Privacy Policy

Privacy, explained clearly.

This Policy explains exactly when information stays on your device, when it is sent to Lensora, how optional analytics works, and the choices available to you.

Last updated: August 26, 2026 · Effective date: August 26, 2026 · Effective for Lensora iOS

01. Scope and Data Controller

This Privacy Policy explains how LENSORA INC, a Delaware corporation ("Lensora," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information when you use the Lensora iOS application, lensora.ai, and related services (collectively, the "Services").

LENSORA INC is the controller or business responsible for the personal information described in this Policy, except where another entity is identified as independently responsible for its own processing.

This Policy applies to the public version of Lensora available on the App Store. It does not describe future features until they are made available to users.

02. Privacy Summary

  • Ordinary photos and videos that you view, edit, capture, or scan stay on your device unless you deliberately choose one as a profile image or send content to us for support.
  • Scan images, live camera previews, face analysis, and composition analysis use Apple Vision and Core ML models and are processed on your iPhone. Camera frames, Scan images, and face-analysis data are not sent to Lensora, PostHog, any cloud AI provider, or any other third party.
  • Your Apple sign-in email, profile name, profile image, and profile background image are stored by Lensora so your account and profile can sync across devices.
  • Optional product analytics and privacy-protected Session Replay are off by default. Lensora does not initialize PostHog or send analytics data unless you open Settings → Allow Analytics, affirmatively enable it, and confirm the disclosure.
  • We do not sell personal information, share it for cross-context behavioral advertising, or use user photos to train AI models.
  • The current public version is completely free. It has no In-App Purchases, subscriptions, trials, paid content, paid feature unlocks, or access to digital benefits purchased through a website or another channel. StoreKit, subscription listeners, product loading, purchase-history checks, and subscription APIs do not start in the current public version.

03. Information We Collect and Its Sources

We collect information directly from you, from Apple when you use Sign in with Apple, from your device only after you opt in to optional analytics, and from service providers that help us operate the Services.

  • Account identifiers: the stable Sign in with Apple account identifier and the email address Apple provides. If you choose Hide My Email, we receive Apple's private relay address rather than your personal email address.
  • Profile information: the name, profile image, and profile background image you choose to provide.
  • Device and app information after analytics opt-in: device model, iOS version, app version, language, and similar technical context.
  • Usage and environment-analysis information after analytics opt-in: selected screen, click, feature-use, template, and interaction events that Lensora deliberately instruments. A completed Scan event may include limited non-image results such as scene category, pose result, object count, and background-complexity classification, but never face data, face bounding boxes, facial geometry, or source-image pixels. Automatic screen-view collection and automatic rage-click collection are disabled.
  • Approximate location after analytics opt-in: PostHog may infer city- or region-level location from the IP address used to transmit analytics. This is separate from any precise location permission used by an on-device camera feature.
  • Diagnostics: deliberately reported app-error events, performance or failure context, and system logs you choose to include in a support request.
  • Support and communications: your email address, message, and any screenshot, photo, video, screen recording, or log that you deliberately send to us.
  • Early-access website information: if you join a waitlist or survey on lensora.ai, we collect the email address and answers you submit.

04. Photos, Videos, Camera, and Photo Library

Lensora requests camera or photo-library permission only to provide features you choose to use. You can change these permissions at any time in iOS Settings.

  • Camera preview: frames may be analyzed in real time on your device to provide composition, framing, face, body, pose, and shooting guidance. Camera frames are not uploaded to Lensora or PostHog.
  • Scan: when you choose a photo for Scan, Apple Vision and Core ML models analyze that photo on your device. The photo itself and all face-analysis data are not sent to Lensora, PostHog, any cloud AI provider, or any other third party. After analytics opt-in, limited non-image results—such as scene category, pose result, object count, and background-complexity classification—may be included in a Scan analytics event sent to PostHog; these results exclude face data, face bounding boxes, and facial geometry.
  • Ordinary viewing or editing: photos remain on your device and are not automatically analyzed by Scan.
  • Profile images: a photo becomes server-hosted personal information only when you deliberately choose and confirm it as your profile image or profile background. The cropped JPEG is then uploaded to Lensora for cross-device sync.
  • Location metadata: if you grant location permission for a capture feature, Lensora may access precise location at the time of capture so iOS can associate location metadata with the photo or video saved on your device. Lensora does not send that precise location to its API or PostHog merely because it is attached to local media. Location metadata may travel with media if you later upload, export, or share it.
  • Microphone and audio: when you choose a capture mode that records video or otherwise includes sound, Lensora uses the microphone to record audio as part of that media. Lensora does not separately upload that audio to its API or PostHog; it remains with the media on your device unless you upload, export, share, or send the media at your direction.
  • Saving and exporting: content you save to the photo library, export, or share is handled at your direction through iOS and the destination you choose.
  • Support: content is transmitted to us only if you deliberately attach or send it in a support or feedback request.

