, secure, and troubleshoot the App, such as request status, errors, device/app version, IP address, and service logs.
We do not require you to create a named FaceToon account.
2. How We Use Information
We use information only as reasonably necessary to:
- upload the photo you selected;
- send that photo and an editing instruction to the AI service;
- generate, deliver, and display the cartoon or stylized result you requested;
- maintain the editing session and prevent duplicate processing;
- authenticate the App anonymously, protect the service, prevent fraud and abuse, and enforce usage limits;
- provide and verify subscriptions and purchases;
- respond to feedback, support requests, privacy requests, or legal obligations; and
- diagnose failures and maintain the security and reliability of the App.
We do not sell your photos or face data. We do not use them for advertising, facial recognition, identity verification, surveillance, profiling, or to train our own AI models. We do not use a photo for a new editing request unless you choose that photo again.
3. AI Processing and Disclosure to Service Providers
FaceToon cannot create an AI-edited image entirely on your device. Before an upload, the App asks for your permission and explains that the selected photo will be sent to Vision Labs' infrastructure and to the third-party providers below to create the requested result. If you do not consent, the photo is not uploaded and the AI editing feature cannot be used.
We disclose only the information needed for the provider's function:
| Provider | Data disclosed | Purpose |
|---|---|---|
| Google LLC / Google Cloud (including Firebase and the paid Gemini API image-generation service, currently using Google's Nano Banana image-editing model or a successor model) | selected photo, editing instruction/style, generated result, anonymous identifier, session data, and technical request data as applicable | anonymous authentication, backend functions, session processing, security, and AI image editing |
| Cloudflare, Inc. (Cloudflare Images and related delivery/security services) | selected photo, generated result, image URL, IP address, and technical request data | temporary image upload, storage, delivery, and service security |
| RevenueCat, Inc. | anonymous app user identifier, product/subscription information, purchase status, and related technical data | subscription entitlement management and analytics related to purchases |
| Apple Inc. | purchase and subscription information and data Apple collects through the App Store | payment processing, subscription management, refunds, and App Store operation |
These providers process data for the purposes described above under their applicable contractual and data-protection obligations. We require service providers that process personal data on our behalf to protect it to a level that is the same as or equivalent to the protections described in this policy and applicable law, and not to use it for unrelated purposes.
We use the paid Gemini API service under a Cloud project with billing enabled. Under Google's terms for paid Gemini API services, Google states that it does not use prompts, files (including images), or responses to improve its products, although Google may retain limited logs for a limited period for safety, security, and legal purposes. Google may process data in countries where it or its subprocessors operate.
Provider information is available at:
- Google Gemini API Additional Terms: https://ai.google.dev/gemini-api/terms
- Google Cloud Data Processing Addendum: https://cloud.google.com/terms/data-processing-addendum
- Google Privacy Policy: https://policies.google.com/privacy
- Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
- Cloudflare Data Processing Addendum: https://www.cloudflare.com/cloudflare-customer-dpa/
- RevenueCat Privacy Policy: https://www.revenuecat.com/privacy/
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
We may also disclose information if required by applicable law, legal process, or a valid governmental request; to protect users, our rights, or service security; or as part of a merger, financing, acquisition, or sale of assets, subject to appropriate safeguards and notice where required.
4. Face Data: Complete Collection, Use, Sharing, Storage, and Retention Statement
What face data is collected: only the photo selected or captured by the user, including any visible face pixels in that photo, and the AI-generated edited result. We do not collect face geometry, faceprints, biometric templates, identity matches, or face-recognition data.
How it is collected: directly from the user when the user selects a photo from the photo library or captures a photo with the camera and then consents to its upload and third-party AI processing.
All uses: to upload the selected photo, apply the style selected by the user, generate the requested edited image, return and display that image, maintain the short-lived editing session, prevent abuse, and diagnose a failed request. It is not used for identification, authentication, surveillance, advertising, profiling, or training Vision Labs' AI models.
Who receives it and where it is stored: the photo and result are processed through Vision Labs' service providers, specifically Google Cloud/Firebase and Google's paid Gemini API for backend and AI processing, and Cloudflare Images for temporary image upload, storage, and delivery. Data may be processed in countries where these providers operate, subject to their contractual safeguards. RevenueCat and Apple do not receive the selected photo or face data from FaceToon.
Retention: Vision Labs retains selected source photos, generated images, and image URLs for no longer than 30 days after the editing session is created, after which they are deleted or de-identified, unless earlier deletion is requested or a longer period is strictly required by law, security, fraud prevention, or dispute resolution. Editing-session records containing image URLs are deleted or stripped of those URLs within the same 30-day period. Temporary copies and cached data may persist for up to 30 additional days in provider backups or security systems before being overwritten or deleted under the provider's retention cycle. Google may retain limited safety and abuse-monitoring logs for the period stated in its paid Gemini API terms. Photos saved by you to your device are controlled by you and are not deleted when server copies are deleted.
5. Legal Bases and International Transfers
Where the GDPR, UK GDPR, or similar law applies, we process the selected photo and face data with your consent and to provide the feature you request; process service, security, and diagnostic data for our legitimate interests in operating and protecting the App; process purchase data to perform our contract with you; and process information when necessary to comply with law. You may withdraw consent before an upload by declining the prompt. After an upload, you may withdraw consent and request deletion as described below; withdrawal does not affect processing already completed lawfully.
Information may be transferred to and processed outside your country, including in Türkiye, the United States, and other locations where our providers operate. Where required, we and our providers use recognized safeguards such as adequacy decisions, standard contractual clauses, and data-processing agreements.
6. Your Choices and Rights
You can decline photo-library or camera access in iOS settings. You can also decline the in-app AI-processing consent; doing so prevents the photo from being uploaded but means the editing feature cannot operate.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of your personal data; withdraw consent; and complain to a data-protection authority. To exercise a right or request deletion of photos, face data, session records, or your anonymous App identifier, email [email protected] with enough information to locate the relevant data. We may need to verify the request. We will respond within the period required by applicable law.
Deleting the App does not cancel an Apple subscription. Subscriptions must be managed in your Apple Account settings.
7. Children's Privacy
The App is not directed to children under 13, or the higher minimum age required in their country. We do not knowingly collect personal data from a child below the applicable minimum age. If you believe a child has provided data, contact us so we can delete it. Users who are minors must have authorization from a parent or legal guardian where required.
8. Photos of Other People
Only upload a photo if you have the right and all necessary permission to use it. If a photo depicts another person, you are responsible for obtaining their permission before uploading it for AI processing. Do not upload a child's photo unless you are the child's parent or legal guardian or have valid authorization.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including encrypted network transmission and access controls. No storage or transmission method is completely secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this policy to reflect changes to the App, providers, or law. We will update the date above and provide additional notice when required. If a change materially expands how we use or disclose photos or face data, we will request new consent before applying that change to future uploads.
11. Contact
Vision Labs Yazılım Hizmetleri Anonim Şirketi
Ankara, Türkiye
Email: [email protected]
If applicable, you may also lodge a complaint with the Turkish Personal Data Protection Authority or the data-protection authority where you live.
© 2026 Vision Labs Yazılım Hizmetleri Anonim Şirketi. All rights reserved.