ReCap
Privacy Policy
Effective date: April 2025  ·  Last updated: April 2026

ReCap ("we", "us", or "our") is a private photo-sharing app. This Privacy Policy explains what information we collect, how we use it, and your rights around it. By using ReCap you agree to this policy.

1. Information We Collect

Account information. When you create an account we collect your email address. If you use the app without signing in, we assign you an anonymous identifier.

Photos and videos. When you upload photos or videos to an album, those files are stored on our servers (Firebase Storage). They are only accessible to participants of the album they were uploaded to.

Face data. ReCap lets you browse album photos grouped by person. To make this work, the app uses Apple's Vision framework and a local machine learning model (ArcFace) to detect faces and generate numerical representations called embeddings. All of this processing happens on your device. No facial images are sent to any server.

The app stores the resulting embeddings (512-dimensional floating-point vectors, roughly 2 KB each) in your album's Firestore database record. These embeddings are just arrays of numbers. They can't be reversed into a photo of someone's face, and they can't be used to look up a person's identity. They exist so the app can group photos consistently across sessions and across devices for all album participants.

We don't share face embeddings or any other face data with third parties. We don't use them for advertising, analytics, or any purpose other than grouping photos within the album they belong to. The embeddings are stored alongside the album data in Google Firebase (Firestore) and are subject to the same access controls as the rest of the album. Only participants with the album's invite code can access them.

Face data is retained for the lifetime of the album. When an album expires (30 days after creation, or longer if extended) or is manually deleted by the owner, all associated face embeddings are permanently deleted along with the album's photos and other data. Users can also trigger a face data reset from the album settings screen, which deletes all stored embeddings for that album and rebuilds them from scratch.

Usage data. We collect basic analytics about how the app is used (e.g., which features are tapped, crash reports) to improve the product. This data is aggregated and not linked to your identity.

Device information. We may collect your device type and operating system version for debugging purposes.

2. How We Use Your Information

3. Information Sharing

We do not sell your personal information. We do not share your photos, videos, or face data with third parties.

We use the following third-party services to operate ReCap:

We may disclose information if required by law or to protect the rights, property, or safety of ReCap, our users, or the public.

4. Data Retention

Albums and their contents (photos, videos, face data) are automatically deleted 30 days after the album's creation date, unless extended by the album owner. You can also delete an album manually at any time. Your account and email address are retained until you delete your account through the app.

5. Your Rights

You can delete your ReCap account at any time from the app's settings screen. Deleting your account removes your email address and anonymous ID from our systems. Photos you uploaded remain in any shared albums until those albums expire or are deleted, as other participants may rely on them.

If you are located in the European Economic Area (EEA), you have rights under GDPR including the right to access, rectify, or erase your personal data. Contact us at the address below to exercise these rights.

6. Children

ReCap is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.

7. Security

All data is transmitted over HTTPS. Albums are private by default — only users with the invite code can access them. We use Firebase's built-in security rules to enforce access control. No system is perfectly secure, and we cannot guarantee absolute security of your data.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the new version at this URL with an updated effective date. Continued use of ReCap after changes constitutes acceptance of the updated policy.

9. Contact

Questions or requests regarding this Privacy Policy can be sent to: hello@getrecap.app


© 2025 ReCap. All rights reserved.