The Tens ("we", "us") provides the fopic photo booth app. This notice explains what personal data we process, why, who we share it with, and what rights you have.
This is the first English version of our privacy notice. It takes effect on 21 August 2026, together with the Korean version. Until then, the Korean privacy policy dated 6 August 2026 applies — it is available here.
The Terms of Service take effect on a different date. That revision may be unfavourable to some users and so requires 30 days' notice; it takes effect on 8 September 2026 as announced.
Questions: contact@thetens.app
Where fopic is available — fopic is not offered in the European Economic Area, the United Kingdom, or Switzerland. If you are in one of those regions, the app is not available to you and this notice does not apply.
A Korean-language version of this notice is published for users in the Republic of Korea. The facts about what we process are the same in both; each states the disclosures required by the law applicable to its readers.
We are established in the Republic of Korea. Send all privacy enquiries, including requests to exercise your rights, to the email address above. Seo Jisoo is our privacy officer and handles these personally.
fopic lets you take four-cut photos, edit them, and optionally share them by QR code.
Taking photos, editing them, separating subject from background, and saving to your device all happen on your device. Your photos are not sent to us unless you choose to share them by QR code.
This notice covers the app and the QR sharing web pages.
Opening the app sends the following to third parties, even without an account:
| Data | Purpose | Recipient |
|---|---|---|
| Device information (operating system, device model), app version, IP address | Diagnosing errors and crashes, usage statistics | Datadog |
| App usage records (e.g. camera facing and screen rotation used when taking photos) | Feature usage statistics, improving capture quality | Datadog |
| Error and crash records | Error diagnosis | Datadog |
| Advertising identifier (iOS IDFA, Android AAID), device information, IP address | Serving and measuring ads | Google AdMob |
| Approximate location (country and city level) | Serving and measuring ads | Google AdMob |
| Account identifier (if signed in) or an anonymous identifier, device information | Verifying subscription entitlement | RevenueCat |
This does not include your name or email address. You can reset or delete the advertising identifier in your device settings at any time — see section 6.
About approximate location — The approximate location above (country and city level) is estimated by the advertising provider from your IP address and device signals. The app does not request location permission and does not collect GPS or other precise location data. We do not collect or store this ourselves.
If you choose to share by QR code, the finished photo strip (which may contain faces) and the video are uploaded to a sharing server. This feature works without an account.
| Data | Purpose | Retention |
|---|---|---|
| Finished photo (may contain faces), video | Temporary sharing via QR code | Automatically deleted 24 hours after upload |
| Frames and stickers you created (only if shared by QR code) | Temporary sharing via QR code | Automatically deleted 24 hours after upload |
| Your IP address | Preventing upload abuse | Used only while handling the request |
Frames and stickers can also be passed to other users by QR code, in which case the file is uploaded to the same sharing server. Sending and receiving frames and stickers requires an account.
Anyone holding the QR code can open the file. Please consider carefully who you share it with and what it contains.
| Data | Purpose |
|---|---|
| Social account identifier | Identifying you as a member |
| Email address | Identifying you and answering enquiries |
| Name or nickname | Identifying you and displaying it in the app |
| Account identifier we issue | Distinguishing who owns saved content |
| Sign-in method (Apple, Google, or Kakao) | Telling you how to sign in again |
| Sign-up date and time | Account management |
Email and name come from Apple, Google, or Kakao during sign-in. If you choose "Hide My Email" with Apple, we never learn your real address.
This requires an account, and the images you create are saved to your account automatically. There is no separate save step. If you do not want them kept in your account, do not use the feature, or delete the items you created.
| Data | Purpose |
|---|---|
| Frame and sticker images you created | Storing in your account and syncing across devices |
Using the contact form in Settings sends your message and the following to our email address — the minimum needed to reproduce and answer your question.
| Data | Purpose |
|---|---|
| Message content, reply email address | Reading and answering your enquiry |
| App version, OS version, device model, app language, sign-in method, account identifier | Reproducing and diagnosing the situation |
We use your data only for the purposes below. If we ever want to use it for something else, we will ask you first.
| Purpose | Data |
|---|---|
| Running your account, and storing and syncing the frames and stickers you make | Sections 3.3, 3.4 |
| Delivering QR sharing | Section 3.2 |
| Operating paid subscriptions — checking and restoring entitlement, applying plan limits | Account or anonymous identifier, device information, purchase history |
| Preventing abuse of the upload endpoint | IP address, used only while handling the request |
| Diagnosing errors and crashes, and understanding which features are used | Section 3.1 (Datadog) |
| Serving ads to users on the free plan, and measuring them | Section 3.1 (Google AdMob) |
| Answering your enquiry | Section 3.5 |
We do not sell your personal data, and we do not use your photos to train machine learning models.
