Privacy Policy
Effective October 6, 2026 · Applies to the PIC iOS app (“PIC”) and picphotospace.pages.dev.
1. Who we are
PIC is developed by Jaemin Song, an independent developer (“we”, “us”). Contact: pic@hello-support.com.
2. Where your data lives
| Data | Where it is stored | Who can read it |
|---|---|---|
| Photos you add (full image and thumbnail) | Your iCloud (CloudKit private database), encrypted with a unique key per photo (AES-256-GCM) | Members of the space whose iPhones hold the space's keys |
| Chat messages, read receipts | The sender's iCloud, end-to-end encrypted with the space's current key | Members at the time of sending |
| Your name in spaces, space names, member list | Your iCloud / the host's iCloud, encrypted | People holding that space's invite link and members |
| Face Passport (face template) | Only on your iPhone (Keychain, this device only, excluded from backups) | Only you — unless you turn on recognition in a space (see §3) |
| Identity keys | Your iCloud Keychain (end-to-end encrypted by Apple) | Only your devices |
| Push notification token | In your space profile, encrypted for members | Members' iPhones, which pass it to our notification relay (§4) |
Photos taken with PIC's camera are not saved to your Photos library. Photos you import are encrypted copies; the originals remain in your Photos library outside PIC's control. PIC removes location and other metadata (EXIF) from photos before encrypting them.
3. Face recognition and biometric data
Face recognition is optional and off until you set up a Face Passport and turn it on for a specific space.
- What we create: During setup, PIC uses your front camera to take a few live frames, detects your face with Apple's Vision framework, and converts it into a numeric face template (“face embedding”) using an on-device model. The camera frames are deleted immediately; they are never saved or uploaded.
- Purpose: only to recognize you in photos taken inside spaces where you enabled recognition, so you can receive control rights over those photos. It is never used for advertising, marketing, profiling or data mining, and never sold or shared with any third party.
- Sharing: when you turn recognition on in a space, an encrypted copy of your template is stored in your own iCloud space zone and can be decrypted only by that space's members' iPhones, which compare it with faces in photos they add — entirely on the iPhone. Our servers never receive your face template or any face image, readable or not.
- Retention: your template stays on your iPhone until you delete your Face Passport (Settings → Delete Face Passport) or use “Erase All PIC Data”. Shared encrypted copies are deleted when you turn recognition off, leave the space, or delete your Face Passport. Members' iPhones hold decrypted templates only in memory while matching.
- Consent: PIC asks for your explicit consent before creating a Face Passport. You can withdraw it at any time by deleting the Face Passport.
Recognition results (which members appear in a photo) are stored inside that photo's encrypted metadata and are visible to members who can open the photo.
4. Service providers
- Apple — iCloud/CloudKit stores your encrypted data in your iCloud account; Apple Push Notification service delivers notifications; the App Store processes subscriptions. Apple's privacy policy applies to those services.
- Cloudflare — hosts this website and a small notification relay. When a member sends a message or photo, their iPhone asks the relay to send a notification to the other members' push tokens. The notification contains no names, text or images — only a generic alert such as “New message in PIC”, localized on your iPhone. The relay processes tokens only to send the notification and does not store or log them.
We do not use analytics SDKs, advertising networks, or tracking of any kind, and we do not sell or share personal information.
5. Subscriptions
Purchases are handled by Apple. We do not receive your payment information. Your subscription status is checked on your iPhone using Apple's StoreKit.
6. Security and its limits
PIC uses Apple's CryptoKit (AES-256-GCM, P-256 key agreement and signatures, HKDF). Each photo has its own key; chat keys rotate when members join or leave so removed members cannot read new content. PIC hides content in the app switcher and during screen recording. However, no app can prevent screenshots, photos of the screen, or copies made by a recipient before content was removed.
7. Deleting your data
Use Settings → Erase All PIC Data in PIC to delete everything PIC stored in your iCloud and on your iPhone. Leaving a space removes your photos and messages from it. Deleting the app alone does not delete iCloud data; you can also remove it in iOS Settings → [your name] → iCloud → Manage Storage.
