Privacy Policy
Your camera stays useful without cloud AI.
Cadra keeps ordinary camera features local. Account services and cloud analysis use only the data needed to provide the feature you request.
Effective August 13, 2026
1. Scope and controller
This policy explains how Cadra processes personal information when you use the mobile app, account services, cloud AI features and these legal pages. The app developer is the data controller for the processing described here.
Before public release, the developer contact email shown on the App Store product page and support page will be the official privacy contact.
2. Data processed on your device
Camera permission enables the live viewfinder. Pose keypoints, subject boxes, device attitude, local composition measurements and filter previews are processed on the device.
- Photos are saved to the system photo library only when you choose to save them.
- Photo-library access is used to display images you choose to view or review.
- Local preferences and cloud AI consent choices are stored on your device.
These local features do not require a Cadra account.
3. Account information
If you create an account, Supabase processes your account identifier, email address or Apple relay email, authentication provider, session tokens and basic profile metadata. This information is used for registration, sign-in, session security, account support and account deletion.
Authentication tokens are stored locally on your device so the app can keep you signed in. We do not receive your Apple ID password or email password.
4. Optional cloud AI
Cloud AI runs only after you choose the feature and grant its upload permission.
AI Composition
Sends one low-resolution viewfinder frame and basic camera context to produce composition guidance.
Photo Review
Sends a compressed copy of the selected photo and basic image context to produce a photography critique.
The request travels through the Cadra server to Volcengine Ark. A signed-in account token is used to authenticate the request and prevent abuse.
5. How information is used
- Provide and secure account access.
- Generate composition guidance or a photo critique you requested.
- Operate, troubleshoot and protect the service.
- Enforce request limits and prevent automated abuse.
- Comply with applicable law and respond to valid legal requests.
We do not use your photos or account information for advertising or cross-app tracking. We do not sell personal information.
6. Retention
The Cadra server processes cloud images in memory, does not write image content to disk or application logs, and discards its copy after the response. Volcengine Ark processes the request under its applicable service and privacy terms.
Operational logs may contain request time, feature type, status, latency, request size, account-scoped authentication results and non-content diagnostic metadata. They do not intentionally contain uploaded image bytes, image URLs, scene descriptions, raw access tokens or full IP addresses.
Account data remains until you delete the account or request deletion, except where limited records must be retained for security, legal compliance or dispute resolution.
7. Service providers and transfers
We use service providers only where needed to run the product:
- Supabase for authentication, session management, account records and account deletion.
- Volcengine Ark for optional visual AI analysis.
- Infrastructure providers used to host the Cadra API.
- GitHub Pages to host these public legal pages. GitHub may receive ordinary web request information when you visit them.
- Apple for App Store distribution and Sign in with Apple when selected.
These providers may process information in countries other than your own. We use contractual and technical safeguards appropriate to the service and applicable law.
8. Your choices and rights
- Decline or revoke cloud AI upload permission without losing local camera functions.
- Use Apple relay email where Apple offers that choice.
- Sign out at any time.
- Delete your account from the Account screen.
- Request access, correction or deletion through the App Store support contact.
- Complain to your local privacy regulator where applicable.
Do not upload an image unless you are authorized to share it. If an image depicts another person, consider their privacy and obtain permission where required.
9. Children
Cadra is not directed to children under 13, or the higher minimum age required in their country. We do not knowingly collect an account from a child below the applicable age. Contact us if you believe this has occurred.
10. Security
We use encrypted network transport for production services, short-lived user sessions, row-level database policies, authenticated AI requests, rate limits, restricted server secrets and log redaction. No service can guarantee absolute security.
11. Changes and contact
Material changes will be published here with a revised effective date. If a change materially affects account or image processing, we will provide an appropriate in-app notice or renewed consent.
Privacy and deletion requests should be sent through the developer support contact displayed on the Cadra App Store product page. A direct support email will be added here before release.