Account identitySign-in, ownership, account recovery, and abuse prevention.Until the account is deleted, except records required for security or legal obligations.
Original, Cam result, and AI remixesRun the faithful enhancement, create four suggested creative variations and any remix you request, deliver the versions, and support deletion.The original and enhanced result are stored privately until you delete the memory or close the account. Remix JPEGs stay in app-private device storage unless you share one. Processor-held copies follow the provider terms linked below.
Custom remix directionApply the visual direction you enter to the private original photo for that memory. Cam does not put custom prompts in product analytics.Kept in the on-device remix queue until that remix, memory, or account is deleted. It passes transiently through Cam and Google Vertex AI to generate the requested image; Cam does not add it to the server generation record.
Generation recordRecover interrupted jobs, show status, prevent duplicate charging, and investigate failures.Kept with the memory until deletion; minimal security records can outlive image bytes.
Photo metadataPreserve the captured original. A file can contain device, time, or location metadata if location tagging is enabled.Follows the original photo. Location is not needed to perform enhancement.
Purchase and credit historyVerify payments, reconcile credits, prevent fraud, and handle disputes.As required for payment, tax, fraud, and dispute obligations.
Notification tokenTell your device when a requested enhancement is ready.Until sign-out, device removal, account deletion, or token expiry.
Product activity eventsMeasure a small allowlist of actions such as capture, verified completion, rejection, sharing, checkout, and deletion. Records can include an opaque session id, timestamp, allowed properties, and a generation reference owned by the same account.Automatically purged after 90 days and deleted earlier when the account closes. Cam does not accept raw location, photo bytes, email addresses, or arbitrary event fields in this channel.
Referral relationshipHold an invite code, the two account ids, qualification status, and reward-ledger references so rewards occur once after a verified photo and abuse can be reviewed.Deleted when either linked Cam account is deleted. A separate pseudonymous welcome-credit marker can remain as described below.
Welcome-credit eligibility markerPrevent the same verified Google identity from repeatedly deleting and recreating accounts to claim introductory credits.A keyed, versioned one-way digest—not the Google id or email—is retained after account deletion for this anti-abuse purpose. Key rotation preserves prior digests so the control remains effective.
Browser preferences and pending actionsRemember an optional private challenge, a pending referral code, and unfinished deletion receipts on this browser.Challenge data remains until you leave it or clear browser storage. Referral data remains until accepted, confirmed invalid, or browser storage is cleared. A deletion receipt remains locally until completion is confirmed or storage is cleared.
Deletion receiptConfirm that account deletion finished even if the final network response was lost.The server record can include an opaque receipt id, status, owner reference while the account exists, and a short operational error. The browser auto-retries a pending receipt for 30 days. A completed pseudonymous tombstone can remain for up to 365 days so a late client can confirm deletion; expired rows remain eligible for database cleanup. No photo bytes are stored in the receipt.