Privacy Policy
Effective date: July 18, 2026
This policy explains what information Lil Friends, LLC ("we," "us," "our" — the data controller, where laws use that term) collects when you use the lil friends mobile app and the website at https://lilfriends.app, how we use it, who we share it with, and the rights you have. If you have questions, contact hello@lilfriends.app.
Summary
- You can use lil friends without providing your name or email. A guest account is created automatically on first launch.
- Uploaded photos and generated portraits are stored privately. One exception: if you flag a portrait with the feedback button, our team may review it for quality assurance.
- Each generation sends your photo and the scene prompt to our AI image-generation provider, a US-based service. We do not use your photos, prompts, or portraits to train AI models, and our provider's API terms state that content submitted through its API is not used to train its models.
- We use analytics, including masked screen recordings of app sessions. Photos, portraits, and typed text are blacked out on your device before a recording is sent.
- Deleting a portrait removes its generated image. Deleting your account removes everything, with two narrow anti-fraud exceptions described in Section 6.
- We do not sell personal information, and the app shows no ads.
1. Information we collect
Information you provide:
- Photos. Pet photos taken with the in-app camera, chosen from your photo library, or shared into the app from another app. Photos are resized and re-encoded on your device before upload, which removes camera metadata such as location (EXIF/GPS).
- Prompts and scenes. The scene you pick for each portrait and, if you use the custom scene option, the text you enter.
- Pet profile. Your pet's name, type, gender, and traits.
- Account details (optional). If you link an Apple or Google account, we receive your email address from that provider and, from Apple on first sign-in only, your name.
- Feedback flags. A record created when you use the feedback button on a portrait (Section 4).
- Referral activity. Your referral code and records of referrals.
- Messages you send us, such as support emails.
Information created by using the app:
- Generated portraits and their thumbnails.
- Subscription, credit, and purchase records, including a ledger of credit-pack purchases (product, quantity, and the app store's transaction ID). We do not receive card or bank details; payment is processed by Apple or Google.
- A device identifier. A random ID stored in your device's secure storage (on iOS, the Keychain, which survives reinstalls). It is used only to enforce the one-per-person limits on the free first portrait and referral rewards.
- A push notification token, if you allow notifications.
Information collected automatically:
- Usage analytics and session replay (PostHog). Screens viewed, buttons tapped, and product events, tied to your account ID, along with device model, OS version, app version, language, and time zone. Session replays are masked: images (including your photos and portraits) and all text inputs are redacted on your device before the recording is sent, and the camera and photo-selection screens are masked entirely.
- Approximate location (city or region level), derived from your IP address by our analytics and crash-reporting tools. The app does not access GPS.
- Crash reports (Sentry, release builds only): stack traces and device information.
- Server logs, kept briefly for security and debugging.
- Website analytics cookies, described in Section 7.
Information from third parties: sign-in providers (Apple, Google) supply your email address and a sign-in token. Payment infrastructure (RevenueCat, Apple, Google) supplies subscription status and purchase events, never card numbers.
2. How we use information, and our legal bases
Where the GDPR or UK GDPR applies, each use has a legal basis:
- Providing the service — generating portraits, running your account, syncing purchases and credits, sending "portrait ready" notifications, operating the referral program. Basis: performance of a contract.
- Safety and fairness — moderating custom prompts before generation, enforcing one-per-person limits across accounts and devices, securing our systems. Basis: legitimate interests.
- Fixing and improving the app — analytics, session replay, crash reports, and human review of flagged portraits. Basis: legitimate interests. Replays are masked and deleted after 30 days, and none of this data is used for advertising. You can object at any time (Section 10), and we honor objections regardless of jurisdiction.
- Legal compliance — responding to lawful requests and keeping required records. Basis: legal obligation.
Camera, photo library, and notification access work only with permissions you grant through your operating system and can be revoked in device settings.
