Skip to policy
Wigglegram← Back to home

Wigglegram legal

Privacy Policy

Wigglegram keeps captured media and TrueDepth face processing on your iPhone. We do not run ads, track you across apps, or sell personal information.

Effective and last updated: August 4, 2026

On this page

  1. Data Controller
  2. The short version
  3. Data we handle
  4. App and website analytics
  5. TrueDepth and face processing
  6. How and why we use data
  7. Sharing and selling
  8. Retention and deletion
  9. Your rights and choices
  10. International transfers
  11. Children’s privacy
  12. Security
  13. Changes
  14. Contact us

Data Controller

Lagodish Tech is the data controller under the GDPR / UK GDPR and the Polish Personal Data Protection Act of 10 May 2018.

  • Company: Lagodish Tech
  • Country / city: Poland, Warsaw
  • Address: Złota 75A, 00-819 Warszawa (Wola), Poland
  • Privacy email: [email protected]

We have not appointed a Data Protection Officer. Privacy requests go to [email protected].

1. The short version

Lagodish Tech (“we,” “us,” or “our”) operates the Wigglegram iOS app and wigglegram.app (together, the “Services”). This notice explains how we handle personal data that we receive through the app, website, or when you contact us.

  • Your camera frames, photos, edits, exports, and TrueDepth face processing remain on your device unless you explicitly save or share an export.
  • We do not receive your camera feed, captured media, or face-position data.
  • The app does not require an account.
  • We do not use advertising SDKs or cross-app tracking.
  • The app uses Firebase Analytics for limited, non-content usage analytics and Firebase Remote Config to retrieve the free-project quota.
  • Google Analytics 4 loads on the website only if you explicitly allow it.
  • We do not sell personal information.

2. Data we handle

DataWhere it is handledWhat happens to it
Photos, camera frames, edits, and exportsYour iPhoneUsed to capture, edit, render, save, and export your work. We do not receive or retain it.
TrueDepth and face-position informationYour iPhoneA face-tracking state and face-anchor transform are processed temporarily to guide Selfie capture. They are not sent to us, used to identify anyone, or written to persistent storage.
Derived crop coordinatesYour iPhoneA normalized crop center derived from a detected face rectangle may be stored with a local project to align its frames. It is deleted with that project.
App analytics and purchase eventsFirebase Analytics, provided by GoogleIncludes a pseudonymous app-instance identifier, approximate location, device and app information, product interactions, and purchase or subscription events. It never includes captured media, project names or identifiers, face data, filenames, or user-entered text.
App configuration requestFirebase Remote Config, provided by GoogleUses a Firebase installation identifier to return the current free-project quota. It does not receive captured media, project data, or face information.
Emails and support messagesEmail systemsIncludes your email address, message, and any attachment you choose to send so we can reply or provide requested updates.
Basic website request dataWebsite hosting systemsA hosting provider may process an IP address, browser type, requested URL, timestamps, and security logs to deliver and protect the site.
Optional website analytics dataGoogle Analytics 4, only with your consentIncludes pages viewed, interaction events, referrer, approximate location, browser and device details, and cookie-based client and session identifiers.

We do not use advertising cookies or tracking pixels. The app does not set a Firebase user ID or use Apple’s advertising identifier. We do not collect precise location, contacts, payment-card details, or account credentials through the Services.

3. App and website analytics

The iOS app uses Firebase Analytics, provided by Google, to understand non-content product usage and improve reliability. Firebase Analytics assigns a pseudonymous app-instance identifier and receives approximate location derived from an IP address, device and app information, app lifecycle and screen events, permission outcomes, whether Rear or Selfie camera mode was selected, capture and export outcomes, paywall interactions, and StoreKit purchase or subscription events. We do not set a Firebase user ID, use the advertising identifier, or enable Google Signals or advertising personalization.

Firebase Remote Config uses a Firebase installation identifier and authentication token to return the app’s free-project quota. It does not receive captured media, project metadata, or face information. Google describes the data its Firebase services process and their safeguards in its Firebase Privacy and Security documentation.

