Lapser — Privacy Policy
Effective Date: September 2, 2026
1. Introduction
Downgate Labs LLC ("we," "us," or "our") operates the Lapser mobile application (the "App"). Lapser is a daily photo timelapse tool that helps you capture consistent photos over time and compile them into timelapse videos and side-by-side comparisons.
This Privacy Policy explains what information the App collects, how it is used, who it is shared with, and what choices you have. Please read it carefully. By using the App, you consent to the practices described here. If you do not agree with this policy, please do not use the App.
The short version: your photos stay on your device. We never receive them, and we operate no server that could store them. What we do collect is usage and diagnostic data about how the App is used, described in §2.2 — including, if you choose to turn on Google Drive backup, the email address of the Google account you sign in with.
2. Information We Collect
2.1 Information You Provide Directly
- Photographs. Photos you capture with the App's camera or import from your device's photo library. These are stored locally on your device and are used to build timelapse projects, generate comparison images, and render timelapse videos. They are never uploaded to Downgate Labs.
- Project data. Project names, subject types, aspect ratios, photo dates, alignment and overlay settings, notes, timeline milestone events, and any custom data fields you create (for example weight or body measurements). This is stored locally alongside your photos.
- Purchase information. Your premium status and feature entitlements, whether obtained by subscription or by one-time lifetime purchase. Payment processing is handled entirely by Google Play, the Apple App Store, and RevenueCat. We never collect, see, or store your payment card details.
- Your Google account name and email address, if you enable Google Drive backup. Enabling backup on Android requires signing in with Google. When you do, we receive the display name and email address of that account. Both are passed to RevenueCat as subscriber attributes so a purchase can be matched to an account for support and restore purposes, and the email address is also attached to our analytics records — please read §2.2. Your Google profile picture is displayed in the App's settings screen but is not stored or transmitted by us. If you never enable cloud backup — and most people do not — we never receive any of this.
- Support correspondence. If you email us, or submit feedback from within the App, we receive whatever you choose to include, including the email address you write from or provide.
2.2 Information Collected Automatically
- Product analytics (Mixpanel). Device type and model, operating system version, app version, session start and duration, screen views, and feature-usage events — for example that a video was exported, at what resolution, or that an alignment attempt failed. These events describe how the App is used, never the content of your photos. How these records are identified. Each installation is given a randomly generated identifier by RevenueCat, and analytics events are recorded against that identifier rather than against your name. It is not derived from your device's hardware IDs and it is not your advertising ID, which we do not collect at all. It is, however, persistent for as long as the App stays installed, so activity over time can be linked to the same installation. Under the GDPR this is personal data, and we treat it as such. If you enable Google Drive backup, your Google email address is added to these records. From that point on, the email address of the account you signed in with is attached as a property to the analytics events the App sends, which means those records are directly identifiable to you rather than only to an installation. A small number of events also carry an email address explicitly: the event recording a successful Google sign-in, and the events recording feedback or a support request you submit from within the App, which carry the contact address so we can reply. We use these to reconnect a support conversation with the relevant account and to diagnose backup problems. If you do not enable cloud backup, no email address is ever attached.
- Uninstall and lifecycle reporting (Firebase Analytics — Android only). The Android build enables Firebase Analytics for a narrow purpose: capturing Google's automatic
app_removeevent so we can measure how many people uninstall the App. Enabling it also causes Firebase's other automatic events (first_open,session_start,screen_view) to be collected. The same installation identifier described above is attached, so an uninstall can be matched to the corresponding analytics record in our reporting. Firebase Analytics is not enabled in the iOS build, and advertising-ID collection is explicitly disabled in it. - Install attribution (Google Play Install Referrer — Android only). On first launch, the Android build reads the referrer string Google Play associates with your install, including any UTM campaign parameters. This tells us which advertisement or link an install came from. There is no equivalent on iOS and none is collected there.
- Diagnostic data. Error logs, failure reasons, and performance metrics used to find and fix bugs.
