Nail Picker

Privacy Policy

Last updated 23 September 2026

Nail Picker is an iPhone app that shows a nail polish colour on a photo of your own hand. This page says what happens to that photo. It is short, because there is not much that happens.

Your hand photo

The photo is shrunk on your phone, then sent over HTTPS to our server.

Our server never writes it to disk. It exists only in memory, for as long as the request takes.

Working out where your fingers are happens on our own server. Nothing leaves us for that step.

Tracing the nails does need outside help. Two services are involved, and only ever one of them per action:

Replicate — tracing the nails
The photo goes to Replicate, which runs the meta/sam-2 model. Replicate keeps request data for up to one hour and gives us no way to delete it sooner. So the honest answer is: up to one hour at our processor, and no longer.
fal.ai — fixing one nail
When you tap a nail to correct it, the photo goes to fal.ai, which runs fal-ai/sam2/image. We send it with payload storage switched off and a five-minute lifetime. If you never tap to fix a nail, your photo never reaches fal.ai.

We do not sell your photo and we do not give it to advertisers.

On training we will only speak for what we actually control. We send the photo to fal.ai with payload storage switched off and a five-minute object lifetime. Replicate's terms reserve a broad licence over data sent to them, so we are not going to promise on their behalf that nothing is ever used for training. What we can tell you is the deletion window above: one hour at Replicate, five minutes at fal.ai.

What we store

Only the result of the tracing, never the picture it came from.

Where this runs

Our server runs on Railway. Railway therefore holds the disk that the outlines, the counters and the spend figure sit on, and receives the stream of our server logs.

Railway keeps that log output for 7 days.

What stays only on your phone

The hand photo itself, the try-on you are working on, your saved shades, and the swatches you photographed. None of that reaches our server.

Payments

Payments are handled by Apple and RevenueCat. We never see or store your card details.

Analytics

In the app, we use PostHog, on their European host. It records product events only — things like "a shade was applied". No photos, no contact details.

On this website, we use Cloudflare Web Analytics to see how many people visit and which pages they read. It sets no cookie and stores nothing in your browser. It does not follow you across sites, and it does not keep your IP address — Cloudflare's own documentation says it is discarded at the nearest data centre and never written to a database. We chose it specifically because it does not need a cookie banner to be honest about; a tool that did would have one on this page.

Events are kept for 30 days, then deleted.

Crash reports

When the app hits an error it sends the error message and the technical stack trace to our server, so the bug can be found. These land in our server's log output, which our host keeps for 7 days. No photo and no identifier is attached to the report itself.

If buying, restoring or loading a subscription fails, the report also carries what the App Store said went wrong, which plan was being bought, your iOS version, your device model and whether it is a phone or a tablet, and the app's version and build number. It does not carry your installation identifier, the name you have given your device, your receipt, or any price — a price would give away which country's store you use.

Our logs are not identifier-free, though, and it would be misleading to leave it there. On every scan and every re-trace our server also writes a line into that log with the start of your installation identifier, the number of scans and the amount spent. Those lines are kept for the same 7 days.

Your IP address

Our server sees your IP address on every request, as any server does, and uses it in memory to stop one device from flooding the service. It is not saved to any database, though it may appear in our host's request logs, which are kept for 7 days. The address your connection comes from is visible to every company a request passes through — the same as for any website you open.

Your rights

Write to support@nailpicker.com. Ask what is held about you, ask for it to be deleted, or ask us to stop.

Being straight about what that reaches matters more than sounding comprehensive, so, item by item:

Deleting the app has the same effect on the counters: the anonymous identifier is issued fresh on the next install, so your scans and spend start from zero. The old record is left behind unattached to anyone and ages out on its 180 days.

What we do not collect

No audio. Nail Picker never records sound. A microphone line appears in the app's permission descriptions because the camera library we use asks for it by default; nothing in Nail Picker requests the microphone or uses it.

Who is responsible

Nail Picker is made by one person, not a company. Under the GDPR that person is the data controller — the one who decides why your photo is processed.

That person is Kristina Malinovskaya, an individual developer established in Indonesia.

Contact for anything on this page: support@nailpicker.com.