Privacy policy

Vanity keeps your products — photos, names, notes and stamps — on your phone and, if you turn sync on, in your own iCloud account. There is no sign-in, no server of ours, and the label reading happens on the phone.

Last updated September 24, 2026

What the app stores, and where

Every product you add — the photo, the cut-out mask, the brand and name, the size, the types you tagged it with, the stamp, the note, the dates — is written to a database inside the app’s own container on your iPhone. There is no login, no password and no profile attached to it. DM Apps has no copy and no way to read it.

Photos and the label

When you photograph a product, two things happen, both on the phone, using Apple’s on-device image framework:

  • the product is separated from the background, so it can stand on the shelf;
  • the text on the label is read, so the brand, name and size can be suggested.

No image and no text from the label is uploaded anywhere. The suggestions are compared against a list of beauty brands that ships inside the app. A barcode, if one is in the frame, is kept only to recognise the same product when you photograph it again; it is never looked up online.

The camera and the photo library are optional. You can add products from existing photos, or with no photo at all, and the app works fully without either permission.

iCloud

With Pro — the Month or Year plan — you can switch on iCloud sync. Vanity then mirrors its database — photos included — into the private area of your own iCloud account, using Apple’s CloudKit. This is what keeps the shelf identical on two of your devices and what brings it back when you replace a phone.

That data sits under your Apple Account, is governed by Apple’s terms, and is readable only by you and by Vanity on your devices. DM Apps operates no server in this path and receives nothing. Switching sync off in Settings — which you can do at any time, whether or not you are still subscribed — stops the mirroring; the shelf stays on the phone.

Anonymous usage events

The app records a small set of product events — the app was opened, a photo was cut out or the cut-out failed, a product was saved, a stamp was left, a search was run, a paywall was shown, a purchase succeeded, an export was made. These carry counts, yes/no flags and fixed option names from a closed list defined in the app’s source.

Never included in an event, by rule:

  • Product names, brands, sizes and the types you named.
  • Notes, and anything you type into search.
  • Photos, the text read from a label, and barcodes.

If you typed or photographed it, it does not go into an event. If we defined the value — a screen, a stamp from a fixed set of four, a count — it may. There is no automatic screen capture, no session recording and no crash reporting turned on; every automatic collector in the analytics SDK is switched off, and the SDK is not even started while collection is off.

These events are processed by PostHog, an analytics service, on servers in the United States. They are not tied to a name, an email or an account, because Vanity has none of those; the only identifier is a random value created at install that identifies a copy of the app, not a person. They are not used for advertising and are not shared with anyone else.

You can switch this off. Privacy & about in Settings has a Usage statistics toggle that stops collection and discards anything still waiting to be sent. The app works exactly the same with it off.

Purchases

The Month and Year subscriptions are handled by Apple through the App Store. DM Apps receives no card details and no billing address. The app knows only whether a plan is active. Cancelling never removes anything you have added.

Export and sharing

Back up & export writes either a PDF of your products or a full backup — a ZIP with every product and its photos — into a temporary file and hands it to the system share sheet; where it goes from there is your choice. The file is deleted from the temporary folder once the share sheet closes. Restore from a backup reads only the ZIP file you pick yourself, on the phone, and adds its products back to your shelf; nothing is uploaded. Sharing a product card produces an image in memory, and nothing is saved by the app.

What the app never does

  • No advertising, no ad identifiers, no ad networks.
  • No selling or sharing of data with third parties.
  • No tracking across other apps or websites, and no App Tracking Transparency prompt, because there is nothing to track.
  • No skin diagnosis, no health data, no contacts, location or microphone access.
  • No notifications: the app never asks for permission to send them.

Deleting everything

Deleting a product inside the app removes it and its photo, on every device signed in to the same iCloud account when sync is on. Removing the app from the phone removes the local database; the copy in your private iCloud is removed by turning Vanity off in the system iCloud settings, or by deleting the app’s data from iCloud storage settings.

Children

Vanity is a tool for adults who buy cosmetics. It is not directed at children, is not in the Kids Category, and collects nothing that would identify anyone.

Changes

If this policy changes, the date at the top changes with it, and the change is described in the app’s release notes.

Contact

Questions about any of this go to support@dmapps.app. See also the support page.