Photos stored locally may also be included in device backups controlled by you and Apple. Deleting the Lensora app does not necessarily delete copies you saved elsewhere or copies contained in your device backups.

05. On-Device AI and Computer Vision

Lensora uses Apple Vision and on-device Core ML models, including object, scene, face, body, and pose analysis, to provide creative photography guidance. Current image analysis occurs locally on your device.

  • We do not use face or body analysis to determine your identity.
  • We do not create facial templates or biometric profiles.
  • We do not send camera frames or Scan photos to a cloud AI service.
  • After analytics opt-in, we may send limited non-image Scan classifications and counts to PostHog for product analytics. We do not send the source photo, camera frame, face data, face bounding boxes, or facial geometry with those results.
  • We do not use your photos, face, body, or appearance to train AI models.
  • Images described in the app as AI-generated are static creative assets prepared by Lensora; they are not generated from a user's prompt or personal photo.

05A. Face Data: Collection, Use, Storage, Sharing, Retention, and Deletion

What is processed. Lensora does not collect face data on its servers. On the device, Lensora temporarily processes face presence and count, normalized face bounding boxes such as position and size, and, where required for framing guidance, limited facial-landmark geometry. These transient observations are used only to position photography guidance and evaluate composition.

What is not derived. Lensora does not identify a person's face; create a faceprint, facial template, or biometric profile; perform facial recognition; infer a name, age, gender, race, ethnicity, health condition, or other sensitive identity attribute; or use any person's face, body, or appearance to train an AI model.

Use. Transient face-analysis values are used only to determine whether a face is in the frame; estimate its position and size; provide subject-distance and composition prompts; provide pose, head-position, and shooting guidance; and update the interface during the current live-camera or Scan analysis. They are not used for advertising, identity verification, or user profiling.

Sharing. Face data, facial geometry, face bounding boxes, camera frames, and Scan images are not transmitted to Lensora, PostHog, any cloud AI provider, or any other third party. They are not uploaded, shared, or sent off the device.

Storage. Face analysis occurs only in temporary memory on the device. Its outputs are not written to a Lensora database, object storage, user account, or PostHog, and Lensora creates no persistent face record. A photo that you deliberately capture or save is user-managed media; saving that photo does not cause Lensora to store the separate face-analysis values.

Retention. Transient face-analysis values are retained only for the time necessary to perform the current live-camera or Scan analysis. They may remain briefly in volatile memory until replaced by later analysis or until the analysis session ends. They are then discarded. Lensora has zero server-side retention of face data.

Deletion and control. Because transient face-analysis values are discarded automatically and never stored by Lensora, no separate deletion request is needed. You can stop further processing by ending Scan, leaving the camera feature, closing the app, or revoking camera or photo access in iOS Settings. Photos you deliberately save are managed by you through Photos and iOS and are a different data category from face-analysis data.

06. Account and Profile Information

Lensora currently supports Sign in with Apple. We use the Apple account identifier and email address to authenticate you, maintain your account, support account recovery, prevent abuse, and communicate about the Services.

Your profile name is sent to the Lensora API hosted on Railway, and account and profile records are stored in a Neon database. Profile and background images are uploaded as JPEG files to Cloudflare R2 object storage, and the API returns hosted image URLs. This information is used to display your profile and synchronize it across devices.

The app also stores a local copy of your profile name and images on your device. A failed upload may remain queued locally and retry automatically when a connection becomes available.

Do not provide another person's name or image without permission. At launch, Lensora does not use profile information for advertising or make it available through a public user-search directory.

07. Analytics, Diagnostics, and Session Replay

Optional Analytics and Session Replay are off by default. Lensora does not initialize PostHog or transmit analytics data until the user opens Settings → Allow Analytics and affirmatively confirms the in-app disclosure. After that choice, Lensora uses PostHog, Inc., through PostHog US Cloud to understand feature use, diagnose problems, and improve reliability. Events are routed through e.lensora.ai, a Cloudflare-hosted endpoint, before reaching PostHog.

