Effective date: 2026-05-29 Last updated: 2026-08-03
This is the privacy policy for the SimuLook iOS and macOS app and the simulook.com website, published by OzyCore GmbH (“we”, “us”). It explains what data these services collect, what we do with it, where it lives, and how you can delete it or withdraw an optional website-analytics choice.
If you have any questions, write to info@simulook.com and we’ll get back to you.
TL;DR
- SimuLook’s local library, community browsing, supported-photo reading and C1–C7 reading/backup are free. Premium unlocks verified camera writing and, on supported Macs, hardware-gated RAF development. A SimuLook account is still optional for local use.
- If you sign in, we collect the minimum necessary to make community features work: your email, a user ID, and the content you choose to upload (recipes, photos, comments).
- We do not sell your data, share it with advertisers, or use it to track you across other apps or websites.
- Only with separate per-recipe permission may selected public recipe content appear in SimuLook’s own official social marketing; this is never ad targeting.
- Website analytics is off by default. Google Analytics is loaded only if you actively allow it, and you can withdraw that choice at any time.
- You can permanently delete your account from inside the app at any time. We remove the data from our servers.
1. Data we collect
Most app data is tied to your SimuLook account. StoreKit checks the signed purchase entitlement on the device; Apple handles billing and does not give us your full payment-card details. Two optional features work without an account: the website launch waitlist and a diagnostic report. A diagnostic report can be sent without an account, because someone whose camera will not connect may not have one, and they are exactly who we need to hear from. Nothing is sent unless you press send after reading what it contains.
| What | Why we collect it |
|---|---|
| Email address | To create an account, sign you in, and let you reset your password. Provided by you at sign-up, or by Apple if you sign in with Apple. |
| Display name and username | Shown on your profile and on the recipes / comments you publish. You choose them. |
| Optional profile contact links | A website URL or Instagram handle you add so other members can find or contact you outside SimuLook. |
| User ID | A random UUID generated by Supabase so we know which recipes / comments / likes belong to you. It is NOT an advertising identifier and not shared with third parties. |
| Recipes you publish | The recipe name, description, settings, tags, mood / lighting / scene labels, an optional public place label you type, difficulty, sample photos, and EXIF metadata for those photos (camera model, lens, focal length, aperture, shutter speed, ISO). |
| Optional social-feature permission | If you opt in for a recipe, we store the permission version and time so a moderator may prepare a branded post using the photo, recipe, and public username. A typed place label is used only with a second opt-in. |
| Comments you write | The text body of any comment you leave on a recipe. |
| Private messages | The text, photo, or voice message you explicitly send to another member, together with the sender, conversation, media type, duration, and send time needed to deliver and display it. Message photos and voice recordings are stored in private media storage and are available only to conversation participants. |
| Likes / follows / blocks | The graph of recipes you liked, photographers you follow, and users you block. Likes are visible to you only (we use the totals to compute recipe popularity). Follows are visible on profile pages. Blocks are visible only to you. |
| Content reports you file | If you report a recipe or comment, we keep your reporter ID, the target, the reason, and any details you wrote, so we can review the report. |
| Purchase history, entitlement, and purchase identifier | Apple StoreKit tells the app which SimuLook product is active and, for a subscription, its expiry date. Before a purchase, SimuLook creates a random installation-level UUID and sends it to Apple as the purchase identifier. Apple returns signed server notifications; our server stores the product ID, original transaction ID, entitlement status, purchase/expiry/revocation dates, and that random identifier so the entitlement can be maintained and restored. If you later sign in and claim it, this purchase history is linked to your SimuLook account. The app uses Apple’s signed entitlement on the device to unlock verified camera writing and, on supported Macs, hardware-gated RAF development, including offline use where the feature itself supports it. The identifier contains no name, email, advertising ID, or payment-card details. Apple handles payment details. |
| Push notification token | If you allow notifications, Apple gives the app a device-specific APNs token. We link it to your signed-in account only to deliver community notifications. It is not an advertising identifier and is removed when the account is deleted. |
| Diagnostic reports you send | Only when you press send on the report screen, after seeing its exact contents. It carries the camera model and firmware, which step failed, an error code, your app and OS version, a short log of the steps taken, and — if it happened — Apple’s summary of the app’s last crash. Identifiers are stripped from the log before it leaves the device. No photographs, no recipes, no recipe names. If you are signed in, your user ID is attached so we can reply; if you are not, the report is anonymous. |
| Service-request and search logs | Supabase’s API edge records request metadata for its plan-based retention period, including the request URL (which contains a PostgREST-formatted search filter), IP address, country code, user agent, response status, and latency. We use these logs only for operating, securing, and troubleshooting the service—not for advertising profiles or cross-app tracking. |
| Launch waitlist email | If you enter your email on simulook.com, we store it for the single launch email and Founding 50 annual offer. We delete the launch list within 30 days after that mailing. To remove your address earlier, email info@simulook.com. |
| Optional website analytics | Only after you actively allow analytics on simulook.com, Google Analytics receives a random first-party client identifier, the page path (without its query string or fragment), referrer path, session and interaction events, browser / device / language information, and approximate region. We use this only to understand aggregate website usage and improve the site. See Section 8. |
We do not collect:
- Device GPS or background location. If you choose to type a public place label on a recipe, we store exactly that label as recipe content; we do not infer it from your device or extract GPS from the photo.
