This Privacy Policy explains how Filipe de Oliveira Silva (the "Company", "we", "us", or "our") collects, uses, shares, and protects your information when you use the DivineME mobile application (the "App") and related services (collectively, the "Service").
PLEASE READ THIS PRIVACY POLICY CAREFULLY. By downloading, accessing, or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.
This Privacy Policy is designed to comply with the EU General Data Protection Regulation (GDPR), the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados – LGPD), the California Consumer Privacy Act as amended (CCPA/CPRA), and Apple App Store requirements.
Key Points About Our Privacy Practices
If you read nothing else, these are the points that matter most:
- DivineME creates faith-inspired photos and videos from a selfie you choose. The App applies your face to pre-designed templates (a "face swap"). There are no free-text prompts — generation is template-based, using only templates we curate and pre-approve.
- We only process the specific photo you select. We never upload or scan your entire photo library, and we do not access your camera.
- Your selfie is processed, not stored. A temporary copy is sent to our AI processing provider only to create your result, and is automatically deleted when generation finishes (and in all cases within 24 hours).
- We ask for your explicit consent before sending your photo to our AI provider. A consent screen identifies the provider (fal.ai) and the purpose; generation does not proceed unless you agree.
- DivineME is not a social network. There is no public feed, and no other user can see your content — only you can view your generated media in the App. Any sharing to other apps is initiated and controlled by you.
- We do not use your photos or generated media to train AI models, and we do not sell your personal information.
- You can use the App anonymously. An anonymous account is created automatically; you are not required to provide your name or email. Signing in with Apple is optional.
- You can delete your account and data from within the App at any time.
- We use trusted third-party providers (including fal.ai, Supabase, Superwall, OneSignal, AppsFlyer, PostHog, and Sentry) to operate the Service. Each is described below.
1. Who We Are (Data Controller)
The data controller responsible for your personal data is:
- Controller: Filipe de Oliveira Silva
- Address: Estrada São Francisco, 2008 - Sala 306 ANEXO B-218, Taboão da Serra/SP 06765-904
- Contact / Privacy requests: privacy@divineme.app
- Data Protection Officer / Encarregado (LGPD): privacy@divineme.app
2. Information We Collect
We practice data minimization: we collect only what is necessary to operate the Service. We do not ask you to type your name, email, phone number, or any free-text prompt during generation.
2.1 Photos You Provide (Selfies)
When you choose to create media, you select a photo from your device's photo library through the system photo picker. We process only the specific image you select. We do not access your camera, and we do not read your full photo library.
- On-device face check: When you select a photo, the App performs a basic, on-device face-presence check using Apple's Vision framework, solely to confirm that a face is present in the image. This check runs entirely on your device. It does not extract, measure, store, or transmit facial geometry, landmarks, biometric templates, or any data that could be used to identify you.
- Local storage: Selected selfies are stored locally on your device (a maximum of the three most recent are kept; older ones are removed automatically). These local files may be included in your device's standard iCloud backup, which is controlled by your Apple account settings, not by us.
- Explicit consent before processing: Before any temporary copy of your photo is sent to our AI provider for the first time, the App shows a consent screen that identifies the provider (fal.ai) and explains the purpose. Generation does not proceed unless you consent. If you decline, no copy is sent and no media is generated; the consent screen reappears on your next attempt until you accept.
- Temporary processing copy: To generate your result, a temporary copy of the selected photo is uploaded to our secure, private cloud storage (hosted by Supabase in the United States) and made available to our AI provider through a short-lived, time-limited secure link. This copy is automatically deleted as soon as generation completes (whether it succeeds or fails), and an additional automatic 24-hour deletion rule ensures no temporary copy persists beyond 24 hours. We do not permanently store your original selfie on our servers.
Note on sensitive data: Although we do not create or retain biometric identifiers, a photo of your face may be considered sensitive personal data under the GDPR, the LGPD, and similar laws. We process it only with your consent and only to provide the feature you requested, as described in this Policy.
2.2 Generated Media
The photos and videos the Service creates for you are stored in our secure, private cloud storage and remain accessible only to you within the App — there is no public feed and no other user can view your media. You can delete individual generated media at any time. Generated media is retained until you delete it or until your account is deleted.
2.3 Account & Identity Data
- Anonymous identifier: When you start using the App, an anonymous account is created and an anonymous user identifier (a random UUID) is generated. This identifier is used to associate your content, credits, and preferences with your account.
- Sign in with Apple (optional): If you choose to link or sign in with Apple, we receive and store the information Apple provides — which may include your name, your email address (or Apple's private relay address), and a stable Apple user identifier. This is only collected if you use Sign in with Apple.
