Retrograde: Vintage Camera

Privacy Policy

Last updated: August 14, 2026

Scope and contact

This policy explains how Dan Toulet, doing business as Bon App Lab, handles information in Retrograde: Vintage Camera and on this site. For privacy questions or requests, contact covertodisco@gmail.com.

Media and device permissions

Retrograde is designed to process photos and videos on your device. Camera, photo library, and microphone permissions are requested only when you choose a feature that needs them. The current app does not request location access. Current Retrograde features do not upload original photos or videos to Retrograde servers. If you use the operating system share sheet, the destination you select receives the content and its own terms and privacy policy apply.

Accounts and sign-in

You can use the core app with an anonymous Retrograde account. Optional Apple or Google sign-in can link that account so Pro access and account data can be restored. Supabase provides authentication and stores the internal account identifier. Apple or Google may provide a provider identifier and, when available, basic profile details such as a name or email address.

Saved edits and cloud sync

When a permanent account uses the saved-edit library, Retrograde syncs edit instructions rather than the original media: the recipe, edit name, media type, timestamps, and one-way fingerprints or hashes used to recognize the source. Original photos and videos remain on the device or in the photo library and are not stored in the saved-edit records.

Purchases and subscription data

Retrograde uses RevenueCat to manage purchase and entitlement events. This can include the internal app user identifier, product and package, store, entitlement status, and renewal or expiration metadata. Apple or Google processes payment details, billing, taxes, refunds, and store transaction records; Retrograde does not receive your payment-card number.

Product analytics and diagnostics

Retrograde uses PostHog with EU-hosted ingestion for privacy-filtered product analytics and technical-error telemetry. The app may send a pseudonymous app user identifier, app and device context, event names, feature-flag assignments, and limited interaction or status properties. The identifier can become associated with a Retrograde account after sign-in. Session replay, surveys, and automatic lifecycle capture are disabled. Retrograde's own analytics events do not include photo or video content, file paths, names, email addresses, tokens, or secrets, and the current release configuration does not use this data for cross-app tracking or advertising.

Service providers and use of data

We use Supabase for authentication, saved-edit metadata, server functions, and deletion operations; RevenueCat for subscription entitlements; PostHog for the analytics described above; and Apple and Google for sign-in and store billing. Netlify hosts these public legal pages and relays signed subscription notifications to our backend. These providers receive only the information needed for their service, and Retrograde does not sell personal data or use it for advertising. We use information to provide and secure the app, restore purchases, support users, measure reliability and product use, prevent abuse, and meet legal or platform requirements.

Retention and account deletion

Local media and exports remain under your device or photo-library controls. Account and saved-edit records are kept while the account is active. When you delete a Retrograde account, Retrograde deletes the Supabase Auth account and associated saved-edit records, requests deletion of the PostHog profile and events, and removes or redacts server-side purchase and paywall event links to that account. Apple or Google store billing and transaction records remain subject to the applicable store's policies and legal obligations. Deleting a Retrograde account does not cancel an active store subscription.

Limited data retained after deletion

Retrograde retains a one-way SHA-256 hash of the deleted internal account identifier to prevent an erased RevenueCat billing identity from being recreated. For promotional Pro access that was not purchased through an app store, Retrograde also retains a one-way SHA-256 hash of the provider-specific Apple or Google identifier and the promotional grant record. This binding contains neither the email address nor the raw provider identifier and is used only to preserve or deduplicate the grant when the same verified identity returns.

The promotional binding is kept while its grant remains valid. You may ask to have it deleted, but doing so permanently disables automatic recovery of that promotional access. If Sign in with Apple is linked, you can separately remove Retrograde from Sign in with Apple in your Apple Account settings.

Your rights

Depending on where you live, you may have rights to request access to, correction of, deletion of, restriction of, objection to, or portability of personal information. Contact covertodisco@gmail.com with your request and, if available, your Retrograde Support ID. Because original media is kept locally, Retrograde generally cannot access or provide a copy of media that never reached its servers.

Security, transfers, and changes

We use reasonable technical and organizational safeguards, but no service can guarantee absolute security. Our service providers may process information in countries other than your own under their applicable safeguards and legal requirements. We may update this policy when the app, providers, or legal requirements change; the date above identifies the current version.

Children

Retrograde is not directed to children under 13, and we do not knowingly collect personal information from children under 13.