Who is responsible
BULB is an iPhone photography application operated by Studio M, Québec, Canada. This policy explains the app’s current data flows and the separate operation of this website.
Before publication: confirm the operator’s full legal name and business address, registration details where applicable, and the title and public contact details of the person responsible for personal information.
Camera, photos and sensors
The camera needs your permission to show a live preview and take photographs. Full-resolution shutter originals and editing recovery files are stored on your device. An original awaiting export is retained until saving to Photos succeeds or you explicitly discard it. Photo-library access is subject to the permission you grant in iOS.
Composition guides, on-device framing and photo editing run locally. Motion sensors help with stability and aiming on the device; BULB does not send their raw readings for cloud composition. Photos saved to your library may sync or be backed up according to your Apple settings.
Google AI analysis
When you request cloud AI framing, BULB sends one reduced camera-preview image, up to 768 pixels on its longest side, with framing instructions to Google’s Gemini service through Firebase. That image can contain people, objects or other information visible in the scene. Google returns a proposed frame and a short explanation. Your full-resolution shutter photo is not uploaded for composition.
Studio M’s framing gateway does not store the submitted image, prompt or AI result. This does not mean that every provider has zero retention: Google may retain data for security and abuse prevention under its service terms. The configured paid Gemini service states that prompts and responses are not used to improve Google’s products. See Gemini’s terms and Google’s retention information.
AI framing starts only when selected. Lines mode and on-device composition do not require this cloud image analysis. You always decide when to take the photo.
Identity and cloud allowance
BULB uses a Firebase anonymous account, without asking you to register with a name or email. Its unique identifier connects your free cloud allowance and subscription entitlement. An anonymous account is pseudonymous, not irreversibly anonymous: activity can be associated with the same identifier.
The current app stores this identifier, quota and decision records, subscription status, app version and platform, creation/activity timestamps, and app-open/photo counters in Firebase. These records support allowance enforcement, subscription synchronization and product operation. The lifetime allowance also uses a local Keychain counter. Uninstalling the app does not automatically erase the server records or reset the allowance.
App Store subscriptions
Pro is sold only through Apple’s App Store. Apple handles your payment details. BULB uses RevenueCat to validate purchases, restore access and determine subscription status, linked to the app identifier. RevenueCat processes purchase/transaction information and technical device or app information needed for that service. Studio M does not receive your full payment-card details.
Read Apple’s privacy policy and RevenueCat’s privacy policy. Cancelling an Apple subscription and requesting deletion of app data are separate actions.
App usage analytics
The current app integrates PostHog through its EU endpoint to understand onboarding, feature use and purchase flows. Events include app activity, onboarding steps and answer counts, camera/AI success or failure, quota notices, paywall and purchase/restore events, and photo capture/save events. Events can include technical app/device information and the same pseudonymous app identifier.
BULB does not send photographs, AI images, prompts, framing explanations, the content of optional onboarding answers, or photo file locations to PostHog. Session recording, automatic screen/text capture and location enrichment are disabled. Optional onboarding choices and preferences are stored locally.
Before publication: confirm analytics consent or other applicable legal basis, a working withdrawal/objection process, and the actual configured retention. The current app has no verified in-app analytics opt-out. This draft does not claim one exists.
Providers and transfers
Google/Firebase provides authentication, database, app-integrity checks and AI services; RevenueCat provides subscription validation; PostHog provides product analytics; Apple provides App Store payment and platform services. Requests may also involve connection and security data, such as IP addresses, at the provider level.
Information may be processed outside Québec and Canada. The current Firebase gateway runs in the United States; the PostHog endpoint is in the EU. That endpoint does not by itself guarantee that every associated service processes data only in the EU. Provider policies describe their respective safeguards and processing: Firebase, RevenueCat and PostHog.
Before publication: complete and document the applicable privacy assessments, service agreements and safeguards for transfers outside Québec.
Retention and deletion
Local photo recovery follows the save/discard rules above. Server identity, allowance and subscription records persist independently of the app installation. Provider security, transaction and operational records can have separate retention requirements.
Before publication: Studio M must set and implement a purpose-based retention schedule for Firebase, PostHog and support records, including deletion after inactivity and handling of legal obligations. No fixed server-deletion period has been verified. The website does not promise an unimplemented automatic deletion process.
Your choices and rights
You can manage Camera and Photos permissions in iOS Settings and use Lines instead of cloud AI. Depending on the applicable law, you can request access to or correction of your personal information, a copy in an available portable format, withdrawal of consent, and deletion where applicable. Some records may need to be retained to meet legal obligations. A request must be matched securely to your pseudonymous app identity.
Questions or complaints should be directed to Studio M’s privacy officer. You may also contact the Commission d’accès à l’information du Québec. Your statutory rights are not limited by this policy.
Public privacy contact and the verified identification/deletion procedure are pending owner confirmation. Do not send photographs or payment-card details to identify a privacy request.
This website and updates
This preview website has no analytics, advertising tracker, signup form or payment form. It saves your language preference in browser local storage. Framing and photo-look demonstrations run in your browser without accessing your camera or uploading images. A public hosting provider may process ordinary connection/security logs when the site is deployed.
The app and this website have different data practices. Material changes will be reflected in this policy with an updated date, with additional information or consent where required. Campaign images are illustrative; see the image credits.