Privacy Policy
Effective date: 2026-05-17 Last updated: 2026-08-29
1. Introduction and Scope
This Privacy Policy explains how Halora ("the App", "we", "us", "our") handles information when you use the Halora iOS application and when you visit our website. The controller within the meaning of Art. 4(7) GDPR is:
Lennox Kornmann
Am Pachtersgrund 14
98617 Meiningen
Germany
Email: halorasupport@gmail.com
We respect your privacy and have designed Halora to collect as little information as possible. The core of the App runs entirely on your device. The only personal data we ever process is what you choose to provide by optionally signing in, and what is needed to validate your one-time Halora Pro purchase.
This Privacy Policy covers two things: (a) your use of the Halora iOS App distributed via the Apple App Store, and (b) your visit to our website at https://halora-app.pages.dev. Sections 2 to 5 concern the App. Section 5a concerns the website and section 5b concerns our advertising. It does not apply to any other third-party service or website that may be linked from the App or the website.
We have not appointed a Data Protection Officer, as we are not required to do so under Art. 37 GDPR or § 38 BDSG.
2. Data We Collect (and Do Not Collect)
Data we do NOT collect
Halora has been built around the principle of data minimisation. We do not:
- Require an account to use the App, Mirror mode and all core features work fully as a guest, with no sign-in
- Collect your phone number or any contact details
- Use analytics SDKs (no Mixpanel, no Amplitude, no Firebase Analytics, no Google Analytics)
- Use attribution or tracking SDKs (no AppsFlyer, no Adjust, no Branch)
- Upload your photos, videos or camera frames to any server
- Display third-party advertising
- Track you across other apps or websites (we do not present an App Tracking Transparency prompt because we do not track you)
- Sell or rent any data about you
Data processed on your device only
The App processes the following information locally on your iPhone, without transmitting it anywhere:
- Camera frames used to render the live ring-light preview and to take photos or record videos. These frames are processed on-device only.
- Photos and videos you create with the App. These are stored in your iOS Photos library if you grant the relevant permission and only when you actively tap the shutter or recording control.
- App settings (such as last-used mode, preferred brightness, preferred colour temperature) stored in iOS UserDefaults locally on your device.
Account data (only if you choose to sign in)
Signing in is completely optional and exists solely to sync your Halora Pro unlock and your settings across your devices. You can use the entire App as a guest without providing any of the data below. If you choose Sign in with Apple or Sign in with Google, we collect:
- Your name and email address as provided by Apple or Google, and a user ID that identifies your account.
This account data is stored on our behalf by Supabase (our authentication and database provider; see section 5), which acts as our data processor and hosts the data in the European Union. You can delete your account and all associated data at any time from Settings → Account → Delete Account.
Data processed by Apple and our purchase processor
When you buy the optional one-time Halora Pro purchase, the following limited information is processed:
- An app user ID used to manage your purchase. For guest users this is a randomly generated, anonymous ID. If you are signed in, this ID is your account user ID, which is associated with the name and email from your sign-in.
- Purchase transaction information from Apple (purchase and refund events) for the purpose of verifying your Halora Pro entitlement.
This information is processed by RevenueCat, Inc. as our data processor (see section 5).
For App Store privacy-label purposes, Halora declares "Purchases" as collected because RevenueCat processes purchase transaction data on our behalf to verify your Halora Pro entitlement. For guest users this is not linked to your real identity; for signed-in users it is associated with your account ID.
Apple itself processes payment information when you make a purchase. Halora never sees or stores your payment details. Please refer to Apple's Privacy Policy for details: https://www.apple.com/legal/privacy/
3. Data We Share
We share data only as strictly necessary to operate the App:
| Recipient | Purpose | Data Shared | Their Policy |
|---|---|---|---|
| Apple Inc. | App distribution and In-App Purchase processing | Managed by Apple under its own policy | https://www.apple.com/legal/privacy/ |
| RevenueCat, Inc. | One-time purchase entitlement validation | App user ID, purchase transaction events | https://www.revenuecat.com/privacy |
| Supabase, Inc. | Optional account sign-in and cross-device sync (EU-hosted) | Name, email, account user ID, only if you sign in | https://supabase.com/privacy |
| Cloudflare, Inc. | Website only, hosting of halora-app.pages.dev | Server log data (IP address, time, page requested, browser) | https://www.cloudflare.com/privacypolicy/ |
| Meta Platforms Ireland Ltd. | Website only, and only with your consent, advertising measurement (section 5b) | IP address, browser/device data, page visited | https://www.facebook.com/privacy/policy/ |
No data from the App is shared with advertisers or data brokers, and we never sell personal information. The two website-only recipients above are listed for completeness: Cloudflare because it hosts the pages you are reading, and Meta only if you have actively consented to advertising measurement on the website (section 5b).
