Privacy Policy
Last updated 23 September 2026
Nail Picker is an iPhone app that shows a nail polish colour on a photo of your own hand. This page says what happens to that photo. It is short, because there is not much that happens.
Your hand photo
The photo is shrunk on your phone, then sent over HTTPS to our server.
Our server never writes it to disk. It exists only in memory, for as long as the request takes.
Working out where your fingers are happens on our own server. Nothing leaves us for that step.
Tracing the nails does need outside help. Two services are involved, and only ever one of them per action:
- Replicate — tracing the nails
- The photo goes to Replicate, which runs the meta/sam-2 model. Replicate keeps request data for up to one hour and gives us no way to delete it sooner. So the honest answer is: up to one hour at our processor, and no longer.
- fal.ai — fixing one nail
- When you tap a nail to correct it, the photo goes to fal.ai, which runs fal-ai/sam2/image. We send it with payload storage switched off and a five-minute lifetime. If you never tap to fix a nail, your photo never reaches fal.ai.
We do not sell your photo and we do not give it to advertisers.
On training we will only speak for what we actually control. We send the photo to fal.ai with payload storage switched off and a five-minute object lifetime. Replicate's terms reserve a broad licence over data sent to them, so we are not going to promise on their behalf that nothing is ever used for training. What we can tell you is the deletion window above: one hour at Replicate, five minutes at fal.ai.
What we store
Only the result of the tracing, never the picture it came from.
- The nail outlines — black-and-white masks — and the coordinates of the points on your hand, saved as JSON under a key that is the SHA-256 hash of the photo. Kept for 30 days. The photo itself is not in there.
- Usage counters — how many scans you have run this month — under an anonymous user identifier from RevenueCat. Kept for 180 days after you last use the app. No name, no email address, nothing about your device.
- What your scans cost us to run. The same record holds the amount this installation has spent on model runs. It is a running total for the current calendar month in UTC and resets to zero when the month turns. It lives in that same record and is deleted with it, on the same 180 days, under the same anonymous identifier.
Where this runs
Our server runs on Railway. Railway therefore holds the disk that the outlines, the counters and the spend figure sit on, and receives the stream of our server logs.
Railway keeps that log output for 7 days.
What stays only on your phone
The hand photo itself, the try-on you are working on, your saved shades, and the swatches you photographed. None of that reaches our server.
Payments
Payments are handled by Apple and RevenueCat. We never see or store your card details.
Analytics
In the app, we use PostHog, on their European host. It records product events only — things like "a shade was applied". No photos, no contact details.
On this website, we use Cloudflare Web Analytics to see how many people visit and which pages they read. It sets no cookie and stores nothing in your browser. It does not follow you across sites, and it does not keep your IP address — Cloudflare's own documentation says it is discarded at the nearest data centre and never written to a database. We chose it specifically because it does not need a cookie banner to be honest about; a tool that did would have one on this page.
Events are kept for 30 days, then deleted.
Crash reports
When the app hits an error it sends the error message and the technical stack trace to our server, so the bug can be found. These land in our server's log output, which our host keeps for 7 days. No photo and no identifier is attached to the report itself.
If buying, restoring or loading a subscription fails, the report also carries what the App Store said went wrong, which plan was being bought, your iOS version, your device model and whether it is a phone or a tablet, and the app's version and build number. It does not carry your installation identifier, the name you have given your device, your receipt, or any price — a price would give away which country's store you use.
Our logs are not identifier-free, though, and it would be misleading to leave it there. On every scan and every re-trace our server also writes a line into that log with the start of your installation identifier, the number of scans and the amount spent. Those lines are kept for the same 7 days.
Your IP address
Our server sees your IP address on every request, as any server does, and uses it in memory to stop one device from flooding the service. It is not saved to any database, though it may appear in our host's request logs, which are kept for 7 days. The address your connection comes from is visible to every company a request passes through — the same as for any website you open.
Your rights
Write to support@nailpicker.com. Ask what is held about you, ask for it to be deleted, or ask us to stop.
Being straight about what that reaches matters more than sounding comprehensive, so, item by item:
- Your counters and your spend figure we delete on request, and I confirm by email when it is done.
- The outlines we cannot delete for one particular person — and the reason is the same one that protects you. They are filed under the hash of the photo, not under you. There is no record anywhere linking a person to their hashes, so we genuinely cannot look up who scanned what. Nothing to search means nothing to hand over, and it also means nothing to delete on request. They expire on their own after 30 days.
- There is no photo to delete. It is never written down in the first place.
Deleting the app has the same effect on the counters: the anonymous identifier is issued fresh on the next install, so your scans and spend start from zero. The old record is left behind unattached to anyone and ages out on its 180 days.
What we do not collect
No audio. Nail Picker never records sound. A microphone line appears in the app's permission descriptions because the camera library we use asks for it by default; nothing in Nail Picker requests the microphone or uses it.
Who is responsible
Nail Picker is made by one person, not a company. Under the GDPR that person is the data controller — the one who decides why your photo is processed.
That person is Kristina Malinovskaya, an individual developer established in Indonesia.
Contact for anything on this page: support@nailpicker.com.