Privacy Policy

Last amended: August 08, 2026

This Privacy Policy explains how Mobicraft Teknoloji A.Ş. d/b/a FaceTrix ("FaceTrix", "we", "us") collects, uses, and shares your personal information, and how you can exercise your privacy rights. We process personal data in accordance with the Turkish Personal Data Protection Law No. 6698 (KVKK), the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA, applicable US state biometric privacy laws, and other applicable laws.

Legal bases. We rely on: your explicit consent for facial data (special-category data under KVKK Article 6 and GDPR Article 9); performance of a contract to deliver the Services and process purchases; legitimate interests for security, fraud prevention, safety screening, service improvement, and advertising measurement; and legal obligation where we must retain or disclose data.

1. Scope

This Privacy Policy applies to the FaceTrix mobile application ("App") and our website at facetrix.app (together, the "Services").

2. Changes to this Policy

We may update this Policy from time to time at our discretion. Routine updates take effect when we post the revised Policy with a new "Last amended" date — we do not provide individual notice of every change, so please review this Policy periodically. Continued use of the Services after an update takes effect constitutes acceptance of it. Where a change is material, we will provide notice as required by applicable law, and where a change materially affects how we process your facial data, we will ask for your explicit consent again before it takes effect.

3. Information We Collect

Content you upload. The photos and videos you upload from your device, and the content generated for you in the App. You control the App's access to your device media through your device settings. To let you easily re-use faces, your saved face library is stored locally on your device, not on our servers; you can delete saved faces in the App at any time, and deleting the App removes them. Content stored only on your device is under your control and is not held by us — when you select a saved face for a new generation, it is uploaded and processed at that time under this Policy.

Facial data. Subject to your separate explicit consent, we process facial data (facial geometry and feature representations) derived from your uploads. We use it solely to generate the output you request. We do not use your photos, videos, prompts, or facial data to train any AI model. We do not use facial data for facial recognition, identification, authentication, profiling, advertising, or tracking, and we never sell it. You may withdraw your consent at any time by emailing info@mobicraft.net or by deleting your account in the App; withdrawal deletes the facial data we hold and stops further processing.

Account and purchase information. Email address, account details, and purchase records. Payments are processed by Apple and Google; we never collect or store your payment card details, though we may receive related billing information.

Communications and surveys. Information you provide when you contact support or choose to take part in a survey.

Automatic data. Device and usage information such as IP address, device identifiers, mobile carrier, approximate location derived from IP address, screens visited, and interaction data. We process this through the analytics, attribution, and subscription-management providers listed in Section 5. Analytics data is pseudonymised and never includes facial or biometric data. On iOS we request your permission through Apple's App Tracking Transparency prompt before accessing your advertising identifier, and we do not use it if you decline; on Android you can reset or delete your advertising identifier in device settings.

Other sources. Information from app stores or third-party login services, per your settings with them.

4. How We Use Your Information

We use your information to: provide the animation and face swap Services and manage your account and purchases; answer support requests; keep the Services safe and secure, detect fraud, and enforce our Terms of Use (including the automated screening described in Section 7); improve and develop the Services; send you push notifications (opt out anytime in your device settings); comply with legal obligations; and create de-identified, aggregated statistics. Facial and biometric data is never used for analytics, aggregation, advertising, or marketing.

Advertising. We share certain device identifiers and app-event data with advertising partners to measure our campaigns and deliver personalised advertising. We never share facial or biometric data, or your uploaded or generated content, with advertising partners. See Sections 6 and 12 for how to opt out.