The website uses local storage to remember your cookie choice. This setting is necessary to respect your choice and is renewed or requested again after 180 days. It does not identify you to us or send information to a third party.

If you select “Allow analytics,” we load Google Analytics 4 (“GA4”), provided by Google. GA4 helps us understand aggregate website use, such as which pages are visited and how visitors navigate the site. Google uses an IP address at collection time to derive approximate location and then discards it before the address is logged in GA4. We disable Google Signals and advertising personalization in our site configuration.

StorageDurationPurpose
Firebase Analytics app event and user-level data2 monthsMeasures non-content app usage and subscription outcomes.
Firebase installation identifierUntil deletion or 270 days of inactivityRetrieves Remote Config values. Firebase begins deleting data associated with a deleted installation identifier from live and backup systems within 180 days.
wigglegram_cookie_consent_v1180 daysRemembers whether you allowed or declined analytics.
_gaUp to 2 yearsDistinguishes visitors after analytics consent.
_ga_<measurement-id>Up to 2 yearsMaintains session state after analytics consent.

Website GA4 does not load and no website analytics data is sent before you consent. You can allow, decline, or later change your website choice through “Cookie settings” in the footer. When you withdraw consent, we deny future website analytics collection, remove accessible GA4 cookies from our domain, and reload the page without the Google tag. Google describes its own processing in its Privacy Policy.

4. TrueDepth and face processing

When you select the Selfie camera on a supported device, Wigglegram uses Apple’s ARKit face-tracking and TrueDepth APIs. The app accesses whether a single face is tracked and the ARFaceAnchor transform representing the face’s position and orientation relative to the camera. This information is used temporarily to measure movement between viewpoints and determine when to capture each of the five frames.

Apple’s Vision framework also detects a face rectangle in each captured image. Wigglegram converts it into normalized crop coordinates used to align the frames. Wigglegram does not access or retain Face ID data, facial identity, facial templates, raw depth maps, face geometry or meshes, blend shapes, or facial-expression data. It does not use face information to identify or authenticate anyone, infer characteristics, train an AI model, advertise, market, or track users.

ARKit tracking states and transforms are not written to persistent storage. They exist transiently in memory while the camera component is active and are discarded when it is reset or released. The five captured images and derived crop coordinates are stored in the app’s local project storage until you delete the project or the app. Copies you explicitly save to Photos or share with another service are controlled by you and the selected destination.

Wigglegram does not transmit TrueDepth data, face positions, face rectangles, crop coordinates, or captured images to Lagodish Tech, Firebase, or any other third party. Firebase may receive non-content usage events such as whether Selfie or Rear camera mode was selected and whether capture succeeded, but it never receives face data or captured media.

5. How and why we use data

We use the limited personal data available to us to:

  • reply to support, privacy, or other messages you send;
  • send launch or product updates that you explicitly request;
  • operate, secure, troubleshoot, and improve the website and Services;
  • prevent abuse and protect our users, rights, and property; and
  • meet legal obligations and resolve disputes.

Where the GDPR or similar law applies, our legal bases are performance of a contract or steps you request before a contract, our legitimate interests in operating, securing, understanding, and improving the Services and answering messages, your consent for optional updates and website GA4 analytics, and compliance with legal obligations. You may withdraw consent where processing relies on it.

6. Sharing and selling

We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use or disclose sensitive personal information to infer characteristics about you.

We may disclose the limited data we receive only:

  • to service providers that host the website, deliver email, or help secure the Services, under appropriate confidentiality and data-protection obligations;
  • to Google for Firebase Analytics and Remote Config in the iOS app and, only after you allow website analytics cookies, for GA4 on the website;
  • to Apple to process subscriptions and entitlement status;
  • when required by law or reasonably necessary to protect safety, rights, and the integrity of the Services; or
  • as part of a merger, acquisition, financing, or sale of assets, with appropriate notice and safeguards where required.