After sign-in, Lensora identifies the PostHog person using the stable Sign in with Apple identifier and aliases the Lensora backend user ID. Analytics associated with that identifier may therefore be linked to your account.

Session Replay records a privacy-protected reconstruction of app-interface interactions. It is not a camera video. Lensora protects or excludes camera surfaces, user photos, text inputs, profile information, photo pickers, cropping flows, passwords, and Apple sign-in interfaces on the device so that protected content is not sent to PostHog.

  • Data that may be sent after opt-in: selected product-interaction events; diagnostic and error events; device model, iOS version, app version, language, and similar device or app information; identifiers associated with the account; approximate location inferred from IP; and privacy-protected Session Replay interface interactions.
  • Data that is never sent to PostHog: camera views or preview frames; user photos or videos; original Scan images; face-analysis data; face position, face bounding boxes, or facial features and geometry; text typed by the user; passwords; or Apple sign-in interfaces.
  • A completed Scan event may include limited non-image environment-analysis results, including scene category, pose result, object count, and background-complexity classification. It excludes the Scan image, camera frame, and all face-analysis data.
  • We use this information for product analytics, troubleshooting, security, and service improvement—not advertising.
  • When Allow Analytics is turned off, Lensora immediately stops future Analytics and Session Replay, closes the PostHog SDK, and clears locally pending PostHog queues without forcing a final upload. No last upload is performed during shutdown.
  • Information already received by PostHog does not disappear solely because the switch is turned off. Deleting your Lensora account submits deletion of the associated PostHog person and queues deletion of account-linked events and Session Replay recordings captured before the deletion request. You may also submit a privacy deletion request to [email protected].

Tutorial choices such as Start Tutorial and Skip Now control only the tutorial. They do not grant analytics consent, initialize PostHog, or send data to a third party.

08. How and Why We Use Information

We use personal information only for the following purposes:

  • Provide, secure, maintain, and troubleshoot the Services.
  • Authenticate accounts and synchronize profile information across devices.
  • Respond to support requests and communicate service or security information.
  • Understand selected feature usage and improve performance when analytics is enabled.
  • Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms.
  • Comply with applicable law, enforce agreements, and establish, exercise, or defend legal claims.
  • Create aggregated or de-identified statistics that are not reasonably capable of identifying an individual.

09. Legal Bases for EEA, UK, and Similar Jurisdictions

Where applicable law requires a legal basis, we rely on the following bases:

  • Contract: processing account identifiers, profile information, and service requests as necessary to provide the Services you request.
  • Consent: optional Analytics and Session Replay always depend on your separate, affirmative choice in Settings → Allow Analytics. Lensora sends no analytics data before that choice. You may withdraw consent at any time; withdrawal does not affect processing lawfully completed before withdrawal. Camera and photo-library permissions are controlled separately by iOS, and Start Tutorial or Skip Now is not privacy consent.
  • Legitimate interests: securing the Services, preventing abuse, responding to support, maintaining reliability, and improving non-sensitive product functionality, balanced against your rights and expectations.
  • Legal obligation: retaining or disclosing information when necessary to comply with law.
  • Legal claims: establishing, exercising, or defending legal rights.

You are not required to provide optional profile images or enable analytics. Without account information, however, we cannot create and synchronize a Lensora account.

10. When We Disclose Information

We do not sell personal information or share it for cross-context behavioral advertising. We disclose only the information reasonably necessary for the purposes below:

  • Apple: Sign in with Apple, iOS permissions and device services, and App Store distribution. Apple acts under its own terms and privacy policy for services it controls.
  • PostHog, Inc. (United States), using PostHog US Cloud: used only after you opt in through Settings → Allow Analytics. PostHog may receive selected product-interaction events, diagnostic and error events, device and app information, pseudonymous or account-linked identifiers, approximate location inferred from IP, and privacy-protected Session Replay. It does not receive camera frames, user photos or videos, original Scan images, face data, face bounding boxes, facial geometry, typed text, passwords, or Apple sign-in interfaces.
  • Cloudflare, Inc. (United States and global infrastructure): network delivery, security, reverse proxying for analytics, and Cloudflare R2 object storage for profile and profile-background JPEG files.
  • Google LLC (United States and global infrastructure): Google Workspace email used to receive and respond to messages sent to Lensora addresses.
  • Railway (US West, California, United States): application and API hosting. Railway may process service requests, account and profile data in transit, and technical or server-log information needed to operate and secure the Services.
  • Neon (AWS US East (N. Virginia), us-east-1, United States): managed PostgreSQL database hosting for account identifiers, email, profile names, profile-image references, and related service records.
  • Professional advisers and authorities: lawyers, auditors, insurers, courts, regulators, or law enforcement when reasonably necessary and legally permitted.
  • Corporate transactions: a prospective or actual buyer, investor, successor, or adviser in connection with financing, merger, reorganization, sale, or transfer, subject to appropriate confidentiality and legal protections.

