← PolaPop

PolaPop Privacy Policy

Effective date: May 29, 2026 · Last updated: September 5, 2026

PolaPop is a mobile instant-photo camera app that lets users create film-style photos and manage Film Sheets, a one-time in-app purchase, ads, and account recovery features. MiniRoom and social features were removed in version 1.3.0; information created by earlier versions may still be stored, and Section 10a explains how it is handled.

This Privacy Policy explains how JoCoding, Inc. ("PolaPop", "we", "us", or "our") collects, uses, discloses, transfers, and protects personal information when you use PolaPop (the "App" or "Service").

1. Controller Information

2. Summary

Topic Summary
Main data we processSupabase user ID, Apple account-linking identifiers, Film Sheet balance and ledger records, purchase status, ad and install-attribution events, support information. Information from earlier versions may still be stored: MiniRoom profile and layout, photos placed in a room, friend connections, likes, room visits, guestbook and comment entries, moderation records.
Main purposesAccount and session operation, Film Sheet grants and spending, purchase validation, advertising and install-attribution measurement, fraud prevention, support, legal compliance
PhotosPhotos you take are processed on your device and stay there. The current version has no feature that uploads a photo to our servers or shows it to other users.
Social featuresNot available in the current version. See Section 10a for information created by earlier versions.
Key service providersApple, RevenueCat, Supabase, Google AdMob, AppsFlyer
International transfersWe are a U.S. company and use global infrastructure and service providers.
Contactmu07010@jocoding.net

3. Personal Information We Collect

We collect or process the following categories of information, depending on how you use the App.

Area Required or optional Examples
App account and sessionRequiredSupabase anonymous user ID, authentication token, session information, account creation and access timestamps
Sign in with Apple account protectionOptional, or required before some commerce/reward actionsApple user identifier, Apple identity token, Apple account-linking status. The App does not request the Sign in with Apple email scope.
Film Sheet ledgerRequiredUser ID, Film Sheet balance, starter grant, capture spend, rewarded-ad grant, refund reversal, ledger event ID, timestamps. While PolaPop Lifetime is active, captures are unlimited and are not written to the ledger.
In-app purchasesRequired for purchasesRevenueCat user ID, Apple transaction ID, product ID, purchase status, refund status, entitlement status, RevenueCat webhook event ID. Legacy subscriptions bought in earlier versions also carry cancellation and renewal status.
AdsOptional (rewarded) / shown to free users (banner)Ad event ID, whether a rewarded ad was completed, reward status, daily reward limit, ad request data, and device or advertising information processed by the ad network. Banner ads are requested as non-personalized. The App does not request App Tracking Transparency permission or access IDFA.
Install attributionRequired for advertising measurementInstall, session, and app-open events; a purchase event (amount, currency, product ID); a first-photo activation event; and device and app information collected by the AppsFlyer SDK. No email, phone number, name, photo, typed text, or product-analytics identifier is sent.
Camera and photosPermission-basedCamera input and photos created in the App. Photos stay in local in-app storage unless you share or export them yourself. The current version has no feature that uploads a photo to our servers.
MiniRoom profile (earlier versions only)No longer collectedPublic handle (display name) and an optional avatar image, created in a version before 1.3.0.
MiniRoom and social activity (earlier versions only)No longer collectedMiniRoom layout and furniture placement, photos placed in the room, room title, public/private setting, friend connections, friend requests, room visits, likes, guestbook entries, and comments, created in a version before 1.3.0.
Content moderation (earlier versions only)No longer collectedReports submitted about content (target, reason, optional detail), block relationships, and automated hide/removal signals, created in a version before 1.3.0.
SupportOptionalEmail address, message content, app version, device model, iOS version, purchase order ID, screenshots or photos you choose to attach
Automatically collected technical informationRequired for service operationIP address, request time, app and OS version, network errors, server request logs, security and abuse-prevention logs

We do not intentionally collect government identifiers, payment card numbers, bank account credentials, health information, biometric identifiers for unique identification, political or religious beliefs, or other sensitive personal information. Please do not include sensitive information in support requests or photos you send us.

