POLICY / UPDATED 2026.07.26
Privacy Policy
Effective July 21, 2026 · Last updated July 26, 2026
Creative work stays on device.
Popcafe is designed to keep creative work private. Projects and imported media are processed primarily on the device. Product analytics and crash reporting are off by default and begin only after the user enables the corresponding setting.
01 / OPERATOR
Who operates Popcafe
Popcafe is operated by OMO Lab (“we”, “us”, or “our”). Privacy questions and requests can be sent to wow@ooooomo.com.
02 / ON DEVICE
Creative content
Photos, videos, drawings, text, project files, thumbnails, and exported media are processed on the device. We do not operate a server that receives or stores this creative content.
03 / OPTIONAL
Product analytics
Product analytics are off by default. If the user turns on Share analytics in Popcafe Settings, Popcafe uses PostHog Cloud in the United States to receive:
- product interactions such as app launches, feature use, project actions, export choices, paywall views, and purchase-flow outcomes;
- technical properties such as app version, build number, selected export format, and whether a Pro entitlement is active; and
- a randomly generated installation identifier used to group anonymous events.
Popcafe does not send project names, filenames, file paths, original photos or videos, Apple IDs, email addresses, StoreKit transaction IDs, advertising identifiers, or session recordings to PostHog. GeoIP enrichment is disabled, so PostHog is instructed not to derive or store a location from these app events. We do not use this information for advertising or cross-app tracking.
04 / OPTIONAL
Crash reports
Crash reporting is off by default. If the user turns on Send crash reports, Popcafe uses Google Firebase Crashlytics. A crash or non-fatal report may include stack traces, relevant application state, device model, operating-system version, app version and build, anonymous installation identifiers, error details, and limited technical screen or flow context.
Crash reports are used only to diagnose and improve Popcafe. They do not intentionally include project media or project names.
PURCHASES / APPLE
Purchases
Subscriptions and payments are processed by Apple through StoreKit. We do not receive payment-card details. Popcafe reads subscription status from Apple to unlock Pro features. If product analytics are enabled, the selected plan and purchase-flow result may be included in PostHog analytics; transaction identifiers are not included.
PHOTOS / PERMISSION
Photos permission
Popcafe requests photo-library access only when the user chooses to browse or import library items, and requests add-only access when the user saves an export. Selected media are copied into project storage on the device. Permission can be changed in iOS Settings.
05 / QUICK REFERENCE
Data summary
| Data | When | Purpose | Processor |
|---|---|---|---|
| Product interaction and other usage data | Only after analytics opt-in | Analytics and product improvement | PostHog |
| Plan and purchase-flow outcome | Only after analytics opt-in | Analytics | PostHog |
| Crash and diagnostic data | Only after crash-reporting opt-in | App functionality and reliability | Google Firebase |
| Project content | When the user creates or imports it | App functionality | On device |
RETENTION / DELETION
Retention and deletion
- Local projects remain until the user deletes them or removes the app.
- PostHog analytics are retained for 1 year under the current PostHog Cloud Free plan. We will update this policy if the project plan or retention setting changes.
- Firebase states that Crashlytics crash traces and associated identifiers are retained for 90 days before removal begins from live and backup systems.
- Support correspondence is retained only as long as needed to resolve the request and meet applicable legal obligations.
06 / CONTROLS
Your choices
The user can stop future analytics or crash collection at any time in Popcafe Settings. Disabling crash reporting also deletes unsent crash reports stored by Popcafe on the device. Photo access can be managed in iOS Settings.
To ask a privacy question or request deletion of data that we can identify, follow the privacy request instructions. Because Popcafe has no user account and analytics are anonymous, we may be unable to associate historical analytics with a particular person without an identifier that the person voluntarily provides.
PROCESSORS / LOCATION
Service providers and international processing
We use Apple for StoreKit and Photos; PostHog for optional product analytics; and Google Firebase for optional crash diagnostics. Data processed by PostHog or Google may be handled outside the user’s country. We require service providers to protect data consistently with their terms, applicable law, and this policy.
COMMITMENT / NO TRACKING
No sale or tracking
We do not sell personal data, use third-party advertising SDKs, use the advertising identifier, or combine Popcafe data with third-party data for targeted advertising. Popcafe does not perform cross-app or cross-website tracking.
Children
Popcafe is not directed to children under the minimum age required to consent to data processing in their jurisdiction. Product analytics and crash reporting remain off unless enabled by the device user.
Changes
We may update this policy when Popcafe’s features or service providers change. The effective date at the top of the page will be updated when material changes are published.
Contact
OMO Labwow@ooooomo.com