If you have explicitly enabled crash and analytics sharing in iOS Settings (Settings > Privacy & Security > Analytics & Improvements > Share With App Developers), Apple may share aggregated, anonymised crash reports with us. This is a setting you control entirely through iOS; Halora does not contain its own crash-reporting SDK.
4. Permissions We Request
Halora requests the minimum iOS permissions needed to function:
- Camera (NSCameraUsageDescription), required so the App can show the live preview and capture photos or video. Camera access is used only while the App is in the foreground and only for the features you actively use.
- Add to Photos (NSPhotoLibraryAddUsageDescription), required only so the App can save the photos and videos you capture to your Photos library. The App does not read your existing photo library; it only writes new media you have just captured, and only when you tap the save/shutter control.
You may revoke either permission at any time in iOS Settings > Privacy & Security. Revoking camera access will disable the App's core functionality; revoking Photos access will prevent saving captured media.
5. Third-Party Services
Supabase (optional account sign-in)
If you choose to sign in, we use Supabase to authenticate you (Sign in with Apple / Google) and to store your account record so your Halora Pro unlock and settings sync across devices. Under the GDPR, Supabase acts as our data processor (Auftragsverarbeiter). Supabase stores your name, email address and account user ID, and hosts this data in the European Union. See https://supabase.com/privacy. You can delete this data at any time via Settings → Account → Delete Account.
RevenueCat (purchase validation)
We use RevenueCat to validate Apple In-App Purchase receipts and manage your Halora Pro entitlement. Under the GDPR, RevenueCat acts as our data processor (Auftragsverarbeiter) on the basis of a written data processing agreement.
RevenueCat receives only:
- Your app user ID (a random anonymous ID for guests, or your account user ID if you are signed in)
- Purchase transaction events from Apple (such as purchase and refund)
RevenueCat does not receive your name, email address, payment details, photos, or videos.
RevenueCat is based in the United States. See its privacy policy at https://www.revenuecat.com/privacy and its security and compliance information at https://www.revenuecat.com/security.
Apple In-App Purchase
All payments are processed by Apple. Halora never receives or stores your payment card or Apple ID credentials. See https://www.apple.com/legal/privacy/.
5a. Our Website (halora-app.pages.dev)
This section applies only when you visit our website. It does not describe the App.
Hosting and server logs
The website is a set of static pages hosted by Cloudflare, Inc. on Cloudflare Pages. When you open a page, your browser necessarily transmits technical information to Cloudflare's servers, which is processed to deliver the page and to keep the service secure and available:
- your IP address,
- the date and time of the request,
- the page or file requested and the HTTP status returned,
- the referring URL, if your browser sends one,
- your browser type, version and operating system.
We do not run our own web analytics on this data, we do not build visitor profiles from it, and we do not combine it with any App data. Cloudflare processes it as our data processor (Auftragsverarbeiter) under a data processing agreement and under the EU Standard Contractual Clauses. See https://www.cloudflare.com/privacypolicy/. The legal basis is our legitimate interest in operating a secure and functioning website (Art. 6(1)(f) GDPR).
Cookies and local storage
The website sets no cookies at all unless you have given consent for advertising measurement as described in section 5b. If you make a choice in the consent banner, that choice alone is stored in your browser's local storage (key halora-consent-v1) so that we do not ask you again. That entry stays in your browser, is never transmitted to us, and can be removed at any time by clearing your browser's site data.
No contact form, no newsletter
The website has no contact form, no comment function, no newsletter sign-up and no user accounts. If you email us at the address above, we process your message and your email address solely to answer you (Art. 6(1)(b) and (f) GDPR) and delete the correspondence once it is no longer needed and no retention obligation applies.
External links
Links to the App Store lead to Apple's servers. Once you follow such a link, Apple's own privacy policy applies; we receive no information about what you do there. See https://www.apple.com/legal/privacy/.
5b. Advertising and Measurement
We advertise Halora. This section explains exactly what that does and does not mean for your data.
The App itself contains no advertising or tracking technology
Advertising happens outside the App. The Halora App contains no advertising SDK, no attribution SDK and no analytics SDK (see section 2), shows no ads, and does not track you across other apps or websites. This remains true regardless of which advertising channels we use.
