Slow Mirror Privacy Policy
Last updated: September 7, 2026
Summary
Slow Mirror is a private longitudinal face journal provided by Venoka Tech Ltd. The app stores your original records in its private iPhone container. It has no advertising SDK, cross-app tracking, product analytics SDK, HealthKit access, microphone recording, Photos-library access, or external AI service.
- We do not identify you from your face or calculate beauty, age, health, or medical scores.
- Optional Slow Mirror backup is encrypted on your iPhone before upload.
- If you turn on account recovery, Slow Mirror stores a private, account-scoped copy of the archive key so the same account can restore on a new device.
- You can stop optional cloud protection or delete your account and data inside the app.
Data handled by the app
- Account information: the Slow Mirror account identifier and either an email you enter for one-time-code login or, when Apple provides it, an email/private relay address.
- Photos and videos: the photo and short silent motion you deliberately capture in Slow Mirror.
- Face geometry: eye, nose, mouth, contour, face-box, confidence, and quality measurements used to help reproduce framing. On supported devices, this may include a derived depth-range and camera-calibration summary. This is biometric/sensitive information, but it is not used for face identity.
- Device and record metadata: Apple’s vendor-scoped device identifier (IDFV), capture date, time-zone identifier, app/OS/device model, thermal state, camera position and settings, capture-protocol events, photo/motion technical metadata, quality-control results, record IDs, resource sizes, and cryptographic checksums.
- Account recovery material: if you enable account recovery, an account-scoped archive key and integrity checksum are stored so the same authenticated account can restore its encrypted archive.
Face data collection and on-device processing
Slow Mirror collects only face data needed to create and operate the private journal: the photo and short silent motion you choose to capture; a personal framing reference containing normalized eye centers, nose anchor, face contour, relative eye distance, eye-line angle, nose offset, Vision revision, and quality flags; and per-capture face count, face box, relative scale, eye-line, eye-midpoint and nose deviations, neutral-stability evidence, confidence, classification, and quality results. On supported devices, it may also retain the numeric depth-range and camera-calibration summary described below.
Camera frames are analyzed on the device using Apple’s Vision framework to derive face count and eye, nose, mouth, contour, face-box, confidence, and neutral-stability measurements. Slow Mirror does not retain every analyzed camera frame or a frame-by-frame landmark stream. It does not collect Face ID enrollment data, a face-identity template, an identity embedding, a raw depth map, a face mesh, or a 3D face model.
Depth boundary
Slow Mirror does not retain a raw depth map, face mesh, or 3D face model. Depth availability is optional and does not block an otherwise valid capture.
Where data is stored
On the iPhone: original media, the archive manifest, personal framing reference, and recovery material are stored in the app’s private container using iOS file protection.
Slow Mirror backup: only after you enable it, media and archive manifests are encrypted on the device and uploaded as ciphertext to private Supabase storage. The service also stores account-linked object metadata such as IDs, kind, encrypted size, checksum, and verification state.
Account recovery: when you choose to make a protected archive recoverable on another device, Slow Mirror stores one private copy of the archive root key under the same account. Ordinary users cannot read another account’s recovery key. Authorized service administrators can technically access this recovery material, so this feature is account-protected rather than zero-knowledge. Slow Mirror has no administrator photo viewer and Venoka does not use private records for advertising, identity recognition, appearance scoring, medical analysis, or external AI.
iCloud: the current version uses your private CloudKit space for a small encrypted recovery-availability check. It does not claim that your complete photo and motion history is stored in iCloud.
Why data is used
- Provide daily capture, consistent framing, archive playback, and Slow Mirror Moments.
- Bind one Slow Mirror account to one private archive and prevent another account from opening it. Sign in with Apple and email one-time codes are account entry methods, not archive keys.
- Provide optional encrypted backup, integrity checks, restore, export, and deletion.
- Protect the service from abuse and operate account and storage infrastructure.
Face data sharing
Slow Mirror does not sell, rent, or share face data with advertisers, analytics providers, data brokers, information resellers, external AI providers, or any third party for its own purposes. Face data stays in the app’s private iPhone container unless the user explicitly enables Slow Mirror backup. In that optional path, the app encrypts the photo, motion, thumbnail, and archive manifest on the iPhone before sending ciphertext to private Supabase storage. Supabase processes that ciphertext and associated storage metadata only as Venoka’s service provider to provide authentication, encrypted storage, restore, integrity verification, and deletion.
Service providers
- Apple: Sign in with Apple, device authentication, App Store distribution, and private CloudKit capability.
