Skip to main content
    LEGAL

    Privacy Policy

    Last updated: August 26, 2026

    This policy explains what xPic: AI Photo Editor collects, why it collects it, who processes it and how you can remove it.

    1. Scope

    This policy covers the xPic: AI Photo Editor mobile app and this page. It does not cover other Horus Studios products, which have their own policies.

    2. Data controller

    Horus Studios is the data controller. Reach us at hello@horusstudios.com.

    3. Information we collect

    • Account and contact information: email address, display name, and, if you use Sign in with Apple, the identifier Apple returns to us.
    • Content you upload: the photos and videos you choose from your photo library as references for a generation, including images that contain a face.
    • Content you create: prompts, generated images and videos, saved characters, identity-lock settings and style preferences.
    • Generation records: which model ran, when, what it cost in tokens, and whether it succeeded.
    • Purchase information: your subscription and token-pack entitlements, as reported to us by Adapty and the App Store. We never see your payment card or Apple ID credentials.
    • Device information: a push notification token, app language, and basic device and app version data needed to deliver a working app.
    • Optional connections: if you connect your own AI provider key or a TikTok account, we store those credentials encrypted.

    4. How we use your information

    • To run the generations you request and return the results to your Library.
    • To keep your account, balance, entitlements and settings working.
    • To send you notifications you have opted into.
    • To detect abuse and to keep the service secure and available.
    • To meet legal and accounting obligations.

    We do not sell personal information, we show no third-party advertising, and we run no third-party analytics or tracking SDKs.

    5. Face data

    5.1 Face data we collect

    The only face data xPic collects is the photo or video you choose to upload from your photo library as a reference for a face swap, portrait or video generation. xPic does not create, derive or store faceprints, face templates, face geometry, face embeddings or any other biometric identifier, and it never uses face recognition to identify or verify a person. Nothing is captured in the background: a face image is uploaded only after you explicitly select it for a generation.

    5.2 How face data is used and shared

    Your uploaded face image is used for one purpose only: producing the AI output you requested. It is sent over an encrypted connection to the third-party AI provider assigned to that model — fal.ai, EachLabs, or Google Gemini reached through fal.ai when you ask xPic to read a reference photo — through a private link that expires after 10 minutes, and it is used solely to render your result. We do not sell face data, do not use it for advertising or profiling, do not use it to train our own or any provider's models, and do not share it with anyone else.

    5.3 Where face data is stored and how long we keep it

    Uploaded face images and generated outputs are stored in a private, per-account Supabase storage bucket protected by row-level access policies; they are never publicly accessible. We keep them only so your own library stays available to you. You can delete any uploaded reference or output at any time from the Library screen, and deleting your account permanently erases all of your stored images and generation records from our systems. We keep no separate copy of face data after deletion.

    6. Processing with AI

    Prompts and selected media are sent to the third-party AI provider chosen for that generation: fal.ai, EachLabs, or Google Gemini reached through fal.ai. xPic asks for your explicit permission before the first job and never sends anything until you grant it; you can withdraw that permission at any time from the profile screen, which blocks all further sending. Connected provider keys and TikTok tokens are encrypted in Supabase Vault and are never displayed back to the app.

    The AI services that receive your content are:

    RecipientWhat it receivesPurpose
    fal.aiThe photo or video you selected and the prompt for that jobGenerates and edits images and video
    EachLabsThe photo or video you selected and the prompt for that jobGenerates and edits images and video
    Google (Gemini, reached through fal.ai)The photo you submit for analysis, or the brief you typeReads a reference photo to suggest a prompt; writes carousel copy

    Before you can create anything, xPic shows a full-screen disclosure naming each recipient above and stating exactly what each one receives. Nothing is sent until you tap "I agree — send my content to these services". There is no pre-selected checkbox, and declining leaves the account unable to generate. Consent is recorded against your account and enforced on our servers, not only in the app: every generation passes through a single database function that refuses the job when consent is absent. Consent is versioned, so if we ever add a recipient we ask you again rather than relying on your earlier answer. To withdraw, open Profile › Withdraw AI permission; withdrawal takes effect immediately and blocks all further sending until you grant permission again.

    Each provider is bound by contract to protections equivalent to those in this policy: your content is processed only to fulfil your request, is not sold, is not used for advertising or profiling, and is not used to train their models.

    7. Service providers

    • Supabase — database, authentication, private file storage and backend functions
    • fal.ai — AI image and video generation
    • EachLabs — AI image and video generation, including face swap
    • Google — Gemini models reached through fal.ai, used to read a reference photo you submit for analysis and to write carousel copy
    • Hugging Face — AI image generation
    • Wiro — AI generation, only when you connect your own Wiro key
    • Adapty — subscription and purchase validation, paywalls, entitlements
    • Apple — App Store purchases, Sign in with Apple, push delivery
    • Expo — push notification delivery
    • TikTok — only if you connect a TikTok account, and only to publish the posts you explicitly choose to publish

    8. Advertising and tracking

    xPic contains no advertising, no ad identifiers and no third-party analytics or tracking SDKs. We do not track you across other companies' apps or websites.

    9. Permissions and choices

    • Photo library: needed to let you pick reference images and to save results back to your library. You can pick a limited selection instead of granting full access, and the app works with the limited selection.
    • Notifications: optional; used to tell you a generation has finished.

    You can change either permission at any time in iOS Settings.

    10. Retention and deletion

    We keep your account data, uploaded references and outputs for as long as your account exists, so your Library stays available to you. You can delete any individual item from the Library screen at any time. Deleting your account from Profile → Delete account permanently erases your stored files, generation records and connected credentials from our systems. We keep no separate copy of your images after deletion, and we retain only the minimal transaction records we are legally required to keep.

    11. Your rights

    Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. Write to hello@horusstudios.com and we will respond within the period the applicable law requires. You can also complain to your local data protection authority.

    12. International data transfers

    Our providers may process data outside your country, including in the United States. Where that happens, transfers rely on the safeguards permitted by applicable law, such as the European Commission's standard contractual clauses.

    13. Security

    Private files are served only through signed, expiring links. Access is restricted per account by database and storage policies. Connected provider keys and TikTok tokens are encrypted at rest and never displayed back to the app. No system is perfectly secure, but we work to keep the surface small.

    14. Children's privacy

    xPic is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, write to hello@horusstudios.com and we will delete it.

    15. Changes to this policy

    We will update this page when our practices change, and we will change the "Last updated" date above. Material changes will be announced in the app.

    16. Contact

    Horus Studios — hello@horusstudios.com