Privacy Policy
Last updated: August 13, 2026
Photo Eraser — Object & BG AI ("the App") is published by Bulpara Inc ("we", "us", "our"). This policy describes how we collect, use, and protect information when you use the App.
1. Photos & Image Files
- By default, your photos never leave your device. Background removal runs on-device using Apple's Vision framework. Standard object erasing runs on-device using a Core ML model (LaMa) that is downloaded once on first use and cached locally. These tools never upload your photos — they work in airplane mode.
- The one exception is HD Erase, an optional Premium feature described in Section 2. It is off unless you turn it on, and we ask for your explicit permission the first time you use it.
- Original and edited photos live in the App's sandbox on your iPhone and are removed when you delete the App or the corresponding history entry.
- If you choose to save a result to Photos or share via the iOS share sheet (Messages, Mail, AirDrop, Files, etc.), you control where it goes — we do not see it.
2. HD Erase (Optional, Premium)
HD Erase is an opt-in Premium feature that removes objects using a cloud AI model when the on-device model isn't good enough. It is the only part of the App that sends your photos anywhere.
- It only runs when you choose it. Standard quality is the default. Selecting HD quality requires an active Premium subscription, and the first time you use it we show a consent prompt explaining that the photo will be uploaded. If you decline, nothing is sent.
- What is sent: the single photo you are editing and the mask you brushed over it. Nothing else — no name, email, account, contacts, location, or device advertising identifiers. We do not require an account to use the App.
- Where it goes: our processing server (operated by us on Railway), object storage at Cloudflare R2, and the AI model provider Replicate, which runs the Bria "Eraser" model. See Section 5.
- What it is used for: producing your edited image, and nothing else. Your photos are not used to train AI models, are not sold, and are not used for advertising or profiling.
- How long it is kept: uploaded photos and generated results are automatically deleted from our storage within 48 hours by an enforced retention rule. We do not keep long-term copies.
- Result delivery: the finished image is downloaded back to your iPhone and stored locally like any other edit.
3. Data We Store Locally
- Edit history: Before/after image data, tool used, dimensions, and timestamps for each edit. Stored locally via SwiftData.
- Preferences: Default brush size, preferred export preset, JPEG quality, and theme.
- Daily usage counter: A local counter that resets at midnight to enforce the free-tier daily limit. No counter data is transmitted off-device.
- Purchase status: Subscription state is managed by Apple's StoreKit and cached locally for feature gating.
4. Permissions We Request
- Photo Library: Only when you choose a photo to edit. We access only the photo you select via the iOS PhotosPicker — we do not enumerate your library.
- Photo Library (add-only): When you tap "Save to Photos", we request permission to add the result to your library. We never read other photos through this permission.
5. Third-Party Services
The App uses the following third-party services:
- Apple App Store / StoreKit: Manages subscriptions and purchases. Governed by Apple's privacy policy.
- Google AdMob (free tier only): Displays banner and interstitial ads to free-tier users. AdMob collects device-level data to serve and measure ads — see "What AdMob Collects" below. Premium subscribers see no ads and trigger no AdMob requests.
- Google User Messaging Platform (free tier only): Presents the GDPR / consent prompt that controls what AdMob may collect for users in covered regions.
- LaMa Core ML model (Object Eraser only): Downloaded once from our CDN on first use of the Object Eraser tool. Only the model file is transferred — never your photos. After download, the tool runs entirely on-device, including in airplane mode.
- Replicate (HD Erase only): Runs the Bria "Eraser" AI model on the photo and mask you submit, and returns the edited image. Used only when you choose HD quality. Governed by Replicate's privacy policy.
- Cloudflare R2 (HD Erase only): Temporary storage for the photo being processed and the result, automatically deleted within 48 hours. Governed by Cloudflare's privacy policy.
- Railway (HD Erase only): Hosts the server that coordinates HD Erase requests. Governed by Railway's privacy policy.
The three services above are used only when you run an HD Erase. If you never use HD Erase, the App never contacts them.
6. What AdMob Collects (Free Tier)
When you use the App on the free tier, Google's AdMob SDK may collect the following:
- Device Identifiers — including the Identifier for Advertisers (IDFA), but only if you grant App Tracking Transparency permission. If you decline the tracking prompt, AdMob receives a zeroed IDFA.
- Coarse Location derived from your IP address, used for ad relevance and frequency capping.
- Advertising Data — which ads were shown, viewed, or clicked, and ad-placement context.
- Product Interaction — basic SDK telemetry such as ad load success/failure.
- Crash & Performance Data — diagnostic data from the AdMob SDK itself.
Your photos, edit history, and the contents of any image you process are never shared with AdMob. HD Erase is a Premium feature and Premium subscribers see no ads, so images sent for HD Erase are never involved in advertising in any way. See Google's Privacy Policy and AdMob's published data-collection details.
7. Data Storage and Security
- Your photos, edits, history, and preferences are stored locally on your device.
- Except for HD Erase, no image data is transmitted to or stored on our servers.
- For HD Erase, the photo and mask are sent over an encrypted (HTTPS) connection, held only as long as needed to process the edit, and automatically deleted within 48 hours. We do not maintain a long-term archive of user photos.
- Purchase verification uses Apple's secure StoreKit framework.
- The Object Eraser model is fetched once from a Content Delivery Network and cached locally; subsequent Standard edits work offline.
8. Data Sharing
We do not sell your personal data. We do not share your photos with any third party except as required to perform an HD Erase you requested — see Sections 2 and 5. AdMob may collect device-level data for advertising on the free tier as described in Section 6; the contents of your photos are never included.
9. Your Rights
You can:
- Delete individual edits from the History tab inside the App
- Delete the App to remove all local photos, history, and preferences
- Decline or stop using HD Erase at any time by choosing Standard quality — no photo is uploaded unless you run an HD Erase
- Decline or revoke App Tracking Transparency permission in iOS Settings → Privacy & Security → Tracking
- Upgrade to Premium to remove ads entirely — this disables AdMob requests at the SDK level
- Request information about data handling by contacting us at privacy@bulpara.com
10. Children's Privacy
The App is rated 4+. We do not knowingly collect personal data from children under 13. AdMob is configured for non-personalized ads when a child user is detected at the system level, in line with COPPA and Apple's guidelines for kids-category apps.
11. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated "Last updated" date.
12. Contact Us
If you have questions about this privacy policy, contact us at: