1. Introduction
Vissulo ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use Vissulo — a professional AI photo editing application for Android ("the App").
Vissulo is designed so photo editing and AI image processing happen locally on your device. We do not upload your photos, masks, face/body landmarks, or rendered edit content to Vissulo servers. Your photos remain on your device unless you explicitly choose to share them through another app or service.
Certain supporting services — including authentication, purchases, advertising, app integrity, server-side quota enforcement, and Community Style — may use an internet connection and third-party or Vissulo backend services. These services are described below.
By using Vissulo, you agree to the practices described in this policy. If you do not agree, please discontinue use of the App.
Your photo content stays on your device.
Core editing, filters, Beauty processing, and AI image effects run locally. Vissulo does not upload photo content to its servers. Some non-photo services may require internet access.
2. Information We Collect
Vissulo is designed to minimize data collection. We do not upload your photos, masks, face/body landmarks, rendered edits, or saved project files to Vissulo servers.
2.1 Information You Provide
- Email address and Google profile information — if you choose to sign in with Google for optional account features and account-based service limits. Google sign-in is optional.
- Customer support communications — if you contact us via email, we retain the correspondence as needed to address your inquiry.
2.2 Optional Diagnostics and Analytics
With your explicit optional consent, we may collect:
- Crash reports (Firebase Crashlytics) — diagnostic crash information used to improve stability.
- Usage analytics (Firebase Analytics) — app interaction and feature-usage information used to understand and improve the App.
Crashlytics and Analytics are disabled by default in Vissulo and activate only if you opt in through the App's consent flow. You can change this optional preference in Settings.
2.3 Service, Security, and Anti-Abuse Data
Some limited technical data is processed when specific online services are used:
- Firebase identity — a Firebase user ID may be used for account features and server-side verification. For certain quota or rewarded-tool verification flows, an anonymous Firebase identity may be created even if you have not signed in with Google; it does not include your Google email.
- Device identifier for export quota enforcement — when server-side export quota enforcement is enabled, Vissulo may send a device identifier such as Android ID to the Vissulo backend to enforce limits and prevent abuse. The backend derives a cryptographic hash for the device quota bucket. Vissulo does not use this identifier for advertising or Vissulo analytics.
- Purchase and entitlement data — product identifiers, purchase verification data, subscription or entitlement status, and trial status may be processed. A Google Play purchase token may be sent to the backend and Google Play for verification; Vissulo stores a cryptographic hash and related binding metadata rather than the raw purchase token.
- Community Style signals — eligible signed-in users may contribute privacy-safe style counters derived from editing preferences. This service does not upload photo content, filenames, face data, masks, or device identifiers.
- App integrity data — Firebase App Check / Play Integrity tokens and related integrity signals may be processed to protect backend services from abuse.
2.4 Information We Do NOT Send to Vissulo Servers
- Your photos or rendered edit content
- Face/body landmarks, masks, or Beauty analysis results
- Saved project image files or local editing history
- Your contact list
- Your live GPS location from device location sensors
Photo files can contain embedded location metadata. Vissulo may read that metadata locally for Image Info. When Image Info opens for a photo with GPS metadata, Vissulo may ask the Android device's geocoding implementation to resolve those coordinates to a place name; the coordinates are not sent to Vissulo servers.
3. Face Data Processing
Vissulo's Beauty Studio uses on-device machine learning to detect facial, pose/body, and segmentation features for local editing. Vissulo does not use this processing to uniquely identify or authenticate you, and no face/body analysis data is sent to Vissulo servers.
How we handle face data
- On-device processing — Face, pose/body, and segmentation analysis runs locally on your device.
- Local editing only — Analysis artifacts are used only as needed to power local editing features and are not used to build a remote identity profile.
- Startup privacy disclosure — Vissulo's required startup privacy notice must be accepted before face/body/segmentation acquisition is allowed.
- No remote face-data storage — Face/body landmarks, masks, and analysis results are not uploaded to or stored on Vissulo servers.
