Privacy Policy
Last updated: July 23, 2026
1. Introduction
LotShow ("we," "our," or "us") is a car-photo enhancement app for iPhone. You take or upload a photo of a car, pick a backdrop, and LotShow returns a clean, showroom-style listing shot. This Privacy Policy explains what data we collect, what we don't, and how your photos, your account, and your enhancement history flow between your device, our backend (Firebase), and the image services that produce your results.
LotShow is built by one developer. We don't sell ads, we don't track you across other apps, and we don't sell your data.
2. How Your Data Flows
- Device ↔ Apple / Google (sign-in): You sign in with Apple, Google, or an email and password. The provider authenticates you and returns a token to Firebase Auth. We never see your Apple or Google password.
- Device → Firebase Storage (your photos): The photo you choose to enhance is uploaded to Google Firebase Storage under your user ID so it can be processed. The finished result is stored there too, so you can find it in your library.
- Your photo → image services (the enhancement): To produce your result, your photo is sent from our backend to Photoroom, which composites the car onto the backdrop, relights it, and adds a contact shadow. The result may then be sent to Google's Gemini image model for an optional final polish. These services process your photo to return an enhanced image; they are not used to advertise to you.
- Device ↔ Firebase (account and history): Your account, your credit balance and plan, and a record of each enhancement are stored in Firebase under your user ID, governed by security rules scoped to your account.
- Device ↔ RevenueCat ↔ Apple: When you subscribe or buy credits, the purchase is processed by the App Store. RevenueCat reports whether your subscription is active and receives an anonymous user ID we generate plus the store receipt data. We never see your payment method.
- Device ↔ PostHog (product analytics):The app may send anonymous usage events (e.g. "enhancement started," "result saved") keyed to your user ID so we can understand which parts of the app work. Session recording / replay is disabled, and the content of your photos is never sent as analytics.
3. Information We Collect
Account information
- Email address (Apple may relay a private address)
- A Firebase Authentication user ID (UID)
- Your display name, if your sign-in provider supplies one
- The sign-in method you used (Apple, Google, or email)
Your photos and enhancements
- The car photos you take or upload for enhancement
- The enhanced results LotShow produces
- Which backdrop you chose and basic job status for each enhancement
Subscription and credits
- Your plan, your remaining credit balance, and whether your entitlement is active, as reported by RevenueCat / the App Store
Product analytics (PostHog, anonymous events)
- Event names and coarse metadata (which screens you used, whether an enhancement was run) keyed to your user ID
- Crash and error reports without the content of your photos
What we do NOT collect
- No location data
- No advertising identifier (no IDFA-based tracking)
- No contacts, calendar, or microphone access
- No access to your photo library beyond the specific photo you pick
- No third-party ad networks, ad SDKs, or retargeting trackers
- No cross-app or cross-site tracking of any kind
- No session recording or screen replay
4. Tracking & Advertising
LotShow does nottrack you across other companies' apps or websites, and does not use Apple's IDFA. The app does not present an App Tracking Transparency prompt because no cross-app tracking occurs.
5. Third-Party Services
- Google Firebase (Authentication, Firestore, Storage, Cloud Functions): hosts your account, your enhancement history, and your uploaded and enhanced photos.
- Photoroom: receives your photo and the chosen backdrop to composite, relight, and shadow the car. Processes data on its servers.
- Google (Gemini image model): may receive the staged image for an optional final polish.
- Apple: Sign in with Apple, App Store distribution, and billing.
- Google: Google Sign-In.
- RevenueCat: reports your subscription and credit entitlement. Receives an anonymous identifier and store receipt data. Processes data in the United States.
- PostHog: product analytics and error monitoring. Anonymous events only. Session recording disabled.
6. Data Retention & Deletion
Your uploaded photos, enhanced results, and enhancement history live in LotShow so you can return to them. You can delete your account from the app's settings, which removes your enhancement records, your uploaded and enhanced photos from storage, your profile, and your Firebase authentication record. This is irreversible. Copies held transiently by an image service to process a request are not retained by us and are subject to that provider's own retention practices.
7. Legal Basis for Processing (GDPR)
- Contractual necessity (Art. 6(1)(b)): creating your account and processing the photos you submit in order to return an enhancement, necessary to provide the app.
- Consent (Art. 6(1)(a)): camera and photo access, which you grant and can withdraw in iOS settings.
- Legitimate interest (Art. 6(1)(f)): basic operation, anonymous analytics, and abuse prevention.
8. International Data Transfers
Firebase, Photoroom, Google, RevenueCat, and PostHog may process data in the United States and other countries. If you use LotShow from outside those countries, your data is transferred there. These providers offer Standard Contractual Clauses for cross-border transfers.
9. Your Rights
- EEA/UK (GDPR): access, portability, restriction, objection, and the right to complain to your data protection authority.
- California (CCPA/CPRA): the right to know, delete, and opt out of "sale" or "sharing." We do not sell or share your personal information.
10. Children's Privacy
LotShow is not directed to children under 13 (or 16 in the EEA). We do not knowingly collect data from children. If you believe a child has signed up, contact us and we will delete the account.
11. Security
Authentication is handled by Firebase Auth, all traffic uses HTTPS, and Firestore and Storage security rules restrict your data and your photos to your own account.
12. Changes to This Policy
We may update this Privacy Policy. Material changes will be announced on this page and, if significant, in the app.
13. Contact
Questions or requests, write to support@moetalaat.com.
