Privacy Policy
Last updated: September 27, 2026
Nuno (“the app”, “we”, “us”) is a daily-selfie app developed by TallStudio. This policy explains, in plain terms, what data the app handles and what leaves your device. We built Nuno to keep your data on your phone. The exceptions are described below.
The short version. Your photos, streak, and montage never leave your device. You don’t create an account, and Nuno doesn’t track you across apps or show ads. Two things do leave your device: the feedback you choose to send, and a small number of usage records tagged with a random number the app generates for itself, which means nothing outside Nuno. Face detection, used only to line your eyes up, runs on your device, is never stored, and is never sent anywhere. See “Face data” below.
If you have any question, contact us at contact@tallstudio.net.
1Data stored only on your device
Everything that makes the app work stays on your iPhone:
- The daily photos you take.
- Your streak, day count, and history.
- The montage / time-lapse the app builds from your photos.
- Your reminder time and frequency, and other in-app settings.
This data is stored in the app’s private storage on your device. We have no access to it. If you delete the app, this data is removed from your device.
2Face data
Nuno’s one job is to put your eyes in the same place in every photo, so the days stack into a steady time-lapse. Doing that means the app has to find your eyes in the photo you just took, so it handles face data. This section describes that in full: what is collected, what it is used for, who it is disclosed to, how long it is kept, and how you delete it or withdraw your consent.
What is collected. When you tap the shutter, and only then, Nuno hands the photo it has just captured to Apple’s Vision framework, which runs on your device and performs a single face-landmark detection. From the result the app reads the position of your two eyes and derives three numbers: the point midway between them, the distance between them, and the tilt angle of the line joining them. Nothing else about your face is read, measured, or computed, and no face template, faceprint, signature, or embedding is ever created. Nothing runs on the live camera preview, and nothing runs in the background. Photos you import from your photo library are not analysed at all: face detection runs only on a photo taken with Nuno’s camera.
What it is used for. Those three numbers are used once, immediately, for a single purpose: rotating, scaling, and cropping that same photo so your eyes land on the same fixed coordinates as on every other day. That alignment is the whole feature. It is the only intended use of face data in Nuno, and no other use is planned.
What it is never used for. Nuno performs no face recognition, identification, verification, matching, or authentication. It never compares the face in one photo with the face in another, never tries to work out who you are, and never infers your age, gender, mood, ethnicity, health, or any other characteristic. Face data is never used for advertising, for profiling, or to train any model.
Disclosure and sharing. Face data is never disclosed to anyone and never shared with anyone. It is not transmitted to us, to any server, to any third party, or to any third-party SDK or analytics provider, and it never leaves your device. Because Nuno shares no face data with any third party, no third party holds any. Should that ever change, we would update this policy before doing so, and we would contractually require any such third party to protect face data to the same standard as, or a higher standard than, this policy sets out.
Storage and retention. Face data is never stored. The landmark points, and the three numbers derived from them, exist only in your device’s working memory for the fraction of a second the alignment takes, and are released as soon as the cropped photo has been produced. They are never written to disk, never attached to the photo, never recorded in a database, and never included in any backup or export. The retention period for face data is therefore zero: none of it survives the capture that produced it. What is kept is the resulting photo itself, held in Nuno’s private storage on your device, which you can view and delete at any time.
Deletion. Because no face data is retained, there is nothing left to delete: it is gone within the same capture that created it, whether or not you keep the photo. The resulting photo is yours to remove whenever you like: open it in the gallery and delete it, or use Settings → Delete all photos to remove every photo at once. Deleting Nuno from your iPhone erases all of them, along with everything else the app had stored. If you would like written confirmation of any of this, write to us at contact@tallstudio.net.
Withdrawing your consent. You consent to this processing by granting Nuno access to the camera; the app explains what the camera is for before the system asks. You can withdraw that consent at any time in the iOS Settings app, under Settings → Nuno → Camera. With camera access switched off, Nuno cannot take a photo and therefore cannot perform face detection at all. Withdrawing consent does not delete photos you have already taken. Delete those as described above.
3Feedback you choose to send
Under this section, data leaves your device only when you take one of these two actions:
- You submit written feedback (from the rating flow after a low rating, or from Settings → Report a bug or idea); or
- You tap “Rate on the App Store” after a positive rating.
When you do, the following is sent to our backend (Google Firebase Firestore, see Section 6):
- The feedback text you wrote, and the star rating (if any).
- Technical context to help us understand and fix issues: app version, iOS version, device model (e.g. “iPhone17,1”), the app’s display language, whether notifications are enabled, your total number of photos, and how many days since you installed the app.
- A per-install identifier: a random number the app generates for itself the first time it runs (see Section 4). It is not your name, not your Apple ID, and not anything issued by Apple or derived from your hardware. It only lets us tell whether two messages came from the same installation. Deleting the app erases it, and reinstalling generates a new one.
