Privacy Policy – GiggleFace
Last updated: September 10, 2026
This policy explains which face data and other information GiggleFace and GiggleFaceCamera process, why they use it, where it is stored, when it is shared, and how long it is retained. Face tracking is performed on the mobile device; sending rendered video to your Mac or sharing saved media is a separate feature you control.
For face data and TrueDepth, see section 3. For saved media, see section 4; for transmission and recipients, section 7; and for deletion, section 9.
1. Scope, Developer, and Accounts
Adriano Souza Costa is responsible for the data practices of GiggleFace for iOS/iPadOS and GiggleFaceCamera for macOS described here. The apps do not require a user account or ask for your name, email, phone number, or contacts to use the camera and mask features. If you contact support, we receive the contact details and information you choose to include in your message, and use them to answer it.
2. Permissions and Device Access
- Camera: GiggleFace accesses the front camera for live masks and the camera for scanning the Mac's pairing QR code. GiggleFaceCamera receives video from the paired device; it does not capture the Mac's physical camera.
- Microphone: GiggleFace captures audio to include in videos you choose to record.
- Photos, Files, and sharing: system interfaces let you select images or mask files to import and destinations for exports. Photo Library permission is requested when needed to save a recording.
- Local Network: device discovery and a local connection let GiggleFace send processed video to GiggleFaceCamera after QR-code pairing. Connection information includes local network addresses, a service name, and session pairing credentials.
- Location on Mac: optional system authorization is used to display the current Wi-Fi network name (SSID), not to track your physical location. The app does not send that name or location to the developer for analytics.
You can change permissions in system settings. Denying or revoking a permission prevents the related access and may make that feature unavailable. Camera permission does not itself authorize uploading your media to the developer.
3. Face Data, ARKit, and TrueDepth
3.1. Face data accessed and generated
With camera permission, GiggleFace uses Apple's ARKit face tracking, including TrueDepth-based tracking on supported devices, to access front-camera frames, a three-dimensional face mesh (vertices and surface coordinates), the face's position and orientation, tracking status, and expression coefficients (blend shapes, including mouth and jaw movements). These measurements describe the face's shape and movement for rendering; the app does not access Face ID enrollment data or an authentication template.
When you import an image to make a mask, Apple's Vision framework detects two-dimensional facial landmarks, such as eyes, eyebrows, nose, and lips, on the device to help align the image. Imported images, mask textures, and recordings may themselves show an identifiable face. They are treated as user media and have the separate storage and sharing practices described below.
3.2. Purposes and limits
Face measurements are used only to fit and animate masks, align imported images, and render the live preview, videos you record, and the processed video you choose to send to your Mac. Face tracking and mask rendering take place on the iPhone or iPad. GiggleFace does not use face data for identity recognition, authentication, profiling, advertising, marketing, data mining, or training machine-learning models. We do not sell or rent face data.
3.3. Storage, retention, and deletion of face measurements
Live face meshes, tracking positions, expression coefficients, and detected image landmarks are processed in device memory. The app does not write these measurement sets to a persistent face database, a recording's metadata, or a developer-operated server. They are replaced as processing advances and released when the objects holding them are released. A last frame or rendering state may remain in memory while the app process is alive, including while tracking is paused; any remaining in-process data is released when that process terminates. There is no persistent retention period for these measurement sets.
Saving a mask keeps its image, source image, thumbnail, and editor adjustments; recording a video keeps the rendered image and recorded audio. These files may contain a visible face even though they do not include the live ARKit mesh or expression coefficients as a separate dataset. Their retention and deletion are explained in section 4 and section 9.
3.4. Disclosure and sharing of face data
The app does not transmit the live face mesh, tracking coordinates, expression coefficients, or detected image landmark sets to the developer, the paired Mac, Himetrica, RevenueCat, advertising networks, or data brokers. Himetrica and RevenueCat do not receive your camera frames, imported images, masks, or recordings from GiggleFace.
When you pair and start streaming, the rendered video, which may show your face, is sent to your Mac over the local network. When you choose to export media or use the virtual camera in a communication app, that selected app or service receives the media. These user-directed transfers, recipients, and storage practices are detailed in section 7. We do not operate a cloud face-processing service or a remote media library.
4. Local Media Storage
GiggleFace saves custom mask images, copies of their source images, thumbnails, editor adjustments, and recordings in app-controlled storage on the device. Mask storage is shared locally between GiggleFace and its sharing extension. Saving a mask allows later reuse and editing; saving a recording allows playback and export. These saved items have no automatic expiration and remain until removed or replaced. Temporary recording and export files can also remain in the app's temporary storage until app or operating-system cleanup.
Exported files and copies saved to Photos, Files, iCloud, or another selected service are separate from the app's library. Device backups or photo/file sync may copy saved media according to your Apple or storage-provider settings. GiggleFace does not upload these files to a developer-operated server. Deleting an item in GiggleFace does not delete copies in Photos, backups, recipient apps, or other storage services; manage those copies with the relevant provider.
