fopic Privacy Notice

The Tens ("we", "us") provides the fopic photo booth app. This notice explains what personal data we process, why, who we share it with, and what rights you have.

Effective 21 August 2026 · Last updated 21 August 2026

This notice takes effect on 21 August 2026

This is the first English version of our privacy notice. It takes effect on 21 August 2026, together with the Korean version. Until then, the Korean privacy policy dated 6 August 2026 applies — it is available here.

The Terms of Service take effect on a different date. That revision may be unfavourable to some users and so requires 30 days' notice; it takes effect on 8 September 2026 as announced.

Questions: contact@thetens.app

Where fopic is available — fopic is not offered in the European Economic Area, the United Kingdom, or Switzerland. If you are in one of those regions, the app is not available to you and this notice does not apply.

A Korean-language version of this notice is published for users in the Republic of Korea. The facts about what we process are the same in both; each states the disclosures required by the law applicable to its readers.

1. Who we are

We are established in the Republic of Korea. Send all privacy enquiries, including requests to exercise your rights, to the email address above. Seo Jisoo is our privacy officer and handles these personally.

2. What this notice covers

fopic lets you take four-cut photos, edit them, and optionally share them by QR code.

Taking photos, editing them, separating subject from background, and saving to your device all happen on your device. Your photos are not sent to us unless you choose to share them by QR code.

This notice covers the app and the QR sharing web pages.

3. What personal data we process

3.1 When you open the app (whether or not you are signed in)

Opening the app sends the following to third parties, even without an account:

DataPurposeRecipient
Device information (operating system, device model), app version, IP addressDiagnosing errors and crashes, usage statisticsDatadog
App usage records (e.g. camera facing and screen rotation used when taking photos)Feature usage statistics, improving capture qualityDatadog
Error and crash recordsError diagnosisDatadog
Advertising identifier (iOS IDFA, Android AAID), device information, IP addressServing and measuring adsGoogle AdMob
Approximate location (country and city level)Serving and measuring adsGoogle AdMob
Account identifier (if signed in) or an anonymous identifier, device informationVerifying subscription entitlementRevenueCat

This does not include your name or email address. You can reset or delete the advertising identifier in your device settings at any time — see section 6.

About approximate location — The approximate location above (country and city level) is estimated by the advertising provider from your IP address and device signals. The app does not request location permission and does not collect GPS or other precise location data. We do not collect or store this ourselves.

3.2 Photos and videos, and QR sharing

If you choose to share by QR code, the finished photo strip (which may contain faces) and the video are uploaded to a sharing server. This feature works without an account.

DataPurposeRetention
Finished photo (may contain faces), videoTemporary sharing via QR codeAutomatically deleted 24 hours after upload
Frames and stickers you created (only if shared by QR code)Temporary sharing via QR codeAutomatically deleted 24 hours after upload
Your IP addressPreventing upload abuseUsed only while handling the request

Frames and stickers can also be passed to other users by QR code, in which case the file is uploaded to the same sharing server. Sending and receiving frames and stickers requires an account.

Anyone holding the QR code can open the file. Please consider carefully who you share it with and what it contains.

3.3 When you sign in

DataPurpose
Social account identifierIdentifying you as a member
Email addressIdentifying you and answering enquiries
Name or nicknameIdentifying you and displaying it in the app
Account identifier we issueDistinguishing who owns saved content
Sign-in method (Apple, Google, or Kakao)Telling you how to sign in again
Sign-up date and timeAccount management

Email and name come from Apple, Google, or Kakao during sign-in. If you choose "Hide My Email" with Apple, we never learn your real address.

3.4 When you create frames or stickers

This requires an account, and the images you create are saved to your account automatically. There is no separate save step. If you do not want them kept in your account, do not use the feature, or delete the items you created.

DataPurpose
Frame and sticker images you createdStoring in your account and syncing across devices

3.5 When you contact us

Using the contact form in Settings sends your message and the following to our email address — the minimum needed to reproduce and answer your question.

DataPurpose
Message content, reply email addressReading and answering your enquiry
App version, OS version, device model, app language, sign-in method, account identifierReproducing and diagnosing the situation

4. Why we process your data

We use your data only for the purposes below. If we ever want to use it for something else, we will ask you first.

