Privacy Policy
Privacy by construction
Verankila processes your facial expression entirely on your device. No camera frame, facial landmark, blendshape value, or emotion reading is ever transmitted to a server. There is no backend for biometric data -- the app has no network endpoint that could receive it, and an automated test (ZeroEgressTests) fails the build if one is ever introduced.
What Verankila processes
While the camera is active:
- Camera frames: processed transiently in memory by on-device MediaPipe; not stored.
- Facial landmarks and blendshape coefficients: computed per frame, held in a short rolling window in memory; discarded when the reading session ends unless you choose to record (see below).
- Emotion readings: computed from the blendshape window; displayed to you, not stored unless you choose to record.
Session recording (opt-in only): if you explicitly tap Record, a session -- including a face-crop image, blendshape data, and emotion readings -- is saved to your device's local storage. You can export it (e.g. to share with a clinician you already work with) or delete it at any time from within the app.
What Verankila does NOT collect:
- Nothing is ever transmitted off your device -- no camera frames, landmarks, blendshapes, or readings
- No accounts, no analytics, no advertising, no tracking
- Your session recordings are not used to train any model -- Verankila's classifier was trained on a separate published dataset
Why we process it
Solely to compute and display a tentative emotion reading and an explanation of which facial cues drove it, for your own reflection. Session recording exists only so you can revisit or share a moment you chose to save.
How long we keep it
Real-time processing: discarded as soon as the reading session ends. Session recordings: kept on your device until you delete them or delete the app -- deleting the app removes everything.
Third parties
Verankila does not engage any data processor for your facial data -- everything happens on-device. Third-party components used, none of which receive your biometric data:
- MediaPipe Tasks Vision (Google AI Edge, Apache 2.0): on-device face-landmarking framework. Runs entirely locally; no MediaPipe cloud service is called.
- Core ML (Apple): on-device inference framework; no data is sent to Apple.
- App Store / TestFlight (Apple): used for distribution; receives only standard app-distribution telemetry (crash reports, install/launch metrics), never biometric data.
Your rights
Right of access and erasure: everything Verankila holds about your face lives only on your device, under your control -- delete a session, or delete the app, and it's gone. There is no server-side copy for us to hold or delete. For any other question about your data, email us at the address below.
Data controller
- Operator: Samuel Harrold, Indianapolis, Indiana, USA
- Privacy contact: support@verankila.app
Verankila is operated by an individual based in the United States, not a registered company. If you are located in the EU or UK and have a data protection concern this policy doesn't address, please contact us directly at the address above -- we will respond, even though we do not currently have a formally designated EU representative under GDPR Article 27.