2.4 Preferences You Provide (Optional)
- Gender — used to personalize template suggestions and offers. Optional; you may skip it.
- Interests — used to curate content. Optional; you may skip it.
- Rating comments — if you choose to leave optional feedback on a generated result (free text, up to 500 characters).
2.5 Information Collected Automatically
- Device language / locale — to localize content.
- Subscription and credit data — your subscription tier, expiration, and credit balance and history, to operate purchases and entitlements.
- Push notification status — whether you have enabled notifications.
- Usage events — approximately 25 product-analytics events describing how you navigate and use features. These events are designed not to contain personal identifiers or content.
- Diagnostics / crash data — technical crash and error reports, which do not include personal content.
- Advertising identifier (IDFA) — only if you grant permission through Apple's App Tracking Transparency (ATT) prompt. See Section 6.
2.6 Payment Information
Purchases are processed by Apple through Apple's in-app purchase system (StoreKit), mediated by our paywall provider (Superwall). We do not collect or store your credit card or payment-card details. We receive transaction confirmations and store your resulting subscription/credit status.
3. How We Use Your Information (Purposes & Legal Bases)
We use your information for the following purposes. Where the GDPR or LGPD applies, the legal basis for each is indicated.
| Purpose | Data used | Legal basis (GDPR / LGPD) |
|---|---|---|
| Provide the core generation feature (face swap) | Selected selfie, template selection | Consent; performance of a contract |
| Operate your account, credits, and subscriptions | Anonymous ID, subscription/credit data, Apple identity (if used) | Performance of a contract |
| Personalize content and offers | Gender, interests, locale | Consent |
| Content safety (screening generated content) | Selected selfie (automated screening) | Legitimate interests; legal obligation |
| Product analytics and improvement | Usage events (non-identifying) | Legitimate interests |
| Security, fraud prevention, and abuse prevention | Anonymous ID, device/usage signals | Legitimate interests |
| Crash and error diagnostics | Diagnostic data (non-identifying) | Legitimate interests |
| Push notifications | Push token, notification status | Consent |
| Advertising attribution / measurement | Advertising identifier (IDFA) | Consent (via ATT) |
| Legal, tax, and accounting obligations | Transaction/credit audit records | Legal obligation |
We do not use your photos, selfies, or generated media to train artificial intelligence models, and we do not use your personal data for unrelated products.
You may withdraw any consent at any time (see Section 9). Withdrawing consent does not affect processing carried out before withdrawal.
4. AI Processing & Third-Party Providers
To deliver the Service, we share limited data with the third-party providers below. Each processes data only to provide services to us and is bound to appropriate confidentiality and security obligations. We do not sell your personal information to any of them.
Explicit consent for AI processing. Before any photo is sent to fal.ai for the first time, we obtain your explicit in-app consent through a screen that identifies fal.ai by name and explains the purpose of the processing, consistent with Apple's requirements for sharing personal data with third-party AI services. You can read more about how that temporary copy is handled and deleted in Section 2.1.
| Provider | Purpose | Data shared |
|---|---|---|
| fal.ai | AI generation (face swap) and automated content-safety screening | A temporary, time-limited secure link to your selected photo and the template reference. The link expires shortly after use. |
| Supabase | Backend: database, authentication, secure storage | Account identifier, preferences, generated media, subscription/credit data, and the temporary processing copy of your selected photo (deleted automatically when generation completes and in all cases within 24 hours) |
| Superwall | Paywalls, purchase orchestration, entitlements | Anonymous account identifier, app environment, app language, gender attribute |
| OneSignal | Push notifications | Anonymous account identifier, locale, premium status |
| AppsFlyer | Marketing attribution and measurement | Advertising identifier (if ATT granted), device/attribution signals, purchase events |
| PostHog | Product analytics | Anonymous identifier, non-identifying usage events and preferences |
| Sentry | Crash and error reporting | Pseudonymous identifier, technical diagnostics (no personal content) |
| Apple | In-app purchases and Sign in with Apple | Purchase receipts; Apple identity data (only if you use Sign in with Apple) |
Each provider maintains its own privacy policy:
- fal.ai — https://fal.ai/privacy
- Supabase — https://supabase.com/privacy
- Superwall — https://superwall.com/legal/privacy-policy
- OneSignal — https://onesignal.com/privacy_policy
- AppsFlyer — https://www.appsflyer.com/legal/services-privacy-policy/
- PostHog — https://posthog.com/privacy
- Sentry — https://sentry.io/privacy/
- Apple — https://www.apple.com/legal/privacy/en-ww/
We may also disclose information when required by law, to comply with legal process, to protect our rights, safety, or property, or to investigate fraud or abuse.
