Privacy Policy
This Privacy Policy explains how J&B Creations LLC (“J&B Creations,” “we,” “us”) handles information in connection with the HolyShot mobile app, the website at holyshot.cc, and the web app at app.holyshot.cc (together, the “Service”). We built HolyShot to be respectful and privacy-minded: the photo you provide is used to create your portraits and is not retained afterward.
The short version
- Your selfie is sent securely, used for one generation, and not kept after your portraits are made.
- We use no advertising SDKs and no cross-site tracking, and we do not sell your personal information. We do use first party product analytics (PostHog) to see how the product is used.
- We never see your card details. In-app purchases go through the App Store and Google Play. Prints, and anything bought on the web, go through Stripe.
- An account is just an email address. There is no password, and we ask for one only when you buy on the web or want your credits on another device.
Information we collect
Photos you provide
To create portraits, you provide a selfie (taken with the camera or chosen from your photo library). This image is transmitted to our service solely to generate your portraits. It is not stored after the generation request completes.
HolyShot does not create, derive, or store a faceprint, facial-geometry template, or other biometric identifier from your photo. Your photo is used only as an input image to generate your portraits.
Portraits we generate for you
The portraits HolyShot creates are stored on our infrastructure so we can deliver your gallery and let you view, save, or re-create images. You can save them to your device and delete them from the Service.
Purchase and entitlement information
HolyShot offers one-time purchases (“packs”) through the App Store and Google Play. Those platforms process your payment — we do not receive your payment-card details. We use RevenueCat to manage purchases and confirm which packs you own. This involves an app-generated identifier and your purchase/entitlement status, used to unlock what you bought and to restore purchases.
Photo checks before generating
There are two checks, and they are different.
In the app, on your device. The app uses on-device face detection (Google ML Kit) to check that your photo is well-lit and shows a single front-facing face. This check runs locally on your device and the analysis does not leave it. It is a quality check, and it is not part of the web app.
On our server, for every photo. Whichever way you send us a photo (app, web upload, webcam, or phone camera), it is also checked by Google Gemini before we generate anything, to confirm it contains a face and is appropriate for a general-audience app. This check happens in the same request as generation, and the photo is not retained after it completes.
Device and diagnostic data
To operate and protect the Service, we process limited technical data such as request metadata, error logs, and abuse-prevention signals (for example, to enforce per-purchase generation limits). We use this to run, secure, and improve the Service.
The website
Our marketing pages at holyshot.cc serve static content and do not set advertising or cross-site tracking cookies. Standard server logs may be processed by our hosting provider to deliver and secure the site.
The web app (app.holyshot.cc)
You can use HolyShot entirely on the web, without installing the app. The web app collects the following:
- Your email address. Accounts are email only, with no password. We email you a 6 digit code to sign you in, and we use your address to send receipts and order updates. We store your email, an account identifier, and the dates you created the account and last used it. Nothing else.
- Photos you provide on the web. You can upload a photo, take one with your computer's webcam, or scan a code to take one on your phone. All three are handled exactly like a photo from the app: used only to generate your portraits, and not stored after the generation request completes. As in the app, we do not create or store a faceprint or other biometric identifier.
- Payment information. Credits, videos, and prints bought on the web are processed by Stripe, which handles your card details directly. We do not receive or store them. For prints we also process the delivery address you enter, including a recipient's address if you are sending a gift.
- Product analytics. The web app uses PostHog to understand how the product is used, for example which steps people complete. This is first party. It is not used for advertising, not sold to anyone, and not present on the marketing pages.
Signing in links your web activity and your app activity to the same account, so your credits and portraits work in both places. That is what the account is for.
The camera on the web
If you take a photo with your webcam or phone camera, your browser asks your permission first. The camera preview stays on your device. Only the single photo you choose to use is sent to us, and it is handled exactly like an uploaded photo. We release the camera as soon as you leave that step.
How we use information
- To generate your portraits and deliver your gallery.
- To unlock, manage, and restore your one-time purchases.
- To operate, secure, troubleshoot, and improve the Service and prevent abuse.
- To comply with legal obligations and enforce our Terms.
How your photo is handled
Your selfie is sent over an encrypted connection to our generation service (a Cloudflare Worker). The image is passed to an AI image model (Google Gemini) that produces your portraits. The resulting portraits are stored in our object storage (Cloudflare R2) and served to you through expiring, signed links. Your original selfie is not retained after the request completes.
Your selfie is sent to Google (Gemini API) solely to generate your portraits for that single request. It is processed in memory, is not used to train Google's models, and is not retained by us after the request completes.
Service providers we share with
We share information only with providers that help us run HolyShot, and only as needed to provide the Service:
- Apple App Store / Google Play: process purchases made inside the apps.
- RevenueCat: manages purchase and entitlement status.
- Cloudflare: hosting, the generation Worker, image storage (R2), and the reel render service.
- Google (Gemini): the AI model that generates your portraits, and the safety check on the photo you provide.
- Stripe: processes payments for prints, and for credits and videos bought on the web. Stripe receives your payment details directly. We never see your card number. Stripe also calculates sales tax.
- Gelato: prints and ships your order. To do that they receive the portrait being printed and the delivery name and address you provide, including a recipient's details if you are sending a gift. They receive this only for orders you place.
- fal.ai: the AI service behind "Bring to Life" videos and print upscaling. It receives the portrait being animated or enlarged. It does not receive your email or address.
- Resend: sends transactional email such as your sign in code, receipts, and shipping updates. It receives your email address.
- PostHog: first party product analytics for the web app.
We do not sell your personal information and we do not share it for advertising.
Data retention
- Your selfie: not retained after the portrait is generated.
- Generated portraits: kept so we can provide your gallery, until you delete them or they are removed from the Service.
- Purchase status: retained as needed to honor and restore your purchases.
- Logs: kept for a limited period for security and troubleshooting.
Your choices and rights
You control the photo-library and camera permissions for HolyShot in your device settings. Depending on where you live, you may have rights to access or delete personal information. To make a request, contact us at [email protected] and we'll respond as required by applicable law.
Children
HolyShot is a general-audience app and is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
Security
We use encryption in transit, scoped access controls, and signed, expiring links to protect data. No method of transmission or storage is perfectly secure, but we work to safeguard your information.
International users
We are based in the United States and process information there and with the providers listed above. By using the Service, you understand your information may be processed in the United States and other countries.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we'll revise the effective date above and, where appropriate, provide additional notice.
Contact us
Questions about this policy or your information? Email [email protected].
J&B Creations LLC · Michigan, USA