PurposeData
Running your account, and storing and syncing the frames and stickers you makeSections 3.3, 3.4
Delivering QR sharingSection 3.2
Operating paid subscriptions — checking and restoring entitlement, applying plan limitsAccount or anonymous identifier, device information, purchase history
Preventing abuse of the upload endpointIP address, used only while handling the request
Diagnosing errors and crashes, and understanding which features are usedSection 3.1 (Datadog)
Serving ads to users on the free plan, and measuring themSection 3.1 (Google AdMob)
Answering your enquirySection 3.5

We do not sell your personal data, and we do not use your photos to train machine learning models.

5. Faces in photos

We know the photos you take or import may contain faces.

We do not use these photos to identify or authenticate anyone, and we do not generate biometric templates from faces. Separating subject from background runs on your device and produces an image, not a biometric identifier. If we ever introduce a feature that identifies or authenticates people by face, we will ask for your consent beforehand and update this notice.

We do not collect government identifiers (resident registration, passport, driving licence, or foreign resident numbers), health data, or other sensitive categories of data.

Device biometric unlock (Face ID and similar) is performed by your operating system; we receive only whether it succeeded.

6. Advertising identifiers, and how to opt out

We show ads to users on the free plan. Ads are served by Google AdMob using the advertising identifier stored on your device.

Who collectsPurposeDataRetentionCountry
Google LLC (Google AdMob) and advertising providers connected through mediationServing ads, measuring performance, personalised adsAdvertising identifier, device information, IP address, approximate location (country and city level), ad view and click recordsPer each provider's own privacy policyUnited States and others

We do not collect or store this behavioural data ourselves. The advertising providers collect it from your device. If you reset or delete the advertising identifier in your device settings, data collected after that point is not linked to earlier data.

Google's privacy policy: https://policies.google.com/privacy

How to opt out

Where the law of your region requires us to obtain consent before ads may be served, the app asks for that consent when you first open it, and you can change your answer at any time in Settings → Ad privacy settings. That screen appears only where such a requirement applies to you.

7. Who we share your data with

We do not sell your data, and we do not provide your account information, photos, videos, frames, or stickers to third parties.

Service providers acting on our instructions

ProviderTaskDurationWhere data is stored
Supabase Pte. Ltd (Singapore company) and its group company Supabase Inc (US company)Account authentication and storing account dataUntil deletion when you close your accountRepublic of Korea (Seoul)
Cloudflare, Inc.Temporary storage of QR sharing files24 hours after uploadUnited States
RevenueCat, Inc.Checking and restoring subscription entitlementSee section 9United States
Datadog, Inc.Error diagnosis, stability monitoring, usage analysis30 days from collectionUnited States

These providers handle your data only within the scope we instruct and do not use it for their own purposes. Our contracts with them cover confidentiality, security measures, limits on sub-contracting, and their obligation to help us answer your requests, as required by Article 26 of the Korean Personal Information Protection Act.

About Supabase — Account data and the frames and stickers you create are stored on servers in Seoul, Republic of Korea. However, we contract with Supabase Pte. Ltd, a Singapore company, and its group company Supabase Inc is a US company, so access from outside Korea and transfers within the group may occur in the course of operations and technical support. Section 8 covers this.

Google is not one of these providers. Google LLC (Google AdMob) collects and uses the advertising identifier, device information, IP address, and approximate location for its own advertising purposes as well, and may pass this to other advertising providers through mediation. Google therefore decides how it uses that data independently of us, rather than acting on our instructions. Section 6 sets out what it collects and how to opt out.

8. Where your data goes

We are established in the Republic of Korea, and some of our service providers are in the United States and Singapore.

RecipientCountryDataPurposeRetention
Cloudflare, Inc.United StatesFinished photo (may contain faces), video, frame and sticker files, IP addressTemporary storage of QR sharing filesDeleted 24 hours after upload
Google LLCUnited StatesAdvertising identifier, device information, IP address, approximate locationServing and measuring adsPer Google's privacy policy
Datadog, Inc.United StatesDevice information, app version, IP address, app usage records, error recordsError diagnosis and monitoring30 days from collection
RevenueCat, Inc.United StatesAccount or anonymous identifier, device information, purchase historyVerifying subscription entitlementSee section 9
Supabase Pte. Ltd and its group company Supabase IncSingapore, United StatesAccount data (email address, name), frames and stickers you createAccount authentication, storing account data, technical supportUntil deletion when you close your account

Account data and the frames and stickers you create are stored in Seoul. However, because the provider's operating entities are outside Korea, access from abroad and transfers within its group may occur during operations and technical support. We treat that as a transfer abroad and list it above.

