This Privacy Policy explains how Thumbnail Face ("we", "us", "our") collects, uses, shares, and protects information when you use our Service.
1. Scope
This Policy covers:
- Information collected through the Service at
thumbnailface.app - Information you submit when creating an account or uploading images
- Information collected automatically (e.g., logs, analytics, crash reports)
It does not cover third-party websites or services you may access through the Service.
2. Information We Collect
A) Information you provide
- Account information: email address, username and/or profile details you provide during registration.
- User Content: images you upload to the Service for expression generation.
- YouTube URLs: YouTube video URLs you provide for thumbnail expression analysis.
- Support communications: information you include when contacting us (e.g., emails to support).
B) Information collected automatically
- Usage and device data: IP address, device/browser type, pages/screens viewed, timestamps, and general usage metrics.
- Log data: server logs and security/audit logs.
- Crash/diagnostic data: error and performance data if the app crashes or encounters issues.
C) Payment information
We do not store full payment card details on our servers. Payments are handled by our payment provider Creem. Depending on your payment method, Creem may collect billing details and payment instrument data. We may receive limited payment-related information such as payment status, purchased credit package, and transaction identifiers.
3. How We Use Information
We use information to:
- Provide, operate, and maintain the Service (including processing your uploaded images and generating expression-swapped results)
- Authenticate users and prevent abuse, fraud, or security incidents
- Monitor performance, troubleshoot issues, and improve reliability
- Communicate with you about the Service (support responses, critical notices, account messages)
- Process credit purchases and manage your credit balance
- Analyze YouTube thumbnails when you provide YouTube URLs for expression extraction
4. Legal Bases (If Applicable)
If you are in a jurisdiction that requires legal bases (e.g., EEA/UK), we process personal data based on:
- Contract necessity (to provide the Service you request)
- Legitimate interests (security, fraud prevention, analytics, service improvement)
- Consent where required by applicable law
5. Sharing and Disclosure
We share information only as needed to run the Service, including with the following categories of service providers ("processors"):
- Analytics: Umami (usage analytics).
- Crash reporting & performance monitoring: Sentry (diagnostics, error logs).
- Payments: Creem (payment processing).
- Backend infrastructure: Convex (application backend and data storage/processing).
- AI processing: Third-party AI services for image generation and analysis.
We may also disclose information:
- For legal reasons: to comply with laws, regulations, lawful requests, or protect rights, safety, and security.
- Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets (you will be notified where required).
- With your direction/consent: when you choose to integrate with or share data via third-party services.
6. Cookies and Similar Technologies
We use minimal cookies that are strictly necessary for the Service to function:
- Authentication cookies: Required to keep you logged in and maintain your session.
- Security cookies: Used to prevent fraud and protect your account.
Analytics: We use Umami, a privacy-focused analytics tool that does not use cookies and does not collect personally identifiable information. It only collects anonymous, aggregated data about page views and usage patterns.
We do not use advertising cookies, tracking cookies, or any third-party cookies for marketing purposes.
7. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy, including:
- Account data: retained while your account is active; may be retained for a limited period after deletion for legal, security, or operational reasons.
- Uploaded images: retained while you store them in the Service; deleted upon your deletion requests or account deletion, subject to backups and legal obligations.
- Generated images: retained while associated with your account; deleted when you delete them or your account.
- Credit transaction history: retained for accounting and audit purposes as required by law.
- Logs/diagnostics: retained for a limited period to maintain security and reliability.
8. Security
We use reasonable administrative, technical, and organizational measures designed to protect information. However, no method of transmission or storage is 100% secure.
9. Your Rights and Choices
Depending on your location, you may have rights such as:
- Access, correction, or deletion of personal data
- Objection or restriction to certain processing
- Data portability
- Withdrawal of consent (where processing is based on consent)
To exercise rights, contact us at support@thumbnailface.app. We may ask you to verify your identity before fulfilling requests.
10. International Data Transfers
Because we operate globally, your information may be processed in countries different from where you live. We take steps to protect your information in accordance with applicable laws.
11. Children's Privacy
The Service is not intended for children under 16 years old. We do not knowingly collect personal information from children under that age.
12. Changes to This Policy
We may update this Policy from time to time. We will post the updated version on thumbnailface.app and update the Effective Date. If changes are material, we may provide additional notice.
13. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Email: support@thumbnailface.app