This Family Album Privacy Policy explains how INVOICENOW Limited handles personal data when you use Family Album, and the choices available to you.
1. Scope and Controller
This Family Album Privacy Policy (the “Policy”) explains how INVOICENOW Limited (“we,” “us,” or “our”) collects, uses, shares, stores, protects, and deletes personal data when you use Family Album (the “App” or “Service”), and how you may exercise your related rights.
We are registered in the Hong Kong Special Administrative Region and are the entity responsible for processing personal data in the App. For questions about privacy, or requests to access, correct, export, or delete data, please contact us at support@picksai.vip.
The App is offered in global markets where we lawfully provide the Service. Depending on where you live, you may have additional statutory rights. This Policy does not limit any rights that cannot be waived by agreement.
2. Our Principles
We process personal data according to the following principles:
- We collect only the data needed to provide the Service, maintain security, analyze and improve the App, manage purchases, and meet legal obligations.
- Family photos and videos are uploaded only after a user actively selects and confirms them.
- Family content is shown by default only to members of the corresponding family group. The App does not provide a public community or a feed for strangers.
- Apple Vision suggestions indicating that a photo may contain a baby or child are processed on the device and are not used to identify a specific child.
- We do not display third-party advertisements in the App.
- Before accessing the IDFA or conducting advertising attribution that requires App Tracking Transparency authorization, we first request permission through the system prompt.
- We do not sell or rent users’ photos, videos, baby profiles, or family content.
3. Data We Collect
3.1 Anonymous Account and Family Identity Data
The App does not require an email address, password, or Sign in with Apple. However, when you create or join a family group, an anonymous account is automatically created. We may process:
- Firebase anonymous account identifiers, member IDs, device sessions, and sign-in status;
- family group IDs, invitation information, family roles, and permissions;
- your relationship to the baby, custom relationship labels, and most recent active time;
- records of invitation code use, members joining or leaving, members being removed, and role changes; and
- IP addresses, timestamps, and anomaly records needed to protect accounts, family permissions, and Service security.
3.2 Baby Profiles
Baby profile data actively provided by an administrator may include:
- an avatar;
- a nickname;
- date of birth; and
- associations with family photos or videos.
This information is used to create a baby profile, calculate the baby’s age when a photo was taken, organize family memories, and display the profile within the family group. We do not require a child’s full legal name, identification number, health data, or school information.
3.3 Photos, Videos, and Related Content
When you actively select and confirm content for upload, we process:
- photos, videos, and baby avatar files;
- original or processed files, thumbnails, and upload status;
- capture time, GPS, or location metadata;
- locations and photo descriptions that a user manually changes or adds;
- associations between a photo or video and one or more babies;
- the uploading member, comments, reactions, and related action timestamps; and
- records required for downloads, deletion, retries, or other Service operations.
Uploaded locations, descriptions, and other content may be displayed to members of the same family group who are authorized to access that content. The App does not automatically upload content from your system photo library before you confirm your selection.
3.4 Device, Network, and Diagnostic Data
To provide the Service, maintain security, send notifications, and troubleshoot issues, we and our service providers may process:
- device model, operating system, system language, time zone, and App version;
- IP address, network status, and country-, region-, or city-level approximate location inferred from IP;
- Firebase Installation ID, IDFV, push notification token, anonymous user identifier, and other necessary app-instance identifiers;
- crash stacks, error logs, performance data, feature malfunctions, and diagnostic information;
- the IDFA obtained after App Tracking Transparency authorization; and
- technical records needed for fraud prevention, abuse prevention, purchase validation, and security audits.
3.5 Usage and Analytics Data
To understand feature usage and improve the product, we may collect the following through Firebase Analytics and Mixpanel:
- App opens, session duration, and page views;
- button taps, feature usage, upload results, and subscription-related events;
- device and App version, anonymous event identifiers, and approximate region; and
- statistics about feature stability, conversion, and retention.