- Supabase: Apple and email one-time-code authentication, account/archive metadata, private encrypted-object storage, account-scoped recovery material, and account-deletion functions.
- Email delivery: when you request an email code, the configured transactional email service processes the destination email and delivery information only to send and protect the requested login. Slow Mirror does not use it for marketing.
Retention and deletion
- Local face data is retained for the life of the private archive. It remains in the app’s private iPhone container until you complete “Delete account and all data” or remove the app from the iPhone. There is no automatic expiration period.
- In version 1.0, “Remove from timeline” creates a recoverable tombstone: it hides the record from the timeline but does not erase the underlying photo, silent motion, thumbnail, archive entry, or derived face data.
- Account information and developer-controlled metadata remain while the account is active.
- Optional encrypted backup and its account recovery material remain until you stop cloud protection or delete the account. The current release does not promise a rolling 90-day retention policy.
- “Stop cloud protection” permanently removes the optional encrypted Storage objects and their active metadata and removes the account recovery key, while keeping the account and local archive.
- “Delete account and all data” permanently removes active encrypted Storage objects, developer-controlled metadata, account recovery material, and authentication records, then removes the local archive and key only after remote deletion is confirmed.
Your choices
- Decline Camera permission; capture will not work, but no camera content is collected.
- Do not enable optional Slow Mirror backup.
- Export an encrypted archive before deletion.
- Stop cloud protection or delete the account in “My Slow Mirror” → “Account & Data.”
- Contact us to ask a privacy or deletion question.
Usage analytics
To understand whether the app is genuinely used over the long term, Slow Mirror records a small set of first-party, action-and-timing usage events — for example: app opened or backgrounded, whether the account gate was shown, whether sign-in or a one-time code succeeded, whether a daily record was started, completed, or abandoned partway, opening the timeline or a specific day's record, key milestones of account restore, protection, or deletion, and whether the "Contact Us" form was opened.
Every recorded value is a fixed option from a short, predefined list (for example a classification such as "standard"/"supplemental"/"invalid", or a duration bucket such as "4-5 seconds"). It never includes any photo or the short silent motion, anything derived from your face or its geometry, any free text you write, your account recovery code, password, or one-time code itself, or an Apple device identifier (IDFA/IDFV) or any identifier used for cross-app tracking.
This data is used only to understand how many people use the app day to day, roughly when, and how long before someone stops (churn), so we know what in the product needs to improve. It is used internally only, is never shown to any user, and is never used for advertising. It is stored only in our own Supabase project database; it is never routed through or shared with any third-party analytics or advertising platform, and the app does not integrate any third-party analytics SDK.
Raw usage events are kept for up to 400 days, after which they are aggregated into statistics and the originals are deleted. Deleting your account immediately deletes all of your usage events, whether or not the 400-day window has passed.
Automatic account recovery
Once you are signed in to a Slow Mirror account, if this device's archive is already bound to that account, Slow Mirror automatically hands an archive key to the account for safekeeping — generating one locally first if this device does not already have one — and it is written to our Supabase project and immediately read back and verified. None of this requires tapping a button or writing down a recovery code. Later, signing in to the same account on a new phone lets you recover your records.
This is not a zero-knowledge design: the archive key is held by the account, not something only you can unlock. Our servers can technically access it, isolated to your account by row-level security so no other account can see it. This trade-off is what makes automatic, no-effort phone-switch recovery possible. If you would rather nothing be accessible on our end, the legacy offline recovery code remains available in the app under "My Slow Mirror" → "Account & Data" → "Advanced."
If you are signed out, or this device's archive is not yet bound to your account, Slow Mirror uploads nothing automatically. Anyone who already confirmed the legacy recovery code is unaffected by this change. Deleting your Slow Mirror account permanently deletes this account recovery key as well.
Contact form
The in-app "Contact Us" form is a separate, optional feedback channel available whether or not you are signed in. Anything you choose to write there is used only so we can read and reply to you; it is stored completely separately from the usage analytics described above and is never combined with them for analysis.
The form also has two optional fields: a name field (up to 40 characters) and a way to reach you (up to 120 characters — an email address, phone number, or a messaging ID). Both are submitted only if you choose to fill them in, and are used only so we can follow up with you, never for any other purpose. Deleting your account does not retroactively delete past feedback submissions, since feedback is a channel kept separate from the account.
Website analytics
Ultrabirdy uses Google Analytics 4 on this public website to understand page visits. Website analytics is separate from the Slow Mirror app and does not receive your archive, photos, face geometry, account ID, or in-app activity.
Contact
Privacy questions or deletion help: support@ultrabirdy.com
Venoka Tech Ltd