You can refuse these transfers. Some of them happen the moment the app starts, so if you want to refuse, please stop using the app or contact us at the address in section 1. Transfers for QR sharing do not happen unless you use that feature, and ad tracking can be refused separately as described in section 6.

9. How long we keep your data

WhatRetention
Account informationDeleted without delay when you close your account
Frames and stickers stored in your accountDeleted without delay when you close your account
Photos, videos, frames, and stickers uploaded for QR sharingDeleted 24 hours after upload. The deletion job runs on the hour, so this can take up to 25 hours
App usage records, error records, device information30 days from collection
Enquiries and the details attached to themDeleted after we have answered (held in our email inbox until then)
Subscription entitlement informationSee below

Why these periods — These are the shortest periods we need to achieve the purposes above, not statutory retention periods. We currently hold no personal data that we are legally required to retain. When paid subscriptions launch we will review whether record-keeping duties under consumer protection law apply to us, and update this notice.

Subscription entitlement information — The processing below happens only if you use a paid subscription. If you do not, no purchase history is created.

We do not collect or hold payment details (card or account numbers). Payment happens through Apple's App Store, and we only check whether a subscription is valid. RevenueCat, which we use for that check, records the account identifier and purchase history. Deleting your account does not currently delete that record automatically. Once your account data is deleted the record can no longer be linked to you, but the record itself remains.

If you want it deleted, please email us before closing your account and we will verify and delete it. After closure we cannot tell whose record it is, so individual deletion is no longer possible. We will update this notice once automatic deletion is built.

10. Your rights

You may ask us at any time to:

How to exercise them

We act without undue delay, and within any time limit applicable law sets — for access requests under the Korean Personal Information Protection Act, within 10 days. We do not charge for this. We may need to confirm your identity first, so that we do not disclose your data to someone else.

Depending on where you live, your local law may give you further rights, such as receiving your data in a portable form or objecting to particular processing. Contact us at the address above and we will honour any right that applies to you.

Requests are received and handled by Seo Jisoo (Representative) · contact@thetens.app. We are a sole proprietorship, so the same person handles privacy matters and access requests.

11. Is providing your data required?

You are not legally required to give us any personal data.

12. Children

fopic is not directed at children.

We do not allow account creation by anyone under 14, and we ask you to confirm you are 14 or older when you sign in. We do not collect dates of birth, so we cannot verify age ourselves. If we learn — from a parent or guardian, from you, or from an authority — that we hold data of a child under that age, we delete it without delay.

Where the law of your country sets a higher age at which a child can agree to this kind of service on their own, a parent or guardian must agree on the child's behalf.

For parents and guardians — Some features work without an account, and data is still processed:

If you do not want a child using QR sharing, use device restrictions such as Screen Time, or contact us at contact@thetens.app to review or delete a child's data. We will act without delay and confirm the outcome.

13. Automated decisions

We do not make decisions about you by automated means that affect your rights or obligations.

Automatic processing inside the app — separating subject from background, applying photo filters — is an editing function you run yourself and does not decide anything about you.

If we ever introduce automated decision-making, we will publish how it works here, together with how to request an explanation, contest the decision, or ask for human review.

14. Security

No system is perfectly secure. If a breach occurs that is likely to put you at risk, we will notify the competent authority and, where required, you, within the time limits applicable law sets.

15. Pseudonymised data

We do not process pseudonymised data for statistical, research, or archiving purposes.

16. Complaints

If you are unhappy with how we handle your data, please contact us first at contact@thetens.app so we can try to resolve it.

You can also complain to a data protection authority. As we are established in the Republic of Korea, the competent authority is the Personal Information Protection Commission (https://www.pipc.go.kr). For dispute resolution or advice:

If your country has its own data protection authority, you may complain to it as well. You may also seek a remedy in the courts.

17. Changes to this notice

We apply this notice from its effective date. Where we add to, remove, or correct it, we give notice in the app or on this page at least 7 days before the change takes effect, and at least 30 days beforehand for changes that disadvantage you.

Revision history

Business information