Other than using Cloud Storage for Firebase, Cloud Firestore, and similar services to provide album storage and family synchronization, we do not intentionally send photos, videos, baby avatars, babies’ dates of birth, comment text, precise GPS coordinates, or system photo library content to Firebase Analytics, Firebase Crashlytics, Mixpanel, Singular, or RevenueCat as part of analytics, diagnostics, attribution, or subscription events. Home-screen search history and Apple Vision recognition caches are processed and stored only on the device. They are sent with a customer support request only if you actively submit them when contacting support.
3.6 Advertising Attribution and Marketing Measurement Data
The App does not display third-party advertisements, but it uses Singular to measure promotional channels, installations, and subscription conversions. Depending on your system authorization and our actual configuration, Singular may process:
- IDFA, IDFV, and anonymous device or installation identifiers;
- IP address, device and App information, and approximate location;
- ad clicks, installations, App opens, subscriptions, and purchase events; and
- timestamps and technical information used for attribution, fraud prevention, and marketing performance statistics.
On iOS, we display the App Tracking Transparency system authorization request before accessing the IDFA or conducting tracking that requires authorization. If you refuse, we will not access the IDFA or conduct tracking that depends on that authorization, and we will not bypass your choice through device fingerprinting or similar methods. We may still use aggregated attribution methods that do not identify an individual, such as SKAdNetwork, as well as necessary security processing permitted by platform rules.
After you authorize tracking, the IDFA and related events may be used for cross-app advertising source attribution, audience measurement, and marketing performance analysis. This processing does not mean that the App displays third-party advertisements in its interface.
3.7 Purchase and Subscription Data
Purchases are processed through the native in-app purchase system of the platform you use. On iOS, purchases are processed by the Apple App Store and StoreKit. We and RevenueCat may receive:
- an anonymous App user ID;
- product identifiers, purchase time, and transaction or purchase receipts;
- subscription status, expiration time, renewal status, purchase restoration results, and the time the App was last used;
- device, platform, App version, and information needed to validate purchases; and
- status information related to refunds, revocations, family entitlements, and customer support troubleshooting.
Full payment card numbers, Apple account passwords, and other app-store payment credentials are processed by the relevant app store and are not received directly by us.
3.8 Customer Support and Rights Request Data
When you contact us, we process the email address, issue description, screenshots, anonymous account or member identifier, purchase information, and other data you actively provide that is needed to verify your identity and resolve the issue. Please do not include unnecessary child data, complete payment credentials, or other sensitive information in customer support emails.
4. Data Sources
Personal data comes mainly from:
- data you provide when you fill in information, select or upload content, post a comment, make a purchase, or contact customer support;
- the system photo library, photo metadata, and notification permissions that you allow the App to access;
- data generated during the operation of the App, device, servers, and security systems;
- subscription status returned by purchase services such as the Apple App Store, StoreKit, and RevenueCat;
- analytics, diagnostics, attribution, or Service records generated by service providers such as Firebase, Mixpanel, and Singular according to our configuration and instructions; and
- data about you provided by a family administrator or other member when inviting you, setting a relationship, posting a comment, or managing content.
5. How We Use Data
We use personal data to:
- create anonymous accounts, family groups, member relationships, and permissions;
- create baby profiles and organize family photos, videos, and timelines;
- provide upload, cloud storage, synchronization, download, sharing, comment, and notification features;
- process capture time, location, descriptions, and associations with babies;
- provide on-device photo suggestions and search;
- validate purchases, restore subscriptions, synchronize entitlements, and process subscription status;
- measure installation sources, product usage, feature performance, and Service stability;
- diagnose crashes and prevent fraud, abuse, and unauthorized access;
- respond to customer support, data rights requests, and complaints; and
- comply with legal obligations, enforce our agreements, and protect the lawful interests of users, children, us, or others.
