This Privacy Policy describes how Razz AI (“Razz”, “we”, “us”) collects, uses, and shares information when you use the Razz AI mobile application (the “App”). By using the App you agree to the practices described here.
1. Information we collect
Account information
The App lets you sign in with Google or Apple. When you sign in, we receive your email address and a unique user identifier from the provider. If you sign in with Apple and choose to share a name, we receive that too. We do not collect or store passwords; authentication is handled entirely by Google, Apple, and Firebase Authentication.
Content you submit for generation
When you create an AI generation, we collect the inputs you provide:
Photos you capture with the in-app camera or select from your device library (up to 14 images per job, up to 15 MB each).
Text prompts you write (up to 2,000 characters).
The template you selected, quality setting, aspect ratio, and media type (image or video).
Screenshots of conversations you select for the Music feature, and the messages we extract from them. See “Conversation screenshots and songs” below.
Face data
Some of the photos you submit for a generation may contain faces — including your own face when you take a selfie or choose a photo of yourself. We treat these photos and any faces they contain (“face data”) as sensitive personal information, and we handle them as described below. This section explains our collection, use, disclosure, sharing, and retention of face data; sections 2, 3, and 4 add further detail on use, sharing, and retention.
What we collect and how. Face data is collected only from the photos you actively capture with the in-app camera or select from your device’s photo library and then submit for a generation. We collect it only at the moment you choose to create a generation — the App does not scan your photo library and does not capture images in the background.
How we use it. We use your face data solely to perform the AI generation you request — that is, to produce the edited image or video you asked for. We do not use face data to identify or recognize you, and the App does not create, derive, or store any faceprint, facial-geometry template, face embedding, or other biometric identifier. The App performs no facial recognition. We do not use face data for advertising, and we never sell it.
Your permission before sharing. Before any photo containing face data leaves your device and is sent to our AI generation provider, the App asks for your explicit consent. If you do not grant consent, the photo is not uploaded and the generation does not run.
Who we share it with. To perform the generation we send the photo to Fal.ai, which runs third-party AI models on our behalf — Google’s Gemini for image edits and xAI’s Grok for video. If you use the Music feature and your screenshots contain faces (for example profile pictures), those images are sent instead to Google’s Gemini on Vertex AI, as described under “Conversation screenshots and songs” below. We share only what is needed to fulfil your request. Fal.ai, Google, and these model providers are contractually required to protect your data with safeguards at least equivalent to those described in this policy and to use it only to perform your requested generation, not for their own purposes.
Where it is stored and for how long. Photos you submit are stored temporarily in Google Firebase Cloud Storage in the United States and are automatically deleted after 7 days, or immediately when you delete your account. The generated output is held briefly on Fal.ai’s CDN (approximately 7 days) so the App can deliver it to your device. We do not retain a separate biometric template or faceprint at any time.
Conversation screenshots and songs
The App’s Music feature turns a chat conversation into a song. Because this flow sends your screenshots to a different provider than image and video generation, we describe it separately here.
What we collect and how. You choose screenshots of a conversation from your device’s photo library and submit them for a song. We collect them only at the moment you create a generation; the App does not scan your photo library. These screenshots contain the message text visible in them, which may include messages written by other people, along with names, handles, timestamps, and profile pictures.
Your permission before sharing. Before any screenshot leaves your device, the App asks for your explicit consent and names the providers it will be sent to. Consent for the Music feature is asked for separately from consent for image and video generation. If you do not grant it, nothing is uploaded and the song is not created.
Who we share it with, and what each receives. The screenshots are sent from your device to Google, whose Gemini model (gemini-2.5-flash, run via Vertex AI) reads the messages out of the images and returns them as text. We then build lyrics and a musical style from that text and send those — not the screenshots — to ElevenLabs, which composes the audio. Google and ElevenLabs are contractually required to protect your data with safeguards at least equivalent to those described in this policy and to use it solely to perform your requested generation, not for their own purposes or to train their models.
Where it is stored and for how long. The screenshots themselves are never uploaded to our servers — they are sent from your device straight to Google for reading, and we do not keep a copy. What we do store, in Firestore in the United States, is the text extracted from them: the message list, the lyrics and composition plan built from it, and an estimate of each conversation side’s gender that the model infers from the screenshots in order to pick a fitting voice. That text is retained as part of your generation history for as long as your account exists, and is deleted when you delete the song or your account. The finished audio is stored in Firebase Cloud Storage so you can play it back from your history.