- Advertising identifiers. We do not collect your device's advertising ID.
2.3 Information We Do Not Collect
- We do not collect precise geolocation data.
- We do not collect health records, medical records, or any information from health platforms such as Apple Health or Google Fit. Weight and measurement values you choose to enter are stored only on your device and are never transmitted to us.
- We do not create, collect, store, or transmit biometric identifiers. See §3.
- We do not access your contacts, call logs, or messages.
- We do not collect your device's advertising identifier.
- We do not collect your phone number, date of birth, gender, or any demographic information.
- We do not require an account, an email address, a phone number, or a username in order to use the App. You can install Lapser and use every core feature without ever identifying yourself. This is a statement about what is required, not a claim that we never receive your identity — if you choose to turn on Google Drive backup, we receive that account's name and email address, as described in §2.1 and §2.2.
3. On-Device Photo Analysis
Lapser's automatic alignment works by analysing your photos. All of that analysis happens on your device. Photos are never uploaded anywhere for processing — not to us, and not to any third-party analysis service.
Depending on the project type you choose, the App may run:
- Face detection, to find facial landmarks such as eye positions, so that consecutive portraits can be aligned to each other.
- Pose detection, to find body keypoints such as shoulders and hips, so that full-body photos can be aligned.
- Object detection, to locate a tracked object within the frame.
- Scene registration, which matches visual detail in the stable parts of the background (a pot, a wall, a horizon) between two photos.
These run through Google ML Kit's on-device models and a copy of the OpenCV computer-vision library bundled inside the App. No network connection is required for any of them.
About face and pose detection specifically: the App detects the geometry of a face or body — where the eyes are in the frame — solely to compute how far to shift, rotate, and scale a photo. It does not perform facial recognition, does not identify or verify who anyone is, and does not create a faceprint, template, or any other biometric identifier. The detected coordinates are used to calculate an alignment transform and are not retained as a profile of you or transmitted off the device.
Alignment is non-destructive. The transform is saved as metadata and applied when a video is rendered; your original photo file is not overwritten.
4. How We Use Your Information
We use the information described above to:
- Provide the App's core functionality: photo capture and import, project management, automatic and manual alignment, comparison image generation, and video export.
- Process purchases and keep your premium entitlements in sync across reinstalls and devices.
- Where you have signed into Google Drive backup, connect your backup and support history to your account so we can diagnose backup failures and reply to you about them (§2.2).
- Deliver the reminder notifications you schedule.
- Understand which features are used and which fail, so we can fix bugs and decide what to build next.
- Measure the effectiveness of our advertising and app-store listings (Android install attribution, §2.2).
- Respond to support requests you send us.
We do not use your information for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.
5. Cloud Backup
All of your photos and project data are stored locally on your device by default. Cloud backup is entirely optional, is off unless you turn it on, and is a premium feature.
When you enable it:
- On Android, backup goes to your own Google Drive. You sign in with Google Sign-In, and the App requests only the Drive access it needs to write and read your backup files. Your project data and photos are uploaded to your personal Google Drive storage. We have no access to your Google Drive.
- On iOS, backup goes to your own iCloud Drive, using your device's existing iCloud account. We have no access to your iCloud Drive.
In both cases your backed-up files live in your own cloud storage account, under your control, governed by that provider's privacy policy (see §6). Nothing is copied to Downgate Labs infrastructure at any point — we operate no photo storage.
You can disable backup or delete your backed-up files at any time, either from within the App or directly through Google Drive or iCloud.
Because Android backs up to Google Drive and iOS backs up to iCloud, a backup made on one platform cannot be restored on the other.