5. How We Disclose Your Information

WE DO NOT SHARE YOUR PHOTOS, VIDEOS, OR FACIAL DATA WITH ANY THIRD PARTY EXCEPT THE PROCESSORS LISTED BELOW, AND ONLY TO DELIVER THE SERVICES YOU REQUEST. FACIAL DATA IS DELETED IMMEDIATELY FROM OUR SYSTEMS AFTER YOUR REQUESTED OUTPUT IS GENERATED, AND ANY COPIES HELD BY OUR PROCESSORS ARE DELETED WITHIN THE PERIODS STATED BELOW — IN ALL CASES WITHIN 30 DAYS, SAVE THAT A GENERATION PROVIDER MAY RETAIN LIMITED ABUSE-MONITORING LOGS OF REQUESTS FOR A SHORT ADDITIONAL PERIOD UNDER ITS OWN TERMS. A LIMITED NUMBER OF AUTHORISED PERSONNEL MAY ACCESS FACIAL DATA ONLY WHERE STRICTLY NECESSARY TO INVESTIGATE A TECHNICAL FAULT, RESPOND TO YOUR SUPPORT REQUEST, OR INVESTIGATE A SUSPECTED VIOLATION OF OUR TERMS OF USE; ALL ACCESS IS LOGGED, ROLE-RESTRICTED, AND SUBJECT TO CONFIDENTIALITY OBLIGATIONS.

We use the following processors. Each is bound by a data processing agreement with deletion, security, and international-transfer safeguards.

Cloud hosting and infrastructure. Google Cloud — stores and manages operational data and content; facial data is handled only as needed and deleted in accordance with Section 10. RunPod — compute for face swap processing; facial data exists only in active server memory for the duration of the operation and is erased immediately afterwards, with nothing retained.

AI generation providers (process your uploads solely to produce your requested output): Atlas Cloud (United States; SOC 2) — an API platform that routes generation requests to third-party model providers bound by equivalent contractual data-protection safeguards; customer content is retained for up to 7 days before scheduled deletion. fal (United States) — image and video generation; uploaded inputs and generated media are retained for up to 30 days. PixVerse (Singapore, with service providers in the United States and other countries) — video generation; facial data extracted from uploads is used solely for the generation process and permanently deleted once processing completes. Google (Veo, Gemini and related generative models) — image and video generation in accordance with Google's terms for the relevant service.

Analytics, attribution, and billing (never receive facial or biometric data, uploads, or generated content): Amplitude — product analytics (United States). AppsFlyer — marketing attribution; receives advertising identifiers, IP address, device information, and app events, and shares attribution data with advertising networks (see Sections 4, 6, and 12). RevenueCat — subscription management (United States). Google Analytics and Google BigQuery — usage analytics and analytics data storage.

We may also disclose information where we believe in good faith it is required to comply with law, legal process, or lawful requests from authorities; to protect the rights, property, or safety of you, us, or others; or to enforce our agreements. If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction as permitted by law.

6. Your Choices and Rights

Depending on your jurisdiction, you have the right to: access and receive a copy of your personal information (including portability); correct it; delete it; restrict or object to processing; and withdraw any consent, including your facial-data consent. You can delete your account and data directly in the App. For any other request, email info@mobicraft.net (subject lines such as "Delete my data", "Withdraw biometric consent", or "Do Not Sell or Share" help us respond quickly). We respond within the periods required by applicable law, and within 30 days for KVKK requests.

You may opt out of the sharing of your identifiers for personalised advertising at any time by emailing info@mobicraft.net with the subject "Do Not Sell or Share". You can also limit this sharing at device level: on iOS, decline tracking in the App Tracking Transparency prompt or in Settings; on Android, reset or delete your advertising identifier and turn off ads personalisation in device settings. Where our website receives a Global Privacy Control (GPC) signal, we treat it as a valid opt-out of sharing for that browser. We do not respond to legacy "Do Not Track" signals.

7. Automated Screening

To keep the Services safe, uploads, written prompts, and generated output are screened by automated filters operated by us or by our AI providers. These include age estimation (with a threshold set conservatively above 18, so some adults may occasionally be rejected) and detection of sexual or explicit material, and content that appears to depict a minor, a public figure, or other material violating our Terms of Use may be rejected or blocked before delivery. Rejected content and the related analysis results are deleted immediately and are not used for any other purpose, including model training or analytics; we retain only an event record (account identifier, timestamp, and a cryptographic hash — never the image). Catalogue templates are reviewed before publication. These filters are a best-effort measure and may produce false positives and false negatives; passing them does not make content lawful, and you remain solely responsible for what you upload and create. If you believe content was rejected in error, contact info@mobicraft.net and a member of our team will review it.

8. Security

We maintain technical and organisational measures appropriate to the sensitivity of the data we process, including encryption in transit and at rest, role-based access controls, logging of access to facial data, and contractual security obligations on our processors. No system is completely secure. If we learn of a personal data breach affecting you, we will notify you and the competent authorities as required by applicable law.

