CurbShot — Privacy Policy

Last updated: August 2, 2026 · Applies to the CurbShot app for iOS and Android

The short version. CurbShot has no accounts and asks for no personal details — no name, no email, no password. Your photos stay on your phone. When you use an AI tool, a copy of that one photo is sent for processing and is not kept on our servers afterwards. We do not use advertising identifiers, we do not track you across apps or websites, and we do not sell or share your personal information.

CurbShot is operated by Metin Güner ("we", "us"). This policy explains what the app collects, why, who processes it on our behalf, and what control you have. It describes the app's actual behaviour rather than every possibility the law allows.

1. We do not ask you to create an account

On first launch the app creates an anonymous identifier for you through our authentication provider. It is a random identifier with no email address, name, phone number or password attached, and it exists for one reason: to hold your credit balance so your purchases follow you between app launches. You are never asked to sign in and there is no way to do so in this version.

2. Your photos

Where they live

Photos you import or capture are stored on your device, inside the app's private storage. This includes the untouched originals CurbShot archives for compliance and every edited version. We do not upload your library, we do not browse it, and we do not keep a copy of your archive on any server.

On both platforms, choosing photos goes through the operating system's own picker, so the app receives only the specific photos you select and never gains access to the rest of your library.

What happens when you use an AI tool

Enhance, Declutter and Virtual Staging cannot run on the phone. When you start one of them, a copy of that single photo is sent over an encrypted connection to our processing service, which passes it to our AI provider to perform the edit and returns the result to your device.

Metadata inside the photo file

A photo file saved by a camera carries more than the picture: capture time, camera model, and, if your device is configured to record it, the GPS coordinates where the photo was taken. For a listing photo those coordinates are the address of the property.

We remove that metadata from the copy we send. Stripping happens on your device, before the upload starts, so the coordinates never leave it. The copy kept in your own archive is untouched — the original stays exactly as your camera wrote it, on your device, where you can still read its metadata in any photo app.

CurbShot never requests the device location permission, and does not read, extract, index or store photo metadata for any purpose of its own.

The record we keep of an edit

So that an edit survives you closing the app, we store a small job record: an internal job id, which operation you asked for, its status, timestamps, your anonymous identifier, your device identifier, and a temporary link to the finished image. It contains no photo content. These records are deleted automatically 7 days after the job finishes.

3. Device identifier

The app uses one device-scoped identifier — on Android the system ANDROID_ID value, on iOS a random identifier the app generates and stores in the keychain. It is used for exactly two things:

It is not an advertising identifier and is never used for advertising, profiling or cross-app measurement. The Android build removes the advertising-ID permissions outright, and the iOS build does not include the optional component that would give Google Analytics access to the advertising identifier — so CurbShot has no IDFA, shows no App Tracking Transparency prompt, and cannot track you across other companies' apps or websites.

4. Purchases

Credit packs and the Pro subscription are sold by Apple and Google. Payment is handled entirely by the store; we never see your card number, billing address or similar details. We use RevenueCat to confirm a purchase happened and to tell our own system how many credits to add. What reaches us is: which product was bought, the store's transaction and event identifiers, and your anonymous identifier.

Because this version has no accounts, credits live on the device that bought them. Subscriptions can be restored from your store account; consumable credit packs cannot be restored by the stores. The app says this at the point of purchase.

5. Diagnostics and product analytics

Crash reports (Firebase Crashlytics). When the app crashes we receive a report containing the crash itself, device model, operating system version, app version and a short trail of the app's own log lines leading up to it. These logs describe app activity such as queue and billing steps; they do not contain your photos.

Product analytics (Firebase Analytics). The app reports three events: a listing was created, photos were imported, and a staged result was accepted, plus the events Firebase collects automatically such as app opens. These carry counts, not content, and no advertising identifier.

Push messaging. The messaging component registers a device token with Google. This version of the app does not send push notifications — the "your listing is ready" alerts you see are generated locally on your device and never leave it.

6. Reporting AI content

If you report a generated image, we receive the reason you selected, your optional comment, your device identifier and a timestamp. The image itself is never sent with a report.

7. What CurbShot does not do

8. Permissions the app asks for

PermissionWhyIf you decline
Camera Taking listing photos inside the app, with the level guide. The camera screen is unavailable; importing from your library still works.
Photos Choosing photos to work on, and saving results back if you ask. You can still shoot with the in-app camera and share results elsewhere.
Notifications Telling you locally when a listing has finished processing. Everything else works; you simply check the app yourself.

9. How long things are kept

DataRetention
Photos, originals and edits on your deviceUntil you delete the listing or photo, or uninstall the app
Photos sent for AI processingNot stored by us; held temporarily by the AI provider to run the job
Edit job recordsDeleted automatically 7 days after the job finishes
Credit ledger and anonymous identifierKept while the balance exists — it is the record of what you paid for
Crash reports and analyticsFor the period set by Google's Firebase retention settings

Device backups. Your photos, the app's database and the device identifier are deliberately excluded from iCloud and Google backups, so copies of your listing photos do not accumulate in your cloud account. The trade-off is stated in the app's settings: your archive does not survive losing the device, and Export is how you keep copies.

10. Service providers

We use these companies to run the service. They process data on our behalf and may store it in the United States.

ProviderWhat it handles
SupabaseAnonymous identity, credit ledger, edit job records
fal.aiThe AI image processing itself — receives the photo, returns the result
CloudflareRequest routing, abuse limits, content reports
Google (Firebase)Crash reports, product analytics, messaging component
RevenueCatConfirming store purchases
Apple & GoogleApp distribution and payment processing

We may also disclose information if required by law, or to investigate abuse of the service.

11. Your choices and rights

United States residents. Depending on your state, you may have the right to know what personal information we have collected, to request its deletion or correction, and not to be discriminated against for exercising those rights. We do not sell or share personal information, and we do not offer financial incentives in exchange for it. Contact us at the address below to make a request. Because CurbShot has no accounts, we may not be able to verify a request beyond the identifiers your app installation holds.

12. Children

CurbShot is a professional tool for real-estate agents and property hosts. It is not directed to children, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, contact us and we will delete it.

13. Security

Data in transit is encrypted with HTTPS. Requests from the app are cryptographically signed so our processing service can reject calls that did not come from the app. Our AI provider's credentials never exist inside the app. No system is perfectly secure, but the strongest protection here is structural: we do not keep your photos, so there is no photo archive of ours to breach.

14. Changes to this policy

If this policy changes we will update the date at the top, and for changes that meaningfully affect you we will say so in the app. Continuing to use CurbShot after a change means you accept the updated policy.

15. Contact

Questions, deletion requests, or anything in this document that does not match what you see in the app:
curbshot.support@gmail.com