Skip to content
shy.
Looks Tools Privacy Support
  • EN
  • RU
  • ES

shy

Privacy Policy

Last updated: 16 September 2026

The short version

  • Your photos, file names, EXIF metadata and location never leave your iPhone. Editing happens on the device, and our servers have no way to receive a photo.
  • There is no account to create. The app keeps working offline.
  • Usage statistics are off until you allow them, and you can switch them off at any time.
  • With your permission we measure which of our ads brought you to shy. This never involves your photos.
  • Apple handles payments. We see which plan is active, never your card or Apple ID details.
  • “Delete my data” in the app erases what our server holds about your installation.

Contents

  1. Who we are
  2. How shy is built — and why that matters
  3. What never leaves your device
  4. What we collect
  5. What we don’t do
  6. Who else is involved
  7. Why we are allowed to use it
  8. International transfers
  9. How long we keep data
  10. Your choices and deleting your data
  11. Your rights
  12. Children
  13. Security
  14. Changes to this policy
  15. Contact

1. Who we are

This policy covers the shy app for iPhone (“the App”) and the website shyedit.com. They are operated by shy (F.T. PC EXPERTS LIMITED, Cyprus) (“shy”, “we”, “us”), which is responsible for the personal data described here. Questions and requests: support@shyedit.com.

2. How shy is built — and why that matters

shy is a photo editor that does all of its work on your iPhone. Looks, light and colour adjustments, curves, HSL, retouching, crop and export are computed on the device with classic image-processing algorithms. Nothing is generated by AI, and there is no cloud photo library.

Your projects and edit history are stored inside the App on your iPhone. Like other app data, they may be included in your device backups (iCloud or computer) under Apple’s terms. When you export, shy saves a new copy to Photos or hands it to the share sheet — where it goes next is your choice. shy never writes location data into exported copies.

3. What never leaves your device

  • your photos, and the edited copies you export;
  • file names, file paths and albums;
  • EXIF and camera metadata, including location;
  • projects, edit history, saved looks and export preferences.

None of this is sent to us, to our service providers, to analytics or to error reports.

4. What we collect

Installation data (needed for the App to work)

When the App first connects to our server it creates a random installation ID and a secret key (we store only a hash of the key). With them we receive: Apple’s identifier for vendor (IDFV), the App version and build, iOS version, device model, language, App Store country, your usage-statistics choice, and when the installation was first and last seen.

We use this to deliver the App’s configuration (for example, which onboarding and paywall screens to show, including simple A/B tests assigned from the installation ID), to confirm purchases and to protect the service from abuse. The App works with a built-in configuration when our server can’t be reached.

Purchases

Apple processes every payment. When you buy or restore shy Pro, we and our subscription provider RevenueCat receive information from Apple about the purchase: the product, subscription status and dates, transaction identifiers, price, currency and store country. We never receive your name, e-mail, Apple ID or payment card. The RevenueCat component inside the App also receives technical request data from your device, such as IP address, device model and App version.

Usage statistics (only with your permission)

If you allow usage statistics (the switch is called “Anonymous usage statistics” in the App), the App sends events about how it is used: screens and onboarding steps viewed, paywall and purchase steps, which look was previewed or applied and at what strength, which adjustments were used, compare, import and export actions (format and size setting, success or an error code), session and timing information.

These events are built from a fixed allowlist of fields. They never contain photo content, file names, paths, EXIF data, location, your name, e-mail or IP address. They are linked to the random installation ID and IDFV, not to who you are. In legal terms they are pseudonymous rather than anonymous data, which is why we ask for your consent. If you don’t allow statistics, no usage events are sent; the App only tells our server your choice and which configuration variant (for example, which paywall layout) it was given.

Ad attribution (only with your permission)

To understand which of our ads bring people to shy, the App uses AppsFlyer. It starts only after you allow usage statistics. AppsFlyer then receives the random installation ID, IDFV, your device’s IP address, device model, iOS and App version, and when the App was installed and opened. If you also choose “Allow” in Apple’s tracking prompt, AppsFlyer receives your device’s advertising identifier (IDFA) as well. If you don’t, it doesn’t, and ad measurement relies on Apple’s SKAdNetwork, which reports campaign results without identifying you.

AppsFlyer tells us which campaign, ad set or ad an installation came from, and we keep only those campaign fields. When you buy shy Pro, RevenueCat forwards the purchase event (product, price and currency) to AppsFlyer so we can measure what our advertising earns. Your photos, file names and EXIF data are never part of this.

E-mails to support

If you write to us, we receive your e-mail address and whatever you include in the message, and use them only to answer you.

This website

shyedit.com uses no cookies, analytics, trackers, third-party fonts or scripts. Our web server keeps technical logs (IP address, page requested, time and response status) to keep the site secure and running; they are rotated automatically and kept for no longer than 30 days.

5. What we don’t do

  • We don’t upload, view, analyse or store your photos.
  • We don’t show ads in the App. We use the advertising identifier (IDFA) only if you allow tracking, and only to measure which of our own ads brought you to shy.
  • We don’t sell your personal data.
  • We don’t ask for an account, contacts or your location, and the App doesn’t send push notifications.

6. Who else is involved

We use a small number of providers who process data on our behalf and under contract:

  • Apple — distributes the App and processes payments and refunds under Apple’s privacy policy.
  • RevenueCat, Inc. (USA) — keeps track of purchases and subscription status for the random installation ID.
  • Amplitude, Inc. (USA) — stores and analyses usage statistics, and only if you allowed them. Collection of IP address, country, region, city and mobile carrier is switched off in the App.
  • AppsFlyer Ltd. (Israel) — measures which of our ads led to an installation or a purchase, and only if you allowed usage statistics; it uses the advertising identifier only if you allowed tracking. To measure a campaign, it tells the ad network that showed the ad (for example Meta or TikTok) that an installation or purchase happened.
  • UpCloud (European Union) — hosts our servers, database and backups.

Error reports from our servers go to a monitoring service run by our own team; request contents and personal data are removed before a report is stored.

7. Why we are allowed to use it

  • Contract — installation data and purchase information, which we need to provide the App and the features you paid for.
  • Consent — usage statistics and ad attribution, including Apple’s tracking permission. You can withdraw consent at any time; this doesn’t affect processing that happened before.
  • Legitimate interests — delivering the App’s configuration and simple A/B tests of its screens, keeping the App, the website and our servers secure, preventing abuse and answering support requests.

8. International transfers

Our servers and backups are located in the European Union. RevenueCat and Amplitude process data in the United States. AppsFlyer is based in Israel, which the European Commission recognises as providing adequate protection, and may also process data in the United States. Where the law requires it, these transfers rely on the EU–U.S. Data Privacy Framework where a provider is certified under it, or on the European Commission’s Standard Contractual Clauses in the providers’ data processing terms.

9. How long we keep data

  • Installation record — for as long as you use the App, or until you delete your data.
  • Usage events on our server — 180 days, then deleted automatically.
  • Raw purchase notifications from RevenueCat — 90 days, then their contents are deleted.
  • Purchase and transaction records — as long as accounting and tax rules require. After you delete your data they are no longer linked to your installation.
  • Backups — overwritten on a rolling basis and gone within 30 days.
  • Usage statistics at Amplitude — under the retention settings of our Amplitude project, and deleted when you ask us to (see below).
  • Campaign attribution on our server — as long as the installation record exists; erased by “Delete my data”.
  • Attribution data at AppsFlyer — under the retention settings of our AppsFlyer account, and deleted when you ask us to (see below).
  • Support e-mails — as long as needed to resolve your request.

10. Your choices and deleting your data

Usage statistics. In the App, open Profile → About shy and switch usage statistics (“Anonymous usage statistics”) on or off. When you switch it off, sending stops and statistics that haven’t been sent yet are discarded.

Tracking. You can change Apple’s tracking permission at any time in iOS Settings → Privacy & Security → Tracking. When it is off, the App doesn’t provide the advertising identifier. Switching usage statistics off also stops ad attribution.

Delete my data. In Profile → About shy, tap “Delete my data”. Our server then erases the usage events, test assignments, subscription status and campaign attribution linked to your installation, clears the device details (including IDFV, the AppsFlyer identifier and your tracking choice) and revokes the installation’s access; purchase records we must keep for accounting remain, but without any link to your installation. The App then starts over as a new installation.

“Delete my data” erases what our own server holds. To also have the purchase history at RevenueCat, the usage statistics at Amplitude and the attribution data at AppsFlyer deleted, e-mail support@shyedit.com — we will explain how to identify your installation and have them deleted within 30 days.

Your purchases stay with your Apple ID — tap “Restore” on the purchase screen to get shy Pro back. Deleting the App removes your projects from the device; copies you exported to Photos stay there.

For anything else, write to support@shyedit.com.

11. Your rights

Depending on where you live (for example under the GDPR, UK GDPR or California law), you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive it in a portable form, and to withdraw consent. You can also complain to a data protection authority: ours is the Commissioner for Personal Data Protection of the Republic of Cyprus, or you can contact the authority where you live.

Because shy has no accounts, the quickest way to erase your data is “Delete my data” in the App. For other requests, e-mail support@shyedit.com — we will explain how to identify your installation. Never send us photos. We don’t sell personal information, and we won’t treat you differently for using your rights. To opt out of ad measurement, decline tracking in Apple’s prompt or switch usage statistics off.

12. Children

shy is intended for people aged 16 and over, and we don’t knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact support@shyedit.com and we will delete it.

13. Security

The App talks to our server only over encrypted connections (HTTPS). Installation keys are stored as hashes, server disks are encrypted, and staff access to our systems requires two-factor authentication and is logged. No system is perfectly secure, but the most sensitive thing — your photos — never reaches us in the first place.

14. Changes to this policy

When this policy changes, we update the date at the top. If a change is significant — for example, if the App were ever to handle photos differently — we will tell you in the App or on this website before it takes effect.

15. Contact

shy (F.T. PC EXPERTS LIMITED, Cyprus) — support@shyedit.com.

shy.

Photo editor for iPhone. Your photo, your light.

shy

  • Looks
  • Tools
  • Support

Legal

  • Privacy
  • Terms

Contact

  • support@shyedit.com

© 2026 F.T. PC EXPERTS LIMITED

Apple, iPhone and App Store are trademarks of Apple Inc., registered in the U.S. and other countries.