POLICY / UPDATED 2026.07.26

Privacy Policy

Effective July 21, 2026 · Last updated July 26, 2026

PRIVACY BY DEFAULT

Creative work stays on device.

Popcafe is designed to keep creative work private. Projects and imported media are processed primarily on the device. Product analytics and crash reporting are off by default and begin only after the user enables the corresponding setting.

01 / OPERATOR

Who operates Popcafe

Popcafe is operated by OMO Lab (“we”, “us”, or “our”). Privacy questions and requests can be sent to wow@ooooomo.com.

02 / ON DEVICE

Creative content

Photos, videos, drawings, text, project files, thumbnails, and exported media are processed on the device. We do not operate a server that receives or stores this creative content.

03 / OPTIONAL

Product analytics

Product analytics are off by default. If the user turns on Share analytics in Popcafe Settings, Popcafe uses PostHog Cloud in the United States to receive:

  • product interactions such as app launches, feature use, project actions, export choices, paywall views, and purchase-flow outcomes;
  • technical properties such as app version, build number, selected export format, and whether a Pro entitlement is active; and
  • a randomly generated installation identifier used to group anonymous events.

Popcafe does not send project names, filenames, file paths, original photos or videos, Apple IDs, email addresses, StoreKit transaction IDs, advertising identifiers, or session recordings to PostHog. GeoIP enrichment is disabled, so PostHog is instructed not to derive or store a location from these app events. We do not use this information for advertising or cross-app tracking.

04 / OPTIONAL

Crash reports

Crash reporting is off by default. If the user turns on Send crash reports, Popcafe uses Google Firebase Crashlytics. A crash or non-fatal report may include stack traces, relevant application state, device model, operating-system version, app version and build, anonymous installation identifiers, error details, and limited technical screen or flow context.

Crash reports are used only to diagnose and improve Popcafe. They do not intentionally include project media or project names.

PURCHASES / APPLE

Purchases

Subscriptions and payments are processed by Apple through StoreKit. We do not receive payment-card details. Popcafe reads subscription status from Apple to unlock Pro features. If product analytics are enabled, the selected plan and purchase-flow result may be included in PostHog analytics; transaction identifiers are not included.

PHOTOS / PERMISSION

Photos permission

Popcafe requests photo-library access only when the user chooses to browse or import library items, and requests add-only access when the user saves an export. Selected media are copied into project storage on the device. Permission can be changed in iOS Settings.

05 / QUICK REFERENCE

Data summary

DataWhenPurposeProcessor
Product interaction and other usage dataOnly after analytics opt-inAnalytics and product improvementPostHog
Plan and purchase-flow outcomeOnly after analytics opt-inAnalyticsPostHog
Crash and diagnostic dataOnly after crash-reporting opt-inApp functionality and reliabilityGoogle Firebase
Project contentWhen the user creates or imports itApp functionalityOn device

RETENTION / DELETION

Retention and deletion

  • Local projects remain until the user deletes them or removes the app.
  • PostHog analytics are retained for 1 year under the current PostHog Cloud Free plan. We will update this policy if the project plan or retention setting changes.
  • Firebase states that Crashlytics crash traces and associated identifiers are retained for 90 days before removal begins from live and backup systems.
  • Support correspondence is retained only as long as needed to resolve the request and meet applicable legal obligations.

06 / CONTROLS

Your choices

The user can stop future analytics or crash collection at any time in Popcafe Settings. Disabling crash reporting also deletes unsent crash reports stored by Popcafe on the device. Photo access can be managed in iOS Settings.

To ask a privacy question or request deletion of data that we can identify, follow the privacy request instructions. Because Popcafe has no user account and analytics are anonymous, we may be unable to associate historical analytics with a particular person without an identifier that the person voluntarily provides.

PROCESSORS / LOCATION

Service providers and international processing

We use Apple for StoreKit and Photos; PostHog for optional product analytics; and Google Firebase for optional crash diagnostics. Data processed by PostHog or Google may be handled outside the user’s country. We require service providers to protect data consistently with their terms, applicable law, and this policy.

COMMITMENT / NO TRACKING

No sale or tracking

We do not sell personal data, use third-party advertising SDKs, use the advertising identifier, or combine Popcafe data with third-party data for targeted advertising. Popcafe does not perform cross-app or cross-website tracking.

Children

Popcafe is not directed to children under the minimum age required to consent to data processing in their jurisdiction. Product analytics and crash reporting remain off unless enabled by the device user.

Changes

We may update this policy when Popcafe’s features or service providers change. The effective date at the top of the page will be updated when material changes are published.

Contact

OMO Lab
wow@ooooomo.com
NEXT TRACK / NOTICESOpen-source licenses