Legal
RetroLens Privacy Policy
RetroLens is a private daily camera and friends-only photo app operated by Banana Apps LLC ("Banana Apps LLC," "we," "us," or "our"). This Privacy Policy explains what information we collect, how we use it, who we share it with, how long we keep it, and the choices you have.
Overview
Your "Circle" is your set of accepted friends. RetroLens does not currently have a public feed. Authenticated RetroLens users can search for other profiles by name or username, and matching profiles are discoverable to them inside the app.
Photos generally stay on your device unless you post them to your Circle, save them through a cloud-backed feature, upload an avatar, or intentionally use the optional "G7X AI Look" feature, which sends the selected image to Google's Gemini AI for processing (see the dedicated section below).
No digital sharing system is perfectly private. People who can see your content may be able to screenshot, screen-record, save, or share it outside the app.
Age. The current minimum age for this policy is ages 13 and up. See also the AI features are intended for users 17 and older; other features are available at the App Store age rating.
What we don't do
- We don't sell your personal information.
- We don't upload your address book to our servers.
- We don't receive your full payment card details.
- We do not intentionally make your private memories, saved items, or friend list public through RetroLens features.
- We don't use your private photos in advertising or marketing without your permission.
- Banana Apps does not use your private photos to train its own public AI models, and does not use your private photos to train Google's models on our behalf. Third-party AI processing (see "G7X AI Look" below) is governed by the third party's own terms; we do not make promises on Google's behalf.
- We do not send your private photo content, private notes, captions, friend lists, or full contact lists to analytics or attribution providers. Our diagnostics and paywall providers still receive account and device identifiers, event metadata, and technical request information described below.
G7X AI Look and third-party AI processing
G7X AI Look is optional. It runs only when you intentionally choose or capture a photo and request AI processing. If you don't use it, no photo is sent for AI processing.
How it works:
- The selected image is uploaded to our private Supabase storage.
- A RetroLens server-side function then sends the image and the processing instruction to Google Gemini, a third-party AI provider, over Google's API.
- Google Gemini processes the image and returns a transformed image to RetroLens.
- The result may be temporarily stored in private RetroLens/Supabase storage so it can be displayed to you, downloaded, posted to your Circle, retried, or cleaned up.
- If you post the result to your Circle, it follows the normal Circle-post visibility and retention rules.
- If you save the result to your device, that local copy is controlled by you.
Third-party terms. Google's processing of images submitted through the Gemini API is governed by Google's applicable API and privacy terms. We do not control, and cannot promise on Google's behalf, whether or how Google may log, retain, review, or use submitted content. Please review Google's terms for the Gemini API and Google's privacy policy. Settings in Google's consumer Gemini app do not necessarily control API processing initiated by RetroLens.
Your responsibility for submitted images. Photos may contain faces, biometric-like visual information, or other people. You must have the right to submit the image and, where required, the permission of any people who appear in it. Do not submit content that violates our Terms of Use or the rights of others.
Quality and accuracy. AI outputs may be inaccurate, unexpected, lower quality than expected, or may visually alter parts of an image (including faces, text, hands, or backgrounds). Review results before saving, downloading, or sharing them.
Safety and abuse prevention. RetroLens may reject or interrupt AI processing for safety, abuse-prevention, technical, capacity, content-policy, or legal reasons.
Training. Banana Apps does not use your private photos to train its own public AI models. We do not make promises on Google's behalf about training; that is governed by Google's applicable API terms.
Information we collect
a. Account Information
- your account identifier (Supabase Auth user ID)
- your email address from Sign in with Apple or Google
- limited profile metadata returned by your sign-in provider, such as name or avatar, when available
- authentication session tokens, stored locally on your device in secure storage
b. Profile Information
- display name and username
- bio
- avatar image
- profile statistics derived from your activity, such as friend count
Your profile (name, username, bio, avatar) is discoverable to other authenticated RetroLens users through in-app profile search.
c. Photos and User Content
- photos you capture in the in-app camera or import from your device
- photos you post to your Circle, uploaded to our cloud storage so accepted friends can see them
- private memories and private notes you save through a cloud-backed feature — visible only to you, but stored in the cloud (not device-only)
- comments and reactions you submit
- saved items
- direct messages you exchange with accepted friends (stored as account-linked message content)
- share cards and invite messages you generate from the app
Photos stay on your device unless you post them or use a feature that requires uploading.
d. Camera and Photo Metadata
- look or recipe ID and version
- capture and post timestamps
- retake count
- flash mode, focal length label, and exposure bias
e. G7X AI Look Data
- the source image you submit for AI processing, temporarily stored in our private storage
- the AI-generated result returned by Google Gemini, which may be temporarily stored in our private storage so you can view, download, retry, or post it
- AI job records such as job status, model or model-version metadata, processing errors, timestamps, and which credit source was used
- your RetroLens-side AI credit balance and credit grant/spend records (see "Subscription and Purchase Information" for store transaction records)
f. Social Graph and Safety Data
- friend requests and accepted friendships (your Circle)
- users you have blocked
- reports you submit, including the report reason (such as spam, harassment, impersonation, sexual content, or fake account)
Current reports target users with limited reason categories. Reports do not reliably identify the exact post, comment, message, or AI output involved.
g. Permissions and Device Features
- Camera — to take photos in the in-app camera.
