Privacy Policy
The short version. Your photos, depth data, Live clips and doodles stay on your device, and we never receive your pictures. We run no advertising and no tracking. What leaves the app is limited to what is needed to sell you Pro and to know that you own it, plus anonymous crash reports and usage statistics that help us keep the app working — none of which identifies you.
1. Who this policy covers
This policy describes how the Toasto iOS app and the website at toasto.app handle information. Toasto is a simulated instant film camera: it reproduces the ejecting, developing and peeling of instant film prints, gives photos a 3D parallax effect, and can keep a short Live clip around each shot.
Toasto has no user accounts. You do not register, and we do not ask for your name, email address or phone number.
2. What Toasto stores on your device
Everything the app produces is written to Toasto's own private storage on your iPhone. This includes:
- the photos you take, including the untouched original pixels that make filters reversible;
- depth data — either recorded by the camera hardware at the moment of the shot, or estimated on device when the hardware cannot supply it;
- Live clips — about a second and a half of motion and sound around a shot, recorded only when the LIVE key on the deck is on;
- the location of a shot, written into the photo's metadata only if you turn on Record location in Settings (it is off by default);
- doodles, frame styles, paper textures, filter and lens-effect choices, and the develop or peel state of each print;
- your film stock count and the timer that restores it;
- app settings, such as the iCloud sync switch and whether Pro is unlocked.
This content is not written to your system photo library, and it is not transmitted to us. We operate no server that receives your photos.
3. iCloud sync (Pro, optional)
iCloud sync is a Pro privilege and is off unless you turn it on in Settings. When it is on, your photo library — photos, depth data, doodles, edit parameters and state — is synchronised through your own private CloudKit database, inside your personal Apple account.
A private CloudKit database is readable only by you and your signed-in devices. We are the app's developer, not a party to that database: we cannot read, browse, copy or recover its contents, and we receive no copy of it.
While sync is on, Apple may deliver silent background notifications to your devices so that they stay in step. These carry no content from us.
Your use of iCloud is also governed by Apple's own terms and privacy policy. Turning sync off stops further synchronisation; data already in your iCloud account remains there until you delete it, which you can do from your device or from iCloud storage management in iOS Settings.
4. Purchases and Pro
Toasto Pro is sold as an auto-renewing subscription (monthly or yearly) or as a one-time lifetime purchase. All payments are handled by Apple through In-App Purchase. We never see or receive your payment card, your Apple account credentials or your billing address.
We use RevenueCat as our purchase infrastructure — it verifies receipts and tells the app whether Pro is unlocked. In connection with a purchase, a restore, or a routine entitlement check, RevenueCat receives:
- an anonymous app user identifier generated on your device by the RevenueCat SDK — it is not your name, email or Apple ID, and we do not link it to your identity;
- the App Store transaction receipt and the resulting subscription or purchase status;
- basic technical context reported by the store or the device, such as platform, app version and store country.
This information is used only to unlock Pro, to keep it unlocked, and to let you restore purchases on another device. It is never used for advertising, profiling or resale. RevenueCat processes it on our behalf as a service provider. Apple's own handling of the transaction is covered by Apple's privacy policy.
5. Device permissions
- Camera — required to take photos. Frames are processed on device. The live preview is never recorded or transmitted.
- Motion sensors — used to drive the 3D parallax effect, so a photo leans as you lean the phone. Readings are used in the moment and are neither stored nor sent.
- Microphone — used only while a Live clip is being recorded, so that the clip has sound. You can decline: Live clips are then recorded without audio. Nothing recorded by the microphone is transmitted to us.
- Photo library — when you save a print, Live photo or short film, Toasto files it into an album named "Toasto" in your system photo library. iOS offers no permission level that can add to a specific album without read access, so Toasto asks for full access — and uses it only to find or create that album. It reads the list of albums; it never reads, uploads or displays any of your existing photos or videos. If you grant access to selected photos only, Toasto saves without an album.
