Privacy, in plain language

Your photo is a memory, not an ad profile.

Cam uses the minimum information needed to capture, process, deliver, charge for, and delete your photos. It does not make them public by default or sell them.

Private by default

Originals and results live in private storage. Delivery requires an authenticated account with ownership of that memory.

Processing has a purpose

Your photo is sent to the providers listed below only to complete the action you requested and keep it recoverable.

Deletion is a product action

You can delete a memory from Cam or close the account. If any cloud object cannot be removed, Cam keeps the deletion request retryable instead of reporting false success.

Data map

What Cam handles and why

InformationPurposeRetention and control
Account identitySign-in, ownership, account recovery, and abuse prevention.Until the account is deleted, except records required for security or legal obligations.
Original, Cam result, and AI remixesRun the faithful enhancement, create four suggested creative variations and any remix you request, deliver the versions, and support deletion.The original and enhanced result are stored privately until you delete the memory or close the account. Remix JPEGs stay in app-private device storage unless you share one. Processor-held copies follow the provider terms linked below.
Custom remix directionApply the visual direction you enter to the private original photo for that memory. Cam does not put custom prompts in product analytics.Kept in the on-device remix queue until that remix, memory, or account is deleted. It passes transiently through Cam and Google Vertex AI to generate the requested image; Cam does not add it to the server generation record.
Generation recordRecover interrupted jobs, show status, prevent duplicate charging, and investigate failures.Kept with the memory until deletion; minimal security records can outlive image bytes.
Photo metadataPreserve the captured original. A file can contain device, time, or location metadata if location tagging is enabled.Follows the original photo. Location is not needed to perform enhancement.
Purchase and credit historyVerify payments, reconcile credits, prevent fraud, and handle disputes.As required for payment, tax, fraud, and dispute obligations.
Notification tokenTell your device when a requested enhancement is ready.Until sign-out, device removal, account deletion, or token expiry.
Product activity eventsMeasure a small allowlist of actions such as capture, verified completion, rejection, sharing, checkout, and deletion. Records can include an opaque session id, timestamp, allowed properties, and a generation reference owned by the same account.Automatically purged after 90 days and deleted earlier when the account closes. Cam does not accept raw location, photo bytes, email addresses, or arbitrary event fields in this channel.
Referral relationshipHold an invite code, the two account ids, qualification status, and reward-ledger references so rewards occur once after a verified photo and abuse can be reviewed.Deleted when either linked Cam account is deleted. A separate pseudonymous welcome-credit marker can remain as described below.
Welcome-credit eligibility markerPrevent the same verified Google identity from repeatedly deleting and recreating accounts to claim introductory credits.A keyed, versioned one-way digest—not the Google id or email—is retained after account deletion for this anti-abuse purpose. Key rotation preserves prior digests so the control remains effective.
Browser preferences and pending actionsRemember an optional private challenge, a pending referral code, and unfinished deletion receipts on this browser.Challenge data remains until you leave it or clear browser storage. Referral data remains until accepted, confirmed invalid, or browser storage is cleared. A deletion receipt remains locally until completion is confirmed or storage is cleared.
Deletion receiptConfirm that account deletion finished even if the final network response was lost.The server record can include an opaque receipt id, status, owner reference while the account exists, and a short operational error. The browser auto-retries a pending receipt for 30 days. A completed pseudonymous tombstone can remain for up to 365 days so a late client can confirm deletion; expired rows remain eligible for database cleanup. No photo bytes are stored in the receipt.

Service providers

Who helps Cam work

Providers receive only the information needed for their role and operate under their own security and retention terms.

Model use

Cam does not turn your private library into its training set.

Cam does not use private account photos to train a Cam model or sell them for training. A requested photo is sent through Google Vertex AI and, for analysis, fidelity review, or a gated restoration fallback, the OpenAI API. Optional remix drafts use Google Vertex AI. Google Cloud and OpenAI each apply their own controls and retention under the linked provider terms. OpenAI’s current API data-control statement says API data is not used for model training by default. Public product samples are handled separately.

Your control

Delete a memory—or the entire account.

Deleting an individual memory attempts to remove its managed cloud files, record, and app-private remixes. Closing an account removes managed cloud photo objects and its app-private remix queue before account access ends. If a step fails, Cam keeps the request retryable; an opaque receipt can confirm completion even after account access ends. Payment providers can retain records under their own legal obligations without giving Cam your full card details.
Start account deletion

Questions or requests

Talk to a person.

If an in-product deletion fails or you need a copy of your account data, email the project owner from the address attached to your Cam account.
ombhojane05@gmail.comLast updated 16 August 2026