True Color ← Back to the site

Privacy Policy

Covers the True Color iOS app and this website.

The short version: your photos stay on your device — we never receive them, and the app has no access to your photo library at all. It does measure how its features are used, and reports crashes and errors, so we can fix what breaks. This website sets no cookies and runs no trackers at all. The only personal data we hold about you directly is your email address, and only if you join our mailing list yourself.

Who we are

True Color is an independent iOS photo editor, built and run by Ihor Malovanyi, a sole trader established in Ukraine. We are the data controller for the personal data described in this policy. For anything in it — including a request to see, correct or delete your data, or to receive our postal address — contact us at connect@gettruecolor.com.

The terms you agree to when you use the app are separate, and live in our Terms of Service.

The app

Your photos

True Color edits your photos on your device. Your images are never uploaded to us, never processed on a server, and never sent to any analytics or crash service. Editing works the same with the phone in airplane mode.

The app has no access to your photo library. Picking a photo uses the system picker, which shows your library without handing the app access to it — the app receives only the individual photos you choose. Saving a result asks for add-only permission, which lets the app write a new photo and never read or change anything already in your library. If you import straight from the camera, iOS asks for the camera at that moment, and the captured photo is handled exactly like a picked one.

The features that look like they need a server do not. Subject and depth detection, colourisation and the automatic adjustments all run on your device: the models are downloaded once (see below), and every photo they touch stays where it is.

Your projects, layers, masks, saved Looks and imported filters live in the app’s private storage on your device — and therefore in your own device backups, according to your iOS backup settings. We hold no copy of any of it.

Your Stats

Settings → Your Stats counts how you use the app — which tools and filters you reach for — and that tally is built and kept only on your device, as a file we never receive. To be precise about what that does and does not mean: the counters stay local, but the same underlying events also feed the analytics described next. Deleting the app deletes the tally.

Usage analytics

The app measures how it is used. We record events such as importing a photo, opening the editor, adding an adjustment layer, applying a Look and finishing an export, along with technical details like app version, device model, operating system and a device identifier generated by the analytics service. These are short labels and counts. They never include your photos, your file names or your contact details.

We use this to see which parts of the editor people actually reach and where the app fails, so we know what to fix and build next.

Crash reports

When the app crashes, we receive a crash report describing what the app was doing at that moment, plus the device model and operating system version.

Error reports

Separately from crash reports, the app reports handled errors — a photo that failed to import, an export that could not be written, a model that failed to load — so we can see failures that do not crash the app but do ruin your session. These reports describe the operation that failed and the app and device version.

Who processes app data

All of them act as our processors — they may use this data to provide the service to us, and not for their own purposes. We keep no separate copy of any of it on our own systems.

As the app grows we may add or replace analytics, crash-reporting and measurement providers. When we do, we will update this page and the effective date below.

Where the data goes, and what protects it

Firebase, Sentry, GitHub and Apple all store this data in the United States — outside the EEA, the UK and Ukraine. Transfers there are covered by the European Commission’s Standard Contractual Clauses, which each of these providers includes in its data processing terms, and by the EU–US Data Privacy Framework where the provider is certified under it. You can ask us for details of the safeguards that apply to any specific provider.

How long we keep app data

Crash and error reports are kept for up to 90 days and then deleted by Firebase Crashlytics and Sentry. Event-level analytics data is kept by Firebase for up to 14 months. The aggregate counts we actually read — how many people reached the editor this month — are kept indefinitely, because at that point they describe the app rather than a device.

Purchases, ads, accounts and tracking

The app shows you no advertising and has no user accounts. It does not track you across other apps or websites, does not ask for your device’s advertising identifier, and does not build a profile about you — which is why it declares no tracking in its App Store privacy report.

If we offer paid features, they are billed by Apple through the App Store; Apple handles the payment and we never see your card details. See the Terms of Service for how subscriptions work.

TestFlight

If you install a beta build through Apple TestFlight, Apple shares crash logs, basic usage information and any feedback you choose to send with us, and shows us the email address you use for TestFlight. That data is collected by Apple under Apple’s privacy terms.

This website

This website — unlike the app — sets no cookies and uses no analytics or tracking of any kind. There are no third-party scripts on it at all. Our hosting provider may keep standard server logs (IP address, time, page requested) for security and operations; we do not use them to identify anyone.

The one exception is the moment you submit the signup form: that sends your email address, and the request itself, to Buttondown. Nothing is sent to them before you press the button.

The mailing list

What we collect

Why

For exactly two purposes: news about True Color, and an invitation to the TestFlight beta. We will not use your email for anything else, and we never sell or share it.

How consent works

Signing up is double opt-in: after you submit the form, you get a confirmation email, and you are only subscribed once you click the link in it. Legally, we process your email on the basis of this consent (GDPR Art. 6(1)(a)).

Who processes it

The list is managed by Buttondown, our email service provider, acting as a data processor on our behalf. See the Buttondown privacy policy.

Buttondown is based in the United States, so your email address is stored there — outside the EEA and outside Ukraine.

How long we keep it

Until you unsubscribe or ask us to delete it. Every email we send includes a one-click unsubscribe link.

Legal basis (EU/EEA)

We process your email address on the basis of your consent (GDPR Art. 6(1)(a)), which you give with the checkbox on the signup form and can withdraw at any time. We process app usage and crash data on the basis of our legitimate interest (Art. 6(1)(f)) in understanding how the app is used and keeping it working. We process crash and error reports on the same basis, for the narrower interest of finding and fixing what breaks. We keep all of it to a minimum, none of it includes your photos, and you can object to any of it using the contact below.

Your rights

You can, at any time: access the data we hold about you, correct it, delete it, withdraw your consent, object to processing, or receive a copy of it. Email connect@gettruecolor.com and we will handle it promptly. If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority.

California residents (CCPA/CPRA)

The categories of personal information we collect are: identifiers (your email address, if you join the mailing list; a device identifier generated by our analytics provider inside the app) and internet or other electronic network activity (which app features you used, crash and error reports, and the IP address seen by our hosting providers). We collect them for the purposes described above — running the mailing list, and improving and fixing the app. We keep no other category: no geolocation, no contacts, no biometrics, and none of the contents of your photos.

We do not sell or share personal information, we do not use it for cross-context behavioural advertising, and we do not use it to build profiles about you. You have the right to know what we hold, to delete it, to correct it, and not to be discriminated against for exercising those rights — same contact as above.

Children

True Color and this website are not directed at children. Please do not join the mailing list if you are under 16. If we learn we hold a child’s email address, we will delete it.

Changes to this policy

If this policy changes, we will update this page and the date below. For material changes affecting the mailing list, we will also mention it by email.

Effective date: July 30, 2026