Legal
Privacy policy
Effective 2026-06-20
This policy explains what Rizzlit collects, how we use it, who we share it with, and the choices you have. Rizzlit is operated by Alconbury Tech ("Alconbury Tech", "we", "us").
What we collect
Account identifier. When you first open Rizzlit we create an anonymous Firebase Auth user id for you. If you choose Sign in with Apple, the linked Apple user id and the email you chose to share are stored too.
Subscription state. RevenueCat records your subscription receipts and entitlement so we know whether to show the watermark.
The photo you upload. To produce a composite, the photo you choose is uploaded to a short lived path on our server. It is deleted as soon as the composite returns. A scheduled sweep deletes anything older than five minutes as a safety net. We do not use your photo to train any model.
The composite we produce for you. We store the composite on our server so you can save or share it. You can delete every composite by deleting your account from Settings.
Usage events. We record how many composites you have produced for free tier accounting. We do not record what you did with them.
Diagnostics. Firebase Analytics and Firebase Crashlytics record anonymous crash and performance information so we can fix bugs. These do not identify you.
Notifications token. If you turn notifications on, we store a Firebase Cloud Messaging device token so we can send you the two notification types described below.
We do not collect or use your location. We do not collect or use your contacts. We do not collect your microphone or your health data.
How we use it
To produce composites you request, including the brief moment your uploaded photo is processed.
To keep track of your free tier allowance and your subscription state.
To send the two notification types: a new trending backdrop drop, and a result is ready message. We do not send marketing pushes.
To fix bugs and improve the app.
To respond when you contact support.
Who we share it with
Google Firebase. Our backend runs on Google Cloud via Firebase, in the europe-west2 region. Firebase processes your account id, subscription state, anonymous diagnostics, and the temporary upload.
Apple. Sign in with Apple if you use it. App Store handles your subscription payment.
RevenueCat. Subscription receipts and entitlement state.
fal.ai. The image model provider that produces the composite. Your uploaded photo and the chosen backdrop are sent to fal.ai for the duration of producing the result. We use two fal.ai models. FLUX Pro 1.1 Ultra generates the backdrop plate before any user is involved, with no user data. BiRefNet handles only the segmentation of your photo (it removes the background and isolates you, it does not alter your face). The composite is then assembled on our server using your real face pixels placed onto the backdrop. fal.ai is contracted to process the request and not to retain your photo. We do not send your account id to fal.ai.
Resend. We use Resend to email Israel when new candidate backdrops await review. No user data is shared with Resend.
Notion. The review database that contains candidate backdrops. No user data is stored in Notion.
We do not sell your data. We do not share your data with advertisers. We do not use your data for ad targeting.
Tracking
Rizzlit does not track you across other apps or websites. We do not show the App Tracking Transparency prompt because we do not track.
Children
Rizzlit is not directed at children. We do not knowingly collect data from anyone under 13. If you believe a child has used Rizzlit, contact us and we will delete the account.
How long we keep your data
Your uploaded photo: deleted as soon as the composite returns, and in any case within five minutes by the scheduled sweep.
Composites: stored until you delete your account or until you delete them from the app.
Account data: stored until you delete your account.
Diagnostics: rolling 90 day window.
Your choices
In app:
- Settings, Account, Delete account removes your account, every composite, any pending upload, and your authentication record.
- Settings, Notifications opens iOS Settings if you change your mind about permission.
- Restore purchases is in Settings, Subscription.
You can ask us a question or make a request at support@rizzlit.app. Under UK and EU law you have rights to access, correct, delete, and port your data, and to object to processing.
Security
Data in transit is over HTTPS. Server side access uses Google IAM. API keys for third party services live in Firebase Functions secrets, not in the app binary. We log enough to debug the service but never log or retain user face photos.
International transfers
We are based in the United Kingdom. Firebase europe-west2 hosts your data in the EU. Some third party providers may process data outside the UK and EU under standard contractual clauses.
Changes
We may update this policy. Material changes will be notified inside the app or by email.
Contact
Alconbury Tech. Email support@rizzlit.app. Postal address available on request.