Last updated 3 September 2026 ยท Applies to the FaceTrap Android app (app.facetrap) and facetrap.app
In one paragraph. FaceTrap photographs whoever fails to unlock your phone and emails it to you. To do that we hold those photos, a small amount of context about each attempt, and the email addresses you choose to send them to. We do not sell anything, we run no advertising or tracking SDKs, we never record audio, and we never attempt to identify anyone in a photo. You can export or permanently erase all of it from inside the app at any time.
FaceTrap is operated by DevFact. For anything in this policy, contact [email protected].
| Data | Why | When |
|---|---|---|
| Front-camera photo | It is the product โ the evidence of who attempted the unlock | Only after a failed unlock meeting the threshold you set |
| Rear-camera photo and a short video clip | More context around the attempt | Premium only, and only if you switch them on |
| Attempt context: time, number of attempts, lock method, battery level, network state, device model | Tells you what happened without you having to guess | With each capture |
| Approximate location | Helps you find a stolen device | Off by default. Only if you enable it and grant the permission |
| Recipient email addresses | Where alerts are delivered | When you add one; each is confirmed by a code before it can receive anything |
| Account email and a password hash | Signing in, and linking your devices | If you create an account. Passwords are stored only as bcrypt hashes |
| Device identifiers: an app-generated install ID, and a push token | Routing alerts to the right phone | On install |
| Purchase records | Confirming a subscription with Google Play | Only if you buy Premium |
Captures go to the recipients you configured, and nobody else. We use a small number of processors purely to make that happen:
| Processor | What it handles |
|---|---|
| Cloudflare R2 | Encrypted storage of capture photos and video |
| Our email provider | Delivering alerts to your recipients |
| Google Firebase (FCM) | The push notification telling your phone a capture happened. The notification carries no photo. |
| Google Play Billing | Verifying purchases, if you subscribe |
We do not sell personal data, and we do not share it for advertising. We would disclose data only where legally compelled, and we treat a request about your own device as your call to make.
All of these are in the app, under Settings โ no need to email anyone:
If you are in the EEA or UK, the lawful basis is your consent (which you give during setup and can withdraw by disarming or uninstalling) and our legitimate interest in protecting a device you own. You may also lodge a complaint with your local data protection authority.
Our servers are in the EU, and capture storage is in the EU region of Cloudflare R2. Email delivery and push notifications may route through providers operating internationally.
FaceTrap is not directed at children under 13, and we do not knowingly collect their data. A parent managing a family device remains responsible for how it is used.
FaceTrap is for a device you own or are explicitly authorised to manage. Installing monitoring software on someone else's device without their knowledge is illegal in most jurisdictions. We gate this with an acknowledgement during setup, and accounts used to monitor others without consent will be terminated.
If we change this policy we will update the date above, and for anything material we will notify you in the app before it takes effect.
Privacy questions: [email protected]
Anything else: [email protected]