Privacy Policy
Last updated 2026-08-07
Effective Date: 2026-08-07
This Policy is offered in Traditional Chinese, Simplified Chinese, English, and Japanese for your convenience. If language versions conflict, the English version prevails.
In short
Amazingface cannot read the photos or videos stored in your local Vault. When you use AmazingDrop, file content is encrypted on the sender’s device, and the Relay temporarily stores encrypted transfer data for delivery.
Amazingface does keep the minimum account identifiers, device public keys, purchase and subscription status, quota usage, referral, report, routing, and encrypted-delivery records needed to operate sign-in, subscriptions, abuse controls, and AmazingDrop. These service records can be linked to your Amazingface account. They do not include plaintext Vault media, plaintext thumbnails, your Vault password, Recovery Phrase, or plaintext content-decryption keys.
Amazingface does not use advertising, third-party analytics SDKs, or cross-app tracking.
1. Scope
This Policy describes how Amazingface, the amazingface.app website, Amazingface apps, and the backend Relay at relay.amazingface.app handle information. “Amazingface,” “we,” “us,” and “our” refer to the Amazingface service operated by OFFERSEES PTE. LTD.
2. Information we keep
We keep only the categories needed to operate the service:
| Category | What it includes | Why we use it |
|---|---|---|
| Account identifiers | Anonymous Sign in with Apple subject (sub), internal account ID, and AmazingDrop handle | Authenticate the account and route AmazingDrop deliveries |
| Device public keys | Ed25519 signing public keys and age/X25519 recipient public keys generated on a device | Verify transfers and let senders encrypt content for the intended recipient device |
| Purchase and subscription records | Apple original transaction ID, tier, subscription state, renewal or cycle end | Activate entitlements, process renewals, prevent replay, and provide paid features |
| Usage and quota records | Transfer byte counts, current-period usage, delivery state, timestamps, and related service ledger entries | Enforce plan limits and operate delivery |
| Referral records | Inviter, invitee, qualification state, and awarded usage | Provide the invite reward program and prevent duplicate rewards |
| Report records | The reporting account, the reported account, an optional transfer ID, a fixed report-reason category, and a timestamp | Investigate abuse, enforce service rules, and protect users |
| Encrypted AmazingDrop data | Ciphertext, encrypted key envelopes, signatures, internal routing identifiers, and expiry information | Temporarily deliver an end-to-end encrypted transfer |
These records are linked through an account, device, purchase, transfer, referral, or report. “Anonymous Sign in with Apple subject” means Amazingface does not receive your ordinary Apple ID from that identifier; it does not mean the service record is unlinked to your Amazingface account.
3. Information we do not receive
Amazingface does not receive or keep:
- plaintext photos or videos stored in your local Vault;
- plaintext Vault thumbnails;
- your Vault password or Recovery Phrase;
- plaintext Vault-decryption keys;
- your Apple ID name or email, unless you voluntarily provide contact information in a support request;
- your contacts;
- precise or coarse location;
- IDFA or data used for advertising or cross-app tracking;
- third-party analytics profiles;
- plaintext AmazingDrop media or AmazingDrop content-decryption keys.
Production Relay access logging is disabled. IP addresses are used transiently to establish TLS connections and apply real-time security or rate-limiting controls, but are not written to production access logs or retained by Amazingface under the current configuration.
Amazingface does store account handles, internal identifiers, device public keys, and delivery relationships needed to route encrypted transfers. We therefore do not describe AmazingDrop routing metadata as anonymous to the service.
4. How we use information
We use service records only to:
- authenticate your account;
- register devices and public keys;
- route and temporarily buffer encrypted AmazingDrop transfers;
- enforce transfer quotas and plan limits;
- activate and maintain subscriptions and one-time usage purchases;
- provide referral rewards and prevent duplicate rewards;
- investigate reports, misuse, fraud, or security incidents;
- maintain the reliability and security of the service;
- respond to support and privacy requests.
We do not:
- sell personal information;
- share information with data brokers;
- use information for third-party advertising;
- use information for cross-app tracking;
- build advertising profiles;
- train AI models on Vault media or AmazingDrop content;
- analyze your Vault photos or videos.
5. AmazingDrop retention
AmazingDrop is a transfer service, not a permanent cloud photo library. Transfer content is encrypted before upload. The Relay removes transfer ciphertext after successful delivery or when its maximum retention expires, whichever happens first.
| Plan | Maximum undelivered ciphertext retention |
|---|---|
| Free | 24 hours |
| Plus | 48 hours |
| Pro | 72 hours |
Delivery and account metadata may remain longer under the retention rules below even after ciphertext is removed.