- Your contacts
- Advertising or vendor identifiers (IDFA / IDFV). The APNs token described above is used only for notifications.
- Search history from your device or browsing activity outside SimuLook. If you allow website analytics, the limited simulook.com page and interaction data described above is collected; otherwise it is not.
- Automatic third-party crash reporting, analytics events, or performance telemetry in the native app. A crash summary or other diagnostic data reaches us only when you review and send a diagnostic report yourself. Optional website analytics is separate and described in Section 8.
- Anything read from or written to a camera you connect by cable. SimuLook can read recipe settings from a supported Fujifilm camera, and—only when you select a photo on the camera—read the beginning of that JPEG to extract its embedded recipe metadata. This camera data stays on your device. It reaches us only if you separately choose to publish a recipe or upload a photo to the community, exactly like content you entered or selected elsewhere in the app. SimuLook can also write verified recipe fields to a custom camera slot, but only after you choose the recipe and slot and confirm the overwrite. The write is read back from the camera for verification. None of these camera operations sends camera data to us by itself
2. Where the data lives
We use Supabase (Supabase Inc., USA) as our backend. Supabase provides authentication, a PostgreSQL database, and file storage for the photos and voice messages you upload. Your account, recipes, message content and media, photos, and social graph are stored there. Waitlist requests are also stored there.
If you allow website analytics, Google Ireland Limited provides Google Analytics and processes the website measurement data described in Section 8. The Google tag and Analytics cookies are not loaded before consent.
Supabase acts as our data processor — they host the data on our behalf and are contractually prohibited from using it for their own purposes. You can read Supabase’s own policies at supabase.com/privacy.
If you enable the optional social-feature permission, the two generated post images and caption are sent to Postiz, our social-publishing processor, so a moderator can review, schedule, and publish them to SimuLook’s official Instagram account. The Postiz API credential is encrypted at rest and never sent to the browser. Content without that explicit permission is not sent to Postiz. Turning the permission off cancels pending items; already-published Instagram content may require a separate removal request.
All traffic between the SimuLook app and Supabase is encrypted in transit with HTTPS. The app does NOT do its own custom encryption.
Content you report
When you report a recipe, a comment or a message, we keep a copy of the reported text so a moderator can act on it. This is the one case where content from a private conversation is retained beyond the conversation itself, and it exists because the alternative does not work: the person who wrote the reported content can delete it, and without a copy the report would arrive with nothing in it.
What is kept: the reported text, who wrote it, when the report was made, and whether the content was deleted afterwards. Nothing is kept for content nobody reported.
3. How we use the data
For app operation and separately consented optional uses:
- Authenticate you when you sign in
- Show your recipes, comments, and profile to other users
- Let you discover, like, comment on, follow, and block others
- Notify people about community activity through in-app counters and, when they opt in at the system prompt, Apple Push Notification service alerts
- Review content reports so we can act on community-rule violations
- When you explicitly opt in, prepare and publish a moderator-approved feature on SimuLook’s official social accounts
- When you separately allow website analytics, understand aggregate visits and interactions so we can improve simulook.com
We do not:
- Sell your data
- Share your data with advertisers
- Show third-party ads
- Build a behavioral profile of you
- Use your photos to train machine-learning models
- Combine your SimuLook data with data from other apps, services, or data brokers
4. Account deletion
You can permanently delete your account from inside the app:
- iOS: Profile tab → ••• menu → Delete Account → type DELETE to confirm.
- macOS: Settings → Account → Delete Account → type DELETE to confirm.
When you confirm, we immediately:
- Delete your authentication record on Supabase (your email and password / Apple Sign-in token are gone).
- Cascade-delete your profile row, which removes all your published recipes, all photos attached to those recipes (including the files in storage), all comments you wrote, all likes you gave, all follows and blocks you made, and any reports you filed.
