Heirloom (“we”, “the app”) helps you restore old photos and create keepsake images. We are built privacy-first: we don’t require an account and we don’t collect personal information such as your name, email, or contacts to use the app. This policy explains what data we collect, how we collect it, every way we use it, and who we share it with.
What data we collect and how
We only collect what is needed to create your result:
Photos you choose, including face data. When you tap Restore or Reunite, you select a photo from your device (or take one with the camera). Photos of people contain facial imagery — we refer to this as “face data”. This is the only sensitive data the app collects, and you provide it directly by choosing the photo.
Purchase records. When you buy a credit pack, Apple and our payments provider (RevenueCat) give us a record of the purchase tied to a random, anonymous identifier so we can grant your credits. We never receive your card details.
A random, anonymous device identifier. To track your credits and free daily uses without an account, the app stores a random ID on your device. It is not your name, email, or Apple ID, and it is not used to track you across other apps or companies.
Face data — collection, use, sharing, and retention
Because face data is sensitive, we handle it with specific care:
What we collect: the facial imagery contained in the photo you choose to restore or reunite. Heirloom itself does not scan your library, detect faces, or run face recognition, and we never build a faceprint, biometric template, or identity database, or use your face to recognize you in any other photo or across sessions. To create your result, the AI models listed below automatically process the faces in your photo (for example, to sharpen a face or place a person naturally into a scene) — only to generate that single result, after which nothing about your face is kept.
How we use it: solely to generate the single result you asked for (a restored photo or a reunited keepsake). We use it for no other purpose.
Who we share it with: to perform the processing, your photo is transmitted to the AI service providers listed below. It is never sold, never shared with data brokers or advertisers, and never used to train AI models.
How long we keep it: the uploaded original is deleted from our servers immediately after your result is generated, and any leftover copies are purged automatically within one hour. Your finished result is stored privately and is reachable only through a private, expiring link.
We ask your permission first
Before your first photo is ever uploaded, the app shows a consent screen that discloses exactly what is sent, names the AI services it is sent to, and requires you to tap “I agree” to continue. No photo or face data is sent to any AI service until you give this permission. You can withdraw consent at any time by not using the Restore and Reunite features.
Third-party AI services we share data with
To create your result we send the photo you choose to the following providers, which process it only to provide their service to us and under confidentiality obligations that offer equivalent protection to this policy:
Supabase — secure cloud storage and backend used to hold the photo briefly during processing.
Replicate — the AI inference platform that runs the image model on your photo.
Google (nano-banana image model) — the AI model, run via Replicate, that generates the restored or reunited image.
RevenueCat — purchase management (receives purchase records only, never your photos).
These providers use your photo only to generate your result and do not retain it for their own purposes or use it to train models.
No training, no ads, no tracking
Your photos and face data are never used to train AI models, never sold, and never shared for advertising. We do not use advertising or third-party tracking SDKs, and we do not track you across other apps.
What stays on your device
Your restored results and keepsakes are saved locally on your device. Your credit balance is stored securely on-device and mirrored under the anonymous identifier so it survives reinstalling. The anonymous mirror is not linked to your identity.
Payments
Purchases are handled by the Apple App Store and RevenueCat. We never see or store your card details.
Children
Heirloom is not directed to children under 13 and we do not knowingly collect information from them.