Privacy Policy
Effective date: 2026-07-14
Last updated: 2026-07-14
This policy explains what data inAmber collects, how we use it, and the choices you have. It is written to be readable — if anything is unclear, email hi@inamber.app.
1. Who we are
inAmber is operated by Amber Labs LLC ("Amber Labs," "we," "us"), a single-member limited liability company organized in Virginia, United States. inAmber is a photo memory application available on iOS.
- Contact: hi@inamber.app
- Mailing address: Amber Labs LLC, 8401 Mayland Drive, Suite A, Richmond, VA 23294-4648, USA
2. The short version
- Your original photos never leave your device. We only upload small thumbnails (~100 KB) so we can show you your memories inside the app.
- We collect basic account info (email, name, the optional birth/location details you choose to share in onboarding).
- We read photo metadata (date, GPS coordinates, camera make/model) so the app can organize and surface meaningful memories.
- AI photo analysis is part of inAmber Pro, and you opt into it when you upgrade. On the Free plan, none of your photos are ever sent to any AI service. When you subscribe to Pro, we show you exactly what's involved and you affirmatively agree before any analysis runs — then we send photo thumbnails (never your originals) to Google Gemini for captions and scene/mood tags. To stop AI analysis, you cancel Pro.
- We do not sell your data. We do not run third-party advertising or analytics. We do not share data with data brokers.
- We do not collect, process, or store your payment card information. All purchases are processed by Apple; we use RevenueCat to verify and manage your subscription status.
3. What we collect
3.1 Information you give us
| Category | Examples | Required? |
|---|---|---|
| Account | Email, password, or Apple ID identifier | Required |
| Profile (onboarding) | First/last name, birth year, birth city/country, hometown, current city/country | Optional |
| Life profile | Life chapters, events, home bases, career and education history, important dates, and habits you choose to add | Optional |
| Journals & reflections | The free-text entries you write in journals and reflections | Optional |
| Communications | Anything you send to hi@inamber.app | When you contact us |
If you use Sign in with Apple, Apple gives us your name (only if you choose to share it) and either your real email address or an anonymized "Hide My Email" relay address (for example, something@privaterelay.appleid.com) that forwards to your inbox. We treat a relay address exactly like a real email and never attempt to unmask it.
3.2 Information from your photo library (with your permission)
When you grant photo-library access, the app reads metadata from the photos you choose to include and uploads compressed thumbnails:
- Thumbnails — the app creates a downscaled copy on your device (about 800px on the long edge, ~100 KB JPEG) and uploads only that copy to our private Supabase Storage
photosbucket. We deliberately do not upload full-resolution originals — keeping originals off our servers reduces your storage footprint and our infrastructure costs. Your originals stay on your device and in whatever backup service you use (such as iCloud), under Apple's terms, not ours. - Photo metadata — capture date, GPS latitude/longitude (when present in EXIF), camera make/model, favorite flag, screenshot flag, and a derived "source" category (camera, screenshot, AirDrop, saved, unknown).
- Derived signals — burst grouping, highlight score, curation flags computed from the metadata above.
We do not scan or upload photos you have not added to the app, and the app does not run in the background reading your library.
3.3 AI photo analysis (inAmber Pro only)
AI analysis is part of inAmber Pro. If you are on the Free plan, none of your photos are ever sent to Google Gemini or any other AI service. Free accounts receive location, date, and basic tagging computed on our own servers only; no photo content leaves to any AI provider. (Even location enrichment sends only GPS coordinates to our geocoding provider — never the image itself.) When you upgrade to Pro, we show you exactly what AI analysis involves and you affirmatively agree to it before any analysis runs — it is an integral part of the Pro service.
As part of Pro, we send the following to Google's Gemini API for each representative photo (one per burst group; screenshots excluded):
- A compressed thumbnail (~100 KB) — never your full-resolution original, which always stays on your device.
- A small amount of metadata already derived from that photo: the date it was taken, the city derived from its GPS coordinates, and the local time of day.
Gemini returns a caption plus scene, mood, activity, and people-count labels, which we store on your account. We do not send your name, email, journal entries, life-profile data, or any other user's photos.
How Google handles it. Google processes this data under the Gemini API terms applicable to paid API customers and does not use it to train its models. Google retains it only as needed to perform the analysis and for the limited abuse-monitoring described in those terms.
