Us Roll

Privacy policy

Effective 25 August 2026

The short version

  • We do not run ads, and there are no advertising or tracking SDKs in the app.
  • We do not sell or share your personal information, and we never will.
  • Your photos belong to the roll you shot them on. They are not published anywhere.
  • We never train any model on your photos, and no AI touches them.
  • Location is used only while a roll is live, only to work out who is together, and is never stored after that roll ends.
  • You can delete your account from inside the app. Frames you shot on a roll that has already developed stay with that group — section 9 says exactly what goes and what does not.
  1. Who we are
  2. What we collect
  3. Your photos
  4. Location
  5. What we never do
  6. Who we share data with
  7. Where data lives, and how long
  8. Your choices and rights
  9. Deleting your account
  10. Children
  11. Security
  12. Changes to this policy
  13. Contact

1. Who we are

Us Roll is an iPhone app made by Flywheel Studio. Flywheel Studio is the data controller for the personal data described here. This policy covers the Us Roll app and this website. It does not cover any other site we link to.

2. What we collect

Everything in this table is listed in the app's privacy manifest and in its App Store privacy labels. Nothing here is used for advertising or cross-app tracking.

WhatWhy
Your name and email, from Sign in with Apple To create your account and let your friends recognise you on a roll. If you use Apple's Hide My Email, we only ever see the relay address Apple gives us.
Your emoji and first name, which you pick This is your identity inside the app. It is what credits your frames in an album.
Photos you take in the app The product. See section 3.
Roll membership — which rolls you are on, who else is on them, how many frames you shot, and when To run the shared roll, credit each frame, and open the album to the right people at the right time.
Coarse location, only while a roll is live To work out who is together. See section 4.
A device identifier — a random ID we generate and keep in your iPhone's Keychain To tell your devices apart, so an iPhone and an iPad do not overwrite each other's settings. It is not Apple's advertising identifier, and it is not used for advertising.
Device and app details — model, iOS version, app version and build, language, time zone, and which permissions you have granted To support the app, to know which iPhones and iOS versions to test against, and to show the right thing when a permission is off.
Usage events — when you open the app, and which steps of a flow you reached (for example: paywall viewed, roll created, album opened) To see where the app confuses people and fix it. Collected only in App Store builds.
Performance data — launch time, request latency, memory and CPU use To find and fix what is slow or crashing. Collected only in App Store builds.
Purchase status — whether you have an active subscription or pass To unlock hosting for people who have paid, and to restore purchases on a new phone. We never see your card. Apple handles the payment.

What our analytics does not capture

Our product analytics records a screen's shape — how deep it is, what kind of view it is, roughly how big, and whether it contains any text at all — as a way of telling one screen from another. It records a yes-or-no for text; it never records the text. It does not take screenshots or thumbnails, and no on-screen wording, message, name, or photo is sent through it. Analytics is switched off entirely outside App Store builds — in a debug, simulator, or TestFlight build the SDK is never started.

3. Your photos

4. Location

Location is the app's most sensitive surface, so here is exactly how it is handled.

5. What we never do

6. Who we share data with

We use a small number of service providers to run the app. They process data on our instructions and for no purpose of their own. This is the whole list.

ProviderWhat it does for us
Google (Firebase) Sign-in, the database of rolls and accounts, photo storage, server-side logic, abuse protection, remote configuration, and performance monitoring. This is where your account and your photos live.
Apple Sign in with Apple, and all payment processing for subscriptions and passes. We never receive your payment details.
RevenueCat Keeps track of whether your subscription or pass is active, so hosting unlocks on every device you sign in on.
ULink Turns an invite into a link that opens the right roll, including after you install the app for the first time.
AnalyticsDrop, operated by Flywheel Studio Product analytics — the usage events in section 2. Our own service, not a third-party ad platform.

We will also disclose data if the law requires it — a valid legal request, a court order — or to protect someone's safety. If Flywheel Studio is ever acquired, your data may transfer to the buyer, who would be bound by this policy until they give you notice of a new one.

7. Where data lives, and how long

8. Your choices and rights

Wherever you live, you can ask us to give you a copy of your data, correct it, or delete it. Write to privacy@usroll.app and we will answer within 30 days.

9. Deleting your account

You can delete your account from inside the app, and you do not have to email anyone to do it. Deleting your account removes:

It also ends your sign-in: we delete the account with our sign-in provider and revoke the grant on Apple's side, which is what stops us from being able to identify you again.

What deleting your account does not remove

Be clear about this before you delete, because we cannot undo it afterwards.

Deletion completes within 30 days, and within 90 days in encrypted backups.

10. Children

Us Roll is rated 17+ and is not for children. We do not knowingly collect personal data from anyone under 13, or under 16 in the UK and EEA. If you believe a child has given us data, write to privacy@usroll.app and we will delete the account.

11. Security

Data is encrypted in transit and at rest. Access to a roll's photos is enforced by server-side rules rather than by the app, so a modified client cannot read a roll it is not on, or read any roll before it develops. The app verifies that requests come from a genuine, unmodified copy of Us Roll before the server accepts them. No system is perfect; if you find a security problem, write to security@usroll.app and we will respond.

12. Changes to this policy

If we change this policy in a way that matters, we will change the effective date at the top and tell you in the app before the change takes effect. We will not start selling your data, running ads, or training models on your photos through a quiet policy update.

13. Contact

Privacy questions and data requests: privacy@usroll.app
Anything else: hello@usroll.app
Flywheel Studio · flywheel.so