- Photo Library (read) — to import a photo into RetroLens.
- Photo Library (add) — to save edited photos to your device.
- Contacts — optional, to help you invite friends. When used, contact names, phone numbers, and the address book are processed locally on your device and are not uploaded to RetroLens. RetroLens may retain limited invite-assist state locally on the device, and may send non-contact analytics such as aggregate counts or whether an invite action occurred.
- Notifications — see the "Notifications" section below. The current build does not send phone notifications, but the app may still show notification-permission and Settings screens and read the operating system's permission status.
You can change or revoke any of these permissions at any time in your device settings.
h. Notification-Related Information
- the operating system's notification-permission status for RetroLens
- your interaction with in-app notification-permission and Settings screens
- in-app Inbox / activity records (such as friend activity, comments, or reactions) shown inside RetroLens — these are separate from phone notifications and may still be created and displayed in the app
- historical push tokens that may remain in backend records from earlier versions until normal cleanup or account deletion. These are not used to deliver notifications while phone notifications are disabled.
The current build does not send phone alerts, schedule local reminders, or register or upload new push tokens. If phone notifications are re-enabled in a future version, we will update this Privacy Policy before or alongside that change.
i. Subscription and Purchase Information
- a Superwall identity linked to your RetroLens user ID
- your subscription status and entitlement for RetroLens Pro
- the store product identifier you purchased, purchase status, transaction identifiers, refunds, and reversals
- the billing period, renewal date, and price as reported by the store
- trial or introductory offer eligibility
- provider-side customer, product, and transaction identifiers used to sync entitlements
- consumable "G7X AI Look" credit purchases, including store product identifiers, purchase status, and transaction identifiers
- your RetroLens-side AI credit balance and credit grant/spend records, including any daily free-allowance grants and reconciliations for refunded, reversed, duplicate, or erroneous transactions
Payments are processed by Apple (and, where available, Google Play). We do not receive your full payment card details.
j. Device and Local Data
- a locally generated retrolens_device_id
- onboarding answers and progress
- local photo library metadata and sandbox file paths for in-app use
- streak and last-photo date
- permission flags and pending access-linking state
- recent invited-contact keys
k. App Usage and Diagnostics
- events such as onboarding, authentication, paywall views, purchases, camera use, posting, sharing, friend activity, in-app notifications, reactions, comments, and AI Look requests and outcomes
- event metadata such as platform, app version, and a session ID
- crash, error, and performance data via Sentry, when enabled in production
Sentry diagnostic events may be tagged with your user ID. Sensitive fields such as auth tokens, private notes, captions, URLs, avatars, and friend lists are partially redacted before being sent.
Exact retention for diagnostic events and for our provider-side backups is not fully verified today. crash and error reports are retained for up to 90 days with PII scrubbed before storage Superwall receives paywall impression and purchase events used to render and measure paywalls
l. Support and Communications
If you contact us, we collect your name, email address, the contents of your message, and any information you choose to attach.
How we use information
- provide and maintain RetroLens, including the camera, posting, private memories, saved items, Circle/friend graph, and in-app activity records
- create and manage your account and profile
- authenticate you through Apple or Google sign-in
- process and store the photos and content you choose to upload
- provide the optional G7X AI Look feature, including transmitting the images you select for AI processing to Google Gemini and returning results to you
- grant, spend, reconcile, refund, and protect consumable AI credits, including daily free allowances and preventing duplicate or fraudulent transactions
- deliver content to the friends you have accepted
- process subscriptions, free trials, entitlements, consumable purchases, and restore-purchase requests
- show in-app activity records (comments, reactions, friend activity) inside RetroLens
- respond to support requests
- monitor performance, prevent abuse, fraud, and spam, and investigate reports
- enforce our Terms of Use and protect users and the Services
- comply with legal obligations
Visibility of your content
Content stays on your device until you post, upload, or save it through a cloud-backed feature. When you post, your post is intended only for your Circle (accepted friends).
Your private memories and saved items are private to you and do not change the visibility of your posts. Blocking a user removes their visibility into your future activity where applicable, and removing a friend may affect what they can see going forward. Blocking, unfriending, or deleting content does not remove or undo content other users have already seen, screenshotted, screen-recorded, saved outside the app, or received through previous sharing.
Recipients may still be able to screenshot, screen-record, or otherwise capture content they can see. Don't upload content you wouldn't want others to see.
Data retention and deletion
We keep information for as long as reasonably necessary to operate the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Approximate retention by category:
- Account and profile — kept while your account is active
- Posted photos and content — kept until deleted by you or removed through account deletion
- Comments, reactions, saves — kept while the related account or content exists
- AI source images submitted to G7X AI Look — retained in private storage only as needed to process the request, deliver results, allow retries, and clean up; then removed on a routine schedule
- AI-generated results — retained in private storage so you can view, download, retry, or post them; results you post follow normal Circle-post retention. Unused results may be removed on a routine schedule.
