Privacy Policy
Effective Date: July 28, 2026
1. Introduction
Welcome to WeThere ("we", "our", "us"). We are committed to protecting your privacy. This Privacy Policy explains how your personal data is collected, used, and shared when you use the WeThere mobile application ("the App").
2. Information We Collect
Photos and visible face data: We collect the one or two photos that you deliberately select from your camera or photo library and submit for a generation. Those photos may contain your face and visible facial characteristics, including face shape, eyes, nose, mouth, skin texture, approximate age, hair, and other visual details. Before the first generation, the App presents a separate notice identifying Replicate, LLC and the data to be shared, then requires you to tick an agreement box and choose "Agree & Create Image." We collect this image data only after that explicit agreement.
What we do not collect: WeThere does not create, collect, retain, or use biometric identifiers, faceprints, face geometry templates, face embeddings, or other identifiers used to identify or authenticate you. We do not use uploaded photos or visible face data for advertising, tracking, identity verification, profiling, or AI-model training.
Generated images: The selfie result we create for you may also contain visible face data. We store that result in your private account so that you can view, save, and share it from the App.
Account information: The App creates an anonymous Firebase account by default. If you choose to link Apple or Google, we store only the identifiers needed to manage your account, credits, and generation history. We do not access your contacts, email content, or other account data.
Purchase information: Apple processes credit-pack payments. RevenueCat receives an app user ID and purchase transaction information so we can grant and restore credits. We store the transaction ID, purchased product, and credits granted. We do not receive payment-card details.
Diagnostics and usage data: Firebase Analytics and Crashlytics may collect app diagnostics, screen views, and general feature-use information to maintain and improve the App. We do not send uploaded photos, generated images, or visible face data to these services for analytics.
3. How We Use and Share Information
We use your photos and visible face data solely to create the AI travel selfie you request. Before the first generation, the App tells you that the selected photos (which may contain face data), selected destination, and image-generation instruction will be shared with Replicate, LLC. You must explicitly agree before any upload or AI request starts. We share only the minimum data needed to operate that request with the service providers below. We do not sell or rent personal data, and we do not authorize these providers to use your photos or visible face data for advertising or marketing.
Firebase (Google): Firebase provides authentication, Firestore, Cloud Storage, Cloud Functions, Analytics, and Crashlytics. We store submitted photos in your private Firebase Storage folder so our Cloud Function can process the generation and the App can maintain your generation history. Submitted photos remain there while your account exists, as described in Section 4. Generated images and account data are also stored in private Firebase resources. Firebase processes this data as a service provider in accordance with Google's privacy policy.
Replicate, LLC: Replicate provides the AI inference service. After you give consent and tap Generate, our Cloud Function sends Replicate a time-limited signed URL to each submitted photo and the generation instruction. The signed URL permits read access only and expires after 15 minutes. Replicate uses the photo to produce the requested image and returns the result to WeThere. We use Replicate's google/nano-banana model, which is labelled "Zero training" by Replicate; we do not submit your photos as training data or create fine-tuned models from them. Replicate acts as a processor/service provider for customer personal information; see Replicate's privacy policy.
RevenueCat: RevenueCat manages in-app purchase entitlement events. It receives your anonymous app user ID and purchase transaction data, but does not receive submitted photos, generated images, or visible face data. See RevenueCat's privacy policy.
We use providers that are necessary to deliver the App and require them, through their applicable service terms and data-protection commitments, to apply privacy and security protections no less protective than those described in this Policy when they process data on our behalf. Providers may process only the data needed to provide their service to us. Their handling of data is also governed by their linked privacy terms.
4. Retention and Deletion
Submitted photos and visible face data: We retain submitted photos in your private Firebase Storage folder while your account exists so we can provide the App and generation history. We do not retain a separate copy of face data or any extracted biometric data.
Replicate processing: Replicate has temporary access to submitted photos through signed URLs that expire after 15 minutes. According to Replicate's API data-retention documentation, input parameters, output values, output files, and logs for API predictions are automatically removed after one hour by default.
Generated results: We retain generated selfies in your private Firebase Storage folder until you delete your account. This lets you revisit, save, and share your generation history in the App.
Account and purchase records: We retain your account record, credit balance, purchase records, and generated-result references while your account exists, so we can provide the App, restore credits, and show your history. We delete them when you delete your account.
5. Your Choices, Consent, and Deletion Requests
Submitting a photo is optional. Before the App sends a photo to our backend or Replicate for the first time, it presents a separate notice describing the specific data to be shared and requires an affirmative agreement. Choosing "Not now" prevents that generation's data from being uploaded or sent to Replicate. Your agreement is remembered only for that signed-in account on that device. You can withdraw it at any time by going to Settings and tapping "Reset AI photo consent"; the App will not send new photos to Replicate until you review and accept the notice again. If you no longer want us to retain generated images or account data, go to Settings in the App and tap "Delete Account." Account deletion permanently removes your account, credits, submitted photos still in our storage, generated images, purchase records, and generation history from our active Firebase systems. You can also contact us using the email address in Section 9 to request help with deletion or privacy questions.
6. Security
We protect submitted photos and account data with HTTPS/TLS in transit, private Firebase access controls and security rules, authenticated Cloud Functions, server-side validation, and time-limited signed URLs for Replicate. Access to user-specific Firebase data is restricted to the authenticated account or the backend services needed to perform the requested generation. No method of transmission or storage is completely secure, but we use reasonable administrative, technical, and organizational safeguards designed to protect your data from unauthorized access, use, or disclosure.
7. Children's Privacy
WeThere is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal data from a child under 13, we will take steps to delete that information promptly. If you believe your child has provided us with personal data, please contact us at the email below.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy on this page with a new effective date. Your continued use of the App after changes are posted constitutes your acceptance of the updated policy.
9. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at oemmobileapp@gmail.com.