Advertising platforms (Meta, Apple)
We may run ads for Halora on platforms including Meta Platforms Ireland Ltd. (Facebook, Instagram) and Apple Search Ads. When we do, the platform itself decides which of its users are shown our ad and reports back only aggregated, statistical results, for example, how many people saw or clicked an ad. We do not receive, and do not ask for, any information that identifies you personally as a viewer of an ad.
The platform's own processing of your data as its user is governed by its own privacy policy and is outside our control: Meta at https://www.facebook.com/privacy/policy/ and Apple at https://www.apple.com/legal/privacy/. Apple Search Ads attribution operates through Apple's privacy-preserving framework and does not identify individual users to us.
Meta pixel on this website, only with your consent
To measure whether our ads actually work, we may use the Meta pixel on this website. If it is active, it is loaded only after you have explicitly agreed in the consent banner. Until you agree, and if you decline, or simply ignore the banner, no Meta script is loaded, no cookie is set and no data is transmitted to Meta.
If you do consent, the pixel transmits to Meta: your IP address, information about your browser and device, the page you are on, and the fact that you clicked through to the App Store. Meta uses this to report campaign performance to us and may link it to your Facebook or Instagram account if you have one. In this respect we and Meta act as joint controllers within the meaning of Art. 26 GDPR for the collection and transmission of the data; the joint-controller arrangement is available at https://www.facebook.com/legal/controller_addendum. Meta's onward processing is carried out by Meta on its own responsibility.
- Legal basis: your consent, Art. 6(1)(a) GDPR and § 25(1) TDDDG.
- Withdrawing consent: you can withdraw at any time with effect for the future, clear this site's data in your browser (which deletes the stored consent entry and makes the banner reappear so you can decline), or email us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Third-country transfer: Meta Platforms Ireland Ltd. is the controller for users in the EU/EEA, but data may be transferred to Meta Platforms, Inc. in the United States. The transfer is based on the EU-U.S. Data Privacy Framework, under which Meta is certified, and additionally on the European Commission's Standard Contractual Clauses. Despite these safeguards, it cannot be entirely excluded that U.S. authorities may access such data.
If no consent banner appears on this website, the pixel is not configured and nothing described in this subsection is taking place.
6. Children's Privacy
Halora is rated 4+ in the App Store. The App is suitable for general audiences and does not contain content directed at children.
We do not knowingly collect personal information from children under the age of 16 (or the applicable age in your jurisdiction). Because Halora can be used fully without an account, most users provide no personal data at all.
In-app purchases require either the user's Apple ID password or a parent's approval through Apple's Family Sharing and Ask to Buy features. Parents are encouraged to use Apple's parental control and Screen Time settings to manage in-app purchases on a child's device.
If you believe that a child has provided personal data to us, please contact halorasupport@gmail.com and we will take reasonable steps to delete it.
7. Your Rights
Under the EU General Data Protection Regulation (GDPR) and similar laws (including the UK GDPR, the Swiss FADP, Brazil's LGPD, and the California Consumer Privacy Act/CPRA), you have the following rights regarding your personal data:
- Right of access, to know what personal data we hold about you
- Right to rectification, to correct inaccurate data
- Right to erasure ("right to be forgotten"), to have your data deleted
- Right to restriction of processing, to limit how we use your data
- Right to data portability, to receive your data in a portable format
- Right to object, to object to certain processing
- Right to withdraw consent at any time, where processing is based on consent
- Right to lodge a complaint with a supervisory authority
If you signed in, you can exercise your right to erasure directly in the App via Settings → Account → Delete Account, which deletes your account and associated data from Supabase. You can also email halorasupport@gmail.com for any request, including resetting or deleting the purchase app user ID held by RevenueCat.
California residents (CCPA/CPRA)
If you are a California resident, you also have the right to:
- Know what personal information is collected about you
- Request deletion of personal information collected about you
- Opt out of the sale or sharing of personal information (we do not sell or share personal information in the meaning of the CCPA)
- Not be discriminated against for exercising your rights
To exercise any of these rights, contact halorasupport@gmail.com. We will respond within the timeframes required by applicable law.
Supervisory authority
EU/EEA residents have the right to lodge a complaint with their local data protection supervisory authority. The competent authority for the operator is:
Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI)
Häßlerstraße 8
99096 Erfurt, Germany
Telephone: +49 361 57 3112900
Email: poststelle@datenschutz.thueringen.de
Web: https://www.tlfdi.de
You may also lodge a complaint with the supervisory authority of your own place of residence or workplace.