- Sign you out on the device and remove your favorites list from local storage.
What stays on your device after deletion: only the recipes you
created locally and never published. Those live in UserDefaults
on your device and have never been sent to our servers; they belong
to you and we don’t want deleting your account to erase work that
only exists locally. To clear them too, delete the SimuLook app
from your device.
Backup snapshots of the database may retain your data for up to 30 days before being overwritten — this is a Supabase platform-level backup we do not control. After that window, the data is unrecoverable.
5. Data we expose to other users
When you publish a recipe or write a comment, other SimuLook users can see:
- Your username
- Your display name (if you set one)
- Your avatar URL (if you set one — currently the avatar is initials-based and not user-uploaded)
- Your camera model (the body you selected in Settings, if any)
- The recipes you published and the photos attached to them
- The comments you wrote
- Your follower and following counts
Your email address is never shown to other users. The list of users you blocked is never shown to anyone but you.
6. Children’s data
SimuLook is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided personal data to SimuLook, write to info@simulook.com and we’ll delete the account.
7. International users
SimuLook is operated from Germany. Account and community data is stored in our production Supabase project in eu-central-1 (Frankfurt, Germany). Supabase and other service providers may process limited technical or support data in other countries when needed to provide the service; where applicable, we rely on contractual and legal safeguards for those transfers.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under GDPR / UK GDPR / nFADP:
- Access: ask us what data we have about you
- Rectification: correct anything inaccurate
- Deletion: see Section 4
- Restriction / objection: ask us to stop processing your data
- Portability: receive your data in a machine-readable format
- Complaint: lodge a complaint with your local data protection authority
To exercise any of these rights, email info@simulook.com.
If you are in California, you have similar rights under the CCPA / CPRA. We don’t sell personal data, so the “Do Not Sell” right is moot for SimuLook — but you can still request access or deletion.
8. Website analytics and cookies
The SimuLook app is a native iOS / macOS app. It does not use cookies. It does not embed third-party trackers, SDKs, or analytics beacons.
The marketing website at simulook.com offers optional Google Analytics 4
(measurement ID G-NYYJEXF2N7), provided by Google Ireland Limited. Analytics
is off by default. Until you select Allow analytics, the site does not load
the Google tag, set Analytics cookies, or send measurement data to Google.
Rejecting analytics does not restrict the site.
If you allow analytics, Google Analytics receives the limited information in Section 1: a random first-party client identifier, the SimuLook page path and referrer path without query strings or fragments, session and interaction events, browser / device / language information, and approximate region. We use it only to measure aggregate website traffic and improve navigation and content. We do not send account IDs, email addresses, waitlist entries, recipe content, or precise location to Analytics. Google Signals, advertising storage, advertising user data, and advertising personalization remain disabled.
The legal basis is your consent under Article 6(1)(a) GDPR and, where
applicable, Section 25(1) TDDDG. You can change or withdraw your choice at any
time with Privacy settings in the website footer. Withdrawal updates consent
to denied, removes accessible Analytics cookies, and reloads the page without
the Google tag. The site stores the choice itself in first-party local storage
(simulook.analyticsConsent.v1); this strictly necessary preference prevents us
from repeatedly asking and is not sent to Google.
When analytics is allowed, Google Analytics may set _ga and a
property-specific _ga_* first-party cookie. SimuLook limits these cookies to
90 days from the first consented visit and does not refresh that expiry on each
page view. Our GA4 property uses the shortest available user- and event-level
retention period, two months; Google notes that this setting does not control
standard aggregated reports.
Google states that for EU, Swiss, and UK traffic it derives coarse geographic information from the IP address and discards the address before the measurement data is logged. Google may process data in countries outside the EEA under its data-processing terms and applicable transfer safeguards. Details are available in Google’s Analytics data and privacy information and privacy policy.
The optional waitlist form is separate from Analytics and sends only the email described in Section 1 after you submit it.
9. Changes to this policy
We may update this policy occasionally. When we do, we’ll update the “Last updated” date at the top and keep the current policy available in the app and on our website. Where applicable law requires additional notice or consent, we will provide it before the change takes effect.
The historical versions are visible in the git history of
docs/PRIVACY_POLICY.md at github.com/imysfylmz/Fujiapp.
10. Contact and who is responsible for your data
The controller for the personal data described in this policy, within the meaning of the General Data Protection Regulation, is:
OzyCore GmbH Kreuzberger Ring 24 65205 Wiesbaden Germany
Email: info@simulook.com
Full provider identification, including the commercial register entry and VAT identification number, is published in our legal notice.