9. International Transfers

Your information may be processed in countries other than your own, including the United States. For transfers from the EU/EEA and the UK, we rely on Standard Contractual Clauses or another lawful mechanism. For transfers from Türkiye, we rely primarily on the standard contracts regime under KVKK Article 9, with the required notification to the Personal Data Protection Authority, or another lawful transfer mechanism under Turkish law.

10. Retention

We keep personal information only as long as needed for the purposes described in this Policy. Specifically: facial data is deleted immediately from our systems once your requested output is generated, and in all cases (including processor-held copies) within 30 days, save for limited abuse-monitoring logs a generation provider may retain under its own terms — and immediately upon withdrawal of consent or deletion of your account, whichever is earlier. Uploaded source files and generated content are kept on our systems for up to 30 days to support delivery of your output, recovery of failed generations, re-downloads, and support, then automatically deleted (or earlier if you delete them); your saved face library resides only on your device and is not subject to these server-side periods — you delete it yourself in the App. Consent records (account identifier, timestamp, consent version, and content hash — never the image) are kept for 5 years to demonstrate consent for the duration of applicable limitation periods. Safety and enforcement records (account identifier, IP address, timestamp, and content hash) are kept for 12 months, or longer where preservation is legally required. Operational and analytics logs are deleted or aggregated within 30 days. Where content relates to suspected child sexual abuse material, we retain records as required by law and disclose them to competent authorities.

11. AI-Generated Content Marking

All content generated by the Services includes a visible label disclosing that it is AI-generated or manipulated, and carries machine-readable marking applied by us or our underlying AI providers, in line with applicable transparency laws including Article 50 of the EU AI Act. You must not remove or obscure these marks (see our Terms of Use).

12. US State Notices

Biometric privacy states (Illinois, Texas, and others). We collect facial geometry derived from your uploads, only after your written consent through our in-app consent screen, and solely to generate the output you request — never for identification, authentication, surveillance, or profiling. We do not sell, lease, trade, or profit from biometric data, and disclose it only to the processors described in Section 5 to deliver the Services. Our written retention and destruction policy: biometric identifiers are permanently destroyed no later than 30 days after collection, or upon withdrawal of consent or account deletion, whichever occurs first.

California. In the preceding 12 months we collected: identifiers, commercial information, biometric information, internet activity, approximate geolocation, and inferences. Biometric information and sensitive personal information are disclosed to service providers only — never to advertising partners. Identifiers, internet activity, approximate geolocation, and inferences may be "shared" with advertising partners for cross-context behavioural advertising; to opt out, email info@mobicraft.net with the subject "Do Not Sell or Share", use the device-level controls described in Section 6, or send a GPC signal from your browser on our website. We do not "sell" personal information and have no actual knowledge of selling or sharing the personal information of consumers under 16. You may limit the use of sensitive personal information to the purposes of providing the Services. You will not be discriminated against for exercising your rights. You or an authorised agent may submit a verifiable request; we will ask for information sufficient to verify you.

Other US states (including Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Montana, and Nevada). You may have rights to access, correct, obtain, and delete your personal data, to opt out of targeted advertising, sale, or profiling, and to appeal a denial. We do not sell personal information as defined under these laws. Contact us as set out in Section 16.

13. Children

The Services are for adults 18 and over. We do not knowingly collect personal information from anyone under 18, and we automatically screen and reject uploads that appear to depict a person under 18. If you believe a minor has provided us with personal information, contact info@mobicraft.net and we will delete it promptly.

14. Third-Party Links

The Services may link to third-party websites or applications we do not control. Review their privacy policies before providing them any information.

15. Supervisory Authorities

If you are in Türkiye, you may lodge a complaint with the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, kvkk.gov.tr). If you are in the EEA, Switzerland, or the UK, you may lodge a complaint with your local supervisory authority.

16. Contact

Mobicraft Teknoloji A.Ş. d/b/a FaceTrix is the data controller (veri sorumlusu).

For all privacy requests and reports: info@mobicraft.net

Requests under KVKK follow the Communiqué on Application Procedures to the Data Controller; we respond within 30 days.

FaceTrix team