8. Your rights
Depending on where you live (for example under the GDPR, the CCPA/CPRA, Korea's PIPA, or Illinois' BIPA), you may have rights to access, correct, delete or port your personal data and to withdraw consent. Because your data is stored in your own iCloud and encrypted with keys only you and your space members hold, you can exercise these rights directly in the app. For anything else, contact us at the address above.
9. Children
PIC is not directed to children under 13, and we do not knowingly collect information from them.
10. Changes
We will post changes on this page and update the effective date. Material changes will also be announced in the app.
개인정보처리방침
시행일: 2026년 10월 6일
1. 개발자
개인 개발자 송재민 · 문의 pic@hello-support.com
2. 데이터 저장 위치
사진(원본·썸네일)은 사진마다 다른 키(AES-256-GCM)로 암호화되어 올린 사람의 iCloud에 저장됩니다. 채팅은 보낸 사람의 iCloud에 공간 키로 종단간 암호화되어 저장됩니다. 이름, 공간 이름, 멤버 목록도 암호화되어 각자 또는 호스트의 iCloud에 저장됩니다. 신원 키는 iCloud 키체인(Apple 종단간 암호화)에, Face Passport는 해당 iPhone의 키체인에만 저장됩니다. PIC 카메라로 찍은 사진은 사진 앱에 저장되지 않으며, 사진 앱에서 가져온 사진은 암호화된 사본이고 원본은 PIC 밖에 남습니다. 위치 등 메타데이터(EXIF)는 암호화 전에 제거합니다.
3. 얼굴 인식 및 생체정보
- 수집 항목·방법: 등록할 때 전면 카메라로 몇 장의 실시간 프레임을 찍고, 기기 안의 모델로 얼굴 특징값(템플릿)을 만듭니다. 촬영 프레임은 즉시 삭제됩니다.
- 이용 목적: 인식을 켠 공간에서 찍힌 사진 속 본인을 알아보고 권리를 부여하는 데에만 씁니다. 광고, 마케팅, 프로파일링 등 다른 목적으로는 쓰지 않으며 제3자에게 제공하거나 판매하지 않습니다.
- 공유: 특정 공간에서 인식을 켜면 암호화된 템플릿이 그 공간 멤버의 iPhone에서만 복호화되며, 비교는 모두 iPhone 안에서 이루어집니다. 개발자 서버는 얼굴 템플릿이나 얼굴 이미지를 받지 않습니다.
- 보유 기간: Face Passport를 삭제하거나 “모든 PIC 데이터 지우기”를 할 때까지 보관합니다. 공유된 암호화 사본은 인식을 끄거나, 공간을 나가거나, Face Passport를 삭제하면 지워집니다.
- 동의: 등록 전에 명시적으로 동의를 받으며, 언제든 삭제해 동의를 철회할 수 있습니다.
4. 처리 위탁
Apple(iCloud 저장, 푸시 알림 전달, 결제)과 Cloudflare(웹사이트, 알림 중계)를 이용합니다. 알림에는 이름, 내용, 이미지가 들어가지 않으며, 중계 서버는 푸시 토큰을 저장하거나 기록하지 않습니다.
5. 구독
결제는 Apple이 처리하며 개발자는 결제 정보를 받지 않습니다.
6. 보안과 한계
Apple CryptoKit 기반 암호화를 쓰고, 멤버가 바뀌면 채팅 키를 교체합니다. 다만 스크린샷, 화면 촬영, 삭제 전에 만든 사본은 어떤 앱도 막거나 회수할 수 없습니다.
7. 삭제 및 권리 행사
앱의 설정 → “모든 PIC 데이터 지우기”로 iCloud와 기기에 저장된 PIC 데이터를 모두 삭제할 수 있습니다. 개인정보 열람·정정·삭제·처리정지 요청은 앱에서 직접 하거나 위 이메일로 문의해 주세요.
8. 아동
만 13세 미만을 대상으로 하지 않습니다.