4. Sources of Personal Information

We collect personal information from:

5. How We Use Personal Information

We use personal information to:

  1. create and operate App sessions and backend account identifiers;
  2. create, display, grant, spend, restore, and audit Film Sheet balances;
  3. validate App Store purchases and unlock the PolaPop Lifetime entitlement;
  4. process refunds, cancellations, and unused Film Sheet reversals;
  5. deliver ads to free users and measure which advertising campaign led to an install;
  6. store and, on request, delete MiniRoom and social information created by versions before 1.3.0;
  7. protect accounts through Sign in with Apple and support recovery after reinstalling or switching devices;
  8. verify rewarded-ad completion, enforce daily limits, and prevent duplicate rewards;
  9. respond to support requests and troubleshoot purchase or App issues;
  10. detect, prevent, and investigate fraud, abuse, security incidents, and policy violations;
  11. comply with legal obligations and enforce our Terms;
  12. maintain and improve the App.

6. Retention

We keep personal information only as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.

Information Retention period or criteria
Supabase account, Film Sheet balance, and ledgerUntil account deletion, service termination, or when no longer needed, except transaction, dispute, security, and legal records may be retained longer.
App Store purchase and subscription validation recordsGenerally up to 5 years after the transaction or as needed for tax, accounting, dispute, fraud-prevention, and legal purposes.
Refund, cancellation, and dispute recordsAs needed to resolve the issue and comply with applicable law.
Rewarded-ad events and abuse-prevention logsGenerally up to 1 year, unless longer retention is needed for fraud, dispute, security, or legal reasons.
MiniRoom profile, layout, published photos, and social activity (friends, likes, visits, guestbook, comments)Until you delete the item, delete your room content, or delete your account, except copies may remain in backups for a limited period and content relevant to a report, dispute, safety, or legal matter may be retained longer.
Moderation records (reports and blocks)As needed to operate safety features and, where applicable, for a reasonable period after the related report or block to prevent repeat abuse and comply with law.
Support requestsGenerally up to 3 years after resolution, unless longer retention is needed for legal or dispute reasons.
Server access and security logsGenerally up to 3 months, unless longer retention is needed for security, fraud, or legal reasons.
Photos kept only on your deviceUntil you delete them from the App or your device. The current version does not upload photos to our servers.

7. How We Disclose Personal Information

We may disclose personal information to:

We do not sell personal information for money. The current App does not request App Tracking Transparency permission and does not access IDFA. Rewarded ads may still require ad request data, device information, diagnostics, and fraud-prevention signals for ad delivery and reward verification. If we later configure advertising features that use data for cross-app tracking or other tracking that requires Apple's App Tracking Transparency permission, we will update this Privacy Policy and request permission before using those features.

8. Service Providers

Provider Purpose Information processed
Apple Inc. and affiliatesApp Store distribution, StoreKit in-app purchases, subscription management, refunds, Sign in with AppleApple account identifier, transaction ID, purchase and subscription status, Apple identity token
RevenueCat, Inc.Purchase and subscription status management, entitlement validation, webhook deliveryRevenueCat user ID, product ID, purchase, refund, subscription, and event data
Supabase, Inc.Authentication, database, Edge Functions, file/object storage, Film Sheet ledger storageUser ID, authentication session, MiniRoom profile, room layout, published photos, friend and social records, moderation records, Film Sheet balance and ledger, server request logs
Google LLCGoogle AdMob banner ads, rewarded ads, and reward verificationAd event data, ad completion status, ad request data, and device information
AppsFlyer Ltd.Mobile install attribution and advertising measurement — measuring which advertising campaign led to an app install, and aggregate conversion measurementInstall and session events, a purchase event (amount, currency, product ID), a first-photo activation event, device and app information collected by the AppsFlyer SDK. We do not send your email, phone number, name, photos, text you type, or our product-analytics identifier to AppsFlyer, and we do not set an AppsFlyer customerUserId.

