Privacy Policy
Effective and last updated August 17, 2026
Who this policy covers
This policy describes how Mogshot handles personal data when you use the Mogshot iOS app, website, and related services. Mogshot is intended only for people who are 18 or older.
Data we collect
Account data: your email address, Apple or Google account identifier, authentication records, and account preferences.
Content and order data: photos you choose to upload, generated photos, face-similarity quality scores, style choices, order status, and support requests.
Payment data: Stripe processes your card details. Mogshot receives transaction identifiers, payment status, amount, currency, and limited billing details, but does not receive or store your full card number.
Technical and advertising measurement data: IP address, request and security logs, device or browser type, app install and launch events, advertising identifiers when you grant iOS tracking permission, and website or app usage events needed to operate, secure, measure, and improve the service. We do not access your contacts, precise location, or social graph.
How we collect and use data
We collect data when you sign in, confirm that you are 18 or older, select photos, configure an order, use checkout, contact support, or interact with our app or website. We use it to authenticate you, process photos, generate and deliver your order, prevent abuse, provide support and refunds, measure advertising performance, maintain security, and comply with legal obligations.
We do not sell personal data. We do not use your photos for advertising or publish them in marketing without separate written permission.
TikTok advertising measurement
After you confirm that you are 18 or older, the Mogshot iOS app initializes the TikTok App Events SDK to report limited events such as app installation, launch, retention, and the start of the upload flow. Mogshot disables TikTok's enhanced data postback and automatic StoreKit purchase reporting, so screen text, button labels, uploaded photos, and payment details are not sent through this integration.
On iOS, Mogshot asks for App Tracking Transparency permission before TikTok may access the advertising identifier (IDFA). You may decline or later change this permission in iOS Settings. TikTok may use permitted device and event data to measure ads, attribute installs or actions, create advertising audiences, and support retargeting under TikTok's own terms. Mogshot never sends your uploaded or generated photos to TikTok.
AI and face processing
Your selected photos and generated results are processed to create your order and check image quality. Face-similarity measurements are used only to compare photos within your own order; Mogshot does not use them to identify you against a database or for surveillance.
Mogshot does not train its own AI models on your photos and does not authorize its service providers to use your photos for advertising or model training.
Service providers and sharing
We share only the data needed to operate the service with: Apple and Google for sign-in; Supabase for authentication, database, and file storage; OpenAI for image generation and image-quality processing; Replicate for face-similarity quality checks; Stripe for payment processing; Vercel for hosting and request delivery; Inngest for background workflow orchestration; Resend for service email; Google Analytics for website usage measurement when enabled; and TikTok for iOS advertising measurement after the adult confirmation described above.
These providers process data under their own privacy terms and contractual or legal safeguards. We require them to protect personal data consistently with this policy and to process it only for the service they provide to us. We may also disclose data when required by law or to protect users and the service.
Retention and deletion
Photos for completed orders are scheduled for deletion from active Mogshot storage 30 days after delivery. Photos for abandoned or failed orders are scheduled for deletion no later than 30 days after the last order activity. Face-quality data is deleted with the related order assets.
You can delete your account from Account settings at any time. This removes your Mogshot account and active order assets. Limited transaction, fraud-prevention, security, or legal records may be retained where required by law, to resolve disputes, or by payment and infrastructure providers under their own retention obligations. Provider backups and logs may take additional time to expire under their documented retention schedules.
Security
Photos are encrypted in transit and at rest. Access to private files uses short-lived signed links tied to your account. No internet service can guarantee absolute security, but we limit access and use technical and organizational safeguards appropriate to the data we process.
Your choices and rights
From Account settings you can export your data, delete your account, or sign out. You can revoke photo-library or tracking permission in iOS Settings and revoke Apple or Google sign-in access from the relevant account provider.
For access, correction, deletion, consent withdrawal, GDPR, or CCPA requests, email support@mogshot.app. We will verify the request before acting on it.
Changes and contact
We may update this policy when the service or legal requirements change. We will update the date on this page and provide additional notice when a material change requires it.
Questions? Email support@mogshot.app.