LightBox — Privacy Policy
Effective Date: March 18, 2026 | Last Updated: April 29, 2026
Thank you for using LightBox (also listed as "LightBox - Selfie & Fill Light" on the App Store, the "App"). We deeply value your privacy and are committed to protecting your personal information to the highest standards. Please read this Privacy Policy carefully to understand how we handle your data.
🔒 Core Promise: This App does not collect your name, email, photos, or any personally identifiable information. Analytics and crash data are collected anonymously to improve app quality and measure advertising effectiveness.
1. Information Collection
This App does not collect any personally identifiable information, including but not limited to:
- Name, email address, phone number, or other identifying information
- Location data
- Photos, videos, or other media content
However, the App uses third-party analytics and attribution services that may collect the following anonymous, non-personal data:
- Device identifiers (IDFA, with your consent via the App Tracking Transparency prompt)
- Anonymous usage analytics (e.g., session duration, feature usage, screen views)
- Crash logs and diagnostic data (device model, OS version, crash stack traces)
- App installation attribution data (which advertisement or source led to the install)
2. Local Data Storage
The App stores the following data locally on your device to remember your usage habits and provide core features:
Preference settings (via iOS UserDefaults):
- Lighting mode selection (Torch / Screen Light / Selfie)
- Brightness level and color temperature offset
- Tone selection and custom color preferences
- Auto-off timer settings
- Toggle states for screen always-on, haptic feedback, and compatibility tips
- Auto-save to system photo library preference
- Onboarding completion status
- In-app language preference
- In-app purchase status (Pro unlock state)
Selfie photos (via app-private Documents directory):
- Photos taken using the Selfie Fill Light feature are saved in an app-private gallery within the app's Documents directory on your device.
- These photos are not uploaded to any server and remain entirely on your device.
- You may optionally choose to save photos to the system photo library. This requires your explicit permission and uses Apple's Photos framework.
- Uninstalling the App will permanently delete all photos stored in the app-private gallery.
All local data is stored entirely on your iPhone and is never sent to any server.
3. Device Permissions
The App may request the following device permissions:
- Camera: Used for two purposes: (1) controlling the brightness of the iPhone's rear LED flashlight in Torch mode; (2) providing a live front-camera preview in Selfie Fill Light mode, allowing you to take photos with screen-powered fill lighting. The camera feed is displayed only on your screen in real-time and is never recorded, streamed, or transmitted to any server. Photos are captured only when you explicitly tap the shutter button, and are saved locally on your device.
- Photo Library (Add Only): When you choose to save selfie photos to the system photo library, the App requests write-only access via Apple's Photos framework. The App does not read or browse your existing photos. This permission is optional and only requested when you explicitly initiate a save action.
- App Tracking Transparency (ATT): On iOS 14.5 and later, the App will ask for your permission to use the Advertising Identifier (IDFA) for advertising attribution and measurement purposes. You may decline this request at any time, and the App will continue to function normally without tracking. You can change this in Settings → Privacy & Security → Tracking.
You can manage these permissions at any time in Settings → LightBox.
4. Network Access
The App uses the following network services:
- Apple StoreKit: Handles in-app purchase transactions. When you purchase or restore LightBox Pro, the StoreKit framework communicates directly with Apple's servers. This is managed entirely by Apple and subject to Apple's Privacy Policy.
- AppsFlyer: Mobile attribution and analytics. AppsFlyer sends anonymous install and in-app event data to its servers for advertising attribution. See Section 6 for details.
- Firebase (Google): Analytics and crash reporting. Firebase sends anonymous usage and crash data to Google servers. See Section 6 for details.
5. In-App Purchases
LightBox offers optional auto-renewable subscriptions ("LightBox Pro") to unlock additional features such as all color tones, all scenes, custom colors, temperature/saturation tuning, auto-off timer, and haptic feedback. Subscription options include Monthly and Yearly plans, both with a free trial period.
- All purchase and subscription transactions are processed by Apple's App Store. LightBox does not process, collect, or store any payment information (credit card numbers, billing addresses, Apple ID, etc.).
- The only data stored locally is a simple boolean flag indicating whether the Pro features are currently active.
- Subscription verification is handled entirely by Apple's StoreKit framework. No purchase data is sent to any third-party server.
- Subscriptions automatically renew unless canceled at least 24 hours before the end of the current period. You can manage and cancel subscriptions in your Apple ID Settings.
- You can restore your subscription at any time from within the App if you reinstall or switch devices.
6. Third-Party Services
This App integrates the following third-party services to improve product quality and measure advertising effectiveness:
AppsFlyer — Mobile Attribution & Analytics
- Purpose: Measures advertising campaign effectiveness by attributing app installs to specific ad sources; tracks anonymous in-app events (e.g., subscription, trial start) for advertising optimization.
- Data collected: IDFA (with your consent), anonymous device information, install referrer data, in-app event names and values.
- Data is processed on AppsFlyer's servers and shared with advertising partners (e.g., Google Ads) solely for attribution and campaign optimization.
- Privacy policy: AppsFlyer Privacy Policy
Firebase Analytics (Google) — Usage Analytics
- Purpose: Collects anonymous usage data to help us understand how users interact with the App, identify popular features, and improve the user experience.
- Data collected: Anonymous session data, screen views, feature usage patterns, device model, OS version.
- Data is processed on Google's servers. No personally identifiable information is collected.
- Privacy policy: Firebase Privacy
Firebase Crashlytics (Google) — Crash Reporting
- Purpose: Automatically collects crash reports and diagnostic data to help us identify and fix bugs, improving app stability.
- Data collected: Crash stack traces, device model, OS version, app version, and anonymous installation identifier.
- Data is processed on Google's servers. No personally identifiable information is collected.
- Privacy policy: Firebase Privacy
7. User Tracking & Advertising
This App uses Apple's App Tracking Transparency (ATT) framework to request your permission before accessing the Advertising Identifier (IDFA). The IDFA is used solely for:
- Attributing app installs to advertising campaigns
- Measuring the effectiveness of advertisements
- Providing aggregated and anonymous advertising performance reports
If you decline the tracking request, the App will still function normally. No personalized advertising is displayed within the App. The IDFA is shared only with AppsFlyer and Google Ads for attribution purposes.
8. Children's Privacy
This App is not directed at children under the age of 13 and does not knowingly collect personal information from children. The anonymous analytics data collected by third-party services does not include any information that could identify a child.
9. Data Security
Your local preference settings and purchase status are protected by the iOS sandbox mechanism and cannot be accessed by other apps. Data transmitted to third-party services (AppsFlyer, Firebase) is encrypted in transit using industry-standard TLS/SSL protocols.
10. Data Retention & Deletion
Local data (preferences, photos) is deleted when you uninstall the App. Anonymous analytics data collected by third-party services is retained according to their respective data retention policies. You can opt out of IDFA tracking at any time via Settings → Privacy & Security → Tracking.
11. Changes to This Policy
If this Privacy Policy is updated, we will revise the content on this page and update the "Last Updated" date. We recommend reviewing this policy periodically.
12. Contact Us
If you have any questions or suggestions regarding this Privacy Policy, please contact us at:
📧 Email: support@boundlessstream.com