These providers process information according to their own terms and privacy policies when they act as independent controllers, and according to our instructions where they act as processors or service providers.

9. International Transfers

We are based in the United States and use service providers with global infrastructure. Your information may be transferred to, stored in, or processed in the United States and other countries where we or our service providers operate.

If you are located in the EEA, UK, Switzerland, or another region with cross-border transfer rules, we rely on appropriate safeguards where required, such as standard contractual clauses, adequacy decisions, platform terms, or other lawful transfer mechanisms.

10. Photos and On-Device Processing

PolaPop processes camera input, filters, and instant-photo effects primarily on your device. Photos you create are first stored in the App's local storage on your device. We do not automatically upload every photo you take to our servers.

In the current version of the App, photos stay on your device. The App no longer has a feature that uploads a photo to our servers or makes it visible to other users. Earlier versions let you place a photo in a MiniRoom and publish it; photos uploaded that way may still be stored in our file storage (operated by Supabase), and you can request their deletion using the contact details in Section 18.

The App does not currently request photo-library permission or automatically save photos to your device photo library. For photos you export locally, the App uses the iOS share sheet. If we add optional photo-library saving or other new photo features later, we will update this Privacy Policy and request any required permission before using those features.

If you choose to send screenshots or photos to support, the information you choose to submit may be transmitted to us or to relevant service providers.

10a. MiniRoom, Profiles, and Social Features

MiniRoom and social features are not available in the current version of the App. They were removed from the App as of version 1.3.0, so no new profile, room, or social information is collected. This section is kept because information created by earlier versions may still be stored on our servers, and it describes how that information is handled. You can request deletion at any time using the contact details in Section 18.

If you used MiniRoom and social features, the following information is stored on our servers and may have been visible to other users:

You can make your room private, remove content you posted, and manage or delete your MiniRoom content. Because other users may see, remember, or screenshot content while it is public, we cannot guarantee retrieval or deletion of copies others have already seen.

10b. Content Safety and Moderation

To keep social spaces safe and comply with App Store requirements, the App provides tools to report content you find objectionable and to block other users. When you submit a report, we process the target, reason, and any optional detail you provide. When you block a user, we hide their content from you and prevent further interaction. We also use automated signals — for example, content that receives multiple reports may be hidden pending review. We may remove content, restrict features, or suspend accounts that violate these rules, our Terms, or applicable law. See the Terms of Service for the content rules that apply.

11. Advertising, Attribution, and Advertising Identifiers

Ads shown in the App

Free users see a banner ad at the bottom of the screen, and may additionally choose to watch a rewarded ad to receive free Film Sheets. Banner ads are requested as non-personalized ads. If you purchase PolaPop Lifetime, both banner and rewarded ads are removed.

Ad providers may process ad request data, completion status, device information, and advertising-related information needed to deliver ads and verify rewards.

Install attribution

We use AppsFlyer to measure which advertising campaign led to an app install, and we connect AppsFlyer to Meta (Facebook) advertising through AppsFlyer's partner integration. We do not embed the Meta SDK in the App.

We use the strict variant of the AppsFlyer SDK, which does not link Apple's AdSupport framework and therefore cannot access the IDFA. Measurement relies on aggregate frameworks such as Apple's SKAdNetwork and Meta's Aggregated Event Measurement rather than on per-user cross-app identifiers.

We send AppsFlyer only: automatic install, session, and app-open events; a purchase event when a purchase succeeds (amount, currency, and product ID); and a first-photo activation event, once per install. We do not send your email address, phone number, name, photos, or anything you type. We keep advertising attribution separate from product analytics and do not merge the two identities.

