Privacy Policy

Last updated: 2026-09-25

This policy explains what Trendshot does with your information. It covers the Trendshot mobile app and this website, both published by Better Life With Apps.

The short version

1. Your account

Trendshot has no email-and-password signup. We do not collect a name or an email address in order to let you use the app. An account is created anonymously from a hash derived from your installation of the app.

Against that account we store:

2. The photos you upload

To make a trend you provide the selfie you take or pick and, only for the Hug my younger self trend, a photo of yourself as a child. You take the photo with the camera or pick it from your photo library; the app reads only the photo you pick.

The photo you pick is uploaded to our server. There it is private: it is never listed publicly, and only your account can open it, through a link that expires after a few minutes. When the photo arrives, our server re-encodes it, which removes the metadata your camera stored in the file, such as the time, the place and the device.

With each trend we store the trend you picked and the choices you made for it.

Faces in your photo

A photo of a face is personal data, and a face becomes biometric data when it is used to recognise a particular person. Trendshot does not do that. We do not run face recognition, face matching or any other analysis that identifies a person, and we do not create a face template or any other biometric identifier. Nothing in the app scores or ranks anyone's appearance.

The app is meant for a photo of your own face. Anyone else in the frame is part of the photo we store and send to OpenAI, so the simplest protection is to take the selfie on your own.

3. How a trend is made

Your photos and the trend you picked go from our server to OpenAI, which makes your picture on our instructions. For each trend we send OpenAI:

The photo check. Before the picture is made, a small OpenAI model looks at your selfie and answers two questions only: how many faces are clearly visible, and whether the main person clearly appears to be under 18. If there is no face, the app asks for another photo. If the person appears to be a child, the selfie is refused, because the selfie must always be of you as an adult. The check does not identify anyone and its answer is not kept as a profile of you. A refused or failed trend costs no credits.

Your permission. Because your photos go on to OpenAI, the app asks your permission before your first trend and names OpenAI when it asks. Nothing goes to OpenAI and nothing is made until you allow it. You can withdraw that permission at any time under Settings → Privacy → AI processing; from then on the app starts no new trend until you allow it again.

What OpenAI does with it. OpenAI's data controls state that data sent through its API is not used to train OpenAI's models unless the business sending it opts in, which we have not done. They also state that the image endpoints keep no application state, and that abuse-monitoring logs, which can contain what we send and what comes back, are kept for up to 30 days unless the law requires longer or a longer period is reasonably necessary to protect OpenAI's services or others from harm (OpenAI: your data). We send the photo check with storage switched off. We have not chosen a processing region with OpenAI, so it may process this data outside the EU. We do not use your photos, or the pictures made from them, to train AI models ourselves.

You get back the trend images the app makes from your selfie and the before-and-after videos made from them. They are made by an AI image model that redraws the whole picture, so a result is a generated image of you, not a photograph, and your likeness and small details can shift between tries. A trend can also fail or be refused. None of these automated steps has legal or similarly significant effects on you.

4. Your results, share videos and history

The pictures a trend makes are stored on our server with that trend, so that your history in the app can show them and you can download, save or share them again. If you upgrade after a free result, the app fetches the clean picture without the Made with Trendshot mark from the same stored trend.

When you share a result as a video, our server makes a 9:16 before-and-after clip from your own selfie and the result, with the trend's name and, on a free result, the Made with Trendshot mark. The clip is made entirely on our server and is not sent to OpenAI or anyone else. The clip is stored with the trend it came from and is deleted with it. When you share a picture or a clip, it goes through your device's share sheet to the apps and people you choose; what happens to it there is up to them.

Your photos, the pictures and the clips of a trend are deleted 30 days after the trend was started (section 10). You can delete a result sooner from your history: it is removed from the app at once, and the files we still hold for it are deleted from our storage.

5. Reporting a result

You can report a result from the app if it is wrong, offensive or should not have been made. The report is recorded against that trend with the reason you chose and any note you write, and we review it. A report does not send us a copy of your photo; we look at the stored trend while it still exists.

6. Purchases

Trendshot sells a subscription, weekly or yearly, and one-time credit packs, through the Apple App Store and Google Play. The store takes the payment under its own terms; we never see your card details or your store account.

RevenueCat checks purchases for us. The app identifies you to RevenueCat with the random billing ID from your account, never with your name, and RevenueCat tells our server when a purchase, renewal, cancellation or refund happens. We store the billing identifier, the state of your subscription, your credit balance and the history of credits added and spent.

If you ask Apple or Google Play for a refund, the store may ask us about the purchase before it decides. If we answer, RevenueCat answers on our behalf with information about the purchase and your use of the app, such as how long you have used the app, how much of the purchase you have used, and your purchase and refund history with us, and may add our view on the request. It sends no photos or pictures. The store makes the decision (Terms of Use, section 7).

While analytics is on, the app also gives RevenueCat its Firebase Analytics instance ID, so that purchases can be matched to app usage in our own reports. When analytics is off, that link is cleared.

7. Diagnostics and analytics

To find crashes, fix problems, deliver notifications and understand how the app is used, we use:

Your analytics choice is stored only on your device.