- Location — optional, and only if you turn on Record location in Settings. The coordinates are written into the metadata of the photo, on your device, the way a system camera does. They are never sent to us, and the "Photo" export strips them before the file leaves the app.
Toasto does not request access to your contacts.
6. What we do not do
- No advertising and no ad networks.
- No tracking of you across other apps or websites, and no data broker relationships.
- No advertising identifier (IDFA), no App Tracking Transparency prompt, and no attribution SDKs.
- No selling or sharing of personal information.
- No accounts, no email lists, no push marketing.
7. Diagnostics and usage analytics
Since version 1.1, Toasto uses Google Firebase — Crashlytics, Performance Monitoring and Google Analytics for Firebase — to learn whether the app crashes, how long it takes to start, and which features are used. This lets us find and fix problems we would otherwise never hear about. Firebase receives:
- crash reports and performance traces: the app version, the iOS version and device model, and a stack trace of what the app was doing when it crashed;
- usage events, such as "a photo was taken", "a Live photo was saved" or "a paywall was shown", with coarse parameters like the paper size or filter chosen — never the photo itself, never its content, and never a location;
- a random installation identifier generated by the SDK on your device, plus coarse device context (locale, country, app version).
We use the build of the analytics SDK that cannot access the advertising identifier (IDFA), the app never shows an App Tracking Transparency prompt, and we do not link this data to you or to your purchases. Google processes it on our behalf as a service provider, under its own Firebase privacy terms. This version of the app does not have an in-app switch to turn diagnostics off; if you would like the data tied to your installation deleted, write to us (section 9) and we will request it.
8. Sharing and export
Nothing leaves Toasto's shelf unless you send it. When you use the share panel to save a print, a Live photo, a 3D wiggle or a short film to your photo library, to message it or to post it, the file goes to the destination you pick, and that destination's own terms and privacy policy then apply to it. Exports made without Pro carry a small Toasto badge. The "Photo" export (the picture without its paper border) carries the usual image metadata but never the location.
9. Retention, deletion and your rights
Because we hold no copy of your content, there is nothing on our side to retain or delete. You are in control of the two places your data can live:
- On your device — delete individual prints in the app, or delete the app to remove its storage entirely. If iCloud sync was never turned on, photos you never exported are gone for good once the app is deleted.
- In your iCloud — delete synced data from any signed-in device, or through iCloud storage management in iOS Settings.
Anonymous crash reports and usage events held by Google Firebase are retained under Google's policies (crash data for 90 days, analytics events for up to 14 months) and are not linked to you. The anonymous purchase record held by RevenueCat, and the transaction record held by Apple, are retained under their respective policies. If you would like the anonymous purchase record associated with your installation deleted, write to [email protected] and we will pass the request on; note that deleting it may prevent Pro from being restored later. The same address works for deleting the Firebase data tied to your installation identifier. Depending on where you live, you may also have rights to access, correct, delete or object to the processing of personal data; the same address is the way to exercise them.
10. Children
Toasto is not directed at children under 13, or under the minimum age of digital consent where you live, and we do not knowingly collect personal information from them. The app collects no personal information from anyone beyond the anonymous identifiers described above, so there is nothing for us to hold — but if you believe a child has provided personal information to us in some other way, please write to us and we will delete it.
11. This website
toasto.app is a static site. It sets no cookies. We use Cloudflare Web Analytics, a cookieless service, to count page views and see which pages people find useful; it does not fingerprint or identify you. If you dismiss the language suggestion bar, that choice is kept in your browser's local storage on your device and is not sent to us. As with any website, the hosting provider may keep short-lived standard server logs — such as IP address, request time and user agent — for delivering and securing the site.
12. Changes to this policy
If this policy changes, the effective date at the top of the page changes with it, and we will describe material changes here or in the app. Continuing to use Toasto after a change means you accept the updated policy.
13. Contact
Questions, requests or corrections: [email protected]. We are a small independent developer and read every message.