fotufilm

Privacy Policy

For the Fotufilm app (com.muastudio.fotufilm) on iOS, iPadOS and macOS.
Effective 27 July 2026 · Last updated 31 August 2026

Your photos and video are processed entirely on your device and are never uploaded. Fotufilm has no advertising or analytics. Optional crash reporting is off by default and sends no media or identifying account or device data. The Mac app has no activation requests. It may fetch a release-description file when checking for updates. Account sign-in and pack downloads happen in the browser portal.

The short version

Fotufilm is a film simulation app. It reads an image you choose, runs it through a physical model of photographic film, and gives you the result. All of that computation happens on your device, using its own processor and GPU.

The Fotufilm engine that performs image processing runs entirely on your device. The Mac build may use the network to check for app updates. Those requests contain no photos, video, editing settings, filenames, or account password. On iPhone and iPad, you may separately choose to share the limited crash diagnostics described below.

Account data

Information about existing accounts

The current Mac app does not send licence keys or device identifiers. Earlier app releases may still use their original activation service. We retain their activation records to support those purchases.

Checking for updates is separate from licensing. The app fetches a release-description file from our download host. The request carries no license, device, or account information; as with any web request, the connection itself reveals your IP address to the host.

The browser portal uses Firebase Authentication. It stores your email address, Firebase user ID, authentication provider, purchase status, and download entitlements. Earlier desktop purchases also retain their licence keys and activated-device lists. Your password, when you use email sign-in, is handled by Firebase Authentication and is not stored in Fotufilm's license database. The license key is not an account credential and cannot be used to retrieve your sign-in information.

Checkout is handled by Stripe. Stripe receives the payment and billing information you enter. We retain Stripe transaction identifiers, purchase amount and currency, and payment status, but do not receive or store your full card number.

What the app accesses on your device

iOS, iPadOS and macOS will ask your permission before Fotufilm can touch any of the following. You can grant or revoke each one at any time in your system Settings, and the app keeps working with reduced functionality if you decline.

Camera

Used only to show and develop the live viewfinder while you have the camera open. Frames are processed in memory and discarded. Nothing is recorded unless you deliberately take a photo.

Photo library

Used only to let you pick a photo or video to develop, and to save a developed result back to your library when you ask. The app reads the item you select; it does not scan, catalog, index or upload your library.

Files you open

Images and video you open stay on your device. Intermediate files the app writes while developing are temporary and are removed by the system.

Optional crash reports

Settings › Privacy › Share Crash Reports is off by default. If you turn it on, Apple's MetricKit gives Fotufilm a diagnostic after a crash. Before it is stored or sent, the app reduces that diagnostic to the Fotufilm app version and build, iOS or iPadOS version, device model, processor architecture, numeric exception and signal values, and the binary names, UUIDs and offsets needed to symbolicate the crash stack.

Crash reports do not include photos, videos, filenames or file paths, photo metadata, location, editing settings, free-form logs, memory contents, exception messages, contact information, account or license identifiers, or a stable device identifier. Each report has a random ID used only to prevent duplicate storage. Reports are sent directly to Fotufilm's service over HTTPS and are not linked to portal or licensing records. You can turn sharing off at any time; doing so deletes reports still queued on the device.

What we collect

Fotufilm does not collect image content or editing activity. The desktop licensing portal processes the limited account and activation information described above. Optional crash data is collected only after you turn on Share Crash Reports.

Data category Collected?
Contact infoEmail address for portal accounts
Health & fitnessNot collected
Financial infoSee existing account information above
LocationNot collected
Sensitive infoNot collected
ContactsNot collected
User content (photos, video, other files)Not collected
Search & browsing historyNot collected
IdentifiersFirebase user ID and one-way desktop device identifier
Account recordsSee existing account information above
Crash dataOptional, unlinked diagnostic reports when Share Crash Reports is on
Usage data and analyticsNot collected by Fotufilm
Other dataNot collected

Fotufilm does not use this information for advertising, does not sell it, does not share it with data brokers, and does not use the Advertising Identifier. The app contains no advertising, attribution, or analytics SDK.

Third parties

Fotufilm bundles no third-party analytics, advertising, or attribution SDKs. The image-processing and numerical libraries run locally and are listed with their licenses in the third-party notices. Account services use Google Firebase and Stripe, which process data as service providers under their own privacy terms. Hosting providers may record standard security and request logs, including an IP address and user agent. The crash-report service necessarily receives an IP address while delivering and rate-limiting the HTTPS request, but does not attach or store it with the report.

Information Apple may collect

Downloading and running an App Store app involves Apple, not just us. Apple operates the App Store and may collect data about App Store activity and app usage under Apple's own privacy policy, which we do not control.

Retention and deletion

Account records are retained while needed to provide access, prevent misuse, handle support, and meet legal obligations. Optional crash reports are automatically deleted within 30 days and cannot be associated with a portal account or person. You may ask us to delete or export portal account data at support@fotufilm.com, subject to records we must retain. You can remove imported packs in the app. Deleting the app does not delete your saved photos or necessarily remove its settings and pack files.

Children

Fotufilm is not directed at children and the portal is intended for adults. The app has no social features, messaging, external user content, or advertising.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete personal information. Send a request from your account email to support@fotufilm.com. We do not sell personal information.

This website

The main site is served as static pages and runs no analytics. The license portal uses browser storage and cookies required for account access. Hosting providers record standard server logs as described in their privacy terms, including GitHub's privacy statement.

Changes to this policy

If Fotufilm ever gains a feature that changes any of this, we will update this page and move the effective date above before that version ships, so the date at the top always tells you which version of the policy you are reading.

Contact

Questions about this policy, or about privacy in the app, go to support@fotufilm.com and a person will answer them.