Privacy Policy
1. Overview
This Privacy Policy explains how FunnyFace collects, uses, stores, shares, and protects data when you use the FunnyFace app on iOS and Android.
FunnyFace is an AI photo generation and editing app. Because the app processes photos you upload, including photos that may show faces, we try to be specific about what is processed and why.
- Operator: Nguyen Van Tuyen, an individual developer
- Contact: support@funny-face.org
FunnyFace is offered in selected countries only, and is not offered in the European Economic Area, the United Kingdom, or Switzerland.
2. Data We Collect
2.1. Account Data
We use Firebase Authentication for sign-in with Apple, Google, and email. Account data may include:
- Firebase user ID;
- Email address;
- Email verification status;
- Sign-in method;
- Display name;
- Avatar, if you upload one;
- Account creation and update timestamps;
- Account status and information needed for support or security;
- The date, time, and document version of the consents you gave when creating the account.
2.2. Photos and Content You Provide
When you generate images with FunnyFace, we process:
- The photos you upload;
- The photos you keep in your Library;
- The images we generate for you;
- The style and settings you chose;
- Whether a generation succeeded or failed, and technical error information when it failed;
- Your generation and download history.
Uploaded and saved photos and generated images are kept until you delete them, or until you delete your account. See section 10.
2.3. Credits and Usage Data
We store what is needed to run the credit system:
- Your credit balances;
- A record of credits spent, refunded, and granted;
- Your account status.
FunnyFace currently has no in-app purchases or subscriptions, and we collect no payment information of any kind.
2.4. Device and Notification Data
If you enable push notifications, we may store:
- An identifier for your device;
- A notification token, so that Firebase can deliver a message to it;
- The type of device;
- What is needed to notify you when a generation finishes.
We do not use push notifications for marketing. Push is used for generation status and app operation.
Push notifications carry no personal content. They say only that an image is ready or that one could not be created, together with whether a credit was returned. They contain no image, no prompt, no account details, and no error text from an AI provider. A notification on your lock screen reveals nothing about what you generated.
2.5. Analytics, Crash Reporting, and Advertising
FunnyFace uses Firebase Analytics to understand how the app is used. Analytics data may include app usage events, device information, session data, an estimated country or region, app version, and similar metrics. Analytics data is retained by Firebase for the period configured in our Firebase project.
FunnyFace uses Firebase Crashlytics to detect, analyse, and fix crashes. Crash reports may include device information, operating system, app version, stack traces, crash timestamps, and related technical data.
FunnyFace uses AdMob to show ads, and we serve personalised ads. This means the ads you see may be selected based on a profile of your interests, built from your activity across apps and websites.
For this, Google may process your advertising identifier (the IDFA on iOS, the Advertising ID on Android), your IP address, device information, your interaction with ads, an estimated location derived from your IP address, and data needed for frequency capping, measurement, and ad fraud prevention. Google may combine this with data it holds from other apps and websites in order to select ads. This constitutes tracking across apps and websites.
Our analytics configuration is linked to advertising, so Firebase Analytics data may also contribute to ad personalisation and measurement.
On iOS, we ask for your permission first. Before we use your advertising identifier for personalised advertising, iOS shows you an App Tracking Transparency prompt. If you decline, we serve non-personalised ads instead, and your advertising identifier is not used for personalisation. You can change this at any time in your device settings.
On Android, personalised advertising uses your Advertising ID unless you opt out in your device settings. See section 13 for how.
We send no marketing email and no marketing push notifications.
2.6. Technical Logs and Security Data
We collect technical logs to operate, secure, debug, and support the Service, and to prevent abuse. Logs may include your IP address, the time of a request, error information, details about your device and app version, and an internal reference to your account.
Technical logs are retained for up to 45 days, unless a longer period is needed to comply with the law, resolve a dispute, or investigate fraud or abuse.
2.7. Support Communications
If you contact us, we may process your email address, the content of your message, screenshots, account information, and what else is needed to answer you.
3. How We Use Data
We use data to:
- Generate, process, store, and return your images;
- Authenticate your account and maintain your session;
- Run the credit system;
- Notify you about generation status;
- Show you your Library, your avatar, and your generation history;
- Provide technical support;
- Analyse how the app performs and improve the product;
- Detect crashes, debug, and fix errors;
- Show personalised ads and measure their delivery;
- Protect our systems against spam, abuse, fraud, and unauthorised access;
- Comply with the law, respond to valid requests from competent authorities, and protect our and our users' legitimate interests.
4. Consent
When you create a FunnyFace account, you give two separate confirmations before the account exists:
- Acceptance of the Terms of Service and this Privacy Policy.