- AI job records (status, model/version metadata, timestamps, errors, credit source) — retained for operations, debugging, safety, and abuse-prevention purposes
- AI credit balance and grant/spend records — retained while your account is active, for reconciliation, fraud-prevention, and dispute resolution
- Store and payment records held by Apple, Google, Superwall, and other providers — retained by those providers under their own policies and legal obligations, outside our direct control
- Historical push tokens — retained in backend records until normal cleanup or account deletion; not used for delivery while phone notifications are disabled
- Diagnostic and error logs — typically 30–90 days
- Safety, abuse, fraud-prevention, and report records — may be retained longer to prevent recurrence
- Backups — may persist for a limited period after deletion
You can delete your account from within RetroLens (Settings → Account → Delete Account). When you delete your account, we work to remove or de-identify your active RetroLens profile and associated account-scoped information — including your stored photos, posts, private memories, comments, reactions, saves, reports, blocks, friendships, friend requests, historical push tokens, in-app notification records, AI-processing jobs, subscription entitlement records on our side, your RetroLens-side AI credit balance and grant records, your profile, and your underlying authentication user — subject to legitimate legal, safety, fraud-prevention, transaction, backup, and technical-retention requirements. Backup deletion may take additional time, and we do not promise an exact deletion deadline.
Unused AI credits. Deleting your RetroLens account can permanently forfeit any unused AI credits associated with that account, except where applicable law or a store-approved refund requires otherwise.
Store subscriptions. Deleting your RetroLens account does not cancel an Apple App Store or Google Play subscription. Apple, Google, Superwall, payment processors, and other providers may also retain their own transaction records under their policies and legal obligations.
Existing external copies. External shares, screenshots, downloads, or copies held by other users cannot be deleted by RetroLens.
If you have trouble deleting your account, contact team@getbananaapps.com.
Data loss
To the fullest extent permitted by law, we are not responsible for the loss, deletion, corruption, or unavailability of photos, posts, private memories, saved items, comments, reactions, AI source images, AI-generated results, or other content stored on your device or in our cloud infrastructure. Please keep your own backups of anything important to you.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect your information, including encrypted transport and secure on-device token storage. No system is completely secure, and we cannot guarantee absolute security.
Automated systems
On-device processing. Certain camera and photo effects run on your device without sending the image to our servers.
Server-side G7X AI Look. The optional G7X AI Look feature is not on-device: the selected image is uploaded to our private storage and sent to Google Gemini for processing, as described in "G7X AI Look and third-party AI processing" above.
Safety, moderation, personalization, analytics, and reliability. We may use automated systems to surface friend activity, personalize app surfaces, detect spam or abuse, filter objectionable text in usernames, bios, or comments, improve reliability, and evaluate performance.
Banana Apps does not use your private photos to train its own public AI models.
We may also use analytics, attribution, and measurement providers to understand how RetroLens is used, improve features, measure performance, debug issues, and evaluate the effectiveness of our marketing. We do not provide private photo content, private notes, captions, friend lists, or full contact lists to these providers.
Children's privacy
RetroLens is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact team@getbananaapps.com.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal information, or to withdraw consent where applicable.
U.S. state privacy rights. Depending on your state of residence (including, for example, California, Colorado, Connecticut, Virginia, Utah, Texas, and other states with comprehensive privacy laws), you may have rights to know what personal information we collect, access or receive a copy of your personal information, correct inaccuracies, delete your personal information, and opt out of certain uses such as targeted advertising, sale of personal information, or significant profiling. We do not sell your personal information. To exercise these rights, contact team@getbananaapps.com. We will not discriminate against you for exercising any of these rights.
EU/UK legal bases. Where the EU or UK GDPR applies, our legal bases for processing your personal information may include: performance of a contract (to provide the Services you request); your consent (for example, optional permissions or marketing where required); our legitimate interests in operating, securing, and improving RetroLens (balanced against your rights); compliance with legal obligations; and protecting the vital interests of users or the public, including safety and abuse prevention. You may withdraw consent at any time where consent is the legal basis.
You can also:
- edit your profile information in the app
- choose not to use the optional G7X AI Look feature, so no photo is sent for AI processing
- manage or revoke Camera, Photo Library, Contacts, and notification permissions in your device settings
- delete individual posts, AI source images, or AI results where supported in the app
- delete your account in the app
- manage or cancel subscriptions and request refunds in your Apple App Store (or, where available, Google Play) account settings
To make a privacy-related request, contact team@getbananaapps.com.
Third-party services
RetroLens relies on the third-party services described above (Supabase, Apple, Google — including Google Gemini for optional AI processing — Superwall, Sentry, and Expo). Those third parties process information in accordance with their own terms and privacy policies.
International users
RetroLens is operated from the United States. If you use RetroLens from outside the United States, your information will be transferred to and processed in the United States and in other countries where our service providers operate. Where required by law, we rely on appropriate legal bases and safeguards for international transfers, including those offered by our service providers.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the Effective Date and may provide additional notice where appropriate.
Contact us
If you have questions about this Privacy Policy, contact us at:
Banana Apps LLC
Florida, United States
team@getbananaapps.com