No App Tracking Transparency prompt

The App does not request App Tracking Transparency permission and does not access the IDFA. Our App Store privacy label declares that device identifiers are not used to track you. If we later add IDFA-based or cross-app tracking that requires Apple's App Tracking Transparency permission, we will update this Privacy Policy and request permission before using it.

You can limit advertising tracking through your device settings:

Changing device advertising settings should not prevent core camera features from working, but it may affect ad availability, ad personalization, or reward verification.

12. Automated Processing

PolaPop does not use automated decision-making to make decisions that have legal or similarly significant effects, such as credit, employment, insurance, housing, healthcare, or education decisions.

We do use rule-based automated processing for service operations, such as Film Sheet grants, duplicate reward checks, purchase validation, refund reversals, fraud prevention, and abuse limits. If you believe an automated operational result is incorrect, contact us at mu07010@jocoding.net and we will review it.

13. Your Privacy Rights

Depending on where you live, you may have rights to:

To exercise rights, contact us at mu07010@jocoding.net. We may need to verify your identity before fulfilling a request. We will respond within the time required by applicable law.

14. U.S. State Privacy Notice

This section applies to residents of U.S. states with comprehensive privacy laws when those laws apply to us, including California.

In the last 12 months, we may have collected the following categories of personal information:

Category Examples Sources Purposes
IdentifiersUser ID, Apple identifier, RevenueCat user ID, IP address, email address if you contact support, and (from versions before 1.3.0) a MiniRoom public handleYou, your device, Apple, RevenueCat, SupabaseAccount operation, purchase validation, support, security
Commercial informationProduct IDs, purchase status, entitlement status, refund status, Film Sheet ledgerApple, RevenueCat, Supabase, App activityPurchase validation, Film Sheet grants, refunds, support
Internet or network activityApp requests, server logs, ad request and reward events, install-attribution events, device or network metadata, and (from versions before 1.3.0) social activityYour device, Supabase, Google AdMob, AppsFlyerService operation, security, advertising and attribution measurement, troubleshooting
Audio, electronic, visual, or similar informationPhotos or screenshots you choose to send to support, and (from versions before 1.3.0) photos placed in a MiniRoom and an avatar imageYouSupport and troubleshooting
InferencesLimited operational flags, such as suspected duplicate reward, abuse indicators, or content-safety signalsApp activity, server logs, reportsFraud prevention, content moderation, and service integrity

We do not knowingly sell personal information. The current App does not request App Tracking Transparency permission or access IDFA. Rewarded-ad providers may process ad request, device, diagnostic, and fraud-prevention information for ad delivery and reward verification. If future advertising features qualify as "sharing" or targeted advertising under applicable U.S. state privacy laws, we will provide any required opt-out method or honor applicable platform signals.

We do not knowingly sell or share personal information of consumers under 16 years of age.

We do not intentionally collect sensitive personal information as defined by California law. If you send us sensitive information in a support message or photo, we will use it only as needed to respond to your request, protect safety or security, comply with law, or delete it.

We will not discriminate against you for exercising privacy rights. This means we will not deny service, charge a different price, or provide a different level of service solely because you exercised a privacy right, except where permitted by law.

You may designate an authorized agent to submit a privacy request where allowed by law. We may require proof of authorization and verification of your identity.

15. Children

The App is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If local law requires a higher age for parental consent, users below that age may use the App only with the required permission.

If you believe a child has provided us personal information without the required consent, contact us at mu07010@jocoding.net and we will take appropriate action.

16. Security

We use administrative, technical, and organizational measures designed to protect personal information, including:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the App, App Store metadata, our website, or another appropriate method. Where required by law, we will ask for your consent.

The "Last updated" date above shows when this Privacy Policy was last revised.

18. Contact

Questions, privacy requests, complaints, and support requests should be sent to:

JoCoding, Inc.

1111B S Governors Ave, STE 80543

Dover, DE 19904

United States

mu07010@jocoding.net

+1 (231) 450-5622