Privacy Policy
Effective date: 2025-09-18
This Privacy Policy describes how Colorium Lab (the “App”) collects, uses, stores, and shares information when you use our mobile application. Please read it carefully. By using the App, you agree to this Policy.
If you have questions, contact us at: support@example.com (update this email).
Summary
- We collect account information if you sign in (email, display name, provider IDs) via Firebase Authentication.
- We process images from your device’s camera or photo library to analyze color locally on your device. By default, images and derived results stay on-device unless you explicitly share or back them up.
- We collect diagnostic and usage data (analytics, crash reports, performance traces) through Firebase to improve reliability and UX.
- We collect device metadata (model, OS version, hardware info) for calibration accuracy and troubleshooting.
- We make a non-personal request to a third-party color name API when showing a color’s common name.
- We do not sell your personal data.
What We Collect
1) Account & Authentication Data
Collected when you create or sign in to an account.
- Email address and display name (if provided)
- Authentication provider information (e.g., Google, Apple) and provider tokens/identifiers handled by Firebase Authentication
- Firebase user ID (UID), email verification status
Sources: Provided by you and your sign-in provider(s). Stored by Firebase Authentication. We do not collect your password when using social sign-in providers.
2) Images and Analysis Inputs
Collected when you capture or select an image for analysis.
- Image data you capture via the camera or select from your gallery
- Extracted technical metadata (EXIF) from selected images, limited to camera make/model, lens model, capture date/time, software, exposure time, f‑number, ISO, focal length, image dimensions, orientation, white balance, and color space
- IMPORTANT: The App does not read GPS location from EXIF in the current implementation. If a future version adds this, we will update this Policy and request consent where required.
Processing: Images are processed on-device. We do not upload images to our servers by default. If you choose to share or export a report (e.g., PDF), the App may temporarily store a file on device for sharing.
3) Device and Platform Metadata
Collected to support calibration and diagnostics.
- Device model, manufacturer/brand, OS/platform name, OS version, hardware identifier (e.g., iOS machine code), is-physical status
Source: device_info_plus (on-device). Used to improve calibration accuracy, show device context in exported reports, and aid troubleshooting.
4) Usage, Analytics, Performance, and Crash Data
Used to improve quality and reliability.
- Event analytics (e.g., screen views, feature usage patterns)
- Crash reports and error diagnostics (stack traces, device state at crash)
- Performance metrics (app startup, network timing, UI responsiveness)
Sources: Firebase Analytics, Firebase Crashlytics, Firebase Performance. In release builds, collection is enabled by default. In debug builds, it may be disabled.
5) Local App Data & Preferences
Stored on your device to provide functionality and offline access.
- Sample and project records (analysis results, titles, notes, timestamps, and optional embedded thumbnails)
- Calibration profiles and metadata (lighting condition, computed patch data, device info, extracted EXIF fields listed above)
- App preferences and state (via shared_preferences)
Sources: Hive (local database), shared_preferences, path_provider. This data remains on-device unless you explicitly export/share it.
6) Network Requests to Third Parties
Non-personal requests may be made to third parties to enhance the experience.
- Color name lookup: We request https://api.color.pizza with a color hex value (derived from your sample). This request does not contain personal identifiers.
- Authentication and platform services: Google Sign-In, Sign in with Apple, and Firebase services.
We do not send your raw images to these services. Standard device/network metadata (e.g., IP address) may be visible to them as with any internet request.
How We Use Your Information
- Provide core features (account access, camera/galleries, analysis and calibration)
- Show color names and generate shareable/exportable PDFs
- Improve performance, stability, and usability (analytics, crashes, performance tracing)
- Secure our services (Firebase App Check)
- Communicate with you (e.g., verification emails, account recovery)
Legal Bases (EEA/UK where applicable)
- Consent: For camera/photos access and analytics where required.
- Contract: To provide requested features when you use the App.
- Legitimate interests: Improve security, performance, and product quality.
Data Sharing and Disclosure
We do not sell your personal data. We share information with vendors only as needed to provide the App:
- Firebase (Authentication, Analytics, Crashlytics, Performance, App Check)
- Google (Google Sign-In)
- Apple (Sign in with Apple)
- Color name API (color.pizza) for non-personal hex lookups
These vendors may process data outside your country. See “International Transfers.”
Retention
- Account data: Kept while your account remains active. Delete your account to remove it from Firebase Authentication.
- Local content (samples, projects, calibration profiles): Stored on your device until you delete it or uninstall the App. We do not back it up to our servers by default.
- Analytics/performance/crash data: Retained by Firebase per their policies.
Your Choices & Rights
- Permissions: You can grant/revoke camera and photo library permissions in system settings.
- Access/Correction/Deletion: Request account deletion via in‑app controls (if available) or by contacting us. Deleting the App does not automatically delete your Firebase account.
- Analytics Opt‑out: Use device settings for ad tracking/analytics where supported. Platform-level privacy controls may limit analytics.
- Data portability & objection (where applicable): Contact us using the email above.
Children’s Privacy
The App is not directed to children under 13 (or minimum age required by your jurisdiction). We do not knowingly collect personal data from children. If you believe a child provided personal data, contact us to remove it.
International Transfers
Our vendors (e.g., Firebase by Google) may process data globally. Where applicable, transfers rely on appropriate safeguards (such as Standard Contractual Clauses).
Security
We use reasonable technical and organizational measures to protect information, including platform‑provided security and Firebase security features. No method of transmission or storage is 100% secure.
Permissions We Request
- Camera: Capture images for analysis and calibration.
- Photos/Media/Library: Select images for analysis and, if you choose, save or share exports.
- Storage (Android): Read images (READ_MEDIA_IMAGES/READ_EXTERNAL_STORAGE) and write temporary export files.
- Network: Access internet for authentication, analytics, crash/performance reporting, and color name lookups.
- Microphone: Not used by current features. Although an iOS usage description string exists, the App does not request or record audio in current versions.
Third‑Party Links & Content
The App may include links or use third‑party features. Their privacy practices are governed by their own policies.
Changes to This Policy
We may update this Policy to reflect changes in our App and practices. Material changes will be indicated by updating the “Effective date” and, where appropriate, in‑app notice.
Contact Us
Email: info@cuboidinc.com
Publisher: Colorium Lab by Cuboid (PRIVATE) Limited