5. Usage Analytics and Error Diagnostics
GiggleFace uses Himetrica to understand feature usage and diagnose technical errors. The integration is configured without Himetrica's identify function and does not send your name, email address, camera image, imported images, masks, audio, video, recordings, facial meshes, expression coefficients, or facial landmarks.
The limited diagnostic information may include:
- Randomly generated visitor and session identifiers;
- App screens or features used and session timing;
- App, operating system, and device version information;
- Error messages, stack traces, and technical context that does not contain media content.
When the device is offline, diagnostic events may be queued locally and sent when connectivity returns. Network information, including an IP address, may be processed by Himetrica and its infrastructure for delivery, security, and approximate geographic statistics as described in Himetrica's policy. Detailed analytics are retained according to the developer's Himetrica plan.
Learn more in Himetrica's Swift SDK documentation and Privacy Policy.
6. Purchases and RevenueCat
GiggleFace Premium is offered as a one-time, non-consumable in-app purchase. Apple handles payment and refunds. GiggleFace also uses RevenueCat to validate transactions, manage and restore Premium access, present purchase offers, and understand purchase activity. RevenueCat processes an app-generated user identifier, purchase and transaction information, entitlement status, and technical information needed to provide those services. Purchase data is processed on Apple and RevenueCat infrastructure; entitlement information is also cached locally so the app can determine access.
No face measurements or user media are sent to RevenueCat. The developer does not receive your complete payment card information. Purchase records may be retained for verification, restoration, fraud prevention, and applicable legal requirements; deleting the app does not erase Apple's or RevenueCat's records. See RevenueCat's Privacy Policy and Apple's Privacy Policy.
7. Local Streaming, Virtual Camera, and Sharing
To use masks on your Mac, you open GiggleFaceCamera, pair GiggleFace by scanning its QR code, and start the connection with both devices on the same local network. The paired connection is authenticated and encrypted. GiggleFace renders the mask on the mobile device and sends encoded video to the Mac; it does not send the underlying ARKit mesh or expression coefficients. The local media connection does not pass through a developer-operated relay server.
GiggleFaceCamera decodes and temporarily buffers the video in Mac memory for preview and the virtual camera. It does not automatically create a saved recording of the incoming stream. Frames are replaced during playback and released as buffers are replaced or the receiving components are released; remaining in-process buffers are released when the process terminates. Disconnecting stops delivery of new video to the Mac.
Selecting GiggleFaceCamera in a compatible communication app makes the rendered video available to that app. Depending on the service and your settings, the video may then leave the local network, reach other participants, and be transmitted or recorded by that service or those participants. A mask does not guarantee anonymity or hide all identifying details. Storage locations, retention, and deletion of these copies follow the recipient's practices.
Exporting a mask or recording through the system Share Sheet sends the selected file to the app or service you choose. Sharing and storage services process their copies under their own privacy policies. Stop streaming, deselect the virtual camera, or leave the call to stop the related ongoing use; these actions cannot recall files or recordings that others already received.
8. Service Providers and Advertising
We do not sell or rent personal information or use face data for advertising. The app's disclosures are limited to Himetrica for the usage and diagnostics described in section 5, Apple and RevenueCat for section 6, and the devices, apps, and services involved in the transfers you initiate in sections 4 and 7. If you contact support, your message is handled by our email provider to let us respond. Service providers may process these non-face operational records outside your country under their policies. This does not involve sending live facial measurements or user media to analytics or purchase providers.
9. Retention, Deletion, and Your Choices
- Face measurements: retained only in device memory as explained in section 3.3; there is no developer-held face dataset to delete.
- Saved masks and recordings: retained locally without automatic expiration. Use the app's deletion controls for library items. Replacing an edited item updates its local files. Deleting the app removes its app data as managed by the operating system; offloading the app may preserve data.
- Exports, backups, and call recordings: delete them separately in Photos, Files, backup settings, or the recipient service. Recently deleted folders and provider retention rules may apply.
- Analytics: detailed Himetrica events follow the retention period of the developer's plan; aggregate statistics may remain longer under Himetrica's policy. These records do not contain face measurements or user media.
- Purchase information: retained for the purposes described in section 6, including restoring the one-time entitlement.
- Support messages: retained as needed to answer and resolve the request and meet applicable legal obligations. You may request deletion using the contact below.
You can stop camera use, disconnect streaming, and revoke device permissions in system settings. To request access, correction, or deletion of personal information we hold, or exercise other rights available under applicable law, contact us. We may need information to locate and verify the relevant record; a name alone may not identify records associated with a random app identifier. We do not need a face scan to handle a privacy request.
10. Security
We minimize the information sent outside your device and apply reasonable technical safeguards. No method of electronic storage or transmission is completely secure, and third-party services remain responsible for their own systems.
11. Children's Privacy
GiggleFace is not designed to knowingly collect personal information from children. If you believe information has been handled in conflict with this policy, please contact us so the issue can be reviewed.
12. Changes to This Policy
We may update this policy to reflect product, technical, or legal changes. The current version and its update date remain available here. A policy update alone does not authorize a new use or transfer of face data; any such change must be disclosed and obtain consent where required before the new processing begins.
13. Contact
For questions about this Privacy Policy or GiggleFace, contact: [email protected]