3. Data, purposes, and retention
| Category | Purpose | Legal basis | Retention | Shared with |
|---|---|---|---|---|
| Guest/account ID; email and name (if linked) | Account administration; keeping creations across devices | Contract | Until account deletion | Supabase (hosting); Apple/Google (sign-in) |
| Uploaded pet photos | Portrait generation, retries, regeneration | Contract | Until account deletion (deleting one portrait keeps its source photo, which is shared across retries and regenerations) | Supabase; our AI provider (US, per generation) |
| Prompts and scene choices | Generation; moderation of custom text | Contract; legitimate interests | Life of the portrait | Supabase; our AI provider (US) |
| Generated portraits and thumbnails | Display, saving, sharing | Contract | Until you delete the portrait or account | Supabase |
| Pet profile | Personalization | Contract | Until account deletion | Supabase |
| Feedback flags | Quality assurance, including human review (Section 4) | Legitimate interests | Until the flagged portrait or account is deleted | Supabase |
| Subscription, credits, purchase ledger | Paid features; preventing double-grants; recordkeeping | Contract; legal obligation | Until account deletion (Apple, Google, and RevenueCat keep their own transaction records) | RevenueCat, Apple, Google, Supabase |
| Device ID + perk ledger; hashed sign-in identity | Anti-fraud | Legitimate interests | Kept after account deletion (Section 6) | Supabase |
| Push token | Service notifications | Contract (with OS permission) | Until invalid or account deletion | Expo (relay), Apple, Google |
| Usage analytics events | Service improvement | Legitimate interests | 7 years | PostHog (US) |
| Masked session replay | Service improvement | Legitimate interests | 30 days | PostHog (US) |
| Crash reports | Debugging | Legitimate interests | 90 days | Sentry (US) |
| Server logs | Security, debugging | Legitimate interests | About 7 days | Supabase |
| Website analytics cookies | Site usage measurement | Legitimate interests | 7 years (event data) | PostHog (US) |
4. Human review of flagged portraits
If you tap the feedback (thumbs-down) button on a portrait:
- What is recorded: a flag linking your account to that portrait, with a timestamp.
- What may be reviewed: authorized employees of Lil Friends, LLC may view the flagged generated portrait, the photo it was made from, and its prompt or scene text, together, through internal tools, to diagnose quality problems.
- Purpose: quality assurance and improving our scenes, prompts, and generation pipeline. Flagged content is not used to train AI models.
- Retention: no separate copies are made for review; review reads the same stored content. If you delete the flagged portrait or your account, the flag is deleted and the content is no longer available for review (the uploaded photo follows the retention rule in Section 3).
- Access: limited to authorized employees who need it for quality assurance.
Using the feedback button is optional.
5. AI generation
To create a portrait, we send your uploaded photo and the scene prompt to our AI image-generation provider, a US-based service, which returns the generated image. Custom scene text is first checked by the provider's content-moderation service and rejected if it violates safety rules.
The provider's API terms state that content submitted through its API is not used to train its models. The provider may keep API content briefly for abuse monitoring under its own policies. We do not use your photos, prompts, or portraits to train AI models.
Generated portraits are stored privately and shown only to your account. Locked portraits carry a watermark until unlocked.
6. Retention and deletion
- Deleting a portrait permanently removes the generated image, its thumbnail, and any feedback flag. The photo it was generated from is kept until account deletion, because retries and regenerations share it.
- Deleting your account (Account screen, while signed in) permanently deletes your profile, pets, photos, portraits, credits, purchase ledger, referral links, and push token, and revokes our Sign in with Apple access. This is irreversible.
- Anti-fraud records kept after deletion: (1) a one-way cryptographic hash of your Apple/Google sign-in identity and (2) the app-generated device ID, each with two yes/no flags recording whether the free first portrait and the referral reward were used. These cannot be used to reconstruct your name, email, photos, or portraits. They exist so account deletion cannot be used to claim one-per-person perks again, which we consider a proportionate anti-fraud measure consistent with data-minimization principles.
- Guest accounts: if you never link an account and uninstall the app, we have no way to connect you to your guest data and cannot verify a later deletion request for it. To ensure deletion, delete your portraits — or link an account and delete it — before uninstalling.
- Third-party copies: analytics, session recordings, and crash reports expire per the retention periods in Section 3. Apple, Google, and RevenueCat retain transaction records under their own policies.
- Residual copies may persist briefly in backups and logs before rotating out.
7. Cookies, tracking, and analytics choices
In the app: the app does not use cookies. It includes SDKs for analytics and session replay (PostHog) and crash reporting (Sentry), and uses on-device storage for your session, preferences, and the device ID described above. There are no advertising SDKs, no use of the advertising identifier (IDFA/AAID), and no tracking across other companies' apps or websites.
On the website: lilfriends.app uses cookies and similar technologies for PostHog analytics to measure site usage. They are not used for advertising, and no third party gets access to them for its own purposes. You can block or delete cookies in your browser settings. Because we do not sell personal information or share it for advertising, there is no "sale" or "sharing" to opt out of, and the site does not respond to Do Not Track or Global Privacy Control signals.
