DivineME

Privacy Policy

Last updated: 07/13/2026


This Privacy Policy explains how Filipe de Oliveira Silva (the "Company", "we", "us", or "our") collects, uses, shares, and protects your information when you use the DivineME mobile application (the "App") and related services (collectively, the "Service").

PLEASE READ THIS PRIVACY POLICY CAREFULLY. By downloading, accessing, or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.

This Privacy Policy is designed to comply with the EU General Data Protection Regulation (GDPR), the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados – LGPD), the California Consumer Privacy Act as amended (CCPA/CPRA), and Apple App Store requirements.


Key Points About Our Privacy Practices

If you read nothing else, these are the points that matter most:


1. Who We Are (Data Controller)

The data controller responsible for your personal data is:


2. Information We Collect

We practice data minimization: we collect only what is necessary to operate the Service. We do not ask you to type your name, email, phone number, or any free-text prompt during generation.

2.1 Photos You Provide (Selfies)

When you choose to create media, you select a photo from your device's photo library through the system photo picker. We process only the specific image you select. We do not access your camera, and we do not read your full photo library.

Note on sensitive data: Although we do not create or retain biometric identifiers, a photo of your face may be considered sensitive personal data under the GDPR, the LGPD, and similar laws. We process it only with your consent and only to provide the feature you requested, as described in this Policy.

2.2 Generated Media

The photos and videos the Service creates for you are stored in our secure, private cloud storage and remain accessible only to you within the App — there is no public feed and no other user can view your media. You can delete individual generated media at any time. Generated media is retained until you delete it or until your account is deleted.

2.3 Account & Identity Data

2.4 Preferences You Provide (Optional)

2.5 Information Collected Automatically

2.6 Payment Information

Purchases are processed by Apple through Apple's in-app purchase system (StoreKit), mediated by our paywall provider (Superwall). We do not collect or store your credit card or payment-card details. We receive transaction confirmations and store your resulting subscription/credit status.


We use your information for the following purposes. Where the GDPR or LGPD applies, the legal basis for each is indicated.

Purpose Data used Legal basis (GDPR / LGPD)
Provide the core generation feature (face swap) Selected selfie, template selection Consent; performance of a contract
Operate your account, credits, and subscriptions Anonymous ID, subscription/credit data, Apple identity (if used) Performance of a contract
Personalize content and offers Gender, interests, locale Consent
Content safety (screening generated content) Selected selfie (automated screening) Legitimate interests; legal obligation
Product analytics and improvement Usage events (non-identifying) Legitimate interests
Security, fraud prevention, and abuse prevention Anonymous ID, device/usage signals Legitimate interests
Crash and error diagnostics Diagnostic data (non-identifying) Legitimate interests
Push notifications Push token, notification status Consent
Advertising attribution / measurement Advertising identifier (IDFA) Consent (via ATT)
Legal, tax, and accounting obligations Transaction/credit audit records Legal obligation

We do not use your photos, selfies, or generated media to train artificial intelligence models, and we do not use your personal data for unrelated products.

You may withdraw any consent at any time (see Section 9). Withdrawing consent does not affect processing carried out before withdrawal.


4. AI Processing & Third-Party Providers

To deliver the Service, we share limited data with the third-party providers below. Each processes data only to provide services to us and is bound to appropriate confidentiality and security obligations. We do not sell your personal information to any of them.

Explicit consent for AI processing. Before any photo is sent to fal.ai for the first time, we obtain your explicit in-app consent through a screen that identifies fal.ai by name and explains the purpose of the processing, consistent with Apple's requirements for sharing personal data with third-party AI services. You can read more about how that temporary copy is handled and deleted in Section 2.1.

