Privacy Policy
8FEED is operated by XTLab ("8FEED," "we," "us"). This policy applies to the 8FEED mobile apps, backend API, public friend-selection pages, subscriptions, AI curation, and related support.
Photo organization, quality analysis, similarity matching, and the GPS metadata index run on your device.
Reduced copies leave the device only when you start AI curation or create a friend-selection link. Friend-sharing copies are not sent to OpenAI.
The core service uses pseudonymous installation and store transaction identifiers—not a named user profile—to manage subscriptions, usage limits, and security.
1. Information we handle
| Information | How it is used | Where it is handled |
|---|---|---|
| Photos, videos, and media metadata Selected library items, capture date, media type, dimensions, quality features, Live Photo frames, and embedded GPS metadata. | Date/place search, local indexing, quality and histogram analysis, similar-photo grouping, comparison, selection, recovery, and album export. | Normally on your device. Original media files, album names, and the GPS index are not uploaded by 8FEED; optional AI and friend-selection features send only the size-limited JPEG copies described below. |
| Optional AI curation content Reduced candidate thumbnails, pseudonymous candidate references, local quality tags, desired count, mood, channel, purpose, caption direction, keywords, and exclusions. | Generate photo selections, reasons, captions, and hashtags when you press the AI recommendation button. | Sent through the 8FEED backend to OpenAI. Thumbnails may visibly contain people, places, documents, or other content present in your media. |
| Optional friend-selection sharing On-device, size-limited JPEG copies of the photos you choose to share; pseudonymous photo references; selection mode and desired count; request and result identifiers; an invited friend's browser-generated random respondent identifier; their selections; apply/decline status; and timestamps. Standard network and security logs may also process IP address, user agent, and error details. | Create a link for an invited friend, run the two-photo tournament or removal review in a browser, prevent accidental duplicate responses, return the result to the requesting app, and let the requester apply or decline it. | JPEG copies are uploaded directly to private Cloudflare R2 object storage and displayed through time-limited signed URLs. Request and response metadata is stored in the 8FEED backend. The respondent identifier is stored as a one-way hash on the backend. Original media files, album names, and the private GPS index are not uploaded for this feature, and friend-sharing copies are not sent to OpenAI. |
| App and installation data Random installation identifier generated by the app, pseudonymous backend user identifier, authentication token, IP address supplied by Cloudflare when the installation registers, language, platform, app/build version, device model, launch count, and timestamps. | Operate the API, secure the installation, prevent abuse, apply remote configuration, diagnose service problems, and enforce usage limits. | On your device and the 8FEED backend. The installation identifier is stored as a one-way hash, and the registration IP address is stored with the corresponding authentication-token record on the backend. |
| Landing and installation attribution First-party random landing visit identifier, UTM source/medium/campaign/id/content/term, Meta click identifier (`fbclid`), landing and referring URLs, locale, store platform and button placement, Cloudflare-supplied IP address, user agent, and timestamps. On Android, Google Play Install Referrer also provides the visit identifier and click/install timestamps. | Measure which campaigns lead from the 8FEED landing page to a store visit and app registration, remove obvious bot traffic, and diagnose acquisition flows. | 8FEED landing page and backend; Google Play supplies the Android install referrer. Android matches are confirmed using the visit identifier. Because iOS does not return that identifier to the app, 8FEED records a probable match only when one unclaimed iOS store visit shares the registration IP within the configured time window. Ambiguous iOS visits are not matched. |
| Subscription and purchase data Store, product and plan identifiers, transaction or purchase-token data, purchase/expiry status, and quota usage. | Verify purchases, provide paid features, prevent fraud, manage renewals, and calculate remaining AI usage. | Apple App Store or Google Play and the 8FEED backend. We do not receive your full card or bank details. |
| Optional product analytics, AI, ad, and service activity If you allow usage analytics: app-instance identifier, first open, screen and feature interactions, subscription funnel events, aggregate item counts and durations, stable error codes, membership plan, app language, and release channel. AI and ad operations also process candidate/request counts, model and token usage, latency, AI results, and aggregated ad eligibility, requests, impressions, and clicks. Analytics events do not include photos, album names, precise coordinates, prompts, captions, purchase tokens, or transaction identifiers. | With your separate analytics permission, understand product funnels, improve reliability, and measure advertising conversions in a privacy-preserving way. Also return AI results, prevent duplicate charges, enforce quotas, measure costs, operate ads, secure the service, and troubleshoot failures. | 8FEED and the providers listed below. Google Analytics for Firebase receives analytics events only after you opt in. |
| Support communications Your email address and anything you voluntarily include in a message. | Answer requests, including access or deletion requests. | Our support email provider and authorized support personnel. |
Identity clarification: 8FEED does not require your name, phone number, postal address, contacts, or social account to operate the core service, and it does not create a named user profile. Operational controls rely on a random installation identifier generated by the app and transaction or purchase identifiers provided by the Apple App Store or Google Play. 8FEED does not directly link these values to your name or contact details. They are used only to authenticate installations, verify subscription status, apply usage limits, prevent abuse, and troubleshoot the service—not to determine your real-world identity or build a separate behavioral profile.