- Consent to FunnyFace processing the photos you upload in order to generate new images.
We record the date, time, and document version for each. You can withdraw your consent by deleting your account, which stops all processing and removes your data as described in section 11. Because processing your photos is what the app does, withdrawing that consent is not compatible with continuing to use the Service.
5. AI Processing and Third-Party Providers
To generate an image, FunnyFace sends the photo you uploaded, together with the instructions describing the style you chose, to a third-party AI service provider.
We send nothing that identifies you. The request carries no account or user identifier, no email address, and no device identifier, and your file is sent under a generic name. The provider receives an image and a set of instructions, with nothing in the request that links either of them to your account.
This is a data minimisation measure, not anonymisation: a photograph of a person is itself identifying, and we do not claim otherwise.
The result is held on the provider's systems for a limited window, currently up to one hour, while we retrieve it. After that it is stored on our own systems.
Why we describe AI providers as a category rather than by name. We name the companies behind our stable infrastructure — Firebase, Cloudflare, Google, Apple — because those choices rarely change. The set of AI providers we use does change over time for operational and cost reasons, and a policy document cannot keep pace with it. We therefore do not name them in this document, which would be out of date the first time we changed one. If you have a FunnyFace account and want to know which AI providers processed your photos, contact support@funny-face.org and we will tell you. We may verify that the request comes from the account holder before answering.
We are an individual developer and we do not have individually negotiated data processing agreements with these providers. A provider's handling of data is therefore also governed by that provider's own published terms and configuration, and we will point you to those terms if you ask. Before enabling a provider, we review its published terms and, where the provider offers a setting that limits retention or the use of submitted data for model training, we enable it. We do not make commitments on a provider's behalf that we are not in a position to enforce.
6. Facial Images and Biometric Data
Many FunnyFace users upload photos of themselves or of people they know, so we want to be precise about what we do and do not do with a face.
FunnyFace does not perform facial recognition. We do not detect, extract, measure, or store facial features, face templates, embeddings, or any other biometric identifier. We do not match one photo against another, we do not group photos by the person shown in them, and nothing in our system can determine that two uploads show the same person.
Our own handling of an image is limited to resizing and re-encoding it for storage. Everything else is the generative transformation performed by the AI provider, which returns a new image and no analysis of the original.
We treat your photos as personal data. We do not process them as biometric data, because we do not derive biometric information from them. If that ever changes, we will update this policy and ask for your consent before the change takes effect.
7. How We Share Data
We do not sell your personal photos. We share data with the following categories of third party, only to the extent necessary:
- Firebase and Google: authentication, push notifications, analytics, crash reporting, and related infrastructure.
- AdMob and Google: selection, personalisation, delivery, measurement, security, and fraud prevention for advertising. Google may combine the data described in section 2.5 with data it holds from other apps and websites.
- Apple and Google: identity providers, when you sign in with an Apple or Google account.
- Cloudflare R2: image storage in production.
- Our hosting provider in Vietnam: running the servers that FunnyFace operates on.
- Third-party AI service providers: image processing and generation, as described in section 5.
- Competent authorities or other relevant parties: where required by law, or where necessary to protect legitimate interests, investigate violations, prevent fraud or abuse, or protect user safety.
8. Staff and Administrative Access
FunnyFace has an internal administration tool used to operate the Service and answer support requests. Through it, the developer can see your account information — including your email address and display name — along with records about your generations: the style you chose, the original name of a file you uploaded, when it ran and whether it succeeded, your credit history, and how much storage your account uses.
The administration tool does not display the content of your photos. It works with records and summaries; it gives no view of the images you upload or generate.
Access is limited to the developer operating the Service and is used only for operation, support, security, and abuse investigation.
9. Storage Location and International Processing
The servers that run FunnyFace are located in Vietnam. Some data and services are handled by Firebase and Google, Cloudflare R2, AdMob, Apple, and third-party AI service providers. Those providers may process or store data in a number of countries and regions, depending on their configuration and infrastructure.
By using FunnyFace, you understand that data may be processed outside the country or region where you live.
10. Retention
We keep data for as long as needed for the purposes described in this policy. Currently:
- Uploaded photos, saved photos, and generated images are kept until you delete them or delete your account. No automatic expiry is applied to them today. We are able to switch on an expiry period for generated images; it is currently switched off, and if we switch it on we will update this policy and notify users before it takes effect.
- Daily credits do not carry over to the next day. Balance and fast credits do not currently expire.
- Technical logs are retained for up to 45 days.
- Analytics data is retained by Firebase for the period configured in our Firebase project.
- After account deletion, one irreversible value derived from your email address is retained for up to 48 hours, as described in section 11.