8. International Data Transfers
Your optional account data is stored with Supabase in the European Union, so account sign-in does not, by itself, involve a transfer outside the EU/EEA.
RevenueCat, Inc. is established in the United States. When we transmit app user IDs and purchase transaction information to RevenueCat, this constitutes a transfer of data to a third country in the meaning of GDPR Articles 44 et seq. We rely on the following safeguards for this transfer:
- The EU-U.S. Data Privacy Framework (DPF) where applicable, and
- The European Commission's Standard Contractual Clauses (SCCs) as supplemental safeguards
For details, see RevenueCat's processing terms at https://www.revenuecat.com/dpa and its privacy notice at https://www.revenuecat.com/privacy.
Apple processes data globally under its own legal framework; see https://www.apple.com/legal/privacy/.
Website-side transfers
Cloudflare, Inc. (website hosting, section 5a) operates a global network, so server log data may be processed outside the EU/EEA. The transfer is covered by the European Commission's Standard Contractual Clauses in Cloudflare's data processing addendum, and Cloudflare is certified under the EU-U.S. Data Privacy Framework.
Meta (advertising measurement, section 5b), only if you have consented. Meta Platforms Ireland Ltd. is the EU-facing controller, but data may reach Meta Platforms, Inc. in the United States under the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses. If you do not consent, no such transfer takes place.
9. Retention
- On-device data (app settings, captured media in your Photos library) remains on your device until you delete the App or remove the media yourself. We have no access to it.
- Account data (name, email, account user ID) held by Supabase is retained until you delete your account (Settings → Account → Delete Account) or otherwise request deletion.
- App user ID and purchase state held by RevenueCat are retained for as long as needed to administer your Halora Pro entitlement and to comply with applicable tax and accounting obligations (typically up to 10 years under German law for financial records associated with purchases).
- Apple-held transaction records are governed by Apple's own retention policies.
Website data
- Server log data held by Cloudflare is retained only for the short period needed for delivery, security and abuse prevention, in line with Cloudflare's own retention practice, and is not archived by us.
- Your consent choice is stored in your own browser until you clear your site data. We hold no copy of it.
- Meta pixel data (only if you consented) is retained by Meta under its own retention policy; we only ever see aggregated campaign reports.
10. Security
We apply reasonable technical and organisational measures to protect any data we process:
- All network communications use TLS encryption in transit.
- Optional account data is stored by Supabase (EU) behind authentication and row-level access controls; we do not run our own additional servers.
- RevenueCat and Supabase maintain industry-standard security practices; see https://www.revenuecat.com/security and https://supabase.com/security.
- Captured photos and videos never leave your device.
No security measure can be guaranteed to be perfect; however, given how little personal data we process, the practical risk from a Halora-side breach is limited.
11. Legal Bases for Processing (GDPR)
Where the GDPR applies, our legal bases for processing are:
- Performance of a contract (Art. 6(1)(b) GDPR), for validating your Halora Pro purchase via RevenueCat and Apple, and for providing the optional account sign-in and cross-device sync that you request
- Consent (Art. 6(1)(a) GDPR), when you choose to sign in (providing your name and email) and when you grant Camera or Photos permissions
- Legitimate interests (Art. 6(1)(f) GDPR), for basic purchase validation and fraud prevention
- Legal obligation (Art. 6(1)(c) GDPR), for retention of financial records under German tax law
- Legitimate interests (Art. 6(1)(f) GDPR), website: delivering the pages you request and keeping the site secure and available (section 5a)
- Consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG), website: the Meta pixel for advertising measurement, which runs only if you agree in the consent banner (section 5b)
You may withdraw consent at any time with effect for the future: delete your account, revoke the relevant permission in iOS Settings, or, for the website, clear this site's data in your browser so the consent banner reappears and you can decline. Withdrawal does not affect the lawfulness of processing carried out beforehand.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this document indicates when the policy was last revised. Material changes will be communicated within the App or by updating the policy at https://halora-app.pages.dev/privacy.
Continued use of the App or the website after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. Where we rely on your consent, we will ask for it again rather than relying on a policy update.
13. Contact
If you have any questions, requests, or concerns regarding this Privacy Policy or the processing of your personal data, please contact:
Lennox Kornmann
Email: halorasupport@gmail.com
Web: https://halora-app.pages.dev
We will respond to verifiable requests within the timeframes required by applicable law (typically within one month under GDPR).