6. Service providers
We use a limited set of providers to operate Amazingface:
| Provider | Role | Information involved |
|---|---|---|
| Apple | Sign in with Apple, StoreKit purchases, subscription notifications | Apple-issued account subject, transaction and subscription records |
| Amazon Web Services | Hosting for Amazingface backend and Relay | Account, device-key, purchase, quota, referral, report, routing, and encrypted-transfer records needed to operate the service |
AWS receives encrypted AmazingDrop blobs and operational records as our infrastructure provider. AWS does not receive the recipient’s private decryption key from Amazingface and cannot turn the encrypted payload into plaintext media through the Amazingface service.
The current app does not integrate Google Analytics, Firebase, Facebook SDK, AppsFlyer, ad SDKs, third-party analytics SDKs, or third-party crash-reporting SDKs.
7. Retention and deletion
| Data type | Retention |
|---|---|
| AmazingDrop ciphertext | Until successful delivery or 24 / 48 / 72-hour plan expiry, whichever occurs first |
| Account identifiers, handles, device keys, subscription and purchase state, quota ledger, referral and linked delivery records | Until you delete your account |
| Report records | For the life of the account or as needed to investigate and document abuse or security enforcement; deleted or de-identified with account deletion unless retention is legally required |
| Application event logs without IP or request content | Up to 30 days |
| Post-deletion backups | Up to 30 days, then permanently destroyed through the normal backup cycle |
Application event logs are a separate operational record, not one of the linked categories in §2 — they are written without the account, device, or purchase identifiers described there, and are erased on a rolling 30-day window.
Account deletion removes active account records and schedules remaining backup copies for destruction. We may retain a narrowly limited record if required by law, to complete a transaction, resolve a dispute, prevent payment or referral fraud, or enforce security. Any such record remains subject to this Policy and is not used for advertising or tracking.
8. App Store privacy summary
Amazingface’s App Store privacy label reports the Apple-standard categories required by the current app and backend:
- Identifiers: User ID and Device ID;
- Purchases: Purchase History;
- Usage Data: Other Usage Data;
- Purpose: App Functionality;
- Linked to you: Yes, because the records are tied to an account, device, purchase, or service use;
- Used for tracking: No.
The App Store label is a developer-submitted summary under Apple’s definitions. This Privacy Policy provides the operational detail behind those categories.
9. Your choices and rights
Regardless of where you live, you can:
- Export: Export supported photos and videos from your Vault through the app.
- Delete: Delete your Amazingface account in the app at Settings → AmazingDrop identity → Delete, or email support@amazingface.app.
- Correct: Update your AmazingDrop handle or contact support when a service record needs correction.
- Cancel: Manage or cancel App Store subscriptions through Apple.
- Ask: Request information about your account data or submit a privacy question by email.
Email requests are handled within 30 days. Additional rights may apply under the GDPR, UK GDPR, CCPA/CPRA, or other local laws, including access, correction, deletion, portability, objection, restriction, and the right to complain to a regulator.
10. Security and encryption
- Vault media: Imported Vault media is encrypted with XChaCha20-Poly1305.
- Password-based key derivation: Amazingface uses Argon2id. New iOS Vaults use
m=64 MiB, t=3, p=4; new macOS Vaults usem=256 MiB, t=3, p=4; both derive a 64-byte output. - Vault parameter portability: Each Vault stores its own key-derivation parameters in its manifest. Supported devices use the parameters recorded when that Vault was created.
- AmazingDrop: Transfer content is encrypted using the age format with the recipient device’s X25519 public key.
- Transport: App-to-Relay connections use TLS 1.3 in addition to AmazingDrop’s application-layer encryption.
Vault passwords, Recovery Phrases, plaintext Vault-decryption material, plaintext transfer media, and content-decryption keys are not sent to Amazingface services.
Publishing implementation details does not replace an independent audit. Amazingface is currently closed source and has not published a third-party security audit. Read the Security page for the complete model and limitations.
11. Children
Amazingface is not directed to children under 13. If we learn that we have collected service data from a child under 13 without valid authorization, contact us and we will take appropriate steps to delete it.
12. International processing
Service providers may process information in countries other than your own. We use providers and contractual or legal safeguards appropriate to the service and applicable law. End-to-end encryption limits provider access to AmazingDrop content, but account and operational metadata remain readable where required to run the service.
13. Changes to this Policy
We update the “Last updated” and “Effective date” when this Policy changes. If a change materially expands how we use linked service data, we will provide an in-app or other appropriate notice before the change takes effect where required.
14. Contact
Privacy questions, corrections, and data-rights requests: support@amazingface.app
We aim to respond within 30 days.
Version history
- 2026-08-07: Clarified account, device-key, purchase, usage, referral, report, and delivery records; aligned the App Store privacy summary; published current Argon2id parameters and plan-based AmazingDrop retention.
- 2026-06-21: Updated the Relay domain and contact email; added Simplified Chinese and Japanese versions.
- 2026-05-26: Initial release.