Privacy Policy
1. Controller and contact
This policy explains how Passport Photo & ID Photo (the “App”) handles information. The data controller is APP BOX EOOD (Bulgarian: “Апп Бокс” ЕООД), UIC 207060361, with registered office at Lazur District, Block 109, Apartment 5, 8000 Burgas, Bulgaria (“APP BOX”, “we”, “us”). Privacy requests may be sent to info@appbox.group.
2. Photos and on-device processing
Photos you select or capture are processed on your device to validate the portrait, remove or replace the background, apply adjustments, crop, encode, export, and prepare print layouts. The App does not upload your photos or document images to APP BOX servers.
Temporary JPEG and PDF exports use iOS complete file protection. The App removes them after sharing finishes or the system share sheet closes. If sharing is interrupted, the App removes its own orphaned export files on the next launch or before another export. A finished photo is added to your library only after you choose to save it.
3. Information stored locally
The App does not require an account. Your language, onboarding state, and review-prompt state are stored locally in iOS user defaults. They remain on the device and can be removed by deleting the App. We do not collect your name, contacts, precise location, or the content of your photos through the App.
4. Analytics and crash diagnostics
Firebase Analytics and Firebase Crashlytics start automatically during ordinary production use of the App. Google may process automatically collected usage and session events; device model, operating-system, language, time-zone, and app-version details; approximate geography derived from an IP address; pseudonymous app-instance and Firebase installation identifiers; StoreKit product and transaction events; crash traces, relevant app state, and related technical diagnostics. Automated XCTest runs disable telemetry so test activity does not enter production reports.
The App never attaches photos or document images to analytics or crash reports. We disable advertising storage, advertising user data, advertising-personalization signals, IDFV collection, and cross-app tracking. We use telemetry only to measure feature use, diagnose failures, maintain security, and improve reliability. We do not sell it or use it for third-party advertising.
Where applicable law permits this processing without consent, our legal basis is our legitimate interest in operating, securing, diagnosing, and improving the App. There is no separate telemetry switch in the App. You may object by contacting us; because the App has no account and the identifiers are pseudonymous, we may be unable to associate an existing record with you. Deleting the App stops collection from that installation. Firebase Crashlytics keeps crash data and associated identifiers for 90 days before beginning removal from live and backup systems. Google Analytics event-level retention depends on the linked property setting and may be 2 or 14 months. Google may process telemetry outside the EEA under its applicable transfer safeguards. See Privacy and Security in Firebase and the Google Privacy Policy.
5. Purchases
Apple processes purchases and subscriptions through the App Store. The App receives product identifiers and verified StoreKit transaction and entitlement status so it can unlock premium features. APP BOX does not receive your payment-card details or Apple Account password. Apple handles purchase information under its App Store privacy notice.
6. Permissions
Camera access is used only when you choose to take a photo. Add-only photo-library access is used only when you save a finished image. The system Photos picker can provide an image you select without granting the App broad access to your library. You can change permissions in iOS Settings.
7. Support messages
If you email support, we receive your email address, message, and any information you choose to include. We use it to answer and administer the request. Please do not attach identity documents or sensitive photos. Support correspondence is removed when no longer needed and, unless a longer period is required for a legal claim, no later than 24 months after the request is closed.
8. Purposes, sharing, and retention
- Local settings are processed to provide the App features you request and remain until you delete the App or its data.
- App Store entitlement information is processed to perform the purchase contract and restore access.
- Analytics and diagnostics are processed for our legitimate interests described above and are shared only with Google for those purposes.
- Support correspondence is processed to answer your request and for our legitimate interest in maintaining the App.
We do not sell personal information. We disclose information only to Apple and Google for the purposes described, to service providers acting under appropriate obligations, or where disclosure is legally required.
9. Your rights
Subject to applicable law, including the GDPR, you may request information, access, correction, deletion, restriction, or portability and object to processing. Because the App has no account and we do not link Firebase identifiers to your identity, we may be unable to identify a particular diagnostic record without additional information. Contact us at info@appbox.group. You may also complain to the Bulgarian Commission for Personal Data Protection or your local EU/EEA supervisory authority.
10. Children, security, and changes
The App is not directed to children under 13. A parent or guardian should operate it when preparing a child’s document photo. We use reasonable technical and organizational safeguards, but no transmission or storage method is completely secure. We may update this policy when the App, providers, or legal requirements change. Material changes will be presented through the App or its store listing, and the effective date will be updated.