11. International Data Transfers

LENSORA INC is located in the United States. Account, profile, analytics, support, and technical information may be processed in the United States and other countries where our service providers operate.

Lensora's current core production deployment uses Railway in California, a Neon database hosted in AWS US East (N. Virginia), us-east-1, and Cloudflare R2 object storage. PostHog analytics is processed in its United States cloud environment. Cloudflare and other providers may process information through their global infrastructure as described in their applicable service documentation and agreements.

Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, we use recognized safeguards such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful mechanism. You may contact us for information about the applicable safeguard.

For users in jurisdictions that require specific notice or consent for overseas processing, including the Republic of Korea, we will provide any required localized disclosure or consent before transferring covered information.

12. Retention and Deletion

We retain personal information only for as long as reasonably necessary for the purposes described above, taking into account account status, the nature and sensitivity of the information, legal obligations, security needs, and limitation periods.

We do not currently apply a fixed maximum calendar retention period to every category of information. This does not override your deletion rights or permit us to keep information after it is no longer reasonably necessary for a disclosed purpose.

  • Local camera, photo, and Scan content: Lensora does not retain a server copy. Local copies remain until you delete them, remove the app, or manage the relevant device backup.
  • Face data: face-analysis values exist only in volatile memory during the current live-camera or Scan analysis, may remain briefly until replaced or the session ends, and are then automatically discarded. They are not written to persistent storage, and Lensora has zero server-side retention of face data.
  • Account email, Apple identifier, name, and profile images: retained while your account is active. When the server confirms an in-app account-deletion request, Lensora removes identifying account fields and related profile records, deletes Lensora session records, revokes the associated Sign in with Apple refresh token, deletes all objects found under the account's avatar and profile-background storage prefixes, and submits deletion of the associated PostHog person, events, and Session Replay recordings. A minimal de-identified account record, deletion timestamps, and de-identified invitation-admission proofs needed to avoid revoking another user's existing access may remain for integrity and deletion-state purposes, except where additional retention is legally required.
  • Superseded profile images and failed upload queues: no separate fixed maximum period currently applies; they are retained only as needed for synchronization, recovery, security, or storage cleanup. Account deletion enumerates and deletes all objects under the account's user-specific avatar and profile-background storage prefixes rather than relying only on the currently referenced image.
  • Analytics events and Session Replay: locally pending PostHog queues are cleared when Allow Analytics is turned off, without a forced final upload. Information already received by PostHog is retained according to the actual retention configuration in Lensora's PostHog project and is deleted or de-identified when no longer needed for the disclosed analytics, debugging, security, or legal purposes. This Policy does not state an unverified number of days.
  • Support communications and attachments: retained while we address the request and for a reasonable period afterward to maintain support history, resolve disputes, and improve recurring issues.
  • Security and legal records: retained for the period reasonably necessary to investigate incidents, comply with law, or establish, exercise, or defend claims.
  • Server logs: Lensora's current Railway plan retains application, deployment, build, and HTTP logs for 7 days. The current logging configuration records limited request metadata such as network address, HTTP method, path, and response status and does not intentionally log user IDs, Apple identifiers, email addresses, authentication tokens, image URLs, or request bodies.
  • Provider recovery systems: deleted database records may remain temporarily within Neon's provider-managed restore history until the applicable recovery window expires. Residual recovery data is not restored to ordinary production use except for legitimate disaster recovery and remains subject to provider expiration and legal-preservation processes.
  • Account deletion and analytics: turning analytics off does not delete information already held by PostHog. An account-deletion request submits deletion of the account-linked PostHog person and queues deletion of associated events and Session Replay recordings captured before the request. PostHog processes queued event and recording deletion asynchronously. You may email [email protected] regarding remaining identifiable information. Deleted database records may remain temporarily in provider recovery history as described above.

When deletion is required, we delete, de-identify, or securely isolate information. Face-analysis values require no request because they are automatically discarded on the device. PostHog account deletion is submitted through the implemented person-deletion process with deletion of linked events and recordings requested; PostHog processes that request asynchronously.

