Effective September 17, 2026
Privacy Policy
Your child's photo is used to make your child's photo. That is the whole of it, and the rest of this page is the detail.
TotShot is a mobile app for taking a child's document photo at home. It is operated by HakkApps, LLC, a company registered in Delaware, USA, which is the data controller for everything described here.
This policy covers the TotShot app and totshot.app. The company publishes a separate policy for its own site at hakkapps.dev; neither stands in for the other.
1. What TotShot does
You pick a country and a document. The app loads the requirements that issuing authority publishes, guides the shot, and sends the frame to our servers, which measure it against those requirements and return a print-ready file.
Two things happen in two different places, and the difference is the whole privacy story: finding the face and guiding the capture happen on your phone, offline, with nothing leaving the device. Measuring the result, replacing the background and producing the final file happen on our servers.
2. What we collect
- Your account. An email address, or the identifier and email address Apple or Google release when you sign in with them — if Apple gives you a private relay address, that is all we ever see. Plus the language you read in.
- Your child. A name, and optionally a nickname and a date of birth. The date of birth does one job: several authorities allow a younger child closed eyes or a looser head size, and the app has to know which rule is yours.
- Photos. The frame you capture, the previews made from it, and the finished file.
- Measurements taken from the photo. Head height, eye line, crown margin, sharpness, exposure, the crop we applied, the verdict, and the exact version of the requirement your photo was judged against.
- Purchases. Which credit pack you bought, and the receipt Apple or Google gives us so we can verify it. Card numbers never reach us — buying happens inside the store's own purchase sheet.
- Notifications. A push token, if you allow notifications.
- How you use the app. Named events for the steps of a session — a shot captured, a verdict shown, a credit pack bought — each carrying numbers and a session id. Never the photo, and never the measurements taken from it.
- Roughly where you are. Google derives a city-level location from the IP address your usage events arrive from. The device itself never reports its location to us, and the app asks for no location permission.
- Crash reports. When the app fails: the error, the stack trace, the device model and OS version, and the id of the account it happened to, so a crash that hits one person can be traced rather than guessed at.
- Server logs. Our servers record the IP address and time of a request, as every web service does, for security and abuse prevention. An IP address can be personal data, so it is named here rather than passed over.
There is nothing else. TotShot asks for no address and no phone number, reads no advertising identifier, and shows no advertising. The usage events and crash reports above are keyed to a random per-install id and to your account, never to an ad profile.
3. The measurements are geometry, not a faceprint
The numbers we take off a photo exist to crop a picture and to judge it against a published rule — how tall the head is in the frame, where the eyes sit, how much room is above the crown.
We never use them to identify anyone. They are not a biometric template, they are never matched against another photo or another person, and no face recognition of any kind runs on them. When the photo they came from is deleted, they are deleted with it.
4. A child's data, and why it is here
TotShot is used by an adult on behalf of a child. The account holder must be 18 or over; the child is the subject of the photograph, not a user of the app.
Their name, their date of birth if you gave one, and their photograph are used for a single purpose — producing and judging that photograph. They are never used for advertising, never sold, never shared for anyone else's purposes, and never used to train any model.
5. How long we keep it
TotShot is a camera and a validator, not a photo library. Everything expires on its own:
- A frame you uploaded but never turned into a session — 24 hours.
- The sources and previews of a session, and the renders of photos you did not buy — 72 hours. This is also why re-cropping a shot stays free for three days.
- A photo you bought — your retention window: 7, 30, 90 or 365 days, or kept indefinitely. The default is 365 days. You can change it in the app at any time and it applies to the photos you already have.
A year is the default because a child's document photo stops being usable well before that — the child has changed. Keeping it longer serves nobody.
When a photo goes, the measurements taken from it go with it. What outlives a single deleted photo is the receipt — which document, when, whether it passed, which credit was spent — because you may still need to query a charge. It is shown nowhere in the app.
Download links are minted fresh each time you open a photo and expire after an hour. Nothing in our storage is publicly listed or publicly reachable.
6. Deleting your account
You can delete your account in the app, and it is unconditional. Your photos, the frames behind them, every measurement, the receipts, your child's details, your credit balance, your push tokens and your sessions are hard-deleted across every service that held them. Nothing is kept as a marker that you were here, and a part that fails is retried until it confirms rather than quietly left behind.