5. International Data Transfers
Our infrastructure and several of our providers are located in the United States. If you use the Service from Brazil, the European Economic Area, the United Kingdom, or elsewhere outside the United States, your information will be transferred to and processed in the United States and in other countries where our providers operate.
These countries may have data-protection laws different from those in your country. Where required, such transfers are carried out under appropriate safeguards (such as the European Commission's Standard Contractual Clauses or equivalent mechanisms recognized under the LGPD).
6. Tracking & Advertising (App Tracking Transparency)
With your permission, we use the Apple Advertising Identifier (IDFA) and AppsFlyer to measure the effectiveness of our marketing and to understand how users discover the App.
We request this permission through Apple's App Tracking Transparency (ATT) prompt. If you decline, we do not use the IDFA to track you, and attribution is handled using privacy-preserving methods (such as Apple's SKAdNetwork). You can change this choice at any time in your device's Settings under Privacy & Security → Tracking.
We do not sell your personal information. Under the CCPA/CPRA, sharing identifiers for cross-context advertising measurement may be considered "sharing"; you can opt out at any time by declining or revoking the ATT permission.
7. Data Retention
| Data | Retention |
|---|---|
| Original selfie (local) | Stored on your device only; up to the 3 most recent; removed automatically or when you sign out / delete your account |
| Temporary processing copy of selfie | Deleted automatically when generation completes; in all cases within 24 hours |
| Generated media | Until you delete it or delete your account |
| Account, preferences (gender, interests, locale) | Until you delete your account |
| Apple identity data (if used) | Until you delete your account |
| Subscription / credit transaction records | Retained, in anonymized or pseudonymized form where applicable, for the period required by accounting, tax, and legal obligations, even after account deletion |
| Rating comments | Retained in anonymized form after account deletion |
| Usage analytics, crash diagnostics | Per the retention periods of PostHog and Sentry respectively |
8. Account & Data Deletion
You can request deletion of your account and associated data directly within the App (in the account settings). When you do:
- Your request begins a deletion process. After a 30-day grace period, your profile, generated media, and associated account records are permanently deleted from our systems.
- Certain records may be retained where required by law or for legitimate purposes — specifically, transaction and credit audit records (retained for accounting/tax/fraud-prevention purposes) and anonymized feedback. These are disassociated from your identity where feasible.
Important: Simply uninstalling the App does not delete your account or your data. Please use the in-app deletion option, or contact us at the email in Section 1.
If you used Sign in with Apple, you may also independently manage or revoke the App's access in your device's Settings → your Apple Account → Sign in with Apple.
9. Your Rights
Depending on where you live, you have rights over your personal data. Subject to applicable law, these include the right to:
- Access the personal data we hold about you and obtain a copy;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict or object to certain processing;
- Data portability — receive your data in a structured, machine-readable format;
- Withdraw consent at any time, where processing is based on consent;
- Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects;
- Lodge a complaint with a supervisory authority — in Brazil, the Autoridade Nacional de Proteção de Dados (ANPD); in the EU/EEA, your local Data Protection Authority; in the UK, the ICO.
California residents additionally have the right to know, delete, correct, and opt out of "sale"/"sharing" of personal information, and the right not to be discriminated against for exercising these rights. We do not sell personal information.
To exercise any right, contact us at privacy@divineme.app. We will respond within the timeframe required by applicable law. We may need to verify your identity before fulfilling certain requests.
10. Security
We use technical and organizational measures to protect your information, including encryption in transit (HTTPS/TLS), private storage buckets accessible only through short-lived signed links, access controls, and encryption at rest provided by our infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children's Privacy
The Service is intended for users aged 16 and older and is rated accordingly on the App Store. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, please contact us at the email in Section 1 and we will take steps to delete it.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date above and, where appropriate, provide additional notice within the App. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
13. Severability and Relationship to the Terms
If any provision of this Privacy Policy is held invalid or unenforceable, the remaining provisions will remain in full force and effect. This Privacy Policy forms part of, and should be read together with, our Terms of Use. Nothing in this Policy limits any non-waivable right you have under the LGPD, the GDPR, or other mandatory data-protection or consumer-protection law applicable to you.
14. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or your personal data, contact us:
- Filipe de Oliveira Silva
- Email: privacy@divineme.app
- Address: Estrada São Francisco, 2008 - Sala 306 ANEXO B-218, Taboão da Serra/SP 06765-904