Clear by design
Privacy Policy
This policy explains what LookYLook processes, why it is processed, where it is stored, and how long it is retained.
19 Jul 2026
1. Short summary
LookYLook has no proprietary account system, advertising, or tracking. Photos remain in Apple Photos. Smile Auto-Capture analyzes camera frames temporarily on-device and does not persist or share face-analysis data. Only feedback you deliberately submit and, if you opt in, aggregate daily counts of played sounds are stored through Apple CloudKit.
2. Data controller
Dennis Nederhof, developer of LookYLook, operating as Xiut in the Netherlands
Privacy and support questions: support@xiut.nl, the Support page, or the Xiut contact page.
3. Data processed
3.1 Camera and photos
- LookYLook uses the camera for live preview and photo capture.
- Photos you capture are stored through Apple frameworks in your Photos library and, where applicable, in the LookYLook album.
- LookYLook uses your Photos library only to perform features you choose, such as saving, displaying, sharing, or deleting photos.
- The developer does not receive or store your photos in CloudKit or on developer-owned servers. If iCloud Photos is enabled, Apple manages synchronization according to your Apple settings.
3.2 Face data and Smile Auto-Capture
- When Smile Auto-Capture is enabled, LookYLook analyzes live front-camera frames only on the device to determine whether a smile is visible.
- The analysis is used only to trigger a photo. It is not used for face recognition, identification, profiling, or tracking.
- Temporary frames and derived measurements, such as face bounds, a mouth-width baseline, and smile or stability scores, exist only in volatile memory during a short rolling analysis window. This state is cleared when analysis stops, including when the feature is disabled, the face is lost, capture starts, the camera changes, or the app leaves active capture.
- LookYLook never writes or transmits these measurements, facial landmarks, depth data, biometric templates, or other separate face-analysis data. No face-analysis data is kept between app sessions.
3.3 Feedback and support
If you voluntarily submit feedback, LookYLook stores the following in Apple's CloudKit public database:
- the free-form text you enter;
- the feedback entry point and submission date;
- app version, build number, and iOS version;
- the number of gallery opens at the time of submission.
Feedback submitted by app versions before 2.1 may also contain the device model, language/region setting, and a coarse response category from the review or support flow. Version 2.1 no longer collects those three legacy context fields. Existing legacy feedback is used only for the same support and product-improvement purposes and follows the same retention and deletion rules below.
This context is used to understand feedback, investigate problems, and provide support. Free-form feedback is limited to 2,000 characters. Do not include sensitive personal information about yourself or a child in this field.
3.4 Aggregate sound analytics
Only after you choose Allow in the in-app prompt does LookYLook count subsequent built-in sound plays locally by sound ID and UTC day. If you decline, no sound-use totals are collected or sent. A current day is never sent as a partial activity timeline. After the UTC day has closed, LookYLook sends one independent contribution for each sound used that day. Each record contains only the sound ID, UTC day, start of that day, and the daily play count. Every contribution has its own random retry record ID, which is not shared with other sounds or days and is never reused as a user, installation, or device identifier.
The custom analytics fields contain no sound title, localized text, category, submission time, shared batch ID, name, email address, developer-defined user ID, device ID, installation ID, locale, location, photo, or camera data. Unsent closed-day totals remain in a bounded local queue. Whenever LookYLook next runs or attempts a sync, contributions older than 31 days are discarded before use or upload.
Sound records written by app versions before 2.1 may additionally contain a localized sound title that can reflect the app language, a broad sound category, a client update time, and a record name derived from the UTC day and sound ID. Version 2.1 no longer writes those legacy fields or updates shared day-and-sound totals. Existing legacy records are used only for aggregate sound-catalog statistics and follow the same retention and deletion rules below.
CloudKit requires an iCloud account for writes to the public database and adds standard record metadata, including creator and last-modifier user record IDs. LookYLook does not use these Apple identifiers to create user profiles or analyze individual playback events.
You can withdraw consent at any time in LookYLook Settings. Turning sound-usage sharing off immediately stops future counting and deletes all unsent local totals and queued contributions.
