Introduction
BabyLook is operated by Lokman Şahin. It creates fictional baby portraits from two selected parent photos for entertainment, not genetic or medical predictions. This policy explains the information used by the current BabyLook app and its service providers.
Photos, Face Data and Consent
Only the two photos you select are used for a generation request. They may contain facial features. Please select photos only with the permission of the people depicted. BabyLook does not scan your entire photo library.
Before uploading, the app asks for explicit consent. Your selected photos and a text prompt are sent over HTTPS through BabyLook’s server hosted on Oracle Cloud in Frankfurt, Germany, to Snapgen, using the Nano Banana 2 model. Snapgen receives the reference photos and prompt to generate your requested portrait. The app downloads the completed image from the result URL provided by Snapgen.
BabyLook uses these photos to fulfill your portrait request. We do not use them for biometric identification, tracking, advertising or our own model training. We have not verified a provider-wide no-training commitment from Snapgen and cannot promise that all downstream providers exclude training or other secondary processing. Do not submit photos if you do not accept this uncertainty.
You can decline or revoke photo-processing consent in Settings → Privacy & Consent. Revocation prevents future uploads until you consent again; it does not cancel an already submitted request or automatically erase provider-held data.
Identifiers, Subscriptions and Technical Data
- Installation identifier: A random installation ID is stored on your device and sent to the BabyLook backend to limit request frequency. It is also used as your app user ID in RevenueCat to associate purchases and subscription access. It is a pseudonymous identifier; purchase information can be associated with it. The BabyLook backend does not forward this ID in its Snapgen generation request.
- Server subscription and usage verification: For generation requests, BabyLook sends Apple-signed app and subscription transaction proofs to its server. The server verifies the app/account binding and asks Apple for current subscription status. It stores a hashed account identifier, request identifiers, generation reservation timestamps and task responses to enforce the rolling 7-day allowance and prevent duplicate charges. These records remain linked to the app account even though the raw account identifier is not stored. Task identifiers may associate provider-held generation data with the usage record. They are not used for advertising tracking.
- RevenueCat: We use RevenueCat to load subscription offers, process and restore purchases, and determine premium access. RevenueCat processes the installation ID, purchase receipts and transaction/subscription information, and technical information such as device and operating-system details. BabyLook does not send parent photos or generated portraits to RevenueCat.
- Apple: Apple processes App Store payments and purchase records. BabyLook does not receive your payment-card details.
- Network and support data: Service providers necessarily process network information, including IP addresses, to deliver requests. If you email support, we receive your email address and the information you include.
BabyLook does not implement advertising tracking or request precise location data. Subscription and operational data described above are still processed to operate the service.
Retention and Deletion
- BabyLook proxy: The Oracle-hosted proxy handles photo and prompt contents in memory while forwarding a request. Its application code does not write reference photos, prompts or generated portraits to persistent storage. This does not describe Snapgen’s storage.
- Snapgen: Snapgen may retain generation history, reference images, prompts and generated portraits under its own processing policies. We have not verified an exact retention period or an automatic deletion deadline. We do not promise immediate deletion when a result is delivered.
- On your device: Generation history is stored locally. The app attempts to remove records older than 30 days when its history cleanup runs; this is not a guaranteed background deletion deadline. You can clear local history in the app. Images you separately save to Photos or share remain under your control and must be deleted separately.
- Generation usage records: Usage reservations older than 7 days are removed when the server next processes a new generation reservation. This is not a guaranteed background deletion deadline. Failed or interrupted requests may still count if the provider may have accepted the work. Clearing local photos/history or reinstalling the app does not reset server usage records. Apple Sandbox test records are kept separately from live purchase records.
- Subscription records: Apple and RevenueCat retain records needed to provide and restore subscriptions and meet applicable obligations. Clearing local history or revoking photo consent does not delete purchase records or cancel a subscription.
- Deletion requests: Contact lokman782782@gmail.com to request access, correction or deletion, including assistance with provider-held data. Include the approximate generation or purchase date; do not resend face photos. We will identify the relevant records with you and coordinate applicable requests with providers. We cannot promise a provider deletion deadline that has not been confirmed.
Service Providers and International Processing
Oracle Cloud hosts the BabyLook proxy in Frankfurt. Snapgen provides AI generation using Nano Banana 2 and supplies result-download URLs. Processing and storage by Snapgen and its infrastructure may occur outside Germany; a Frankfurt proxy does not guarantee that all processing remains in the EU.
RevenueCat provides subscription infrastructure and processes customer data on infrastructure in the United States. Its end-user processing is governed by its service agreements. See RevenueCat’s privacy information and data processing addendum. Apple handles purchases under Apple’s App Store privacy information.
The current app’s photo generation route uses Oracle Cloud and Snapgen. It does not use the former Cloudflare Workers / CreativeLabs route.
Security and Your Choices
Photo uploads use HTTPS. Provider credentials remain on the backend rather than in the app. No system can guarantee absolute security.
You may choose not to generate portraits, revoke upload consent, clear local history, and request access, correction or deletion by contacting us. Depending on your location, you may also have rights to restrict or object to processing, obtain a copy of your data, or complain to a data-protection authority. Manage or cancel subscriptions through your Apple account’s subscription settings.
Children’s Privacy
BabyLook is not intended for children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has submitted personal information so we can investigate and address the relevant records.
Changes and Contact
We update this page when our data practices change and show the latest update date. Material changes to photo processing are reflected in the app’s consent notice.
For privacy questions or requests, contact Lokman Şahin at lokman782782@gmail.com.