- Some data may persist for a limited period in backups, or where necessary for security, fraud prevention, dispute resolution, or legal compliance.
11. Deleting Data and Deleting Your Account
You can delete your account from the app's settings. Deleting your account requires a recent sign-in; if you have not signed in recently, the app will ask you to sign in again first.
When you delete your account, we permanently delete the account and the data attached to it in our systems, including:
- The photos you uploaded and saved;
- The images we generated for you;
- Your avatar;
- Your generation and download history;
- Your devices and their notification tokens;
- Your credit balances and credit history.
Account deletion cannot be undone. If you signed in with Apple, the app may require you to revoke your Apple token first.
Two things do not disappear at the moment you press delete, and we state them explicitly:
- Your Firebase sign-in record is deleted on a best-effort basis. Your account in our system is removed first, which ends access immediately. If the Firebase deletion then fails, we log it; the leftover record is inert, and signing in again produces a clean, empty registration.
- One irreversible value derived from your email address is kept for up to 48 hours. It is a hash, not the address. Its only purpose is to prevent an account being deleted and recreated to collect the daily credit allowance more than once in a day. It is deleted automatically after that window and is used for nothing else.
You can also delete individual images in the app. If we cannot delete a stored image, the whole deletion fails rather than half-succeeding — so you are never left with a record saying an image is gone while the image itself survives.
12. Your Rights
Depending on where you live, you may have the right to:
- Ask what data we hold about you;
- Ask to access, correct, or update it;
- Ask us to delete your data or your account;
- Object to or restrict certain processing;
- Withdraw consent where processing is based on it;
- Ask for an export of your data, within what is technically reasonable.
In the app you can edit your display name, upload or remove your avatar, and delete your account. For access, export, correction requests, or any other question, contact support@funny-face.org.
We will respond as soon as reasonably possible. If you are not satisfied with our response, you may complain to the competent data protection authority where you live. In Vietnam, personal data protection is administered by the Ministry of Public Security.
13. Advertising Choices
FunnyFace shows personalised ads through AdMob. You can turn personalisation off at any time, and the app keeps working — you will simply see non-personalised ads instead.
On iOS. When iOS shows the App Tracking Transparency prompt, choosing "Ask App Not to Track" stops your advertising identifier being used for personalisation. You can change your answer later in Settings → Privacy & Security → Tracking, either for FunnyFace specifically or for all apps at once.
On Android. Open Settings → Google → Ads. You can turn on "Opt out of Ads Personalization", or delete your Advertising ID entirely, which stops apps receiving it.
Across Google services. You can review and change what Google uses to personalise ads at adssettings.google.com, using the Google account signed in on your device.
If you are in a United States state with applicable privacy legislation, AdMob may show you an additional privacy notice with the choices available to you there.
Ads cannot be removed from FunnyFace, since the app is provided free of charge and advertising is what funds it.
14. Security
We apply reasonable technical and organisational measures to protect data, including Firebase authentication, restricted access, storage through established infrastructure providers, and appropriate operational practices. Your images are served only to the signed-in account that owns them — this covers both the images you generate and your avatar. Download links expire a short time after they are issued.
No system is perfectly secure. Keep your device, your Apple, Google, or email account, and your sign-in credentials protected, and do not share them.
15. Data Breach Notification
If personal data we hold is lost, disclosed, altered, or accessed without authorisation, and that is likely to affect you, we will:
- Act to contain the incident and limit its effects as soon as we become aware of it;
- Notify the competent authority where the law requires it, within the period the law sets;
- Notify affected users without undue delay, in the app or by email, describing what happened, what data was involved, what we have done, and what you can do;
- Record the incident and what we changed as a result.
FunnyFace is operated by one person, so we would rather tell you plainly what we know when we know it than delay a notice until every detail is settled.
16. Children
FunnyFace is for people aged 16 and over. It is not designed for and not directed at anyone under 16, and we do not knowingly collect personal data from anyone under 16.
If you become aware that someone under 16 has created an account, contact support@funny-face.org. If we confirm it, we delete the account and its data, in the same way as described in section 11, and we do so without requiring the account holder to act.
17. Third-Party Services and Links
FunnyFace integrates with or links to third-party services including Apple, Google, Firebase, AdMob, Cloudflare, and third-party AI service providers. Your use of those services may be governed by their own privacy policies and terms.
We encourage you to read them, particularly when you sign in, view ads, or use AI generation features.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Each version carries the version identifier shown at the top of this document.
Where a change is significant, we will try to notify you in the app or by another appropriate means. The last updated date is always shown at the top.
19. Contact
Questions, requests, or complaints about privacy, and support requests:
- Email: support@funny-face.org