The models used for face/body processing are bundled with the App and run locally. No internet connection is required for the face/body analysis itself.
4. Device Permissions
Vissulo requests Android permissions only for the related app functions:
| Permission | Purpose | Required? |
|---|---|---|
| READ_MEDIA_IMAGES (Android 13+) | Open and edit photos from your gallery | For gallery access |
| READ_EXTERNAL_STORAGE (Android 12 and below) | Open and edit photos from device storage | For legacy gallery access |
| WRITE_EXTERNAL_STORAGE (Android 12 and below) | Save edited photos to your gallery on supported legacy Android versions | For legacy export |
| ACCESS_MEDIA_LOCATION | Read unredacted location metadata embedded in a selected photo when available, for Image Info | No |
| CAMERA | Take a photo directly within the App for editing | No |
| VIBRATE | Haptic feedback during slider and tool interactions | No |
| INTERNET / ACCESS_NETWORK_STATE | Online services such as purchases, authentication, ads, app integrity, quotas, and Community Style | Only for online services |
You can grant or revoke user-controlled permissions through Android settings. Some functionality may be unavailable when a related permission is denied.
Photo location metadata: when a selected photo contains GPS metadata, Vissulo can display the coordinates in Image Info. When Image Info opens for a photo with GPS metadata, Android's Geocoder may use a network-backed implementation to resolve the coordinates to a place name. Vissulo does not send those coordinates to its own servers.
5. Third-Party Services
Vissulo uses the following services for specific online functions. Each provider may process data under its own privacy terms:
| Service | Purpose | Data Processed / Shared |
|---|---|---|
| Firebase Crashlytics | Crash reporting (optional, consent required) | Crash and diagnostic information. Disabled by default in Vissulo. |
| Firebase Analytics | Usage analytics (optional, consent required) | App interaction and analytics event data. Disabled by default in Vissulo. |
| Firebase Auth / Google Sign-In | Google account sign-in and limited anonymous service identity | Email/profile information when you use Google Sign-In; Firebase UID for authenticated or anonymous service identity. |
| Firebase Firestore / Vissulo backend | Premium and trial state, quota/service records, Community Style, and app configuration | Firebase UID, entitlement and quota metadata, privacy-safe Community Style signals, and a hashed device quota key when applicable. No photo content or face/body analysis is stored. |
| Firebase App Check / Play Integrity | App integrity and backend abuse prevention | Integrity tokens and related device/app integrity signals processed by Google/Firebase. |
| Google Play Billing | Purchase and subscription processing and verification | Purchase/product information and purchase token for verification. Vissulo may store a cryptographic hash of the token and related entitlement/binding metadata. |
| Google AdMob / Google Mobile Ads SDK | Banner ads, tool-entry interstitial ads, and rewarded export ads for eligible non-Pro users | Google's Mobile Ads SDK may automatically process data such as IP address, ad/app-set or other device/account identifiers, product interactions, and diagnostics for advertising, analytics, and fraud prevention. |
| Android Geocoder | Place-name resolution in Image Info | When Image Info opens for a photo with GPS metadata, photo-embedded coordinates may be processed by the device's geocoding implementation to resolve a place name. They are not sent to Vissulo servers. |
Vissulo's Crashlytics and Firebase Analytics collection is separate from advertising and remains disabled unless you opt in. AdMob data processing is governed by Google's Mobile Ads SDK and applicable platform/privacy controls. Ads may include an editor banner for eligible non-Pro users, skippable interstitials when entering certain ad-supported tools, and rewarded ads used for eligible exports.
6. Data Storage and Security
Local device storage
Vissulo stores app data locally using Hive and app-private files. Depending on the features you use, local data can include:
- App settings and preferences, including theme, language, and tool arrangement
- Consent preferences for the startup privacy notice, crash reporting, and analytics
- Local export/ad quota counters and access ledgers
- Saved Projects, including app-private source/resume image copies, thumbnails, editor state, and editing history needed to reopen a project
- Temporary caches and analysis resources used to provide local editing features
These local files are not cloud-synced by Vissulo. Uninstalling the App removes its app-private local data under normal Android behavior.