Unused credits are destroyed with the account and are not refundable, so spend them or ask us first. You can also delete any single photo at any time, or write to support@totshot.app and we will do it for you.
7. Who else touches it
We do not sell or trade personal data. It reaches exactly these companies, each for one job:
- Apple and Google — signing in, and buying credits. They confirm to us that a purchase is real; we tell them nothing about your child. Apple can also ask what became of a purchase when you request a refund — the section after this one is about exactly that.
- Google (Firebase Cloud Messaging) — delivering a push notification to your device, if you turned notifications on.
- Google (Firebase Analytics and Crashlytics) — counting the usage events above and receiving crash reports. This is how we learn that a step of the flow is failing for people who never write to us. Google processes it on our instructions and on servers in the United States.
- Resend — sending account and support email.
- Our hosting provider — running the servers the app talks to.
Background removal runs on our own servers, inside a private network. Your child's photo is never sent to a third-party AI service, and it is never sent to Google: the analytics and crash SDKs above see event names, numbers and identifiers, and no image data of any kind. The app carries no advertising or ad-tracking SDK.
8. If you ask Apple for a refund
When you request a refund through the App Store, Apple may ask us what became of the purchase, and gives us a short window to answer. We answer. It is the only point at which we can say anything at all, and a request nobody answers is decided without us. Google Play has no equivalent step, so none of this applies to a purchase made there.
What we send is a summary, not a record: how much of the pack had been spent, whether the finished photos had been delivered, and the lifetime value of your purchases and your refunds as a range rather than an amount — and not even the range if any of your purchases were in another currency, because a dollar figure we cannot state is one we will not estimate. It is attached to the purchase by the token the store issued for it, and to nothing else.
We also tell Apple what we think the answer should be, and you are entitled to know the rule we use, because it is the whole of it: if you never spent the credits, we say the refund should be granted. If you spent all of them, we say it should be declined. If you spent some, we state no preference. We do not ask Apple to refuse a refund for something you never used.
We never send your photographs, and we send no personal data beyond that purchase identifier. Apple also asks how long you have held the account and how long you have spent in the app. We answer "not declared" to both, rather than estimate something we would then be asserting.
9. Where it is kept, and how
Our servers are in the European Union, rented from a commercial hosting provider. We name the region rather than the provider: the provider can change, the region is the commitment. Photos and everything measured from them stay there.
Two things leave that region. Usage events and crash reports go to Google in the United States, and push notifications pass through Google and Apple. Both transfers run on the European Commission's Standard Contractual Clauses, which is the mechanism those companies publish for exactly this. Nothing else crosses the border.
Traffic is encrypted with TLS. Photos sit in private storage that is never publicly listed, and every download is a short-lived signed link. Sign-in tokens are held in your device's own keychain or keystore. Access is limited to the services that need it. No system is perfectly secure, and we will not pretend otherwise.
10. This website
totshot.app runs no analytics, serves no advertising, and loads no third-party scripts, fonts or images — every file the page uses comes from this domain. The analytics described above are in the app; this site has none.
The site itself is served by Vercel, our website host, which records the IP address, time and user agent of each request in its access logs for delivery and abuse prevention. That is the only company involved in showing you this page.
It stores one cookie, NEXT_LOCALE, which remembers whether you are reading in English or Russian. It holds no identifier, is read by nobody else, and follows you nowhere.
11. Your rights
You can ask for a copy of your data, a correction, an export, or its deletion. Deletion you can do yourself in the app; for anything else write to support@totshot.app. Every request is answered by a person.
In the EU and the UK these are your rights under the GDPR, and you may complain to your local data protection authority. In California, we do not sell or share personal information as the CCPA defines those words, and exercising a right costs you nothing.
12. Changes
The effective date at the top of this page is the version you are reading. If we change something material, we will say so by email or in the app before it takes effect.
13. Contact
Anything on this page — access, correction, export, deletion, or a question you cannot find the answer to: support@totshot.app. It is the fastest way to reach us and it is read by a person. Post reaches us at the address below.
14. Governing law
This policy is governed by the laws of the State of Delaware, United States.
It is published in English and in Russian. The English version is the one that governs; the translation is there to be read, not to be argued from.