6. Third-Party Services
The App uses the following third-party services. Each may collect information as described in its own privacy policy.
| Service | Purpose | Platform | Privacy Policy |
|---|---|---|---|
| Google Play Services | App distribution, licensing, billing | Android | https://policies.google.com/privacy |
| Apple App Store | App distribution, licensing, billing | iOS | https://www.apple.com/legal/privacy/ |
| Google Drive (via Google Sign-In) | Optional cloud backup, to your own account | Android | https://policies.google.com/privacy |
| iCloud Drive | Optional cloud backup, to your own account | iOS | https://www.apple.com/legal/privacy/ |
| Mixpanel | Product analytics and usage insights | Android, iOS | https://mixpanel.com/legal/privacy-policy/ |
| Firebase Analytics | Uninstall (app_remove) and lifecycle reporting | Android only | https://firebase.google.com/support/privacy |
| Google Play Install Referrer | Install attribution (UTM parameters) | Android only | https://policies.google.com/privacy |
| RevenueCat | Purchase and subscription management; receives your name and email address if you enable Google Drive backup (§2.1) | Android, iOS | https://www.revenuecat.com/privacy/ |
Google ML Kit's detection models and the OpenCV library are bundled into the App and run entirely on your device. They are not network services and they transmit nothing.
7. Data Storage and Security
- Photos and project data are stored in storage private to the App on your device, indexed by a local database. We do not transmit your photos to our servers at any time, because we operate no such servers.
- Cloud backups, if you enable them, are stored in your personal Google Drive or iCloud Drive account. They are accessible to you through that account and are not stored on, or reachable from, our infrastructure. Their security is provided by Google's or Apple's protections for your account — including whatever two-factor authentication you have enabled. Lapser does not apply an additional layer of encryption of its own, and you should not assume one.
- Analytics data sent to Mixpanel and Firebase Analytics is transmitted over encrypted connections (TLS) and stored under those providers' security practices.
- Purchase records are held by RevenueCat and the respective app store. We store no payment credentials.
All network communication between the App and the services in §6 uses encrypted connections (TLS). No method of electronic storage or transmission is completely secure, however, and we cannot guarantee absolute security. Because your photos live on your device, keeping your device secure — a screen lock, up-to-date software, and device encryption — is the most important protection for them, and that part is in your hands.
8. Data Retention
- Your photos and project data remain on your device for exactly as long as you keep them. We retain no copies, so there is nothing on our side to expire.
- Cloud backups, if enabled, remain in your personal cloud storage account until you delete them, either from the App or through Google Drive or iCloud directly.
- Analytics data collected through Mixpanel and Firebase Analytics is retained according to those providers' retention policies and our configuration within them. This includes any email address attached to those records under §2.2.
- Support correspondence may be retained for up to 24 months so we can follow up and improve the App.
9. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We have not done so in the preceding 12 months, and we do not share personal information for cross-context behavioral advertising.
We disclose information only in these circumstances:
- To the third-party service providers listed in §6, for the purposes stated there and subject to their own privacy policies.
- To comply with legal obligations, such as a subpoena, court order, or other lawful governmental request.
- To protect rights and safety, where we reasonably believe disclosure is necessary to protect our rights, your safety, or the safety of others, or to investigate fraud.
- In connection with a business transfer, if we are involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction. We will notify users through an in-app notice or an update to this policy.
Note that in none of these cases could we disclose your photos: we do not have them.
10. Your Rights and Choices
All users
- Delete your content. Delete any individual photo or an entire project from within the App at any time.
- Control cloud backup. Disable it, or delete backed-up files, from the App or from Google Drive or iCloud directly.
- Manage permissions. Grant or revoke camera, photo library, and notification permissions through your device's system settings at any time (§13).
- Opt out of analytics. Email us at downgatelabsllc@gmail.com (§16) and we will exclude your data from analytics collection. On Android you can also limit Firebase collection through your device's Google settings.
- Manage your subscription. Cancel or change it in your Google Play or App Store account settings. A lifetime purchase is not a subscription and does not renew.
- Uninstall. Uninstalling the App removes all local data from your device and ends all collection.
What deletion means here. Because of how Lapser is built, a deletion request to us covers a narrower set of things than it would for most apps, and it is worth being precise about which is which:
- Your photos and projects are on your device, and in your own cloud account if you enabled backup. We hold no copy, so there is nothing for us to delete — and equally, nothing we could delete on your behalf. You remove them yourself, in the App or through Google Drive or iCloud.