When you choose to save an export to Photos or share it through Apple’s share sheet, the recipient service handles that content under its own privacy terms. We do not control the sharing destination you select.

7. Retention and deletion

  • Raw TrueDepth information: Face-tracking states and transforms exist only in memory while the camera component is active. They are not written to disk and are discarded when the component is reset or released.
  • On-device content: Captured frames and derived crop coordinates stay in local project storage until you delete the project or the app. Deleting a project removes its original frames, metadata, thumbnail, and cached exports. Copies already saved to Photos or shared elsewhere must be managed at their destination.
  • Firebase Analytics: We configure user-level and event-level app data to be retained for 2 months. Aggregated reports that no longer identify an app installation may remain available after that period.
  • Firebase Remote Config: Firebase retains installation identifiers until deletion and may trigger deletion after 270 days of inactivity. After an installation identifier is deleted, Firebase removes associated data from live and backup systems within 180 days.
  • Website analytics: We configure GA4 user-level and event-level data to be retained for 2 months. GA4 cookies may remain for up to 2 years unless you withdraw consent, clear them, or your browser removes them sooner.
  • Support messages: We generally retain them for up to 24 months after the last interaction, then delete or anonymize them unless a longer period is needed for security, legal, tax, or dispute purposes.
  • Requested updates: We retain your contact details until you opt out or ask us to delete them. We may keep a minimal suppression record so we do not contact you again.
  • Technical logs: Hosting and security logs are kept only as long as reasonably necessary for site delivery, security, and legal compliance, according to the relevant provider’s retention schedule.

To delete data held by us, email [email protected]. We may ask for enough information to verify and complete your request, but we will not collect extra data solely because you made a request.

8. Your rights and choices

Depending on where you live, you may have rights to know or access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to withdraw consent. You may also have the right to opt out of sale, targeted-advertising sharing, or certain profiling and to receive equal service when exercising privacy rights. We do not sell personal data, share it for targeted advertising, or conduct qualifying profiling, so no separate opt-out is needed for those activities. You can change website GA4 consent at any time through “Cookie settings” in the footer. Deleting the app stops future app analytics from that installation and removes its local projects and identifiers.

You can unsubscribe from optional updates by replying to the message or emailing us. Because Wigglegram has no account and does not set a developer-defined user ID, we may not be able to associate an email request with pseudonymous Firebase Analytics data. To exercise privacy rights, email [email protected]. We will respond to verified requests within the period required by applicable law and may deny or limit a request only where the law permits.

Users in the EEA, UK, Switzerland, or another place with a data-protection authority may lodge a complaint with their local authority. Because Lagodish Tech is established in Poland, the lead supervisory authority is Urząd Ochrony Danych Osobowych (UODO). Prefer contacting [email protected] first.

9. International transfers

Firebase and Google Analytics, email, and website providers may process limited personal data in countries other than your own. Where required, we rely on recognized safeguards such as adequacy decisions, standard contractual clauses, or another lawful transfer mechanism. For more information about safeguards relevant to your data, email [email protected].

10. Children’s privacy

The Services are not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has sent personal data to us, email [email protected] and we will take appropriate steps to delete it. A parent or guardian should supervise a child’s use of the app and any sharing of photos.

11. Security

Keeping captured media and TrueDepth processing on-device limits the data exposed to us. For the limited information we do receive, we use reasonable administrative and technical safeguards appropriate to its nature. No transmission or storage method is completely secure, so we cannot guarantee absolute security.

12. Changes to this policy

We may update this policy when the Services or legal requirements change. We will post the revised version here, update the date above, and provide additional notice when a change is material and applicable law requires it.

13. Contact us

The data controller is Lagodish Tech, Złota 75A, 00-819 Warszawa (Wola), Poland. For privacy questions, rights requests, deletion, or transfer-safeguard information, email [email protected]. For product support, email [email protected].

Wigglegram

A moving-photo camera by Lagodish Tech.

How it worksGuidesApp StorePrivacyTermsSupport

© 2026 Lagodish Tech