Privacy Policy
Last updated: August 1, 2026
This Privacy Policy explains how Locket (“we”, “us”) collects, uses, and shares information when you use the Locket iOS app and related websites and APIs (the “Service”). Locket is a private personal archive — not a social network.
Contact: hello@locket.mobile. For users in the EU/EEA/UK, this is also the contact for privacy requests.
1. Who this applies to
Locket is intended for adults 18 and older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
2. Information we collect
Account information. When you sign in with Google or Sign in with Apple, we receive a provider account identifier and, when available, your email address, name, and profile photo URL. If you use Apple’s Hide My Email, we receive a private relay address instead of your personal email. We also store session credentials needed to keep you signed in.
Archive content. Photos you upload; AI-generated studio images (including prior renders kept for history); titles, stories, tags, memory dates, favorites; collection names; and any correction notes you provide when regenerating a render.
Purchase and entitlement data. If you buy a subscription or consumable item pack through the App Store, we (and our billing processor, RevenueCat) process purchase and entitlement information such as your Locket user id as the App Store / RevenueCat customer id, product identifiers, transaction ids, subscription status, renewal and expiration timing, and credit or quota balances. We also record welcome-item grants given when a new account is created. We do not collect or store payment card numbers, bank details, or Apple ID passwords. Apple processes your payment method under Apple’s terms and privacy policy. Locket does not currently offer subscription trials or introductory pricing.
Technical information. IP address and basic request metadata used for rate limiting, security, and operating the Service. Our hosting provider may also process standard server logs.
On your device only. Optional Face ID / App Lock, grid and similar preferences, on-device cutouts used in the Chaos archive view, motion/tilt data for that view, and optional story dictation audio processed through Apple’s on-device speech APIs stay on your device (or are handled by Apple under Apple’s privacy terms) and are not uploaded to Locket as audio or biometric templates.
We do not currently collect precise location, contacts, advertising identifiers, or analytics SDK profiles.
3. How we use information
We use personal data to:
- Create and maintain your account and private archive
- Classify items and generate studio-style images with AI
- Provide subscriptions, consumable item packs, welcome items, and usage limits
- Provide settings, export to Photos, and related features
- Prevent abuse and enforce rate limits
- Improve render quality and operate the Service
- Respond to your requests and meet legal obligations
4. Photos, AI processing, and cloud storage
When you capture or upload a photo, we store the original image in private Cloudflare R2 object storage and create an item record in our database (Neon). To provide studio renders, we send your photos and related text (such as titles or regeneration notes) to Google Gemini, which:
- Classifies the item (for example title, category, and pose hints)
- Generates studio-style images
- May score or re-check a render for quality before we promote it to your archive
Generated images are stored in your private R2 archive and linked to your account. Background jobs for this pipeline are orchestrated by Inngest. Do not upload content you are not comfortable sending to our AI provider for this purpose.
Cutouts used in the Chaos view are created on your device from the studio image and are not generated or stored by our servers.
5. Legal bases (EU/EEA/UK)
Where the GDPR or UK GDPR applies, we process personal data on these bases:
- Contract — to provide the Service you request (account, archive, rendering, subscriptions)
- Legitimate interests — to secure the Service, prevent abuse, and improve render quality, balanced against your rights
- Legal obligation — when we must retain or disclose data to comply with law
- Consent — where required (for example, certain device permissions you grant in iOS)
6. How we share information
We do not sell your personal data. Your archive is private by default — nothing in it is public unless you choose to make it so.
People you choose to share with. You can create a share link for a single item. Anyone with that link can view that item — the studio image, its title, its story, and its date — without signing in or having a Locket account. A share link does not include your name, email, or any other personal information, and it covers only the one item you shared. A shared page always reflects the current version of the item. You can stop sharing at any time, and deleting an item or your account removes its link too.
We use service providers (“processors”) only as needed to run Locket:
- Google — sign-in (OAuth) and Gemini AI processing
- Apple — Sign in with Apple; App Store billing for purchases and subscriptions
- RevenueCat — purchase and entitlement processing (not payment card storage)
- Cloudflare R2 — private storage of your images (accessed via time-limited URLs)
- Neon — database hosting
- Vercel — application hosting
- Inngest — background jobs for the render pipeline
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets (with notice where required).
7. Staff access for quality
Authorized Locket personnel may view originals and renders solely to label and improve render quality. They do not publish your items. Access is limited to accounts marked as admin.
8. International transfers
We and our providers may process data in the United States and other countries. Where we transfer personal data from the EU/EEA/UK to countries without an adequacy decision, we rely on appropriate safeguards used by our providers (such as Standard Contractual Clauses), where applicable.
9. Retention and deletion
We keep your account and archive data while your account is active.
Archiving an item in the app hides it from your main archive and is not the same as deleting your account or permanently erasing that item’s data from our systems.
Deleting your account immediately and permanently removes your item records and the images we store for you (both the originals you captured and the studio renders), your collections, tags, titles, and descriptions, along with your email address, name, and profile photo, and unlinks your Google and Apple sign-ins. None of it is recoverable afterwards, by you or by us. Delete from the Delete account control in Settings, or by emailing hello@locket.mobile. We retain limited information where we must for legal, security, tax, fraud-prevention, or dispute-resolution purposes — principally billing ledger records, which are kept so App Store transactions stay reconcilable and are stripped of anything identifying you. Backups may take a short additional period, up to 30 days, to fully clear.
Deleting your Locket account does not cancel an App Store subscription. Manage or cancel billing in your Apple ID subscription settings; Apple may retain purchase records under Apple’s policies.
10. Your choices and rights
You can:
- Sign out in the app at any time
- Archive or restore items in the app
- Export studio images to your Photos library from Settings
- Export a full archive of your original and studio images together with a spreadsheet of their titles, descriptions, dates, and tags, offered as the first step of account deletion
- Delete your account in Settings, or request access, correction, or deletion by emailing hello@locket.mobile
- Manage App Store subscriptions and purchases in your Apple ID settings
If you are in the EU/EEA/UK, you also have the right to request data portability, restrict or object to certain processing, and lodge a complaint with your local supervisory authority. You may withdraw consent where processing is based on consent, without affecting prior lawful processing.
Optional Face ID / App Lock uses Apple’s biometrics on your device only. We never receive Face ID or fingerprint data.
11. Security
We use reasonable technical and organizational measures to protect personal data, including private object storage and authenticated API access. No method of transmission or storage is completely secure.
12. Children
The Service is not directed to children. You must be 18 or older to use Locket. See also our Terms of Service.
13. Changes
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the “Last updated” date. If changes are material, we will take additional steps as required by law.
14. Contact
Locket — hello@locket.mobile