Location clarification: 8FEED reads location already embedded in photos to power place search. It does not need your live device location for that feature. The private location index stays on the device and is not included in AI requests.
Friend-link clarification: an invited friend does not need an 8FEED account. The request URL is a bearer link: anyone who receives it can view its reduced photo copies and respond while it is valid. Share it only with intended recipients. A recipient may still save, screenshot, or forward content they can see; 8FEED cannot control copies made outside the service.
2. Analytics, ads, maps, and stores
- Google Mobile Ads and User Messaging Platform (iOS and Android): depending on your consent and region, Google may process IP-derived approximate location, ad/device identifiers, app interactions, and diagnostics for ad delivery, measurement, and fraud prevention. Ad privacy choices are available in 8FEED Settings where required. See Google Advertising and the Google Privacy Policy.
- Google Analytics for Firebase (iOS and Android, optional): analytics collection is disabled by default and begins only after you choose “Allow” for optional usage analytics. It may process an app-instance identifier, first open, app sessions and interactions, IP-derived approximate location, device/app information, aggregate counts and durations, stable error codes, and subscription funnel events. If the Analytics property is linked to Google Ads, consented first opens and in-app events may also be used for aggregate advertising measurement and campaign optimization. You can turn this off at any time in 8FEED Settings; doing so stops collection and resets the SDK's local analytics data. This choice is separate from advertising consent and iOS App Tracking Transparency. The iOS app links FirebaseAnalyticsCore, which does not collect IDFA. When ATT is denied, 8FEED does not initialize Google Mobile Ads or access IDFA; eligible advertising attribution instead relies on Apple's SKAdNetwork and Google's privacy-preserving on-device or modeled measurement. Analytics data is not enabled for personalized advertising. See Firebase Privacy and Security.
- Maps: iOS uses Apple MapKit and Android uses Google Maps Platform. Map providers may receive map viewport, interaction, device, and network information under their own privacy terms. 8FEED does not send the private photo-location index to the map provider.
- Subscriptions: Apple and Google process payment information and provide transaction status to 8FEED. Their respective privacy policies apply to store payments.
3. AI and friend-selection processing
AI curation. AI requests are sent only after you initiate curation. The 8FEED private queue temporarily holds the reduced thumbnails and request snapshot while the job is queued or processing, then clears that request content after success or failure. We retain AI results and limited usage metadata as needed for result delivery, idempotency, quotas, security, billing, and troubleshooting.
8FEED sends OpenAI Responses API requests with provider storage disabled. Under OpenAI's published API data controls, API content is not used to train models by default unless the customer opts in, while abuse-monitoring data may be retained for up to 30 days or longer when legally required.
Friend-selection sharing. This feature begins only when the requester chooses photos and asks 8FEED to create a link. The app creates size-limited JPEG copies on the device and uploads them directly to private Cloudflare R2 storage. 8FEED returns short-lived signed image URLs to the public request page, stores the invited friend's selection as pseudonymous request data, and makes the result available to the authenticated requester. When the iOS requester previews a result, the app may replace the server copy with the original already present in the requester's own photo library; that local preview does not upload the original.
