← Aperi
Last updated 1 August 2026
Privacy Policy: Aperi
Aperi ("the app", "we") helps you control a tethered camera and get AI photography coaching. This policy explains what the app collects, where data goes, and your choices. Plain-language summary first; specifics follow.
Your photographs are the sensitive thing here, so this policy is unusually specific about where they go.
The short version
- The app has no accounts and no analytics or tracking SDKs of our own.
- Your API keys and conversation history stay on your device.
- When you ask the coach about a shot, that photo + camera settings + your message are sent to the AI provider you chose (Google Gemini, Anthropic Claude, or OpenAI) to generate a reply. That is the one time your data leaves the device, and it goes to that provider, not to us.
- Which provider you choose, and which tier, decides what happens to your photographs. See the section below: this genuinely differs between providers, and a free tier is not the same as a paid one.
- If ads are shown, the Google Mobile Ads (AdMob) SDK collects advertising identifiers. Removing ads (one-time purchase) stops ad requests.
Read your AI provider's terms. This part is not ours to control.
When you bring your own API key, the request goes from your phone straight to that provider, under your own account. We are not in the path, we never see the image, and we cannot change what that provider does with it. Their terms govern, not ours.
That distinction matters more than it might sound, because the providers differ:
- Google Gemini, free tier. Google states that content submitted on the unpaid tier is used to provide, improve and develop Google's products, and that human reviewers may read it. For this app, that content is your photographs. If that is not acceptable to you, do not use a free-tier Gemini key here.
- Google Gemini, paid tier. Google states that paid-tier prompts and responses are not used to train or improve its models.
- OpenAI API. OpenAI states that API inputs and outputs are not used to train its models by default, and are retained for a limited period (published as up to 30 days at the time of writing) for abuse monitoring, then deleted.
- Anthropic API. Anthropic states that API inputs and outputs are not used to train its models by default.
Verify these against each provider's current terms before you send anything you would mind being read. They are summarised here in good faith and they change; the provider's own policy is the authority, not this page. Links are in the app next to each provider's key field.
Our key will never be used to share your photographs for AI training
A managed tier is planned, where coaching runs on our API key instead of yours, for people who would rather not obtain one.
If and when that ships, we commit that:
- We will not enable any data-sharing or model-training option on the accounts we operate. Our provider's API default is that API data is not used for training, and we will not opt in to anything that changes it.
- We will not sell, share, or license your photographs, to anyone, for any purpose.
- We will not use your photographs to train models of our own.
- Frames will be relayed and dropped. Our metering records counts, costs and outcomes, never image data, never your prompts, never the coach's replies.
- The provider may still retain data briefly for its own abuse monitoring, as described above. That is outside our control and we will not claim otherwise.
What the relay would keep. Not your photograph, not your question, not the reply. Those are passed to the provider and dropped. What is written down is the accounting needed to run a metered service:
- a per-user identifier (see below), the time of the request, which AI model answered it, how many tokens it used, what it cost us, how long it took, whether it succeeded, and the size in bytes of the image
- usage rows are deleted after 90 days
- day-by-day totals are kept longer, with no identifier attached. They say how many people used the coach, never who
- a suspension record, if we ever have to block an account for abuse, is kept for as long as the block stands
- all of it is stored in the European Union, wherever you are. Your photograph still travels to the AI provider in the United States, because that is where the model runs, under the safeguards their data processing terms provide.
How we would know it is you, without an account. There are no usernames and no passwords, and we would rather not start now.
- If you subscribe, we use the transaction identifier Apple signs for your purchase. It identifies the subscription, not you: no name, no email.
- On the free tier, we use App Attest, an Apple feature that confirms the request came from a genuine, unmodified copy of this app. It gives us a meaningless-looking key that lets us count your four daily prompts. Deleting and reinstalling the app clears it and gives you a fresh one. We considered a mechanism that survives reinstalling and deliberately rejected it, because it would have meant setting an identifier you could not get rid of.
Erasing it. A button in the app deletes everything above for you. You will not need to email us or quote an identifier. The one exception is a suspension record, which we keep so that erasing your data cannot lift a ban. If that ever applies to you, the app will say so rather than claiming everything went.
Until the managed tier ships, none of this applies in practice, because we operate no server that receives your photographs at all.
What the app stores on your device
- API keys: in the platform secure store (Android DataStore / iOS Keychain). Never transmitted anywhere except, as a bearer credential, to the matching AI provider's own API endpoint over HTTPS. Never logged, never sent to us.
- Coaching history: your questions, the live-view frames you sent, the camera settings at that moment, and the coach's replies, saved locally so you can revisit them. You can clear this at any time in the app; uninstalling removes it.
- Preferences: chosen AI provider/model, connection mode, camera IP, toggles. Local only.
What is sent off the device, and to whom
- AI coaching requests → the provider you select in Settings:
- Google Gemini API (
generativelanguage.googleapis.com)
- Anthropic Claude API (
api.anthropic.com)
- OpenAI API (
api.openai.com)
Each request contains the live-view image, structured camera settings, your typed or spoken text, and recent conversation context. What each provider then does with it is covered in the section above.
- Purchases → RevenueCat, Inc., which validates your receipt with Apple or Google and tells the app what you are entitled to. RevenueCat receives purchase events and an anonymous identifier it generates. It is never given a photograph, a prompt, or an API key. See RevenueCat's own privacy policy. Payment itself is handled by Apple or Google; we never see your card details.
- Voice input → Apple, when you dictate a question. iOS speech recognition may send the audio to Apple for transcription. Type instead of speaking if you would rather it stayed on the device.
- Ads → Google AdMob, which may collect an advertising ID and device or coarse location data to serve and measure ads, per Google's policies. Buying "Remove ads" stops all ad requests. A consent prompt is shown where required (for example EEA and UK).
Today, we operate no servers that receive your photographs or messages. Bring-your-own-key is what ships, and in that mode there is nothing between your phone and the provider you chose.
If the managed tier described above ships, that changes for the people who use it: their frames would pass through our relay on the way to the provider. It would not change for anyone using their own key. We will say so here before it happens, not after.
Microphone, camera connection, network
- Microphone is used only while you hold or activate voice input, to transcribe your spoken question. The app does not record the audio or save it anywhere. Apple's speech recognition may process that audio on Apple's servers rather than on the device, under Apple's privacy policy, which is how iOS dictation works generally. The audio is your question, not your photograph: images are never part of it.
- USB / Wi-Fi access is used solely to communicate with your camera.
- Internet access is used for AI requests, purchases, and ads.
Children
Not directed to children under 13 (16 in some regions). No knowing collection of children's data.
Your choices
- Choose or remove any AI provider key. With no key and no managed subscription, the coach does not run and no photograph is sent anywhere.
- Choose a paid provider tier if you do not want your photographs used to improve that provider's products.
- Clear coaching history in-app. If you use the managed tier, the same screen erases what our relay recorded.
- Remove ads via one-time purchase to stop ad data collection.
- Uninstalling deletes all local app data.
Changes & contact
We'll update this policy as the app evolves and note the date above. The managed tier described above will be reflected here before it ships, not after. Questions: support@aperi.photo.