Privacy Policy
Last Updated: September 11, 2026
1. Introduction
Welcome to The Critiqueur. We are committed to protecting your privacy. This Privacy Policy explains how The Critiqueur ("we," "us," or "our") handles your information when you use our mobile application ("the App").
The Critiqueur is developed and operated by German Kirshin, an individual developer based in Cyprus, who is the data controller for the purposes of this policy. You can reach us through the Support Page.
2. Information We Collect
2.1 No Account Required
The Critiqueur does not require you to create an account or provide personal information such as your name, email address, or phone number. Instead, the App uses a randomly generated, pseudonymous identifier issued by our server. It is stored in your device's secure storage (Keychain on iOS and macOS, encrypted account storage on Android, DPAPI on Windows) and is what your critique-token balance, your purchases and your rate limits are recorded against. It is not derived from your personal data and does not identify you personally, and it is never handed to a third party as it stands — the analytics identifier described in Section 6 is a one-way hash of it.
2.2 Photos You Submit for Critique
Generating a critique requires processing your photo. When you submit a photo:
- The photo is transmitted securely (over HTTPS) to our service, which forwards it to an AI model provider to generate the critique.
- What is sent is a re-encoded copy at reduced resolution, never your original file. Because the App draws that copy afresh, the original's embedded metadata — including any GPS location, camera serial number, and capture time — is not part of it and never leaves your device.
- The settings that shape the critique travel with the photo: the critic persona you chose, the language the critique should be written in, and — only if you have set one — the form of address you prefer ("masculine" or "feminine"). Nothing else about you accompanies the request.
- When you re-shoot the same subject, the text of the earlier critiques in that session is sent along so the critic can say what changed. Your earlier photos are not re-sent.
- The photo is processed to produce the critique and is not used for advertising, not shared publicly, and not sold.
- We do not build a server-side gallery of your photos: your sessions, attempts, and badge collection are stored locally on your device.
- AI model providers process the photo as our data processors to generate the critique response. We use providers under terms that do not permit them to use API data to train their models.
Submit only photos you have the right to share. Please avoid submitting photos containing other people's identifiable faces or sensitive personal information unless you have their consent.
2.3 Purchase and Quota Data
To operate the token economy without accounts, our server stores, linked to your pseudonymous identifier:
- Your remaining critique-token balance and granted free-trial allotments
- Purchase verification records (store receipts / purchase tokens issued by Apple, Google, or Microsoft) for token packs and subscriptions
- License keys, if you activate one
We do not receive or store your payment details — payments are processed entirely by the Apple App Store, Google Play, or Microsoft Store.
2.4 Device Attestation
To protect the integrity of our service, and to keep the free trial to one per device, the App uses your platform's built-in attestation (Apple App Attest on iOS and macOS, Google Play Integrity on Android, and Microsoft Store account verification on Windows). This lets our server verify that requests come from a genuine, unmodified copy of the App tied to a legitimate store account. Attestation produces cryptographic tokens and technical device signals; it does not reveal your name, contacts, or files.
The device anchor. One free trial per device is enforced with a marker our server stores, and that marker is derived from a device or store-account identifier:
| Platform |
What the anchor is derived from |
| Android |
The App sends the Android ID (SSAID) — the identifier the system assigns to this app on this device. Our server stores only a hashed form of it, never the value itself. |
| Windows |
An identifier derived from your Microsoft Store account, returned to us by the Microsoft Store when it confirms you own the App. |
| iOS and macOS |
No device anchor is stored. |
An anchor records that a device has claimed its free trial and which pseudonymous identifier claimed it. It is deliberately persistent: it is held on our server and reinstalling the App does not clear it, which is what stops one device claiming free trials without end. It is not used for advertising, for analytics, or to recognise you across other apps or websites.
2.5 Diagnostics and Analytics
We collect limited technical data through third-party services to identify bugs, understand overall app usage, and measure app install campaign performance:
- Crash logs and diagnostic information (e.g., stack traces, app state at time of crash)
- App and device identifiers generated by analytics services
- Technical device and app data (device model, operating system version, app version, locale, timestamps)
- App event data (such as app opens for analytics and conversion measurement)
This data is collected pseudonymously and is used for analytics, diagnostics, app functionality, and aggregated ad attribution. We do not use permission-based cross-app tracking; on iOS, install measurement may use Apple's privacy-preserving, aggregated reporting.
3. Device Permissions
The Critiqueur requires certain device permissions to function:
| Permission |
Purpose |
| Camera |
To capture photos for critique |
| Photos / Media |
To import existing photos for critique |
| Photos (adding only) |
On iOS, to save an edited photo or a critique card to your library when you choose to |
These permissions are used solely for the App's core functionality. We do not scan your photo library; only photos you explicitly capture or select are processed.
