Privacy Policy
Effective 27 July 2026
SpecFit is an iPhone app by Codemad ("we", "us") that shows you how glasses look on your real face and estimates your pupillary distance (PD). This policy explains what the app processes on your device, what it sends to service providers, how long data is kept, and the choices available to you.
The short version
- Your 3D face scan, face mesh, and measurements never leave your iPhone.
- For each new try-on, the one photo you approve is sent over HTTPS through Cloudflare to Google's paid Gemini API. Codemad does not store the photo or generated image on its servers, but Google may retain prompts and responses for a limited period for abuse prevention as described below.
- SpecFit sends one anonymous device identifier that doubles as your RevenueCat customer id and your PostHog analytics id. There is no weekly render cap: renders are limited by your purchased credit balance and a global daily cost budget.
- No account, no advertising, no cross-app tracking, and no sale of personal data.
Data that stays on your device
When you complete the guided face scan on a Face ID iPhone, SpecFit captures a depth mesh of your face and derives measurements from it: your pupillary distance, face width, and bridge width. The scan, mesh, measurements, prescription values, approved base photo, saved try-on renders, and saved product-link frames are stored in the app's iOS sandbox. The face profile is written using complete file protection.
Drawing the measurement lines on your photo uses Apple's on-device Vision framework. That analysis also happens entirely on your phone.
Choosing Delete my capture and all renders deletes the face profile, approved photo, measurements, mesh, and renders for that profile. It does not delete your prescription setting, saved product-link frames, or the quota identifier. You can clear the prescription separately in Settings. Deleting the app removes its sandboxed files; the quota identifier is stored in the iOS Keychain and may survive reinstall.
Data that leaves your device, and where it goes
Your chosen photo, per new render. To generate a photorealistic try-on, the front-facing photo you approved is transmitted over HTTPS to our Cloudflare Worker and forwarded to Google's Gemini image API with an editing instruction and, for product-link try-ons, a product image. Codemad processes these items in memory for the duration of the request and does not write the photo or generated image to its server-side KV or Durable Object storage.
Google processes the request as our service provider under the Gemini API Additional Terms. For paid Gemini API use, Google states that it does not use prompts or responses to improve its products, but it may log prompts and responses for a limited period to detect and prevent prohibited use and meet legal obligations. That processing may occur in countries where Google or its agents operate. Codemad does not use your photo for advertising, identification, or model training.
Anonymous device identifier and render activity. The app creates a random UUID, stores it in the iOS Keychain, and sends it to our Cloudflare service. It contains no name, email address, advertising ID, or face data. The same identifier is also your RevenueCat customer id and your PostHog analytics id, so purchases and usage analytics key to one anonymous id with no account or personal data. There is no weekly render cap: renders are paid for with credits, and a global daily budget bounds total rendering cost. The service keeps recent successful-render timestamps against the identifier for cost control; older timestamps are pruned over time, and the record may otherwise remain until a verified deletion request.
Pasted product links. If you paste a store link, the URL is sent to our Cloudflare service, which fetches public listing data and product images and asks Gemini to select a suitable product photo. The extracted result, including the source URL and product image, is cached by a hash of the URL for seven days. The cache entry does not contain your quota identifier.
Service request logs. Cloudflare processes ordinary network information, such as IP address, request path, time, response status, and related security or operational metadata, to deliver and protect the service. Workers invocation logs are retained for no more than seven days. Our Worker code does not add photos, prompts, product URLs, or quota identifiers to custom logs.
Purchases. Credits are one-time consumable purchases billed by Apple through your App Store account using StoreKit in-app purchases. RevenueCat records the purchase and holds your credit balance server-side, keyed to the anonymous device identifier. Codemad receives no payment-card details. Nothing you buy is a subscription, and nothing auto-renews.
Product analytics. SpecFit uses PostHog (EU Cloud) for anonymous usage and funnel analytics - for example a screen viewed, a style previewed, or a purchase started - keyed to the same anonymous device identifier. Analytics events never include your photo, face scan, facial measurements, or prescription values. You can turn analytics off at any time in Settings → Privacy.
Service providers
- Cloudflare hosts the SpecFit API, applies credit checks and the global daily cost budget, caches extracted public product listings, and supplies network security and operational logging.
- Google supplies the paid Gemini API used for image rendering and product-image selection.
- PostHog provides anonymous product analytics, hosted in the EU.
- RevenueCat processes in-app purchases and stores your credit balance, keyed to the anonymous device identifier.
- Apple supplies the App Store, StoreKit in-app purchases, system photo picker, and iOS platform services.
We require providers acting on our behalf to protect personal data consistently with this policy and applicable law. Their independent processing is also governed by their own terms and privacy notices.
Retention summary
- Face profile and renders on your device: until you delete the capture, replace it, or delete the app.
- Prescription and saved product-link frames on your device: until you clear or remove them where available, or delete the app.
- Render photos and outputs on Codemad servers: only for the live request; they are not written to our content storage.
- Gemini prompts and responses: Google may retain them for a limited abuse-monitoring period under its paid-service terms. Google does not publish a fixed maximum in those public terms.
- Product-link extraction cache: seven days.
- Cloudflare invocation logs: no more than seven days.
- Product analytics: retained according to the PostHog project configuration; opting out in Settings stops further collection immediately.
- Purchases and credit balance: held by RevenueCat, keyed to the anonymous device identifier, and persisting across reinstalls until a new purchase or a verified deletion request changes it.
- Cost-control record: recent successful-render timestamps are kept against the anonymous identifier for cost control and pruned over time; the identifier may persist in Keychain and server storage as described above. There is no weekly render allowance.
What we don't do
- No user account or server-side face profile.
- No advertising or ad-attribution SDKs.
- No tracking as defined by Apple's App Tracking Transparency: data is not combined with third-party data for targeted advertising or advertising measurement.
- No selling, renting, or sharing of personal data.
- No facial recognition, identity verification, or attempt to identify you from your photo.
Permissions the app asks for
- Camera / TrueDepth - for the one-time guided face scan. Used only during capture.
- Photo library - only when you choose to pick a photo for the try-on path, or save an export.
Children
SpecFit's current AI rendering service is not intended for use by anyone under 18. We do not knowingly process photos or other personal data from children. If you believe a child has provided personal data through SpecFit, contact us so we can investigate and take appropriate deletion steps.
Your rights and choices
You can stop future photo processing by not requesting another render and can revoke Camera or Photos access in iOS Settings. Use Delete my capture and all renders to erase the face profile and its renders from your device, and Clear prescription to remove saved prescription values. Deleting the app removes its sandboxed data. You can turn product analytics off at any time in Settings → Privacy. Before the first photo is ever sent for rendering, SpecFit shows a consent screen naming Google Gemini as the third-party AI provider, and nothing is sent until you accept it.
For questions, access requests, objections, or a request to delete server-side quota data, contact codemad.edu@gmail.com. Because SpecFit has no account, we may need information from the device to verify and locate a quota record. We will respond in accordance with applicable privacy law and will also work with our service providers when a request concerns data they process for us.
Security
The face profile is protected with iOS complete file protection, and other local files remain inside the app sandbox. Everything sent to the SpecFit service uses TLS (HTTPS). The render service validates requests, rate-limits successful renders, and does not write user photos or generated try-on images to its content stores. No system is perfectly secure, so we cannot guarantee absolute security.
Changes to this policy
If we change how SpecFit handles data, we'll update this page and its effective date before the change ships. Material changes will also be called out in the app's release notes.
Contact
Codemad · codemad.edu@gmail.com