We do not collect your name, email address, contacts, precise location, health, financial, or biometric data. Face detection used to align your selfie happens entirely on your device and is never sent anywhere.
4Usage statistics
Nuno sends a small number of usage records so we can tell whether the app actually works: whether people keep a streak going, where they stop, and whether reminders help. This happens automatically, without any action on your part.
What is sent. Each record describes one event and its coarse context:
- The event: reaching a streak milestone (7, 15, 30, 60, 100, 180 or 365 days), breaking a streak and the length it had reached, finishing onboarding, taking your first photo, adding the widget, exporting a montage, importing older photos, or a face-alignment failure and its reason.
- The context: app version, major iOS version (e.g. “18”), iPhone generation (e.g. “iPhone17”), the app’s display language, the month you installed the app, how long you have had it as a broad range, whether reminders are enabled, and your reminder frequency.
- A per-install identifier: a random number the app generates for itself the first time it runs. It is not issued by Apple, is not derived from your hardware, and means nothing outside Nuno. Its only purpose is to let records sent months apart be recognised as coming from the same installation, so we can count people rather than only events. Deleting the app erases it.
What is not sent.
- No identity. No name, no email address, no account, and no advertising identifier. The identifier above is generated by the app itself, and we hold no list connecting it to a person. It is specific to Nuno and is never used to follow you into another app or website.
- No photo, ever.
- No precise timing. Capture times are reduced to a two-hour band, your install date to a month, and how long you have had the app to a range.
Nothing is sent when you open the app or take your daily photo. A typical user sends about sixteen of these records over a year, and roughly one per year after that.
5What we do with it, and why
- To read and act on your feedback and fix bugs.
- To understand the context a bug report came from (device, version, etc.).
- To count, in aggregate, how many satisfied users choose to rate the app.
- To measure, in aggregate, how far people get and where the app loses them, so we can improve it.
We do not use this data for advertising, profiling, or tracking across other apps or websites, and we do not sell or share it with data brokers.
Legal basis (EEA/UK, GDPR): for feedback, we rely on your consent, given by voluntarily choosing to send it, and on our legitimate interest in improving the app. For the usage records, we rely on our legitimate interest in understanding and improving the app. These records serve audience measurement for our own use only: they are never cross-referenced with any other source, never shared with third parties, and never used to follow you outside Nuno. You are never required to send feedback to use Nuno.
6Who processes the data (Google Firebase)
Feedback and the anonymous usage records are stored using Google Firebase Firestore, acting as our data processor. Google may process this data on servers located in the United States. Where applicable, international transfers are covered by Google’s Standard Contractual Clauses and the EU–US Data Privacy Framework. Google’s handling of this data is governed by the Firebase Data Processing Terms and Google’s Privacy Policy.
7Permissions the app may ask for
- Camera, to take your daily selfie. Photos are processed and stored on your device.
- Photo Library, to save your photos and montage to your camera roll and to import older photos. Nuno only ever touches its own album. It does not read the rest of your library.
- Notifications, to send your daily reminder. Reminders are scheduled locally on your device; there is no push server and no data is sent for this.
You can change any of these at any time in the iOS Settings app.
8Retention
Feedback records are kept only as long as needed to act on them and improve the app, then deleted. Usage records are kept only as long as they remain useful for producing these statistics, and are purged periodically. Data stored locally on your device stays until you delete it, or delete the app.
9Your rights
Depending on where you live (e.g. under the GDPR, UK GDPR, LGPD, PIPA, CCPA), you may have the right to access, correct, or delete your data, and to object to or restrict its processing. Because we don’t hold an account or your name, the practical way to exercise these rights is to email us at contact@tallstudio.net. To help us find your feedback record, you can include the date you sent it.
The usage records described in Section 4 are identified only by a random number that corresponds to nothing outside the app. We hold no name, email address, or account, so we have no way to determine which records came from your device, and we do not collect additional information for the sole purpose of making that possible. The GDPR expressly provides for this situation: where a controller cannot identify a person from the data it holds, the rights of access, correction, and deletion do not apply to that data.
Note: uninstalling Nuno immediately deletes all locally-stored data (your photos, streak, and montage) from your device.
10Children
Nuno contains no age-restricted content, and there is no minimum age to use it. The app is not specifically aimed at children, and we never ask anyone their age. Everything described in this policy applies to every user alike: the photos stay on the device, there is no account, no advertising, and no tracking across apps or websites. We do not knowingly collect personal information from a child. If you are a parent or guardian and believe your child has sent us feedback you would like removed, write to us at contact@tallstudio.net and we will delete it.
11Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top will reflect any change.
12Contact
TallStudio
Email: contact@tallstudio.net