Other people’s messages. A conversation screenshot usually contains someone else’s words. Only upload conversations you are comfortable sharing, and do not upload conversations you do not have the rights to. You are responsible for the content you submit.
If we change the provider that composes the audio, we will update this policy and the in-App disclosure before the change ships.
Generated content and history
We store metadata for each generation job — including its status, the model used, the cost in credits, and a reference to the resulting image, video, or song — so that you can view your history inside the App.
Subscription and credit data
To deliver subscriptions and credit bundles, we store your subscription status, renewal date, remaining credit balance, daily usage, and a ledger of credit grants and charges. We receive purchase and renewal events from RevenueCat, our in-app purchase processor.
Product analytics
We use PostHog, a third-party product analytics service, to understand how the App is used so we can fix bugs and improve features. PostHog receives:
A distinct identifier — your Firebase user ID once you sign in.
Your email address, attached as a user property after sign-in.
Your platform (iOS, Android, etc.).
Events describing in-App actions you take — for example, opening a screen, tapping a button, starting or finishing a generation, opening or dismissing a paywall, completing or restoring a purchase, or changing language or theme.
Non-content properties attached to those events — for example, the template you selected, the media type and quality, the length of your prompt (not its contents), the model used, the credit cost, and error codes when something fails.
We do not send the contents of your prompts or your photos to PostHog, and we never send face data to PostHog. PostHog also automatically logs technical information such as IP address, device type, and timestamp for purposes of operating its service.
Information we do not collect
We do not record audio. The App does not capture sound during photo capture.
We do not perform facial recognition and do not collect biometric identifiers such as faceprints or facial-geometry templates.
We do not embed advertising or ad-tracking SDKs.
We never receive your payment card details. All purchases are processed by Apple or Google through their respective app stores.
Information collected automatically by our providers
Our infrastructure providers (listed in section 3) may automatically log technical information such as IP addresses, device identifiers, request timestamps, and error data for purposes of operating their services and preventing abuse. We do not combine this technical data with your generation content.
2. How we use information
To authenticate you and maintain your account.
To process the photos and prompts you submit — including any faces they contain — and return the AI-generated images or videos you request. We do not use face data for facial recognition or to build any biometric profile.
To read the messages out of conversation screenshots you submit to the Music feature, and turn them into the lyrics and audio of the song you request.
To track and enforce your credit balance, daily allowance, and subscription entitlements.
To show you your generation history.
To diagnose errors, prevent abuse, and improve the reliability of the App.
To understand how the App is used and improve features through product analytics.
To comply with legal obligations.
3. How we share information
We do not sell your personal information. We ask for your permission — naming the providers involved — before sending photos that may contain face data, or conversation screenshots, to any AI provider. We share information only with the service providers that make the App work:
Google Firebase (Authentication, Firestore, Cloud Storage, Cloud Functions) — hosts your account, generation history, credit ledger, and temporarily stores the photos you upload. Firebase data is stored in the United States (region nam5).
Fal.ai — performs the actual AI image and video generation. With your consent (see “Face data” in section 1), we send your prompt and a short-lived signed link to your input image(s) — which may contain face data — to Fal.ai. Fal.ai runs third-party models on our behalf, including fal-ai/gemini-3.1-flash-image-preview/edit (Google’s Gemini) for image edits and xai/grok-imagine-video (xAI’s Grok) for video generation. Fal.ai and these model providers are contractually required to protect your data with safeguards at least equivalent to those described in this policy and to use it solely to perform your requested generation. The generated output is stored on Fal.ai’s CDN for a limited time so the App can deliver it to your device.
Google (Gemini on Vertex AI) — reads the messages out of conversation screenshots for the Music feature. With your consent (see “Conversation screenshots and songs” in section 1), the App sends the screenshots you selected — which may contain other people’s messages and profile pictures — from your device to gemini-2.5-flash via Vertex AI, which returns the messages as text. Google is contractually required to protect this data with safeguards at least equivalent to those described in this policy, to use it solely to perform your requested generation, and not to train its models on it.