Provider Purpose Data shared
fal.ai AI generation (face swap) and automated content-safety screening A temporary, time-limited secure link to your selected photo and the template reference. The link expires shortly after use.
Supabase Backend: database, authentication, secure storage Account identifier, preferences, generated media, subscription/credit data, and the temporary processing copy of your selected photo (deleted automatically when generation completes and in all cases within 24 hours)
Superwall Paywalls, purchase orchestration, entitlements Anonymous account identifier, app environment, app language, gender attribute
OneSignal Push notifications Anonymous account identifier, locale, premium status
AppsFlyer Marketing attribution and measurement Advertising identifier (if ATT granted), device/attribution signals, purchase events
PostHog Product analytics Anonymous identifier, non-identifying usage events and preferences
Sentry Crash and error reporting Pseudonymous identifier, technical diagnostics (no personal content)
Apple In-app purchases and Sign in with Apple Purchase receipts; Apple identity data (only if you use Sign in with Apple)

Each provider maintains its own privacy policy:

We may also disclose information when required by law, to comply with legal process, to protect our rights, safety, or property, or to investigate fraud or abuse.


5. International Data Transfers

Our infrastructure and several of our providers are located in the United States. If you use the Service from Brazil, the European Economic Area, the United Kingdom, or elsewhere outside the United States, your information will be transferred to and processed in the United States and in other countries where our providers operate.

These countries may have data-protection laws different from those in your country. Where required, such transfers are carried out under appropriate safeguards (such as the European Commission's Standard Contractual Clauses or equivalent mechanisms recognized under the LGPD).


6. Tracking & Advertising (App Tracking Transparency)

With your permission, we use the Apple Advertising Identifier (IDFA) and AppsFlyer to measure the effectiveness of our marketing and to understand how users discover the App.

We request this permission through Apple's App Tracking Transparency (ATT) prompt. If you decline, we do not use the IDFA to track you, and attribution is handled using privacy-preserving methods (such as Apple's SKAdNetwork). You can change this choice at any time in your device's Settings under Privacy & Security → Tracking.

We do not sell your personal information. Under the CCPA/CPRA, sharing identifiers for cross-context advertising measurement may be considered "sharing"; you can opt out at any time by declining or revoking the ATT permission.


7. Data Retention

Data Retention
Original selfie (local) Stored on your device only; up to the 3 most recent; removed automatically or when you sign out / delete your account
Temporary processing copy of selfie Deleted automatically when generation completes; in all cases within 24 hours
Generated media Until you delete it or delete your account
Account, preferences (gender, interests, locale) Until you delete your account
Apple identity data (if used) Until you delete your account
Subscription / credit transaction records Retained, in anonymized or pseudonymized form where applicable, for the period required by accounting, tax, and legal obligations, even after account deletion
Rating comments Retained in anonymized form after account deletion
Usage analytics, crash diagnostics Per the retention periods of PostHog and Sentry respectively

8. Account & Data Deletion

You can request deletion of your account and associated data directly within the App (in the account settings). When you do:

Important: Simply uninstalling the App does not delete your account or your data. Please use the in-app deletion option, or contact us at the email in Section 1.

If you used Sign in with Apple, you may also independently manage or revoke the App's access in your device's Settings → your Apple Account → Sign in with Apple.


9. Your Rights

Depending on where you live, you have rights over your personal data. Subject to applicable law, these include the right to:

California residents additionally have the right to know, delete, correct, and opt out of "sale"/"sharing" of personal information, and the right not to be discriminated against for exercising these rights. We do not sell personal information.

To exercise any right, contact us at privacy@divineme.app. We will respond within the timeframe required by applicable law. We may need to verify your identity before fulfilling certain requests.


10. Security

We use technical and organizational measures to protect your information, including encryption in transit (HTTPS/TLS), private storage buckets accessible only through short-lived signed links, access controls, and encryption at rest provided by our infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.


11. Children's Privacy

The Service is intended for users aged 16 and older and is rated accordingly on the App Store. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, please contact us at the email in Section 1 and we will take steps to delete it.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date above and, where appropriate, provide additional notice within the App. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.


13. Severability and Relationship to the Terms

If any provision of this Privacy Policy is held invalid or unenforceable, the remaining provisions will remain in full force and effect. This Privacy Policy forms part of, and should be read together with, our Terms of Use. Nothing in this Policy limits any non-waivable right you have under the LGPD, the GDPR, or other mandatory data-protection or consumer-protection law applicable to you.


14. Contact Us

If you have questions, requests, or concerns about this Privacy Policy or your personal data, contact us: