Sundae Camera

Privacy Policy

Your photos belong to you. Sundae develops them on your Apple devices and limits the information that leaves the app.

Effective August 25, 2026

The short version

Sundae has no account system, does not upload your photo library, does not sell personal data, and does not use analytics for targeted advertising. App analytics can be turned off during onboarding or later in Settings → Analytics & Privacy.

1. Scope

This policy explains how Sundae Camera ("Sundae"), an app by Andre Dalwin Tan, handles information when you use the Sundae app, its Apple Watch companion, nearby-device camera features, and the TestFlight beta.

Apple separately controls information it processes through the App Store, TestFlight, iCloud, Photos, and other Apple services. Those activities are governed by Apple's own terms and privacy notices.

2. Data at a glance

Photos and RAW negatives
Processed on your device and saved to your Photo Library. They are not uploaded to Sundae or its analytics provider.
Location
Optional. When Location Tagging is on, location can be embedded in the photo you save. Photo coordinates are never sent to app analytics.
App analytics
Product, performance, and bounded failure events associated with a random analytics identifier and handled by PostHog. Enabled by default during beta and switchable off at any time.
Accounts and ads
Sundae has no user accounts, targeted advertising, cross-app tracking, or sale of personal data.

3. Photos, settings, and device permissions

Sundae's camera, Vibes, Film Emulation, Adaptive Tone, Gallery, and Lab run on your device. Developed photos and optional RAW negatives are written to Apple Photos. App preferences, onboarding progress, and editing state are also stored locally in the app or alongside the relevant Photos asset.

Sundae asks for access only when a feature needs it:

  • Camera to capture photos and provide the live viewfinder.
  • Photos to save work and let you browse, favorite, import, edit, and redevelop media in the Gallery and Lab.
  • Location to tag where a photo was taken when Location Tagging is on. This permission and feature are optional.
  • Motion to render the live horizon level in the viewfinder.
  • Local network and nearby-device access for remote camera control.

You can change system permissions in Apple Settings. Turning off a permission may make the related feature unavailable. Deleting Sundae does not delete photos or RAW negatives already written to Apple Photos; manage those separately in Photos and through your Apple sync and backup settings.

4. Apple Watch and nearby-device features

When you use the Apple Watch companion or Sundae Director, live preview frames, camera state, and control commands travel between your nearby Apple devices using Apple connectivity frameworks. This content is used to operate the session and is not routed through a Sundae server or included in PostHog analytics.

Limited operational events—such as whether a nearby-device session connected or a remote Shutter request succeeded—may be included in optional app analytics. Endpoint addresses, ports, device-to-device identifiers, packet previews, and diagnostic log text are removed before an event can be sent.

5. App analytics

Sundae uses PostHog Cloud in the United States for product, performance, and bounded reliability analytics. Events retain a random analytics identifier and technical context but are not tied to a Sundae account because Sundae has no accounts. Analytics are enabled by default during the beta. You can turn them off during onboarding or later in Settings → Analytics & Privacy. Turning the setting off stops future Sundae app analytics events.

What may be sent

  • App interactions and outcomes, such as completing onboarding, taking a photo, opening the Gallery or Lab, saving an edit, or using a companion feature.
  • Bounded capture context, such as Vibe identifier, resolution, capture family, output format, lens category, camera position, and whether Save Negative was on.
  • Performance and reliability measurements, including durations, memory or thermal conditions, queue state, and bounded app-defined operation or failure codes.
  • Standard technical context supplied by the analytics SDK, such as app version, build, device model and type, operating-system version, locale, screen size, network type, TestFlight status, and the random analytics identifier.
  • An approximate country may be derived by PostHog from the network address used to deliver an event. Sundae does not send photo GPS coordinates for this purpose.

Before an app event is sent, Sundae applies a key-based denylist and value-type checks. The filter removes designated sensitive property names and unsupported opaque values; non-redacted scalar properties, including scalar values inside sanitized arrays or dictionaries, can be forwarded. It is not a strict property allowlist.

What is deliberately excluded

Sundae does not send photos, thumbnails, live-preview media, image bytes, filenames, file paths, Photo Library identifiers, photo GPS coordinates, nearby-device endpoints, free-form diagnostic logs, raw system errors, stack traces, or exception screenshots. Session replay, automatic screen capture, automatic element interaction capture, person profiles, surveys, advertising profiles, and automatic fatal-crash capture are disabled in Sundae's app configuration.

Learn more in the PostHog privacy policy.

6. TestFlight beta data and feedback

If you install Sundae through TestFlight, Apple automatically provides Apple and the developer with beta testing data such as sessions, device and operating-system details, performance statistics, and crash logs. This collection is part of TestFlight and cannot be controlled by Sundae's in-app analytics switch.

You may also choose to submit written feedback, screenshots, or crash comments. That feedback can contain personal information or visible photo content, so review it before sending. Public-link testers normally appear anonymous unless they include an email address with feedback. Apple controls TestFlight's collection and delivery of this information.

See Apple's TestFlight Terms of Service and Privacy Policy.

7. Sharing and service providers

Sundae does not sell personal information or share it for targeted advertising.

Information is handled only where needed by these categories of recipient:

  • PostHog, which processes optional app analytics and bounded app reliability events. PostHog also receives website usage and diagnostic data when you visit sundae.cam.
  • Vercel, which hosts the supporting website and provides web traffic measurement.
  • Apple, which distributes Sundae, runs TestFlight, provides Photos and device connectivity frameworks, and processes information under Apple's own policies.
  • Authorities or other parties when disclosure is required by law, needed to protect rights or safety, or necessary to investigate misuse.

8. Retention

  • App-local preferences, onboarding state, and working data remain until you reset them where a control is available or delete Sundae, subject to device backups and operating-system behavior.
  • Photos and RAW negatives already written to Apple Photos are not app-local data and are not removed when you delete Sundae. They remain until you delete them through Apple Photos, subject to Recently Deleted, iCloud Photos, and backup settings.
  • PostHog controls storage for app analytics and website analytics data under the project's service configuration and PostHog's retention practices. Sundae does not promise a fixed event-retention period in this policy.
  • TestFlight information and Vercel Web Analytics data follow Apple's and Vercel's respective service configurations and retention practices.

9. International processing

Sundae is developed in the Philippines. PostHog's configured app analytics service is hosted in the United States, and Apple and Vercel may process information in other countries where they operate. Data-protection laws in those places may differ from the laws where you live. Sundae limits the information sent to these providers and relies on their contractual and technical safeguards.

10. Security

Sundae uses on-device processing, Apple platform protections, transport encryption, and a key-based analytics denylist with value-type filtering to reduce risk. The filter forwards non-redacted scalar properties and is not a strict allowlist. No method of storage or transmission is perfectly secure, so absolute security cannot be guaranteed. Keep your device and operating system updated, protect your device passcode, and maintain backups of photos that matter to you.

11. Children

Sundae is not directed to children under 13, or the equivalent minimum age in their jurisdiction. Children below that age are not permitted to use TestFlight. If you believe a child has provided personal information through beta feedback or another channel, please get in touch so it can be addressed.

12. Your choices and privacy rights

  • Turn off app analytics in Settings → Analytics & Privacy.
  • Change Camera, Photos, Location, Motion, and network access in Apple Settings.
  • Turn Location Tagging off in Sundae's capture settings.
  • Delete photos and RAW negatives using Apple Photos. Deleting Sundae removes app-local data but does not delete media already saved to Apple Photos.
  • Stop participating in the beta by deleting the beta app from your device.

Depending on where you live, you may have rights to be informed, access, correct, delete, restrict, object to, or receive a copy of personal information, and to lodge a complaint with a privacy regulator. Sundae has no account and intentionally avoids direct account identifiers, so it may not be possible to connect an event associated with a random analytics identifier to a particular requester. Requests will be handled to the extent the information can be reasonably identified and applicable law requires.

13. Changes and contact

This policy may change as Sundae leaves beta or adds features. Material changes will be reflected by a new effective date and, when appropriate, an in-app notice.

For privacy questions or requests, contact Andre Dalwin Tan through andredalwin.com. If you are in the Philippines, you may also learn about your rights or submit a complaint through the National Privacy Commission.