๐Ÿ‘ FaceTrap
HomeTermsSupport

Privacy Policy

Last updated 3 September 2026 ยท Applies to the FaceTrap Android app (app.facetrap) and facetrap.app

In one paragraph. FaceTrap photographs whoever fails to unlock your phone and emails it to you. To do that we hold those photos, a small amount of context about each attempt, and the email addresses you choose to send them to. We do not sell anything, we run no advertising or tracking SDKs, we never record audio, and we never attempt to identify anyone in a photo. You can export or permanently erase all of it from inside the app at any time.

Who we are

FaceTrap is operated by DevFact. For anything in this policy, contact [email protected].

What we collect, and why

DataWhyWhen
Front-camera photoIt is the product โ€” the evidence of who attempted the unlockOnly after a failed unlock meeting the threshold you set
Rear-camera photo and a short video clipMore context around the attemptPremium only, and only if you switch them on
Attempt context: time, number of attempts, lock method, battery level, network state, device modelTells you what happened without you having to guessWith each capture
Approximate locationHelps you find a stolen deviceOff by default. Only if you enable it and grant the permission
Recipient email addressesWhere alerts are deliveredWhen you add one; each is confirmed by a code before it can receive anything
Account email and a password hashSigning in, and linking your devicesIf you create an account. Passwords are stored only as bcrypt hashes
Device identifiers: an app-generated install ID, and a push tokenRouting alerts to the right phoneOn install
Purchase recordsConfirming a subscription with Google PlayOnly if you buy Premium

What we never collect

  • Audio. The app never records sound. This is deliberate โ€” it avoids the two-party consent problem entirely.
  • Biometric identification. We do not run face recognition, matching, or any attempt to work out who a person in a photo is.
  • Your activity. No browsing history, no contacts, no messages, no app usage, no continuous location.
  • Advertising or analytics identifiers. There are no ad SDKs and no third-party trackers in the app or on this website.

Who your data reaches

Captures go to the recipients you configured, and nobody else. We use a small number of processors purely to make that happen:

ProcessorWhat it handles
Cloudflare R2Encrypted storage of capture photos and video
Our email providerDelivering alerts to your recipients
Google Firebase (FCM)The push notification telling your phone a capture happened. The notification carries no photo.
Google Play BillingVerifying purchases, if you subscribe

We do not sell personal data, and we do not share it for advertising. We would disclose data only where legally compelled, and we treat a request about your own device as your call to make.

How long it is kept

  • Captures are kept until you delete them. You can turn on auto-delete in Settings to remove them automatically after 30 days.
  • Links to photos expire. A photo link inside the app lasts 15 minutes; a video link in an email lasts 7 days. After that the link stops working and the file cannot be fetched.
  • Deletion is permanent. There is no recycle bin and no recovery window. When you delete a capture, the stored file goes with it.
  • Purchase records may be retained where tax and accounting law requires, unlinked from your account.

How it is protected

  • Captures waiting to upload are encrypted on your device with AES-256-GCM.
  • All traffic is HTTPS. The app is configured to refuse plaintext connections outright, not merely to prefer encryption.
  • Stored photos are private. They are reachable only through short-lived signed links; an unsigned request is rejected.
  • Passwords are hashed with bcrypt and are never stored or logged in readable form.
  • Recipient addresses are masked in our server logs.

Your rights and controls

All of these are in the app, under Settings โ€” no need to email anyone:

  • Export โ€” download everything held about your device.
  • Delete all captures โ€” erase every photo and record immediately.
  • Delete your account โ€” removes the account and every capture, device, setting and recipient attached to it. See deleting your account.
  • Auto-delete โ€” have captures removed after 30 days automatically.
  • Disarm or uninstall โ€” stops all capture at once.

If you are in the EEA or UK, the lawful basis is your consent (which you give during setup and can withdraw by disarming or uninstalling) and our legitimate interest in protecting a device you own. You may also lodge a complaint with your local data protection authority.

Where data is processed

Our servers are in the EU, and capture storage is in the EU region of Cloudflare R2. Email delivery and push notifications may route through providers operating internationally.

Children

FaceTrap is not directed at children under 13, and we do not knowingly collect their data. A parent managing a family device remains responsible for how it is used.

Responsible use

FaceTrap is for a device you own or are explicitly authorised to manage. Installing monitoring software on someone else's device without their knowledge is illegal in most jurisdictions. We gate this with an acknowledgement during setup, and accounts used to monitor others without consent will be terminated.

Changes

If we change this policy we will update the date above, and for anything material we will notify you in the app before it takes effect.

Contact

Privacy questions: [email protected]
Anything else: [email protected]

Privacy PolicyTerms Delete your accountSupport
ยฉ 2026 FaceTrap