Limited server-side service records
Vissulo and its service providers may store limited non-photo records needed for online features, including Firebase authentication identity, premium/trial entitlement metadata, server-side quota and anti-abuse records, purchase-token hashes and binding metadata, Community Style signals/aggregates, and app configuration.
No photos, saved project images, masks, face/body landmarks, or rendered edit content are stored on Vissulo servers. Vissulo does not provide cloud backup or cloud sync for your photos or editing projects.
7. Children's Privacy
Vissulo is not directed to children under the age of 13 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at support@vissulo.com so we can delete it.
8. Your Rights
GDPR (European Economic Area)
If you are in the EEA, applicable data-protection law may give you rights including:
- Right of access — Request a copy of personal data we hold about you.
- Right to rectification — Request correction of inaccurate personal data.
- Right to erasure — Request deletion of personal data where applicable.
- Right to restrict processing — Request restrictions on certain processing.
- Right to data portability — Request eligible personal data in a portable form.
- Right to object — Object to certain processing where applicable.
Uninstalling Vissulo removes app-private local data under normal Android behavior, but it does not necessarily delete limited server-side identity, entitlement, purchase-verification, quota, or security records. Use our Account Deletion process for account-linked server data.
To exercise applicable rights, contact us at support@vissulo.com. We will respond within the period required by applicable law.
CCPA / CPRA (California)
If you are a California resident, applicable California privacy law may provide rights including:
- Right to know/access — Request information about personal information collected, used, disclosed, or shared.
- Right to delete — Request deletion of eligible personal information.
- Right to correct — Request correction of inaccurate personal information where applicable.
- Right to opt out — Exercise applicable opt-out rights. Vissulo does not sell personal information for money.
- Right to non-discrimination — We will not discriminate against you for exercising applicable privacy rights.
To exercise applicable California privacy rights, email support@vissulo.com. We may need to verify your request.
Data Subject Requests
Your photo content and saved editing projects remain local to your device and are not available to us. We may, however, hold limited account or service records as described in this Policy. Contact support@vissulo.com or use the Account Deletion page for requests concerning those records.
9. Data Retention
- Photos and saved editing projects — remain on your device until you delete them or uninstall the App. Vissulo does not keep server copies.
- Crash reports (if consented) — Firebase Crashlytics retains crash stack traces and associated identifiers for approximately 90 days before removal from live and backup systems begins.
- Analytics (if consented) — retained according to the configured Google Analytics for Firebase retention settings and Google's applicable policies. User-level/event retention for standard Google Analytics properties is configurable up to 14 months; aggregated reporting may be subject to different retention behavior.
- Account and entitlement records — Firebase authentication and account-linked entitlement/trial records may remain while the account or related service is active and until an applicable deletion request is processed, subject to legal, security, and fraud-prevention requirements.
- Quota and anti-abuse records — server-side quota, integrity, and pseudonymous anti-abuse records may be retained as needed to enforce service limits and protect the service.
- Purchase verification records — limited purchase-token hashes, product/binding metadata, and entitlement records may be retained as needed for purchase restoration, fraud prevention, dispute handling, or legal obligations. Google Play maintains its own purchase records under Google's policies.
- Community Style — per-user contribution signals may be retained for the Community Style service until deleted, replaced, de-linked, or no longer needed; aggregate statistics may remain after individual contributions are no longer identifiable.
- Email correspondence — retained for as long as reasonably necessary to address your inquiry and related support or legal needs.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will notify you through the App (e.g., a prompt on the next launch) or via email if you have provided one.
We encourage you to review this Privacy Policy periodically. Your continued use of Vissulo after any changes constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:
To request deletion of your account and associated data, visit our Account Deletion page.
For the terms governing your use of Vissulo, see our Terms of Service.