3.5 Local settings and photo metadata
Preferences, review state, selected sounds, capture settings, and local shot metadata remain on your device. Local shot metadata can record whether a photo was captured manually, by interval capture, or by Smile Auto-Capture, plus a random burst-group ID and the photo's position within that burst. It contains no camera frames, face bounds, facial landmarks, mouth measurements, smile or stability scores, depth data, or biometric templates. This metadata is not used for advertising or tracking.
4. Purposes and legal bases
- Requested app functionality (GDPR Article 6(1)(b)): operate the camera, preview, photo storage, local settings, purchase and restoration flows, and support you request.
- Optional feedback and sound analytics (GDPR Article 6(1)(a)): process feedback you deliberately submit and, only after you choose Allow, aggregate sound counts for product improvement. You may withdraw consent at any time; this does not affect processing that was lawful before withdrawal.
- Purchase and legal records (GDPR Articles 6(1)(b) and 6(1)(c)): validate entitlements and retain records where required for contractual, tax, accounting, or legal obligations.
- Security and abuse prevention (GDPR Article 6(1)(f)): protect the service and CloudKit submissions based on our legitimate interest in operating a secure product, balanced against user privacy.
- Smile Auto-Capture: run only when you enable it. Face analysis remains on-device and is never made available to the developer.
5. Storage and sharing
Feedback and consented daily sound counts are stored in LookYLook's Apple CloudKit container. Apple processes data as the platform and hosting provider under the applicable Apple terms. Public database is a CloudKit database type; feedback is not intended to be publicly readable, and production access controls must prevent ordinary users from accessing other feedback records.
Any service provider that processes LookYLook user data on our behalf, including Apple as the CloudKit hosting provider, is required to provide the same or equivalent protection described in this policy and required by applicable law.
Photos are stored in Apple Photos. If you use iCloud Photos, Apple may synchronize them. LookYLook does not share data with ad networks, data brokers, or marketing providers and does not use tracking or advertising SDKs.
CloudKit records contain Apple-managed, account-related record metadata. LookYLook therefore conservatively treats CloudKit data as linked to a user, even though the app does not store a separate user or device identifier in its sound-analytics fields.
6. Retention and deletion
- Face-analysis data: never persisted. Temporary frames and derived measurements remain only for a short rolling analysis window in volatile memory and are cleared when analysis stops. Nothing is kept between app sessions.
- Feedback: retained for no more than 24 months after submission. At least quarterly, the developer deletes records once their Apple-managed creation time is older than 20 months, so even cleanup near the end of a quarterly window remains below the maximum.
- Daily sound counts: retained for no more than 24 months after the applicable UTC day. At least quarterly, the developer deletes contributions for UTC days older than 20 months. Records whose Apple-managed creation time is older than 20 months are also deleted as a server-controlled fallback.
- Individual sound plays: not retained as separate server records. With consent, current-day totals remain on-device. On the next app launch or sync attempt, unsent closed-day contributions older than 31 days are discarded before use or upload. Turning sharing off deletes all unsent local totals immediately. It does not remove daily totals already uploaded; those remain until the retention period ends.
- Photos: remain in your Photos library until you delete them. Deleted photos may remain temporarily in Apple's Recently Deleted album.
- Local data: remains on the device until the related photo or setting is removed, or until you delete the app.
To request earlier deletion of feedback, email support@xiut.nl. Include the approximate submission date/time and a short, non-sensitive excerpt so the record can be located. A verifiably matching record will be deleted within 30 days. Apple may retain limited operational copies or logs under its own terms and legal obligations.
7. Your choices and rights
- Manage Camera and Photos permissions in iOS Settings.
- Enable or disable Smile Auto-Capture in LookYLook.
- Allow or withdraw sound-usage sharing in LookYLook Settings. Withdrawing stops future counting and deletes unsent local totals.
- Submitting feedback is optional.
- Delete photos through LookYLook or Apple Photos.
- Email support@xiut.nl to request access, correction, deletion, or to object where the relevant data can be located.
8. Children
LookYLook is a tool for adults taking photos of children or pets. The app does not provide children with an account and is not designed for children to submit personal information independently. Adult users should not include sensitive information about children in feedback.
9. Security
LookYLook limits data to what is needed for the described features and uses Apple platform security and CloudKit access controls. No storage method is entirely risk-free; report questions or suspected issues to support@xiut.nl.
10. Changes
This Privacy Policy may be updated when the app or its data processing changes. The latest version and date are shown on this page.