Effective date: August 2026 | Last updated: August 2026
This Privacy Policy describes how Ali3N Studios LLC (“we,” “us,” or “our”) collects, uses, and protects information in connection with the Heirloom mobile application (“App”). This policy supplements our general Ali3N Studios Privacy Policy.
Heirloom repairs damaged photographs. The photographs people send us are often the only surviving image of someone who has died, and we treat them accordingly. We do not sell your data, we do not show ads, we do not use your photographs to train any model, and we delete your original as soon as it has been restored.
1. Data We Collect
Account Data
The App uses Firebase Authentication. You sign in with an email address and password, or with Google. When you sign in with Google we receive your email address and a unique user ID. There is no anonymous or guest mode: an account exists so that credits you have paid for survive reinstalling the App or changing phone.
Your Photographs
When you choose a photograph to restore, the App uploads a copy of it to our server so that it can be repaired. Before uploading, the App re-encodes the image on your device, which removes embedded metadata — GPS coordinates, camera make and serial number, and the original filename are not transmitted.
Your original is deleted from our servers as soon as processing finishes. The restored result is kept for a short window, currently seven days, so that you can download it again if the first save failed. After that it is deleted automatically. You can delete a restored file from our servers at any time before then, from the result screen in the App.
Photographs you never approve for restoration — uploaded for a free assessment and then abandoned — are deleted within hours.
Restoration Records
For each restoration we keep a record of what was done: which processing stages ran, which providers performed them, what it cost, the honesty label the result was given, and when it happened. This record does not contain the photograph. It exists so that we can answer questions about your credit balance and issue refunds correctly.
Credits
Your credit balance and its history are stored on our server in Google Firestore. Purchases are processed by Google Play; we never receive or store your payment card details. We use RevenueCat to validate purchases and keep track of what you have bought — it receives your account identifier and your purchase history, but never your photographs.
Preventing Repeat Free Allowances
To stop the free-restoration allowance being claimed over and over, we store a one-way hash of your verified sign-in identity — your Google account identifier, or your email address once you have confirmed it. It cannot be reversed, and it is used for nothing else.
We do not read your Android device ID. An earlier version of the App derived a hash from it to limit the free-restoration allowance; that was removed in August 2026.
Crash reporting does generate an installation identifier. Firebase Crashlytics creates a random ID for each install so repeated crash reports can be recognised as coming from the same copy of the App. It is not an advertising identifier, it is not tied to your identity, it is not shared with anyone else, and it is erased when you uninstall. This is why our Google Play Data Safety declaration lists "Device or other IDs" as collected.
Crash Reports
The App uses Firebase Crashlytics. If it crashes, a report is sent to Google containing the technical details of the failure and basic information about your device and the App version. Crash reports never contain your photographs.
What We Do Not Collect
Heirloom contains no advertising SDK and never collects an advertising identifier. The Android advertising permission is explicitly removed from the App. We do not track you across other apps or websites, and we do not build a profile of you.
2. How Your Photographs Are Processed
Restoration is performed by specialist image-processing services operating on our instruction. Depending on what your photograph needs, a copy may be sent to:
- Amazon Web Services — automated safety checking of every upload, and repair of physical damage.
- OpenAI — photograph restoration.
- Replicate — enlargement, facial detail recovery, and colourisation.
These providers act as processors on our behalf. They are not permitted to retain your photograph or to use it to train their models. Some processing happens entirely on our own server and involves no third party at all.
We do not use your photographs to train any model, ours or anyone else’s. We do not sell them, publish them, or share them with anyone other than the processors listed above.
3. Safety Checking
Every uploaded photograph is checked automatically before anything else happens. This check refuses unlawful material and content that is explicit or sexual in nature. It runs on every upload without exception, whatever restoration was requested.
The check also detects whether a child appears in the photograph. Photographs of children are accepted. Baby pictures, school portraits and family groups are among the most treasured and most damaged photographs people own, and refusing them would make the App useless for much of its purpose. When a child is detected, the free-text request field is unavailable and only the standard restoration presets can be used, so no instruction written by anyone reaches an image model for those photographs.
When a photograph is refused by the safety check, it is not stored, no restoration record is created, and you are not charged.
4. How We Store and Protect Your Data
Photographs held during the retention window are stored in a private location that is not publicly reachable. They are served only through short-lived, cryptographically signed links, so a restored file has no guessable public address. Account and credit data are stored in Google Firestore with access rules that prevent any user from reading another user’s data or modifying their own balance. All communication between the App and our servers uses HTTPS.
5. Data Retention
| Your original photograph | Deleted as soon as processing finishes |
| Restored result | Seven days, then deleted automatically |
| Uploads never approved for restoration | Hours |
| Account, credit balance and restoration records | Until you delete your account |
| Photographs refused by the safety check | Never stored |
6. Your Rights and Choices
- Delete a restored file early. Use “Delete from the server now” on the result screen.
- Delete your account. Settings → Delete my account. This removes your account, your restoration history and any remaining credits. Credits cannot be recovered afterwards.
- Request a copy of your data, or ask us to delete it. Email us and we will action it.
7. Children
Heirloom is not intended for use by people under 13, and we do not knowingly collect personal information from them. This is separate from the subject matter of photographs: a photograph of a child is an ordinary and expected use of the App, as described in Section 3.
8. International Users
Our servers and processors are located in the United States. If you use the App from outside the United States, your photograph is transferred to and processed there.
9. Changes to This Policy
If we change this policy materially we will update the date at the top and, where the change is significant, notify you in the App.
10. Contact
If you have questions about this Privacy Policy or your data, contact:
Ali3N Studios LLC
Email: developer@ali3nstudios.com