Where consent is required as a legal basis for processing in your region, we will obtain consent before processing, and you may withdraw it as described in this Policy. Data required to provide accounts, family albums, uploads, synchronization, and purchase management is generally processed to perform our agreement with you. Non-essential analytics, IDFA tracking, and advertising attribution are processed based on your consent where applicable law requires it. Security, fraud prevention, and necessary Service improvements may be based on our legitimate interests where those interests do not override your fundamental rights. Tax, accounting, and regulatory records are processed to meet legal obligations.
6. System Permissions
6.1 Photo Library Permission
The App uses the system photo picker and photo library access to let you select photos or videos, set a baby avatar, download content, and display on-device baby or child suggestions. You may grant limited or full access and may change the permission through system settings.
If you decline full access, you may still manually select content to the extent allowed by the system. If you completely disable photo library access, features related to selecting photos, on-device recognition, avatar settings, or saving content may be unavailable. The App does not use camera permission.
6.2 Notification Permission
With your authorization, the App may send notifications about new content, comments or reactions, family changes, upload results, and subscription status. You may disable all or some notifications in the App or system settings. Disabling notifications does not delete family data or prevent you from viewing updates in the App.
6.3 Tracking Permission
The App may request App Tracking Transparency authorization to perform advertising source attribution and marketing performance measurement through Singular. We access the IDFA or conduct tracking that relies on this authorization only after you grant permission. You may change the authorization at any time in system settings.
App Tracking Transparency is an Apple platform permission and does not replace other privacy consent required by the laws where you live. Where required by applicable law, we will separately obtain consent before starting non-essential analytics or attribution processing through services such as Firebase Analytics, Mixpanel, and Singular, and we will provide a way to refuse or withdraw consent. Refusing this non-essential processing will not affect the core family album features.
6.4 Sensitive Permissions We Do Not Use
The current product does not use system permissions for the camera, real-time location, microphone, contacts, or health data. GPS information in photos comes from the metadata of photos you choose to upload. A location may also be added through active user input or a MapKit search. This is not the same as continuously reading the device’s real-time location.
7. Sharing Within a Family Group
Authorized members of a family group can view the baby profiles, photos, videos, capture times, locations, descriptions, comments, and reactions that you upload. Administrators can also manage members, baby profiles, and family content according to the family permissions.
A family group is a private, invitation-only space, but any authorized member may download or screenshot content or use system sharing features to send content outside the App. We cannot control a member’s independent handling of content after download or sharing. Invite only adults you trust, and obtain any necessary authorization before uploading content involving other people.
8. Third-Party Services and Data Recipients
We transfer only the data necessary for service providers to perform the functions they provide, and we restrict use according to their actual functions.
8.1 Google Firebase
We use the following Firebase modules:
- Firebase Anonymous Authentication: creates anonymous accounts and member identities;
- Cloud Firestore: stores families, members, baby profiles, content metadata, comments, and permission information;
- Cloud Storage for Firebase: stores photos, videos, baby avatars, and thumbnails;
- Cloud Functions for Firebase: processes invitations, uploads, deletion, permissions, and other backend logic;
- Firebase Cloud Messaging: sends Service notifications and processes push notification tokens;
- Firebase Analytics: measures product usage and conversion; and
- Firebase Crashlytics: collects crash, error, and diagnostic information.
Where a service allows location selection, the project’s primary Cloud Firestore, Cloud Storage for Firebase, and Cloud Functions for Firebase resources are configured in the United States. Firebase Authentication runs only from data centers in the United States. Most Firebase services, including Firebase Cloud Messaging and Firebase Crashlytics, operate on Google’s global infrastructure, and Firebase Analytics is also governed by separate Google Analytics terms. We therefore cannot make a single promise that all Firebase processing occurs only in the United States.
Firebase privacy and security information ↗8.2 Mixpanel
Mixpanel is used to analyze anonymous or pseudonymous product usage events, device and App information, and approximate region to improve features, experience, and stability. The Mixpanel project uses the United States data region. We do not intentionally send family photos, videos, child profiles, comment text, or precise GPS coordinates to Mixpanel.