Opting in, and how to stop it. You opt into AI analysis when you upgrade to Pro — we show you what it involves and you affirmatively agree before any analysis runs. Because AI analysis is part of the Pro service rather than a separate, toggleable setting, you stop it by canceling Pro (Profile → Subscription, or your Apple ID settings). When you cancel, all future AI analysis stops; any captions or insights already generated remain on your account in read-only form until you delete the underlying photos or your account. (If you live somewhere that treats this as consent-based — for example the EEA or UK — you may withdraw your consent at any time, which ends AI analysis going forward; in practice this means returning to the Free plan.)
3.4 Subscriptions and payments
inAmber Pro is an auto-renewable subscription sold through Apple's App Store. We do not collect, see, or store your payment card details — all billing is handled by Apple under your Apple ID. To verify and manage your subscription, we use RevenueCat, Inc., which receives your App Store purchase receipt, transaction history, the subscribed product identifier, and a randomly-assigned account identifier (your inAmber user ID) so your subscription can be recognized across your devices.
We store only your subscription status in our own database — specifically the plan tier (Free or Pro), the active product (monthly vs. annual), and a log of billing events received from Apple/RevenueCat. Card numbers, expiry dates, billing addresses, and CVCs never reach us.
For details on how these providers handle data, see Apple's Privacy Policy and RevenueCat's Privacy Policy.
3.5 Information stored on your device
Some information stays only on your phone and is never transmitted to us. To keep you signed in, the app stores your authentication session token in your device's secure, encrypted storage (the iOS Keychain, via Expo SecureStore). It also keeps lightweight local configuration and onboarding progress in on-device app storage. You can clear all of it at any time by signing out or deleting the app.
3.6 Information we do not collect
For clarity, inAmber does not currently collect:
- Device location (we only read GPS that is already inside your photos' EXIF)
- Advertising identifiers (IDFA), IDFV, or other persistent device IDs
- Contacts, calendar, microphone, camera roll content beyond what you import
- Analytics events, crash reports, or product-usage telemetry from third-party trackers
- Biometric face data or facial geometry templates of any kind. Sending photos to Gemini for scene/mood/caption analysis does not constitute biometric processing — Gemini returns descriptive tags, not faceprints. If face clustering (which derives persistent mathematical face templates to identify people across photos) is ever activated, this policy will be updated with explicit consent language before it ships.
- We do not generate or store facial recognition templates.
- Payment card information (see §3.4 above)
If this changes, we will update this policy and notify you in-app before the change takes effect.
4. How we use your information
We use the data above to:
- Run the app — authenticate you, sync your timeline across devices you sign in to, render your memories.
- Organize your library — group bursts, build the "Today / Reflect / Explore" surfaces, compute highlight scores.
- Geocode locations — convert GPS coordinates into city/country labels so locations are human-readable.
- AI tagging (Pro) — enrich photos with scene, mood, and activity labels (you opt in when you upgrade).
- Communicate with you — respond to support requests, send service-critical notices (e.g., a security incident, a material policy change), and — if you opted in (for example by joining the waitlist or toggling "Product updates" in Settings) — send occasional product-update and announcement emails. Every such email contains a one-click unsubscribe; service-critical notices remain even if you unsubscribe.
- Keep the service safe — detect abuse, debug errors, enforce our Terms.
We do not use your photos or metadata for advertising, profiling, or sale to third parties.
5. Service providers we use
We work with the following processors. Each receives only the data they need to perform their function, and each is bound by contract to handle that data securely.
| Provider | What they do | Data they see |
|---|---|---|
| Supabase, Inc. (USA) | Authentication, PostgreSQL database, photo thumbnail storage | Account record, photo metadata, thumbnails |
| Railway Corp. (USA) | Hosts our processing service (brain.py) | Photo metadata in transit during processing |
| Google LLC — Gemini API (USA) | AI scene/mood tagging (Pro plan) | Representative photo thumbnails, returned tags |
| Google LLC — Maps Geocoding API (USA) | Convert GPS to city/country labels | Approximate coordinates (~1 km precision, cached) |
| Mapbox, Inc. (USA) | Static map images on the Explore screen | Approximate coordinates rendered in tiles |
| Apple Inc. (USA) | "Sign in with Apple," App Store distribution, push delivery, subscription billing | Email, name (only what you share at sign-in); subscription receipts |
| RevenueCat, Inc. (USA) | Manages your Pro subscription status across devices | Anonymous user ID, subscription state, App Store receipt |
| Resend, Inc. (USA) | Delivers transactional and product-update email | Your email address and the contents of the messages we send you |
When the Google Sign-In option launches, Google LLC will also be a processor for that flow.