We know the photos you take or import may contain faces.
We do not use these photos to identify or authenticate anyone, and we do not generate biometric templates from faces. Separating subject from background runs on your device and produces an image, not a biometric identifier. If we ever introduce a feature that identifies or authenticates people by face, we will ask for your consent beforehand and update this notice.
We do not collect government identifiers (resident registration, passport, driving licence, or foreign resident numbers), health data, or other sensitive categories of data.
Device biometric unlock (Face ID and similar) is performed by your operating system; we receive only whether it succeeded.
We show ads to users on the free plan. Ads are served by Google AdMob using the advertising identifier stored on your device.
| Who collects | Purpose | Data | Retention | Country |
|---|---|---|---|---|
| Google LLC (Google AdMob) and advertising providers connected through mediation | Serving ads, measuring performance, personalised ads | Advertising identifier, device information, IP address, approximate location (country and city level), ad view and click records | Per each provider's own privacy policy | United States and others |
We do not collect or store this behavioural data ourselves. The advertising providers collect it from your device. If you reset or delete the advertising identifier in your device settings, data collected after that point is not linked to earlier data.
Google's privacy policy: https://policies.google.com/privacy
How to opt out
Where the law of your region requires us to obtain consent before ads may be served, the app asks for that consent when you first open it, and you can change your answer at any time in Settings → Ad privacy settings. That screen appears only where such a requirement applies to you.
We do not sell your data, and we do not provide your account information, photos, videos, frames, or stickers to third parties.
Service providers acting on our instructions
| Provider | Task | Duration | Where data is stored |
|---|---|---|---|
| Supabase Pte. Ltd (Singapore company) and its group company Supabase Inc (US company) | Account authentication and storing account data | Until deletion when you close your account | Republic of Korea (Seoul) |
| Cloudflare, Inc. | Temporary storage of QR sharing files | 24 hours after upload | United States |
| RevenueCat, Inc. | Checking and restoring subscription entitlement | See section 9 | United States |
| Datadog, Inc. | Error diagnosis, stability monitoring, usage analysis | 30 days from collection | United States |
These providers handle your data only within the scope we instruct and do not use it for their own purposes. Our contracts with them cover confidentiality, security measures, limits on sub-contracting, and their obligation to help us answer your requests, as required by Article 26 of the Korean Personal Information Protection Act.
About Supabase — Account data and the frames and stickers you create are stored on servers in Seoul, Republic of Korea. However, we contract with Supabase Pte. Ltd, a Singapore company, and its group company Supabase Inc is a US company, so access from outside Korea and transfers within the group may occur in the course of operations and technical support. Section 8 covers this.
Google is not one of these providers. Google LLC (Google AdMob) collects and uses the advertising identifier, device information, IP address, and approximate location for its own advertising purposes as well, and may pass this to other advertising providers through mediation. Google therefore decides how it uses that data independently of us, rather than acting on our instructions. Section 6 sets out what it collects and how to opt out.
We are established in the Republic of Korea, and some of our service providers are in the United States and Singapore.
| Recipient | Country | Data | Purpose | Retention |
|---|---|---|---|---|
| Cloudflare, Inc. | United States | Finished photo (may contain faces), video, frame and sticker files, IP address | Temporary storage of QR sharing files | Deleted 24 hours after upload |
| Google LLC | United States | Advertising identifier, device information, IP address, approximate location | Serving and measuring ads | Per Google's privacy policy |
| Datadog, Inc. | United States | Device information, app version, IP address, app usage records, error records | Error diagnosis and monitoring | 30 days from collection |
| RevenueCat, Inc. | United States | Account or anonymous identifier, device information, purchase history | Verifying subscription entitlement | See section 9 |
| Supabase Pte. Ltd and its group company Supabase Inc | Singapore, United States | Account data (email address, name), frames and stickers you create | Account authentication, storing account data, technical support | Until deletion when you close your account |
Account data and the frames and stickers you create are stored in Seoul. However, because the provider's operating entities are outside Korea, access from abroad and transfers within its group may occur during operations and technical support. We treat that as a transfer abroad and list it above.