Opting out of analytics: email hello@lilfriends.app and we will exclude you from analytics and session replay going forward and delete the analytics data associated with you. We honor these requests regardless of where you live.
8. When we share information
We share personal information only with:
- Service providers operating parts of the service under contracts that limit their use of it: Supabase (database, storage, authentication — hosted on AWS in Oregon, USA), an AI image-generation provider (image generation and prompt moderation, US), PostHog (analytics/replay, US), Sentry (crash reporting, US), RevenueCat (subscription management), Expo (push delivery and app updates), and Apple/Google (sign-in, payments, push delivery).
- Authorities and others when legally required, to comply with law or valid legal process, enforce our Terms, or protect the rights, safety, or property of users, the public, or Lil Friends, LLC.
- A successor business, if we are involved in a merger, acquisition, or sale of assets, subject to this policy's protections.
- Recipients you choose, for example when you use the share button.
We do not sell personal information and do not share it for cross-context behavioral advertising.
9. International transfers
We are a US company. Our database and storage run on AWS in Oregon, and the providers above process data in the United States. If you use lil friends from the EU, UK, Switzerland, or elsewhere, your information is transferred to the US.
These providers maintain their own transfer safeguards: several are certified under the EU–US Data Privacy Framework (with UK and Swiss extensions), and their standard service terms incorporate the EU's Standard Contractual Clauses for customer data — for example, the cloud platform hosting our database applies its data-processing terms, including those clauses, to all customers. Contact hello@lilfriends.app for details.
10. Your rights
Depending on where you live, you may have the right to: access the personal information we hold about you and receive a copy in a portable format; correct inaccurate information; delete your information; object to or restrict certain processing (including analytics based on legitimate interests); withdraw consent where processing is based on consent; and complain to your local data protection authority (EU: edpb.europa.eu; UK: ico.org.uk).
Portrait deletion and account deletion are available directly in the app (Section 6). For other requests, email hello@lilfriends.app from the email linked to your account so we can verify you. We respond within the time your local law requires (one month under GDPR; 45 days under California law). We may decline requests we cannot verify or that the law permits us to decline — including for the anti-fraud records in Section 6 — and will explain why. You may act through an authorized agent where the law provides; we will verify the agent's authority. We do not discriminate against anyone for exercising privacy rights.
11. California residents (CCPA/CPRA)
In the last 12 months we collected these categories of personal information: identifiers (account ID, device ID, email if linked, IP address); commercial information (purchases, subscriptions, credits); internet or electronic network activity (app usage, masked session replays, website analytics); audio/visual information (uploaded photos, generated portraits); approximate geolocation (from IP); and inferences only to the extent of product analytics. Sources, purposes, and recipients are described in Sections 1–3 and 8.
We do not sell personal information or share it for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. We do not use or disclose sensitive personal information beyond what is necessary to provide the service.
California residents have the rights to know/access, delete, correct, limit certain uses, non-discrimination, and use of an authorized agent, exercisable as described in Section 10. Because there is no sale or sharing, there is nothing to opt out of; per Section 7, the website does not respond to Do Not Track or GPC signals.
12. Other regions
This policy applies globally, and we honor the rights your local law provides — including Brazil's LGPD, Canada's PIPEDA, and Australia's Privacy Act — exercisable as described in Section 10.
13. Security
Photos and portraits are stored in private buckets readable only by your account, and portrait images are served through short-lived signed links. Custom prompts are moderated before generation. Access to production systems is limited to authorized people. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects you, we will notify you as the law requires.
14. Children
lil friends is not directed at children under 13, and we do not knowingly collect personal information from them. The app does not ask for your age. If you believe a child under 13 has used lil friends, contact hello@lilfriends.app and we will delete the associated information. Users under the age of majority should use lil friends only with a parent or guardian's consent.
15. Changes to this policy
We may update this policy. For material changes, we will give notice in the app or by other reasonable means before they take effect and update the date above. Where the law requires consent to a change, we will ask for it.
16. Contact
Lil Friends, LLC
7601 Cooper Ln, Bldg 23
Austin, TX 78745, USA
Email: hello@lilfriends.app
Website: https://lilfriends.app
We have not appointed a Data Protection Officer or an EU/UK representative. If that changes, we will list them here.