Mixpanel Privacy Policy ↗8.3 Singular
Singular is used for mobile marketing attribution, installation sources, fraud prevention, and marketing performance measurement. After obtaining any necessary authorization, Singular may process the IDFA. It may also process the IDFV, IP address, device and App information, approximate location, and installation or purchase events. This processing is planned for the United States region.
Singular Privacy Policy ↗8.4 RevenueCat
RevenueCat is used to receive and validate app-store purchase receipts, synchronize subscription status, manage entitlements, restore purchases, and provide subscription support. RevenueCat may process an anonymous App user ID, device and platform information, Apple receipts or purchase tokens from other platforms, and product and subscription status. This processing occurs mainly in the United States.
RevenueCat Privacy Policy ↗8.5 Apple and App Store Services
Apple may provide photo library access, on-device recognition, location search, purchases, and notification capabilities through PhotoKit, Vision, MapKit, the App Store and StoreKit, and Apple Push Notification service. Data processing independently determined by Apple is governed by Apple’s own privacy policy and platform rules.
8.6 Legal, Security, and Business Changes
Where there is a lawful basis and disclosure is necessary, we may disclose necessary data to courts, regulators, law enforcement agencies, professional advisers, or parties involved in a corporate reorganization to comply with law, resolve disputes, investigate fraud, protect child safety, or preserve lawful interests. If a merger, acquisition, or asset transfer occurs, we will require the recipient to continue handling relevant data according to this Policy or standards no less protective than this Policy, and we will notify you where required by law.
9. Data Storage and Cross-Border Transfers
We are registered in the Hong Kong Special Administrative Region, and the Service is offered to users worldwide. To provide cloud storage, accounts, push notifications, analytics, attribution, and subscription services, personal data may be transferred from your country or region to the United States and processed at facilities in the United States or other regions in which our service providers are authorized to operate.
We take reasonable safeguards under applicable law, such as entering into data processing terms with service providers, restricting processing purposes, controlling access, requiring confidentiality and security measures, and using recognized cross-border transfer mechanisms where applicable. Data protection rules vary between countries, but this does not reduce our responsibilities under this Policy.
10. Data Retention and Deletion
We retain data for as long as needed to fulfill the relevant purpose:
- While a family group remains active, family information, baby profiles, and user content are continuously retained to provide the family album Service.
- When a user actively deletes an individual photo, video, comment, or profile, the related online data enters the deletion process.
- If other members remain in a family, a member who leaves or is removed will have the member identity, permissions, family relationship, and personal profile related to that family deleted or disassociated. Shared family content may continue to be retained and may be disassociated from the former member’s identity or de-identified. Ordinarily leaving or being removed does not delete the entire App account.
- After a user requests “Delete Account and All Personal Data,” the online account, related personal data, and photos, videos, descriptions, comments, reactions, and other user content associated with the account that we are not legally required to retain will be deleted within 30 days. This action is different from ordinarily leaving or being removed from a family.
- If only one member remains in a family group and that member confirms that they wish to leave, delete the account, or dissolve the family, all members, babies, photos, videos, descriptions, comments, reactions, and other online family data will be deleted within 30 days.
- Data that has entered routine business backups under our control will be deleted through backup rotation or cleanup within no more than 90 days, except where retention is required by law or necessary to investigate fraud, security incidents, or disputes.
- Purchase, refund, and transaction records may be retained for the periods needed for tax, accounting, fraud prevention, or dispute resolution.
- Analytics, attribution, crash, and security logs are stored for the periods needed to fulfill the relevant purposes and according to the applicable retention periods of the service providers, and are deleted or anonymized when no longer needed.
Deletion may need to be performed separately in Firebase, Mixpanel, Singular, RevenueCat, and other processing systems. We take reasonable steps to synchronize deletion requests, but anonymized statistics, aggregated data that can no longer identify an individual, and data that must be retained by law may not be subject to a deletion request.
