crown

Privacy Policy

Last updated July 27, 2026

The short version: one processor sees your photo just long enough to score it. We don't know who you are, and we like it that way.

Your permission

Before your first scan uploads anything, Crown asks for your explicit permission and names exactly what is shared and with whom. The question comes when you start a scan, before the camera opens. You can decline — no scan photo or scan context leaves your device without it. You can withdraw permission at any time in Settings → AI processing consent; scanning stops until you allow it again.

One thing happens before that question is asked, and you should know the order. When you open Crown, the app registers its anonymous identifier with Crown's server and checks with Apple that it is running on a real device, so it can tell you whether a scan is available. No photo and no scan context is sent at that point. What is sent, and what Apple records as a result, is described under Device authenticity signals below.

What Crown collects and shares

What we keep, and for how long

What Crown keeps, where it is stored, and for how long
DataWhereKept for
PhotosCrown servers: not stored. Anthropic: transient processingMoments, then discarded
Scan request markers (includes a cryptographic fingerprint of the request, not the photo itself)Crown servers7 days
Anonymous auth token mappingCrown servers180 days
Device-authenticity token (used to read and set the marker described above)Crown servers180 days
Free-scan-used marker for this deviceApple, against your deviceUntil the device is erased. Crown cannot remove it
Registration rate-limit dataCrown serversCurrent keyed hash/count: until the UTC hour ends. Legacy raw-IP bucket: up to 2 hours
Free-scan-used flag (anonymous ID only)Crown serversRetained to keep the free scan one-per-person
Free-scan deletion tombstone (one-way)Crown serversRetained indefinitely, if you erase your data after using a scan
Scan quota counters (anonymous ID only)Crown serversDaily counters: up to 2 days; monthly counters: up to 40 days
AI-analysis counters (anonymous ID only)Crown serversHourly: 1 hour; daily: up to 2 days; monthly: up to 40 days. A lifetime count of free analyses is retained
Subscription entitlement cache (anonymous ID only)Crown serversUp to 24 hours
Leftover records from an earlier version of Crown (anonymous ID only)Crown serversNo expiry in code; they stay until you erase your Crown data
Scan results & historyYour device onlyUntil you delete them

Settings → Erase all Crown data removes everything Crown has put on this iPhone: your scan results, the scans still awaiting confirmation, your three answers, your AI-processing permission record, your reminder settings, and the anonymous identifier itself — which otherwise survives deleting the app. Crown then reopens as if it were newly installed. Photos are not on that list because Crown never wrote one to your disk in the first place.

Server records are keyed by your anonymous Support ID and contain no photos, name, email, or Apple ID. Registration rate-limit data is keyed separately by a keyed hash of a network address and cannot be located from that Support ID. These records expire on the schedules listed above.

You can also see them and delete them, from inside the app. Settings → Your data shows what is on this iPhone and the accounting record Crown's server keeps under your anonymous ID — how many scans you have left and whether the free one is spent — and lets you copy it. Erasing your Crown data also asks Crown's server to erase its side, which removes your scan markers, quota counters, AI-analysis counters, entitlement cache, stored device-authenticity token, and access token. If that request cannot get through — you are offline, or the server is down — the erase on your iPhone still completes, but the server records are left to expire on the schedules above, and once your iPhone has minted a new identifier Crown can no longer reach them on your behalf.

Two things deliberately survive deletion. One is a one-way token derived from your anonymous identifier. It records that the free scan is spent and, if you had already used scans in the current day or month, that those periods are used up — so erasing does not hand back an allowance you had already spent. It cannot be reversed to that identifier and it holds no record of how many scans you ran. The other is the marker Apple stores against your device, described above. Without them, deleting and re-registering would hand out unlimited free scans and reset the paid scan limit every time. Deleting your data does not restore the free scan.

Questions can be sent to [email protected]; you may include the Support ID shown in Settings. One caveat, stated plainly: a Support ID names your records but does not open them. The only key is the access token held by your copy of the app, and Crown has deliberately not built a way around that — so support will point you back to Settings → Your data rather than read or delete anything for you.

What Crown does NOT collect

No name, no email, no account, no password, no phone number, no precise location, no contacts, no advertising identifier, and no analytics profile of your face or body. Crown has no named user-account database. Crown and RevenueCat do keep aggregate subscription analytics — how many people subscribe, renew, or cancel — tied only to the anonymous identifier.

Subscriptions

Purchases are processed by Apple. Crown uses RevenueCat to tell whether a subscription is active: RevenueCat receives your anonymous identifier and your purchase records from Apple, both from the app and from Crown's server, which asks RevenueCat about your subscription when you scan. Crown never receives your payment details or your identity. RevenueCat processes this data on Crown's behalf under its data-processing terms.

Health disclaimer

Crown provides wellness insights, not medical advice. Scores are informational estimates from photos and are not a medical assessment of any kind.

Age

Crown is intended for users 17 and older.

Changes & contact

We'll update this policy here if practices change. Questions: [email protected].