TwinShot

TwinShot

Privacy Policy

Last updated: September 12, 2026

1. Overview

This Privacy Policy explains how TwinShot ("TwinShot," "we," "us") handles information when you use our iOS app and these legal pages. TwinShot lets you place yourself into a pose or scene: you save identity photos of yourself, choose a pose (from our catalog, your library, or a public Pinterest Pin), and we generate a result image.

2. Photos and media

To generate a look, TwinShot uploads media you choose to our servers:

  • Identity photos (typically 4–10 photos of you from the camera or photo library).
  • Pose / scene images (catalog poses, photos you pick, or a still fetched from a public Pinterest Pin you share into TwinShot).
  • Generated result images we return to the app.

These files are stored in Google Firebase Storage under your account and sent to our image-generation provider (fal.ai, model fal-ai/nano-banana-2/edit) so the result can be created. Saving or sharing a result uses iOS Photos / share sheets you choose.

3. Face data

Identity photos usually include a person's face. We process that imagery so TwinShot can generate a result that looks like you in the selected pose. TwinShot does not perform facial recognition, face matching against a database, biometric template or faceprint creation, emotion analysis, or identity verification. We do not sell face imagery. Face photos are stored and processed as ordinary photos needed to run the service, then deleted from systems we control when you delete your account (see below). Generation is performed by fal.ai as a processor; their handling of uploaded images is governed by their terms and privacy policy.

4. Account data

To run the app we may process:

  • Authentication identifiers from Firebase Authentication, including anonymous sign-in and Sign in with Apple when you link an Apple ID (required before purchase or restore).
  • Account records in Firestore (for example twins, generation jobs, looks, credit balances, and account metadata).
  • A hashed Share Extension credential (not the raw secret) so the iOS Share Extension can submit a public Pin URL without embedding the full Firebase SDK.

5. Purchases and subscriptions

Paid features are sold through the Apple App Store. We use RevenueCat to manage entitlements, credit packs, and restore eligibility. We do not receive or store your full payment card numbers. Apple processes payment. Subscription and credit status may be mirrored in Firebase so the app can enforce generation limits.

6. Analytics and diagnostics

We use PostHog for product analytics, error reporting, and sampled session replay to understand reliability and improve the product. This may include device and usage signals (for example app events, crash or exception data, and limited session context). Session replay is sampled (currently 10% of sessions in production) and configured to mask text inputs and images so photos shown in the UI are not recorded as clear screenshots. You can also control related OS privacy settings on your device where available.

7. Pinterest Share Extension

If you share a public Pinterest Pin URL into TwinShot, we resolve a still image through Pinterest's public oEmbed endpoint. We do not scrape Pin HTML, log in to Pinterest, or bypass access controls. Private or unavailable Pins fail closed. TwinShot is not affiliated with, endorsed by, or sponsored by Pinterest.

8. Service providers

Depending on how you use TwinShot, information may be processed by:

  • Apple (App Store, Sign in with Apple, Photos, Camera, device OS services)
  • Google Firebase (Authentication, Firestore, Cloud Storage, Cloud Functions)
  • RevenueCat (subscription and consumable entitlement state)
  • PostHog (analytics, session replay, error reporting)
  • fal.ai (image generation from identity + pose images)
  • Pinterest (public oEmbed for shared Pin URLs)
  • Vercel (hosting these legal pages only — not used as an official App Store URL)

9. Retention and deletion

Identity photos, pose images, and results are kept while your account exists so you can reopen twins and generations. In the app, open Profile → Delete my data to request deletion. That process wipes Storage files under your user prefix, identity photos, jobs, looks, Share Extension credentials and imports, billing aliases we store, your Firestore user document, and your Firebase Auth user. Apple subscriptions are billed by Apple and continue until you cancel them in your Apple ID settings. Analytics and provider logs may persist for a limited time under those providers' retention policies.

10. Children

TwinShot is not directed at children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children under that age.

11. International processing

We and our providers may process information in the United States and other countries. If you use TwinShot from another region, your information may be transferred to those locations.

12. Your rights

Depending on your country or region, you may request access, correction, export, or deletion of personal data we control. Use in-app deletion where available, or email us. We may need enough information to locate the account (for example the Apple ID used with TwinShot).

13. Changes

We may update this Privacy Policy. The "Last updated" date will change when we do. Continued use after an update means you accept the revised policy.

14. Contact

Privacy questions: mmdincer@outlook.com.