The 90-day period above applies only to routine business backups under our control. Technical identifiers, logs, and backups controlled by third-party services are cleared under the providers’ own rules and may be retained for more than 90 days. For example, Google states that certain data associated with Firebase Authentication and Firebase Cloud Messaging may take up to 180 days after a deletion request to be removed from active and backup systems. Firebase Crashlytics crash data is generally retained for 90 days before removal from active and backup systems begins. This service-provider retention does not mean that deleted data remains accessible to other family members.
11. Data Security
We use administrative and technical measures proportionate to the risks, including encryption in transit, server-side access controls, permission checks, least-necessary access, log auditing, backups, and service-provider management, to protect personal data against unauthorized access, use, alteration, disclosure, or loss.
No network or storage method can guarantee absolute security. If a data security incident may materially affect you, we will investigate, respond, and provide any required notice to users or regulators under applicable law.
12. Your Rights and How to Exercise Them
Depending on the laws where you live, you may have the right to:
- access personal data we hold;
- correct inaccurate or incomplete data;
- delete your account, profile, or user content;
- obtain a portable copy of your data;
- withdraw consent or object to or restrict certain processing;
- disable notification, photo library, or tracking permissions; and
- complain to a competent supervisory authority about data processing.
Within the App, you can edit member or baby profiles that you are authorized to modify, delete content that you uploaded, and request account deletion through the in-App account deletion entry point. Photo library, notification, and tracking permissions can be managed in your device’s system settings.
For a formal access, export, correction, or complaint request, or if the in-App features cannot fulfill your request, email support@picksai.vip. We may verify your identity through your current valid session, member or family information, anonymous account identifier, purchase records, or other minimum necessary information to avoid disclosing family data to an unauthorized person.
Where the laws of the Hong Kong Special Administrative Region apply, we will respond within 40 days after receiving a valid data access or correction request. If we cannot fully comply within that period, we will explain the reason in writing within 40 days and complete the request as soon as practicable afterward. Where another region’s law requires a shorter period, the shorter period applies. If we cannot fulfill a request, we will explain the reason to the extent permitted by applicable law.
13. Children’s Privacy
The App’s account and family member features are available only to adults who have reached the legal age of majority where they live and are at least 18 years old. The App does not offer independent accounts to minors.
Photos, videos, nicknames, dates of birth, and other information about babies or children must be provided by a parent, guardian, or lawfully authorized adult. The uploader must confirm that they are authorized to provide data on behalf of the relevant child and must respect the privacy of other children, parents, and family members.
If you believe that a child’s data has been provided without authorization, contact us at support@picksai.vip. After verification, we will take reasonable measures such as restricting access, correcting the data, or deleting it.
14. Additional Rights Where You Live
If you are located in the European Economic Area, the United Kingdom, Switzerland, certain U.S. states, or another region that provides additional data protection rights, you may exercise rights under local law to access, correct, or delete data; restrict processing; obtain data portability; object to processing; withdraw consent; or opt out of sale or sharing.
We do not sell personal data for money or other valuable consideration. The App does not display third-party advertisements, but after obtaining required system authorization, we use the IDFA and Singular for advertising source attribution and marketing performance measurement. In some regions, this type of cross-app tracking may be considered “sharing,” targeted advertising, or cross-context behavioral advertising under local law. You may refuse or withdraw tracking authorization. You may also contact support@picksai.vip to submit an applicable request to opt out of sale, sharing, or targeted advertising. We will not subject you to unreasonable discriminatory treatment because you exercise a privacy right.
15. Policy Updates
We may update this Policy because of changes to features, SDKs, permissions, data uses, storage regions, subscription methods, the company entity, or law. We will provide notice of material changes through an in-App notice, the Policy page, or another reasonable method and will update the effective date. Where the law requires renewed consent, we will obtain it before the relevant processing begins.
16. Contact and Complaints
If you have any questions, requests, or complaints about this Policy or our processing of personal data, please contact us:
- Data controller: INVOICENOW Limited
- Place of registration: Hong Kong Special Administrative Region
- Customer support and privacy email: support@picksai.vip
If you believe that we have not properly handled your request, you may also complain to the competent data protection authority where you live.
Back to top