The public invitation and new friend responses expire after the configured request period, which is currently three days by default. Expiration blocks further public request access and submissions; it does not necessarily cause immediate physical deletion of related backend records, security logs, backups, or R2 objects. Reduced JPEG copies, response records, and the requester's apply/decline decision are retained only as needed to deliver and reconcile the result, secure and troubleshoot the service, handle disputes, satisfy legal obligations, or complete a verified deletion request. Friend-sharing copies are not used for AI curation or model training.
4. Sharing and sale
At the requester's direction, the friend-selection feature displays reduced JPEG copies and request context to anyone who has the invitation link. The invited friend is an independent recipient chosen by the requester, not an 8FEED processor. The requester is responsible for choosing the photos and intended recipients.
Otherwise, we share data only with processors needed to provide the service: OpenAI for optional AI curation; Cloudflare for private R2 object storage and related infrastructure; Google for ads, consent, optional iOS and Android analytics, and Android maps; Apple and Google for purchases; and hosting, database, security, and support providers. We do not sell your photos, prompts, location index, or personal information for money. Advertising-related processing by Google may be treated as "sharing" or targeted advertising under some laws; applicable consent and device controls are provided.
We may also disclose information when required by law, to protect users or the service, or as part of a business transfer with appropriate safeguards. We expect service providers to protect information consistently with this policy and applicable law.
5. Retention and deletion
- On-device data: sessions, local analysis caches, preferences, AI results, and the location index remain until you delete relevant sessions/data or uninstall the app. Uninstalling does not delete your original photo library items.
- Backend data: installation, entitlement, AI-result, quota, advertising counter, and operational records are retained while needed to provide the service and thereafter only for legitimate security, fraud, accounting, dispute, and legal obligations. Purchase records may be retained for the legally required period.
- Acquisition data: landing/store IP addresses, user agents, landing/referring URLs, and the raw `fbclid` are removed after 30 days by default. Normalized UTM fields, visit/click times, platform, and confirmed or probable installation links may be retained as operational and aggregate acquisition records. The raw-data period may be changed for legitimate operational or legal needs.
- AI queue content: reduced thumbnails and the queued request snapshot are cleared from our private job queue after the job succeeds or fails.
- Friend-selection content: public invitation access and submissions currently expire after three days by default. Expiration is an access control, not a promise of immediate storage deletion. Reduced JPEG copies and selection records follow the purpose-based retention and deletion process described in Section 3.
- Third parties: Cloudflare, Google, Apple, and OpenAI retain data under their own policies, contracts, and configured controls.
6. Your choices and rights
- Limit or revoke photo-library access in iOS or Android system settings. Core photo features may stop working.
- Do not start AI curation if you do not want thumbnails or written directions sent to our AI processor.
- Do not create a friend-selection link if you do not want reduced copies stored in our private cloud storage or viewed by anyone who receives the link. Share only photos you are authorized to share.
- Turn optional usage analytics on or off at any time in 8FEED Settings. This choice is separate from iOS App Tracking Transparency.
- Manage ad consent from 8FEED Settings where the privacy option is available, and manage advertising identifiers in device settings.
- Delete individual saved sessions in the app; uninstall the app to remove its remaining local data.
- Request access, correction, restriction, objection, or deletion of backend data by emailing [email protected] with the subject 8FEED Privacy Request. We may request limited information to verify the installation and will respond as required by applicable law.
7. Security and international processing
We use transport encryption, pseudonymous identifiers, hashed server-side link and respondent credentials, private object storage, time-limited signed image URLs, access controls, and data minimization. No system is perfectly secure. Providers may process data in South Korea, the United States, or other countries where they operate, subject to applicable transfer safeguards.
8. Children
8FEED is not directed to children under 13, or under 14 in South Korea, and we do not knowingly create profiles for them. A parent or guardian who believes a child has provided data should contact us for deletion.
9. Changes and contact
We may update this policy when features, providers, or laws change. We will update the effective date and provide additional notice when required.
Privacy contact: [email protected]
Address: 602 Yeongdong-daero, Gangnam-gu, Seoul 06083, Republic of Korea