13. Your Choices and Privacy Rights

Depending on your location, you may have rights to access, know about, correct, delete, restrict, or object to processing of personal information; withdraw consent; receive a portable copy; appeal a decision; or complain to a regulator.

  • Profile: edit your name, profile image, or background image within the app.
  • Account deletion: use Profile → Settings → Account → Delete Account. The server removes identifying account fields and related profile records, deletes Lensora session records, revokes the associated Sign in with Apple refresh token, deletes all profile-image objects found under the account's user-specific storage prefixes, and submits deletion of the associated PostHog person, events, and Session Replay recordings. After the server confirms the request, the app clears local credentials and profile data. Contact [email protected] regarding other remaining identifiable information.
  • Analytics: disable new analytics and Session Replay in Settings → Allow Analytics.
  • Camera and photos: change permissions in iOS Settings.
  • Communications: use any unsubscribe method provided or contact us. Service and security messages may still be necessary for an active account.
  • Privacy request: email [email protected] with the subject “Privacy Request.” We may verify your identity and authority before acting.

We will not discriminate against you for exercising a privacy right.

14. Regional Privacy Disclosures

These disclosures supplement the rest of this Policy and apply only where the relevant law applies to Lensora.

  • California and other U.S. states: in the preceding 12 months, we may have collected the identifiers, profile content, internet or electronic activity, approximate geolocation, device information, and support content described above. We use and disclose those categories for the business purposes stated in this Policy. We do not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer characteristics. Eligible residents may request access, correction, deletion, or portability and may appeal or use an authorized agent where applicable.
  • EEA, United Kingdom, and Switzerland: you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and lodge a complaint with your local data protection authority. Withdrawal does not affect processing already lawfully completed.
  • Canada: you may request access to and correction of personal information and challenge our compliance. We limit collection, use, disclosure, and retention to appropriate stated purposes and use consent or another basis permitted by applicable Canadian law.
  • Japan: you may request notification of purpose, disclosure, correction, suspension of use, or deletion of retained personal data to the extent provided by the Act on the Protection of Personal Information.
  • Republic of Korea: where the Personal Information Protection Act applies, you may request access, correction, deletion, suspension, or withdrawal. Lensora will provide legally required information about overseas recipients, destination countries, transfer timing and method, purposes, and retention, and obtain separate consent where required before covered transfers.
  • Taiwan: where the Personal Data Protection Act applies, you may inquire about, review, copy, supplement, correct, discontinue collection or processing of, or request deletion of your personal data, subject to applicable exceptions.

15. Children's Privacy

Lensora is a general-audience service and is not directed to children under 13. To create or use a Lensora account, you must be at least 13 and must also meet any higher minimum age required in your country or region to use the Services and consent to the processing described in this Policy without parental authorization.

Lensora does not currently provide a parental-consent process. If you are below the applicable minimum age, you may not create or use a Lensora account.

We do not knowingly collect personal information from a person below the applicable minimum age. If we learn that we have done so, we will suspend or close the account and delete the associated personal information unless applicable law requires or permits limited retention.

If you believe an underage person has provided personal information to Lensora, contact us at [email protected] so we can investigate and take appropriate action.

Lensora does not knowingly sell or share the personal information of users under 16 for cross-context behavioral advertising.

16. Security

We use administrative, technical, and organizational measures designed to protect personal information, including encrypted network transmission, access restrictions, privacy masking, data minimization, and service-provider controls.

No system is completely secure. You are responsible for protecting access to your Apple account and device. Please notify us promptly if you believe your Lensora account or information has been compromised.

17. Automated Decisions and Do Not Track

Lensora does not use personal information to make solely automated decisions that produce legal or similarly significant effects.

The Lensora iOS app does not respond to browser Do Not Track signals. We do not sell personal information or use it for cross-context behavioral advertising. Where legally required, we will honor applicable universal opt-out signals on web properties that engage in covered processing.

18. Changes to This Policy

We may update this Policy to reflect changes to the Services, providers, law, or our practices. We will post the revised Policy and update the Last Updated date.

If a change materially affects your rights or expands how we use previously collected personal information, we will provide additional notice and obtain consent where required. The archived version applicable when information was collected may remain available on request.

19. Contact Us

To ask a question, exercise a privacy right, or make a complaint, contact our privacy team. Please do not send sensitive photos or information unless needed for your request.

LENSORA INC
Privacy contact: [email protected]
Website: lensora.ai