- Analytics records identified by your installation identifier, and any email address attached to them under §2.2, we can delete on request.
- Support correspondence we can delete on request.
- Purchase records are held by Google, Apple, and RevenueCat, and we may be required to retain transaction records for tax and accounting purposes even after a deletion request.
California residents (CCPA/CPRA)
If you are a California resident you have the right to: know what personal information we collect and how it is used; request deletion of your personal information; request correction of inaccurate personal information; opt out of the sale or sharing of personal information (we do not sell or share personal information); limit the use of sensitive personal information (we do not collect sensitive personal information as defined by the CPRA); and not be discriminated against for exercising any of these rights. To exercise them, contact us using the details in §16.
European Economic Area, UK, and Switzerland (GDPR / UK GDPR)
If you are located in the EEA, the UK, or Switzerland you have the right to access your personal data, to have inaccurate data corrected, to have your data erased, to restrict or object to processing, to data portability, and to lodge a complaint with your local supervisory authority.
Our legal bases for processing are: performance of a contract for the functionality you request and for purchase management; legitimate interests for analytics, diagnostics, and attribution used to maintain and improve the App; and consent where required, which you may withdraw at any time. Data processed by the providers in §6 may be transferred to and stored in the United States under those providers' transfer mechanisms.
To exercise any of these rights, contact us using the details in §16.
11. Children's Privacy
The App is not directed at, and is not intended for use by, anyone under 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child without verifiable parental consent, we will delete it promptly. If you believe a child has provided us with personal information, please contact us using the details in §16.
Note that a parent photographing their own child within a project is storing those photos on their own device; those photos are not transmitted to us.
12. Advertising
The App displays no advertisements. It contains no advertising SDK, we share no data with advertising networks or ad exchanges, and we do not collect your device's advertising identifier. This is true on both the free and premium tiers.
The Android install attribution described in §2.2 measures the effectiveness of our own advertising; it does not deliver advertising to you inside the App.
13. Permissions
The App may request the following device permissions. Each is used only for the stated purpose, and you can manage all of them in your device's system settings.
| Permission | Why the App asks | Optional? |
|---|---|---|
| Camera | To capture photos for your projects. Photos are stored locally and are not transmitted to us. | Required to use the in-app camera; you can import photos instead. |
| Photo library (read) | To import existing photos into a project. | Optional — only needed if you import. |
| Photo library / gallery (write) | To save an exported timelapse video or comparison image to your camera roll. | Optional — only needed when you save an export. |
| Notifications | To deliver the photo reminders you schedule, and occasional important notices about your projects or subscription. | Optional; the App works without them. |
| Internet / network access | For analytics, purchase validation, and optional cloud backup. | Required by the platform; core capture, alignment, and export work offline. |
| Run at startup (Android) | To re-register your scheduled reminders after the device restarts, so they are not silently lost. | Tied to notifications. |
| Microphone (iOS) | Declared because the App bundles a camera component capable of video capture. Lapser does not record audio. | Never requested in normal use. |
14. Third-Party Terms
Purchases made through the Apple App Store are additionally governed by Apple's standard End User License Agreement: https://www.apple.com/legal/internet-services/itunes/dev/stdeula/
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the Effective Date at the top of this page and, where practicable, notify you through an in-app notice. Your continued use of the App after a change takes effect constitutes acceptance of the updated policy. We encourage you to review this page periodically.
16. Contact Us
For any question, concern, or request about this Privacy Policy or our data practices — including analytics opt-out and any rights described in §10 — contact us at:
Downgate Labs LLC 2222 W Grand River Ave, Ste A Okemos, MI 48864-1604 United States
Email: downgatelabsllc@gmail.com
We respond to all legitimate requests within 30 days.
© 2026 Downgate Labs LLC. All rights reserved.
Last updated: September 2, 2026