PASSPORT PHOTO MAKER

Privacy Policy.

Effective: July 25, 2026

The short version. Your photo is captured, cropped, framed to your country's spec, and checked for compliance entirely on your phone. The image never reaches our servers and is never uploaded anywhere. There is no account to create and no email collected. The one exception to "nothing leaves your phone" is entirely your choice: if you tap to watch a short video to remove the watermark, Google AdMob serves that ad and uses an advertising identifier — never your photo. Our own backend stores just a single anonymous "first opened on" timestamp to manage your purchase.

1. Who we are

Passport Photo Maker is a mobile app published by CodeEnsis Ltd. ("we", "our", "us"). This policy explains exactly what the app does and does not collect, and the rights you have.

2. Your photos never leave your device

Every step that touches your image happens locally on your phone:

Your original photo and the processed result are stored only in the app's private storage on your device, plus anywhere you deliberately send them (saving to your photo library, the system share sheet, or printing). We never receive them. When you uninstall the app, they are removed with it — there is nothing on a server for us to delete, because we never had it.

3. What our backend stores

On first launch the app signs in anonymously through Firebase Authentication. This creates a random, opaque user identifier. It is not linked to your name, email, phone number, or any contact detail — we never ask for those, and no sign-up screen exists.

Against that anonymous identifier we store a single value in Google Firestore: a server timestamp of when the app was first opened. We use it only to anchor your purchase and entitlement to a stable date. No photo, no measurement, no personal information is ever written to this record.

4. Purchases

Passport Photo Maker is a one-time purchase. Payment is handled entirely by the Apple App Store or Google Play under their own terms; we never see or store your card details. Purchase validation and restore are processed through RevenueCat, which receives a purchase receipt and the anonymous identifier described above so your entitlement can be restored on your device. RevenueCat's privacy practices are described at revenuecat.com/privacy.

5. Crash diagnostics and anonymous usage

If the app crashes, Firebase Crashlytics records a diagnostic report — the stack trace, device model, and OS version — so we can fix the fault. These reports contain no photo, no face data, and no personal information.

We also use Firebase Analytics to count, in aggregate and without building any profile of you, which screens and steps get used — for example how many people reach the export screen — so we can see what to improve. These events carry no photo, no face data, and no contact information. Google's processing is described in the Firebase Privacy and Security documentation.

6. Advertising (optional)

Passport Photo Maker is free to use. To export a photo without the watermark you can either make a one-time purchase or, as a free alternative, choose to watch a short rewarded video. These videos are served by Google AdMob.

The ads SDK is loaded only if you tap to watch a video. When you do, Google's Mobile Ads SDK may use an advertising identifier (the Android Advertising ID) together with coarse device and ad-interaction data to serve and measure the ad — this is standard for any app that shows ads. Your photo, your face, and any image data are never shared with the ad network or used to target ads. A user who never taps to watch a video never loads the ads SDK and is never assigned an advertising identifier by this app.

Where the law requires it (for example in the EEA and the UK), we show a Google-certified consent form before any ad is requested, and you can change or withdraw your choice at any time from Settings → "Ad privacy choices" in the app. You can also reset or delete your Advertising ID in your device's system settings. Google's use of advertising data is described in Google's Advertising policies and Privacy Policy.

7. What Passport Photo Maker does not do

8. Permissions the app asks for

You can grant or revoke either permission at any time in your device's system settings.

9. Network access

The app connects to the network only for the limited functions described above — anonymous sign-in, the install-timestamp record, purchase validation, crash and anonymous-usage reporting, and, if you choose to watch a rewarded video, ad serving — and to load these legal pages. The app includes an on-device network audit that reports, in Settings, how many bytes left the device during your last session; for your photo itself that figure is zero.

10. Children

Passport Photo Maker is a general-purpose utility and is not directed at children under 13. We do not knowingly collect data from children.

11. Your rights

Because there is no account and your photos never reach our servers, exercising your rights is simple:

12. Data retention

On-device data is retained until you delete it or uninstall the app. The anonymous install-timestamp record is retained while the app remains installed and for a reasonable period afterward to support purchase restoration; crash reports are retained per Firebase's standard retention.

13. Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected here with an updated "Effective" date above. Continuing to use the app after a change means you accept the updated policy.

14. Contact

Questions or requests about this policy: support@codeensis.com. A human reads every message.