ElevenLabs — composes the audio for songs created with the Music feature. We send the lyrics and musical style built from your extracted messages to ElevenLabs’ music API, and receive the finished audio and word timings. We do not send your screenshots, photos, or face data to ElevenLabs. ElevenLabs is contractually required to protect this data with safeguards at least equivalent to those described in this policy and to use it solely to render your requested song. If we switch the audio provider (for example to MiniMax, an alternative music provider), we will update this policy and the in-App disclosure before the change ships.
RevenueCat — manages subscription and bundle purchases. We send your Razz user identifier to RevenueCat so it can associate a purchase with your account. RevenueCat sends us purchase, renewal, and cancellation events.
PostHog — provides product analytics. We send your Firebase user identifier, email address, platform, and a stream of in-App and server-side events (with non-content properties such as template, media type, quality, model, and credit cost) so we can understand how the App is used. We do not send your photos or face data to PostHog. PostHog stores this data in the United States.
Apple and Google — process the actual payment for in-app purchases through their respective app stores under their own privacy terms.
We may also disclose information when we believe in good faith that disclosure is required by law, legal process, or to protect the rights, property, or safety of Razz, our users, or the public.
4. Data retention
Photos you upload as input — including any face data they contain — are automatically deleted from our storage after 7 days, or immediately when you delete your account. We do not create or retain any separate biometric template or faceprint.
Conversation screenshots you submit to the Music feature are not retained by us at all — they are sent from your device directly to Google for reading and are never uploaded to our storage.
Generated media URLs we receive from Fal.ai expire on Fal.ai’s side after a limited window (approximately 7 days). After expiry, the generation appears in your history without a viewable image.
Generation metadata (prompt text, template, status, cost) is retained in Firestore for as long as your account exists, so that your history is available. For songs this includes the messages extracted from your screenshots and the lyrics generated from them.
Account, subscription, and credit ledger records are retained while your account is active and for as long as required to meet our legal and tax obligations.
Media you choose to save to your device’s photo library remains on your device until you delete it. Saved photos are placed in the “Razz” album.
5. Security
Data sent between the App and our infrastructure is protected in transit by TLS. Data stored in Firebase Authentication, Firestore, and Cloud Storage is encrypted at rest by Google. The App does not implement custom cryptography. While we use commercially reasonable safeguards, no system is perfectly secure and we cannot guarantee absolute security.
6. Your rights and choices
Access and deletion
You can view your generation history at any time inside the App. To request a copy or deletion of the personal information we hold about you — including your Firebase account, Firestore data, and any stored uploads — contact us at the address in section 10. We will respond within a reasonable time and in accordance with applicable law.
Subscription management
You can manage or cancel an active subscription from the “Manage Subscription” option in the App, which opens the RevenueCat customer center, or directly from your Apple ID or Google Play account settings.
Device permissions and consent
You can revoke the App’s access to your camera and photo library at any time from your device’s system settings. Revoking these permissions may prevent you from creating new generations or saving outputs. Separately, the App asks for your explicit consent — naming the providers that will receive your data — before sending any photo that may contain face data, or any conversation screenshot, to an AI provider; if you decline, nothing is uploaded and the generation does not run. Because the image, video, and Music features send your data to different providers, each asks for its own consent, and agreeing to one does not grant the others.
Regional rights
Depending on where you live, you may have additional rights under laws such as the EU General Data Protection Regulation (GDPR), the UK GDPR, or the California Consumer Privacy Act (CCPA), including the right to access, correct, delete, port, or restrict processing of your personal information, and the right to lodge a complaint with a supervisory authority. Contact us to exercise these rights.
7. Children’s privacy
The App is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
8. International data transfers
Our service providers are located primarily in the United States. If you access the App from outside the United States, your information will be transferred to and processed in the United States and other countries where our providers operate. Where required, we rely on appropriate safeguards for these transfers, including standard contractual clauses.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Effective date” above and, where appropriate, notify you within the App. Continued use of the App after a change becomes effective indicates your acceptance of the updated policy.
10. Contact us
If you have questions about this Privacy Policy or want to exercise your rights, contact us at abi@stickgen.app.