4. How Your Data is Stored
- On your device: sessions, attempt photos, critiques, and badges are stored locally in the App's private storage. Once a critique has been generated, the original import is deleted and only the edited photo is kept.
- In your device's secure storage: the pseudonymous identifier described in Section 2.1 — the Keychain on iOS and macOS, encrypted account storage on Android, DPAPI on Windows.
- In your platform's backup, if you use one: your badge collection and your App settings are small enough to ride along in the backup your platform already makes (iCloud on Apple devices, Google's backup on Android), so they follow you to a new device. Your session history — the photos and the renders of them — is deliberately excluded from that backup and does not.
- On our servers: your pseudonymous identifier, token balance, purchase verification records, and the device anchor described in Section 2.4. We do not store your name, email, or payment details.
- Photos: transmitted for processing as described in Section 2.2; not retained as a browsable server-side gallery.
5. In-App Purchases and Sharing Access Across Devices
The Critiqueur offers auto-renewing subscriptions, billed monthly or yearly, and consumable token packs. All transactions are processed securely by the Apple App Store, Google Play Store, or Microsoft Store. The App sends the store-issued receipt or purchase token to our server to verify the purchase and credit your balance. We do not collect, process, or store any payment information, including credit card numbers or billing details.
Access can be shared across your own devices in two ways, neither of which needs an account:
- Re-submitting a subscription receipt on another device signed in to the same store account links that device to the same balance.
- A device link code. One device can produce a code which another device pastes in, merging the two balances — consumable packs included — onto a single pseudonymous identifier. The code is a bearer credential: whoever holds it can reach and spend the balance it names, so share it only with a device you trust and treat it as you would a password. What a merge means for your purchases is set out in Section 6 of the Terms of Use.
6. Third-Party Services
The App uses the following third-party services, which may collect or process data according to their own policies:
- Anthropic — the AI model provider that analyzes submitted photos and generates critiques, as our data processor, under terms that do not permit it to use API data to train its models. Should we add or change providers, we will do so only under equivalent terms and will update this list. Anthropic Privacy Policy
- Sentry (Functional Software, Inc.) — for crash and error reporting. Sentry Privacy Policy
- Google Analytics 4 (Google) — for app usage analytics. Events are sent from our own server, not from the App, and are keyed to a pseudonymous per-install identifier derived from your identifier; your identifier itself is never shared with Google. Google Privacy Policy
- Meta App Events (Meta Platforms) — for app event measurement and install campaign attribution. On iOS, attribution may use Apple's privacy-preserving, aggregated reporting methods. Meta Privacy Policy
- Google Forms (Google) — our support form runs on Google Forms. Whatever you type into it, including any contact details you give us so that we can reply, is processed by Google on our behalf. Google Privacy Policy
- Apple App Attest / Google Play Integrity / Microsoft Store — for device and app integrity verification (trial abuse prevention).
- Apple App Store / Google Play Store / Microsoft Store — for in-app purchases and app distribution.
7. Data Retention and Deletion
- Local data: your sessions, photos, and badges remain on your device until you delete them in the App or uninstall it. Uninstalling removes the App's local storage and we cannot recover it. Two things deliberately outlive an uninstall: on iOS and macOS the pseudonymous identifier held in the Keychain, so that reinstalling does not cost you critiques you have already paid for; and, if you use a platform backup, the badges and settings it restores (see Section 4).
- Server data: quota and purchase records are retained while they are needed to honor your purchases and prevent abuse. The device anchor described in Section 2.4 is retained for as long as the one-trial-per-device rule it enforces applies.
- Third-party data: data sent to third-party services is retained according to each provider's policies and configuration.
To request deletion of the server-side records associated with your pseudonymous identifier, contact us via the Support Page. Note that deleting these records will forfeit any remaining token balance.
8. Children's Privacy
The Critiqueur is not directed at children. You must be at least 14 years old to use it, as set out in our Terms of Use, and we do not knowingly collect personal information from anyone younger. If you believe a child has provided us with personal data, please contact us and we will take steps to address the issue.
9. Your Rights
Depending on your location, you may have rights regarding your data, including the right to access or delete it. Your creative content is stored locally and is under your full control. For server-side records (token balance, purchase verification), contact us via the Support Page and we will assist you.
10. International Users
The Critiqueur is available worldwide. Photos submitted for critique, technical data, diagnostics, and analytics events may be processed by our service providers in the United States or other regions in accordance with their privacy policies and applicable data-transfer safeguards.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Last Updated" date at the top of this page. Your continued use of the App after such changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions or concerns about this Privacy Policy, please visit our Support Page and contact us there.