Phototag Privacy Policy
Effective Date: 22.09.2026
This policy covers AI Hashtag Generator Phototag for iPhone and iPad (the "App") and the page about it on pictorai.app. It is separate from the policy for PictorAI, a different app on the same domain. Until September 2026 this policy was published at aitagger.online; that domain has been retired and this is its replacement. The practices described here did not change with the move.
1. No account, no sign-in
Phototag has no login. We do not ask for your name, email address, phone number or date of birth, and there is no account to create or delete. Everything below is either processed to produce a result you asked for, or collected as anonymous analytics and diagnostics.
2. What you send when you generate
When you ask for captions and hashtags, the App sends the following to our own backend, which forwards it to Google's Gemini API (see Section 3):
- The image you selected or shot, as a resized JPEG — for a photo generation.
- A few still frames sampled from the clip (start, middle and end) — for a video generation. The video file itself is never uploaded.
- The text you typed — for a generation from a description.
- Your output settings: the caption language, the hashtag language, the requested title length, whether emoji are on, any extra instructions you entered, and the previous result when you ask for a regeneration.
Nothing else travels with the request. We do not attach your name, email, contacts, location or advertising identifier, because the App does not collect them for this purpose. Your photo library is read only for the items you pick; the App never scans or uploads it in the background.
Requests are sent over HTTPS and are validated with Firebase App Check, which confirms the request came from a genuine copy of the App rather than a script. It carries no information about you.
3. The AI provider (Google)
The captions and hashtags are produced by Google Gemini models. Your device does not talk to Google directly: the App calls our backend, which holds the API key, builds the prompt and passes on the image, frames or text described in Section 2. That is also why no API key ships inside the App.
Google processes this data on our behalf to return the one result you requested, and does not use it to train its generally available machine-learning models, consistent with the Gemini API terms for paid services. Google's handling of the data is governed by Google's Privacy Policy and the Gemini API Additional Terms of Service.
We do not use your photos, videos, frames, text or the generated results to train any model, and we do not use them for advertising or profiling.
4. What stays on your device
- History. Your generations — captions, titles and tag sets — are stored on the device only. They are not uploaded to us and not synced between devices. Delete a single entry, or all of them, from the History screen.
- Settings. Output languages, the signature, emoji and title-length preferences live in the App's own storage on the device.
- Free-tier counters. How many generations you have used today is kept in the device Keychain, scoped to this device and not backed up elsewhere. It exists so the daily allowance cannot be reset by reinstalling.
5. Analytics, diagnostics and tracking
We use the following third-party SDKs inside the App:
- Firebase Analytics and Mixpanel — which screens are opened and which actions are taken, so we can see where the App is confusing. Events describe the interaction, not the content you generated.
- Firebase Crashlytics — crash reports and error diagnostics, including device model, OS version and the state of the App at the moment it failed.
- Adapty — subscription and purchase state, so the App knows whether Pro is active and can restore it.
- Google Ads on-device conversion SDK — measures installs attributed to our advertising, on the device.
- Firebase App Check — App integrity attestation, as described in Section 2.
App Tracking Transparency. On first launch, iOS asks whether the App may track you across other companies' apps and websites. If you decline, no tracking identifier is used, and the analytics above stay limited to what is needed to operate and improve the App. You can change the answer at any time in iOS Settings → Privacy & Security → Tracking.
Diagnostics may include the device type, operating system version, language settings and IP address.
6. Permissions the App asks for
- Photo library — to let you choose the photo or video you want tags for.
- Camera — only if you shoot the photo from inside the App.
Both are optional and can be revoked in iOS Settings; the relevant feature simply stops working.
7. Data retention
Images, video frames and text are passed through to fulfil one generation and are not retained on our side once the result has been returned, except where a short-lived log is needed for abuse prevention or to meet a legal obligation. Analytics and crash data are retained by the providers above under their own retention schedules. Your history and settings stay on the device until you delete them or remove the App.
8. Sharing
We do not sell or rent your data. It is shared only:
- With the providers named in Sections 3 and 5, for the purposes stated there.
- With Apple, where you have made an in-app purchase and Apple asks us for consumption data while reviewing a refund request. Shared only as far as Apple's policies require, to let Apple decide the request.
- Where required by law, regulation or legal process.
- In a merger, acquisition or sale of assets, in which case this policy travels with the data.
9. Your rights
Because there is no account, most of your data is already in your hands: clear your history in the App and uninstall it to remove the rest from the device. Depending on where you live, you may also ask us to confirm what we hold, provide a copy of it, or delete it. Write to support@pictorai.app and say which app your request is about, since this address also serves PictorAI.
To opt out of analytics tracking, decline the App Tracking Transparency prompt or turn tracking off in iOS Settings.
10. Security
Requests travel over encrypted connections (HTTPS/TLS), the Gemini API key is held on the backend rather than in the App, and App Check rejects requests that do not come from a genuine build. We take reasonable technical and organisational measures to protect your data, but no system can be entirely secure.
11. This website
- Analytics cookies: pictorai.app uses Firebase Analytics to count page views and clicks on the App Store link. It runs only after you press Accept in the consent banner. Decline and no analytics script loads.
- Your choice is stored locally in your browser so we do not ask again. Clearing site data brings the banner back.
- No accounts or forms: this site does not ask for an email address and does not process payments. Purchases happen in the App and in the App Store.
12. Children's privacy
Phototag is not directed at children under 13, or under the minimum age set by local law. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this policy. Changes are posted on this page with a new Effective Date; continued use of the App means you accept the revised policy.
14. Contact
Email: support@pictorai.app
App: AI Hashtag Generator Phototag (iPhone, iPad)