In-app feedback (Wiredash)

The feedback form in the app is provided by Wiredash. Each time the app starts, at most once every 30 minutes, it checks in with Wiredash, whether or not you ever send feedback. The check-in carries a random identifier that Wiredash's code creates on your device, the app's version and build, its bundle ID, whether it is a production or development build, your device's language setting, and your operating system and its version. None of this includes your user ID or your photos. Wiredash's documentation says it works out your country from the connection's IP address and does not store the address (Wiredash: analytics privacy). We rely on our legitimate interest in operating the feedback form (GDPR Art. 6(1)(f)).

When you choose Send feedback, the app sends Wiredash your message, your email address if you enter one, and a screenshot if you add one. A screenshot shows whatever is on the screen at that moment, which can include your selfie or a result. With your feedback go device and app details and details we add so that we can follow up: your user ID, the app's name, your subscription status and, when the app has loaded it, your credit balance. We do this at your request and in our legitimate interest in improving the app (GDPR Art. 6(1)(b) and (f)).

8. Where your data is stored

Our backend runs on a server we rent from Hetzner in Helsinki, Finland, inside the EU. The PostgreSQL database, the queue and the private object storage that holds your photos, results and share videos all run on that server.

Feedback you send from the app, and the feedback form's check-ins, are kept by Wiredash, not on our servers. Wiredash GmbH is based in Germany, but its privacy policy says that data may be transferred to the United States, processed there and stored on Google Cloud servers (Wiredash: privacy policy).

9. Who your data reaches

Besides the infrastructure above, your data reaches only the service providers we need to run Trendshot:

ProviderWhat it is used for
OpenAIMaking your trend picture from your photos, and the photo check on your selfie
HetznerHosting our servers, database, queue and object storage in Finland (EU)
Apple App Store, Google PlaySelling and billing the subscription and credit packs
RevenueCatVerifying purchases and subscription state and reporting them to our servers
Google FirebaseAnalytics (in the EEA and the UK only if you switch it on), crash reporting, push notifications through Firebase Cloud Messaging, remote configuration, and App Check device attestation
WiredashThe in-app feedback form: its check-ins and the feedback you send (Wiredash GmbH, based in Germany; according to its privacy policy, data is stored on Google Cloud and may be transferred to the United States)
SentryError reports from our servers

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

10. How long we keep things

11. Deleting your account

You can delete your account at any time in the app, under Settings → Your data → Delete my data. If you can no longer open the app, write to privacy@blwapps.com; the deletion page explains what to include. Deleting revokes your access immediately and queues a deletion request. After a short safety delay, the stored photos, results, share videos, trend inputs, push tokens, consent records and billing identity attached to your account are removed. What remains is a non-identifying tombstone record, the audit evidence that the deletion happened, records of your trends and files without the inputs or the files themselves, your reports, your purchase and credit records, and database backups for about two weeks. A documented legal hold can pause a deletion.

Deleting your account does not cancel a subscription; cancel it in your App Store or Google Play settings.

12. Your rights

Under the GDPR and the Turkish personal data protection law (KVKK), you can ask us to give you access to your personal data, correct it, erase it, restrict how we process it, hand it over in a portable form, or stop processing it altogether. You can withdraw consent at any time without affecting processing that happened before, and you can complain to the data protection authority where you live or work. Under US state privacy laws, including California's, you can ask to know, delete or correct the personal information we hold; we do not sell or share personal information.

To exercise any of these, write to privacy@blwapps.com. Because we do not ask for your name or email address when you use the app, please read the deletion page first — it explains what we need in order to find your record.

13. Children

Trendshot is not directed at children. You must be 18 or over to use it, and the selfie must be of you. A selfie in which the person appears to be under 18 is refused by the photo check (section 3). The only photo of a child the app accepts is a photo of you as a child, in the Hug my younger self trend; it is used only to make that picture and is deleted like any other photo (section 10). The app's store age rating describes the content of the app and is separate from this requirement. If you believe a child has used the app, write to us and we will delete the account.

14. AI-generated content

Every picture and video Trendshot makes is AI-generated, and the app says so where it shows a result. Free results and their share videos also carry a visible Made with Trendshot mark. A clean picture you save after upgrading carries no visible mark, so say that it is AI-generated where you post it when the platform or the law asks you to.

15. This website

This website is a set of static pages. It sets no cookies, runs no analytics or tracking scripts, and loads nothing from other websites. It is served from the same server in Helsinki as our backend.

When someone shares the app from its settings, the link they send opens this website's /get page and carries a ref tag naming where the link came from. The page sends you on to the App Store, Google Play or this website's home page and passes the tag along. When /get is opened, our server records only the time, the website, the page address with its tag, and whether the page loaded: no IP address, no cookies, no device identifiers. We use these records to count how many visits share links bring. The App Store and Google Play may count installs that came through the tag in the statistics they give us.

A shared trend link, /open/trend/…, opens the app directly when it is installed. Otherwise it shows a page that reads the trend's name from the link inside your browser, offers to open the app, and links to /get with the tag trend_ followed by the trend's name. Visits to that page are not recorded.

16. Changes to this policy

When the app changes in a way that affects this policy, we update this page and change the date at the top.

17. Contact

Privacy questions and requests: privacy@blwapps.com
Everything else: support@blwapps.com