Privacy Policy
Effective August 12, 2026
Lapse processes your selected photos, video, and custom soundtrack on your device and does not upload that media to its servers. Here is exactly what stays local and what service providers receive.
Lapse ("we", "our", or "the app") is a timelapse photo animation app developed by Minalogic. This privacy policy explains how we handle your data.
Data Collection
We do not collect your photos, video, or custom soundtrack or store them on a Minalogic server. Photo, video, and soundtrack processing, face detection, and timelapse creation happen on your device. If you choose Google Photos, Google sends the photos you explicitly select to the app on your device. If you choose a soundtrack from a cloud-backed file provider, that provider may first download your selection under its own privacy policy. Your operating system may separately include local app data in a device or cloud backup, and the functional, diagnostic, and purchase providers described below retain their own service records.
Camera Access
Lapse requests camera access solely to let you take new photos for your timelapse projects. Camera images are stored in the local project; Lapse does not send them to its servers or to a photo-content provider. Device-backup behavior is described below.
Photo & Video Library Access
Lapse uses your device's system picker so you can import existing photos or one video into your timelapse projects — the app itself holds no permission to read your photo library and can only see the media you explicitly pick. Selected media is processed locally and is not uploaded by Lapse.
When your film is ready, Lapse hands the video file to your device's system share sheet — saving it to your photo library or sending it to another app happens through the sheet, under your control and the operating system's rules. The destination app may upload or retain the film under its own privacy policy. Lapse itself requests no permission to write to (or read from) your photo library.
Video Import
If your build offers video import, you can choose one source video from 2 seconds to 10 minutes, up to 750 MB and 4K, then select a 2–60 second part. Lapse samples up to 60 still frames, asks which person the story should follow, and leaves out moments where that person is not found. Sound is not imported. Sampling, face matching, and framing happen locally on your device.
Extracted frames become photos in the local project. To support recovery and choosing a different part without reopening the system picker, Lapse can keep an app-private temporary copy of the selected source video for up to 24 hours; normal completion or project deletion can remove it sooner. The temporary source is never uploaded to a Lapse content backend.
Custom Soundtracks
You can choose one MP3, M4A, AAC, or WAV soundtrack from 2 seconds to 10 minutes and up to 100 MB. Lapse checks the selected file, copies it into app-private project storage, and processes it locally for preview and export. Lapse does not upload the soundtrack, its filename, or its audio content to Minalogic, analytics providers, or a music service. Replacing the soundtrack removes the older active project copy. Deleting the project or uninstalling Lapse removes the active app copy, subject to the device or cloud backup behavior described below.
Google Photos Import (optional)
You can optionally connect Google Photos to import photos. If you choose this, you sign in with your Google account and pick photos inside Google's Photos Picker; Lapse then downloads only the photos you selected to your device to build your timelapse. Lapse cannot browse the rest of your library and does not upload or modify anything in Google Photos. Google processes the sign-in, account, Picker, and download requests under its privacy policy, and Google Sign-In provides your basic profile (name and email address) to the app on your device. Lapse does not persist that profile, send it to a Lapse backend, or disclose it to additional third parties; the app uses the authorization only for the selected-photo import. Access tokens are short-lived, but the Google account authorization can remain active so Google Sign-In can refresh access on a later import. It does not necessarily expire after one selection. You can review or revoke Lapse at any time at myaccount.google.com/permissions. Revocation prevents future access but does not delete photos already copied into a local project. Delete those in Lapse, subject to the backup caveat below.
Lapse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: photos obtained via Google Photos are used solely to provide the timelapse features you see in the app — not for advertising, not sold, not disclosed by Lapse to another party except when you explicitly direct an export through the system share sheet, and not used to train generalized models.
Face Detection
Lapse detects and aligns faces using on-device AI. Face detection, recognition, and the numeric face descriptors used to align your subject across photos or extracted video frames are computed and stored in the local project. Lapse does not transmit selected media or face descriptors to Minalogic, Firebase, Sentry, AppsFlyer, RevenueCat, or an AI service for this processing. Local project data may be included in an operating-system backup as described below.
Analytics
With Share usage data enabled (the default), Firebase Analytics, Crashlytics, Firebase Performance Monitoring, Sentry, and Minalogic's Firebase Cloud Firestore receive pseudonymous usage, crash, error, and performance data. “Pseudonymous” means records can be linked to the same app installation or service-generated identifier even though Lapse does not attach your name, email address, Google account, advertising identifier, selected media, or face data. Providers can also receive ordinary network and device metadata such as IP address, app and OS version, device model, timestamps, stack traces, session or installation identifiers, and performance timings; they retain previously received records under their own policies.
Optional ad measurement is a separate Settings › Privacy choice and is off by default. Only after you turn it on, and only in an Android release where paid-attribution measurement is enabled, AppsFlyer receives a pseudonymous AppsFlyer installation ID, install and app-session attribution, campaign or store-referrer information when available, and ordinary device and network metadata such as IP address, device model, app/OS version, language, timestamps, and approximate location derived from network information. AppsFlyer may share those details with the selected advertising partners Reddit, Snapchat, and TikTok to attribute their campaigns. Separately, RevenueCat sends AppsFlyer server-side purchase, renewal, cancellation, and refund outcomes, including product, currency, and value; AppsFlyer may share those outcomes with the same selected partners for campaign measurement. RevenueCat remains the only source of these revenue events, so Lapse does not send client-side purchase events or duplicate them.
This partner measurement does not use Advanced Matching or advertising IDs, and Lapse does not give AppsFlyer, Reddit, Snapchat, or TikTok your contacts, name, email, Google account, selected photos or video, face data or descriptors, project names or other project metadata, filenames, or a Lapse user ID. Creative-content events are not sent. AppsFlyer runtime collection, its developer key, its installation ID, and its partner postbacks remain disabled in Lapse iOS builds.
Apple Ads attribution on iOS uses a separate, Apple-only standard attribution route. After anonymous RevenueCat purchase management is configured, RevenueCat's SDK requests an Apple AdServices attribution token and sends it to RevenueCat so RevenueCat can ask Apple whether the install came from an Apple Ads campaign. Apple can return standard campaign, ad group, keyword, placement, claim type, and download/redownload information; RevenueCat can associate those campaign fields with its anonymous App User ID and store purchase, subscription, renewal, cancellation, and refund records for campaign reporting. This standard route does not request App Tracking Transparency permission, IDFA, another advertising/device identifier, or detailed Apple attribution. It does not send data to AppsFlyer, Reddit, Snapchat, or TikTok, and never includes selected photos or video, face data, contacts, Google identity, filenames, or project metadata.
Minalogic's Firestore dashboard stores a narrow event allowlist (for example, that an install opened the importer, confirmed a subject, reached a preview, exported, shared, viewed the Pro screen, or reached a coarse purchase outcome such as cancelled or failed) under a random installation UUID. Journey payloads contain only the allowlisted step and, where relevant, a broad source, product category, or bounded count — not store error text, prices, receipts, selected content, project identifiers, or project names. A completed-purchase payload contains only an allowlisted store product identifier, its coarse kind (subscription, lifetime/one-time access, or tokens), and a store environment label of production, sandbox, or unknown when the app cannot establish it. It does not contain a price, currency, receipt, or transaction identifier. The event envelope also includes the app version, platform, date, build provenance, server timestamp, and a persisted install-local event-order counter. The UUID links events from that installation but is not intentionally linked to your support email, Google account, RevenueCat identifier, AppsFlyer identifier, or app-store account. These Firestore rows have a 180-day deletion deadline. Turning Settings › Privacy › Share usage data off disables new optional app-initiated Analytics, crash, performance, Sentry, and dashboard events and deletes the dashboard UUID from your device. It does not change the separate Optional ad measurement choice. In current mobile builds, including build 230, native crash or session telemetry may still reach Sentry after opt-out; this exception does not include selected media or face data. Prior rows remain until their retention deadline, and deleting a local identifier does not itself erase records already retained by Firebase, Sentry, RevenueCat, or their backups.
Data Collected by Analytics
- Pseudonymous usage events such as app launches, allowlisted journey steps and coarse stop outcomes, feature usage, photo counts, and export settings (format, resolution, aspect ratio, and soundtrack preset)
- Minalogic dashboard fields: event name, short allowlisted properties, app version, platform, date, schema version, build provenance, server timestamp, a persisted install-local event-order counter, and the random installation UUID — not file names, media pixels, face descriptors, project names, or free-form text
- A consent-gated purchase event containing an allowlisted store product identifier, category (subscription, lifetime/one-time access, or tokens), and the coarse store environment (production, sandbox, or unknown), linked to the dashboard UUID — never a price, currency, receipt, or transaction identifier; payment and receipt handling is separately described under Purchases
- Sanitized error categories, bounded diagnostic reasons, crash stack traces and breadcrumbs, app/device/OS metadata, and service-generated installation or session identifiers
- Performance information such as startup, rendering, and network timing
- Only after you enable the separate, default-off Optional ad measurement choice in an enabled Android build: AppsFlyer install/session attribution, a pseudonymous AppsFlyer installation ID, campaign or store-referrer information when available, ordinary device/network metadata, and RevenueCat purchase/refund outcomes; AppsFlyer may share these with the selected advertising partners Reddit, Snapchat, and TikTok — without Advanced Matching, advertising IDs, contacts, Lapse account data, selected media, face data, or project metadata
- On iOS: an Apple AdServices attribution token and the standard Apple Ads campaign attributes Apple returns, associated by RevenueCat with its anonymous App User ID and purchase lifecycle records — without ATT, IDFA, another advertising/device identifier, detailed Apple attribution, AppsFlyer, selected media, face data, contacts, Google identity, or project metadata
App Configuration & Security
Separately from optional telemetry, Firebase Remote Config fetches feature switches and settings, and Firebase App Check uses Google Play Integrity on Android or Apple DeviceCheck on iOS to attest that requests come from a genuine app. These functional requests can use app identifiers, app version, Firebase installation identifiers, IP/network information, and platform attestation tokens. They do not contain your selected media or face data. Google/Firebase may retain service records under its policy, and these essential configuration and abuse-prevention requests are not disabled by the Share usage data toggle.
Notifications
With your permission, Lapse shows notifications for things happening on your own device — for example, when an export or a photo import finishes while the app is in the background. These are local notifications generated entirely on your phone: Lapse does not use push notifications, holds no push token, and nothing about your notifications ever leaves your device.
Purchases
In-app purchases and subscriptions are processed by the Apple App Store or Google Play and managed through RevenueCat. Lapse does not give RevenueCat your name, email address, Google Photos identity, or advertising identifier. RevenueCat generates a random pseudonymous App User ID (called an anonymous App User ID by RevenueCat) and receives store product, receipt/transaction, purchase, renewal, cancellation, refund, and entitlement history needed to validate purchases and restore access; restore operations may associate successive anonymous IDs with the same store receipt. Apple or Google retains purchase and payment-account history under the store's policies; RevenueCat retains its customer and transaction records under its policy. These functional billing records are collected independently of both privacy switches. On iOS, RevenueCat can associate the standard Apple Ads campaign attributes described above with this anonymous customer and purchase history. Only when the separate Optional ad measurement choice is on in an AppsFlyer-enabled Android build does Lapse pass the pseudonymous AppsFlyer installation ID to RevenueCat so RevenueCat can attribute server-side purchase, renewal, cancellation, and refund records to the installation. RevenueCat sends those outcomes, including product, currency, and value, to AppsFlyer; AppsFlyer may share them with the selected advertising partners Reddit, Snapchat, and TikTok. RevenueCat remains the only source of those revenue events, avoiding duplicate client-side reporting. Turning Optional ad measurement off stops AppsFlyer and clears and synchronizes that AppsFlyer ID from RevenueCat. When Share usage data is on, Lapse also records the limited pseudonymous dashboard purchase event described above: the allowlisted product, its coarse kind, and a production, sandbox, or unknown store environment label. That dashboard event does not contain a receipt or transaction identifier. Payment-card details are handled by the app store and are not provided to Lapse.
Accounts & Backend
Lapse has no Lapse user accounts and no media-content backend. Google sign-in is used only for optional Google Photos import. Your active projects, imported photos or extracted video frames, custom-soundtrack copies, and face data live in app-private storage on your device, subject to system backups. Minalogic's own server-side records are the pseudonymous, auto-expiring Firestore events described above; Firebase, Sentry, AppsFlyer, RevenueCat, Google, Apple, and Google Play separately process and retain the service, diagnostic, attribution, authorization, or purchase records needed for their roles.
Device & Cloud Backups
Lapse stores projects, imported photos or extracted video frames, custom-soundtrack copies, face descriptors, settings, and token balances in app-private storage. Depending on your iOS or Android settings and platform rules, some of that local app data may be copied into a device or cloud backup controlled by Apple or Google. Deleting a project or uninstalling Lapse removes the active app copy, but does not necessarily erase an older operating-system backup immediately. Review or delete device backups in your Apple or Google account if you need those copies removed; backup retention is controlled by the platform provider, not Lapse.
Your Choices & Data Deletion
- Delete a project in Lapse to remove its active local photos or extracted video frames, custom-soundtrack copy, temporary retrim source, face data, and managed export; uninstalling removes the app's active local data. Check platform backups separately.
- Turn Settings › Privacy › Share usage data off to disable future optional app-initiated diagnostics and rotate away the local dashboard UUID. In current mobile builds, including build 230, native crash or session telemetry may still reach Sentry after opt-out. Previously received records follow the retention rules above.
- Leave the separate Settings › Privacy › Optional ad measurement switch off (its default), or turn it off later, to stop future AppsFlyer and advertising-partner measurement and clear and synchronize its installation ID from RevenueCat. Previously received AppsFlyer, RevenueCat, Reddit, Snapchat, and TikTok records follow those providers' retention rules.
- Remove Lapse at Google Account permissions to revoke future Google Photos access. Delete imported local copies separately.
- Manage subscriptions, refunds, and store purchase history through Apple or Google Play. Store and RevenueCat records may be retained for transaction, fraud-prevention, tax, accounting, dispute, or legal obligations.
For an access or deletion request, email info@minalogicgh.com with the subject Lapse data request. Do not email photos, passwords, or payment receipts. We will act on Minalogic-controlled data that can be identified and explain any provider-specific step. Because Lapse has no user account and does not link your email address to pseudonymous installation identifiers, an email alone may not let us identify a particular historical telemetry row; unidentified Firestore rows expire after 180 days.
Third-Party Services
- Firebase (Analytics, Crashlytics, Performance Monitoring, Remote Config, App Check, Cloud Firestore) — Privacy Policy
- Sentry (error & performance monitoring) — Privacy Policy
- AppsFlyer (consent-gated install, session, campaign, and purchase/refund attribution in eligible builds; currently enabled only for Android releases) — Privacy Policy
- RevenueCat (subscription management and standard Apple Ads attribution on iOS) — Privacy Policy
- Reddit (selected advertising partner for eligible attribution-enabled campaigns) — Privacy Policy
- Snapchat (selected advertising partner for eligible attribution-enabled campaigns) — Privacy Policy
- TikTok (selected advertising partner for eligible attribution-enabled campaigns) — Privacy Policy
- Google Photos Picker API & Google Sign-In (optional import) — Privacy Policy
- Apple (App Store purchases, Apple AdServices standard attribution, DeviceCheck, and device/iCloud backup where enabled) — Privacy Policy
- Google (Google Play purchases, Play Integrity, Firebase, and Android/Google backup where enabled) — Privacy Policy
Children's Privacy
Lapse is not directed at children under 13. Many adults use Lapse to make timelapses of their children; selected media and the face data derived from it are processed in the local project and are not sent to Lapse's content backend or analytics providers. The same pseudonymous diagnostics, functional service records, purchase processing, and backup caveats described above apply to the device running the app.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date.
Contact
Privacy question or data request?
info@minalogicgh.com