6. Where your data is stored
- Primary storage: Supabase regions in the United States.
- Processing: Railway data centers in the United States.
- AI providers: Google Cloud, processed in the United States and other regions per Google's infrastructure.
If you access inAmber from outside the United States (including the EU/UK), your data will be transferred to and processed in the US. Where required, transfers rely on the EU Standard Contractual Clauses (or the UK IDTA) entered into with our processors.
7. How long we keep it
- Account and content: kept for as long as your account is active.
- Account deletion: when you tap "Delete Account" in Settings, your account is marked for deletion immediately. After a 30-day grace period (during which you can reactivate by signing back in), all account data, metadata, and thumbnails are permanently erased from our active production systems. Residual copies in routine, encrypted infrastructure backups maintained by our hosting providers roll off according to those providers' retention schedules.
- Geocoding cache: city/country lookups are stored against a coarse ~1 km geohash, shared across users, and evicted after 30 days of disuse. This cache is not personally identifiable on its own.
- Support correspondence: retained for up to 24 months to handle follow-up questions, then deleted.
- Legal/tax records: retained for the period required by US law (typically up to 7 years for billing records).
8. Your choices and rights
You can, at any time:
- Access and edit your profile and uploaded content inside the app.
- Stop AI analysis by canceling Pro in Profile → Subscription (AI analysis is part of the Pro service, not a separate switch). Future analysis stops; insights already generated stay until you delete the underlying photos or your account.
- Delete your account in Settings → Account → Delete Account.
- Export your data — email hi@inamber.app and we will send a machine-readable archive of your account data within 30 days. (Self-serve export is planned; until then, the email channel is the supported path.)
If you live in the European Economic Area, the United Kingdom, or Switzerland, the GDPR gives you the rights of access, rectification, erasure, restriction, portability, and objection; the right to withdraw consent at any time (without affecting processing done before withdrawal); and the right to lodge a complaint with your local supervisory authority. Our lawful bases for processing are: (a) performance of the contract (running the service — including AI photo analysis, which is an integral part of the Pro subscription you purchase), (b) your consent (optional profile fields, and AI photo analysis in any region whose law requires consent for it — in which case you can withdraw by returning to the Free plan), and (c) our legitimate interest in keeping the service secure and operational.
If you live in California, the CCPA/CPRA gives you the right to know, delete, correct, and limit use of sensitive personal information, and the right to non-discrimination for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under the CCPA.
To exercise any right, email hi@inamber.app from the address tied to your account. We will respond within 30 days (45 in complex cases).
9. Security
- All traffic between the app and our servers uses TLS 1.2+.
- Your photo thumbnails are stored in a private bucket protected by Supabase Row-Level Security — only your account can read them.
- Passwords (when used) are salted and hashed by Supabase Auth; we never see your plaintext password.
- Access to production systems is limited to authorized Amber Labs personnel using multi-factor authentication.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you within 72 hours of confirmation and report to authorities where required by law.
10. Children
inAmber carries a 17+ App Store rating and is intended for adults. Separately, and regardless of that rating, we do not knowingly collect or solicit personal information from children under 13 (or under 16 in the EEA and UK), consistent with COPPA, the GDPR, and similar laws. If you believe a child has provided us with personal information, email hi@inamber.app and we will delete the account and its data promptly.
11. Changes to this policy
We may update this policy as the product and the law evolve. If we make material changes, we will notify you in-app and by email (if you've provided one) at least 14 days before the changes take effect. The "Last updated" date at the top always reflects the current version.
12. Contact
- Email: hi@inamber.app
- Mail: Amber Labs LLC, 8401 Mayland Drive, Suite A, Richmond, VA 23294-4648, USA
If you stop here remembering one thing: your originals stay on your device, and you can delete everything in two taps from Settings.