You can refuse these transfers. Some of them happen the moment the app starts, so if you want to refuse, please stop using the app or contact us at the address in section 1. Transfers for QR sharing do not happen unless you use that feature, and ad tracking can be refused separately as described in section 6.
| What | Retention |
|---|---|
| Account information | Deleted without delay when you close your account |
| Frames and stickers stored in your account | Deleted without delay when you close your account |
| Photos, videos, frames, and stickers uploaded for QR sharing | Deleted 24 hours after upload. The deletion job runs on the hour, so this can take up to 25 hours |
| App usage records, error records, device information | 30 days from collection |
| Enquiries and the details attached to them | Deleted after we have answered (held in our email inbox until then) |
| Subscription entitlement information | See below |
Why these periods — These are the shortest periods we need to achieve the purposes above, not statutory retention periods. We currently hold no personal data that we are legally required to retain. When paid subscriptions launch we will review whether record-keeping duties under consumer protection law apply to us, and update this notice.
Subscription entitlement information — The processing below happens only if you use a paid subscription. If you do not, no purchase history is created.
We do not collect or hold payment details (card or account numbers). Payment happens through Apple's App Store, and we only check whether a subscription is valid. RevenueCat, which we use for that check, records the account identifier and purchase history. Deleting your account does not currently delete that record automatically. Once your account data is deleted the record can no longer be linked to you, but the record itself remains.
If you want it deleted, please email us before closing your account and we will verify and delete it. After closure we cannot tell whose record it is, so individual deletion is no longer possible. We will update this notice once automatic deletion is built.
You may ask us at any time to:
How to exercise them
We act without undue delay, and within any time limit applicable law sets — for access requests under the Korean Personal Information Protection Act, within 10 days. We do not charge for this. We may need to confirm your identity first, so that we do not disclose your data to someone else.
Depending on where you live, your local law may give you further rights, such as receiving your data in a portable form or objecting to particular processing. Contact us at the address above and we will honour any right that applies to you.
Requests are received and handled by Seo Jisoo (Representative) · contact@thetens.app. We are a sole proprietorship, so the same person handles privacy matters and access requests.
You are not legally required to give us any personal data.
fopic is not directed at children.
We do not allow account creation by anyone under 14, and we ask you to confirm you are 14 or older when you sign in. We do not collect dates of birth, so we cannot verify age ourselves. If we learn — from a parent or guardian, from you, or from an authority — that we hold data of a child under that age, we delete it without delay.
Where the law of your country sets a higher age at which a child can agree to this kind of service on their own, a parent or guardian must agree on the child's behalf.
For parents and guardians — Some features work without an account, and data is still processed:
If you do not want a child using QR sharing, use device restrictions such as Screen Time, or contact us at contact@thetens.app to review or delete a child's data. We will act without delay and confirm the outcome.
We do not make decisions about you by automated means that affect your rights or obligations.
Automatic processing inside the app — separating subject from background, applying photo filters — is an editing function you run yourself and does not decide anything about you.
If we ever introduce automated decision-making, we will publish how it works here, together with how to request an explanation, contest the decision, or ask for human review.
No system is perfectly secure. If a breach occurs that is likely to put you at risk, we will notify the competent authority and, where required, you, within the time limits applicable law sets.
We do not process pseudonymised data for statistical, research, or archiving purposes.
If you are unhappy with how we handle your data, please contact us first at contact@thetens.app so we can try to resolve it.
You can also complain to a data protection authority. As we are established in the Republic of Korea, the competent authority is the Personal Information Protection Commission (https://www.pipc.go.kr). For dispute resolution or advice:
If your country has its own data protection authority, you may complain to it as well. You may also seek a remedy in the courts.
We apply this notice from its effective date. Where we add to, remove, or correct it, we give notice in the app or on this page at least 7 days before the change takes effect, and at least 30 days beforehand for changes that disadvantage you.
Revision history