← Back to Tumble

Privacy

Last updated September 5, 2026.

Photos and local storage

Tumble processes photos on your device. An account is optional and is used only for purchases and cross-platform purchase linking. An unfinished edit is kept as one recoverable private draft. The draft source and recipe are removed after a successful save or when you choose Discard.

Android draft files are excluded from cloud backup and device transfer. On iOS, photos created by older Tumble versions remain in the private Legacy Drawer until you export or delete them. Tumble does not upload draft or Legacy Drawer photos.

Tapping Save or Share creates an image without source or location metadata. Images saved to the system photo library may sync through your own iCloud Photos, Google Photos, or other device settings; those services are controlled by you and are not Tumble cloud sync.

Optional Tumble account

If you choose Continue with Apple or Continue with Google, Firebase Authentication processes the account identifier and provider details needed to sign you in. Tumble does not use Firebase Analytics, Firestore, Storage, or any photo-upload service.

Provider accounts are never merged merely because email addresses match. You can link providers, sign out, or request account deletion from Settings. You can also follow the steps on our account-deletion page. Signing out removes account-linked access on that device but does not remove purchases owned by its current store account.

Camera and photo-library access

Tumble asks for camera permission only when you choose to use the camera. Import uses the iOS or Android system photo picker, so the app does not request broad access to your photo library. Camera and import remain separate choices if camera access is denied.

Saving explicitly writes the finished JPEG to your photo library. A failed save leaves the private draft available so you can retry.

Optional analytics and diagnostics

Analytics is off by default on iOS and Android. After your first successful save, Tumble offers an optional choice to share anonymous product events, crash diagnostics, and masked session replay through PostHog. Nothing is sent to PostHog before you consent.

Tumble never includes photo pixels, filenames, private draft IDs, crop contents, handwritten notes, or photo-library metadata in analytics events. Replay masks images and text; camera and Studio content is excluded or paused wherever masking cannot be verified.

You can change this choice in Settings. Turning analytics off stops capture, clears queued events, and resets the anonymous analytics identity. Tumble does not use analytics for advertising or tracking across other companies’ apps and websites.

Purchases

Tumble Complete is a one-time purchase handled by Apple StoreKit or Google Play Billing. The app uses store transaction information to unlock premium films and restore purchases. When you choose to link purchases, RevenueCat processes an opaque Firebase user ID and store purchase history to synchronize eligible film ownership across iOS and Android. Tumble does not send your email address or any photo, filename, note, crop, or draft identifier to RevenueCat. Retired iOS products remain restorable for legacy ownership.

Website and waitlist

If you joined the launch list, we stored your email address, signup source, timestamp, and browser user agent in Firebase so we could send the App Store launch email and reduce spam submissions.

If you email support, we receive the contact information and message you choose to send.

Your choices

Want off the launch list or need a privacy request handled? Email [email protected] and we will delete your waitlist address or respond to your request.