Privacy Policy
Last updated August 15, 2026
This Privacy Policy explains how Vangu and Learn to Draw (together, “Vangu”, “we”, “us”, or “our”) collect, use, disclose, and retain personal information when you use our mobile app, website, and related services (the “Service”). It is a privacy notice, not a request to waive any privacy right. Where the law requires consent, we ask for it separately.
1. Who is responsible for your information
The Service is operated by Jesse Deng under the names Vangu and Learn to Draw. Jesse Deng is the controller of personal information described in this policy.
Contact: privacy@howtodraw.app
Postal address: 13 The Hoe, Watford WD19 5AY, United Kingdom.
2. Information we collect
Account information. We create an anonymous Firebase account and user ID so the Service can protect and restore your data. If you choose email verification, we also collect your email address and verification status. You do not need to give us your name to use the core Service.
Photos and AI content. We collect reference photos you choose, photos of drawing attempts, instructions connected to those photos, generated tutorials, AI feedback, and related project information. A photo may contain personal information about you or another person. We do not use face recognition or create biometric identity profiles.
Usage and technical information. We collect app interactions, feature and screen usage, tutorial and purchase events, IP address, device and advertising identifiers, device model, operating system, app version, language, approximate location inferred from IP, crash logs, diagnostics, and performance information.
Purchase information. Apple or Google processes your payment. We receive transaction, product, subscription, renewal, refund, store, price, currency, and entitlement information. We do not receive your full payment-card number.
Attribution and advertising information. Depending on your device settings and consent choices, this can include an advertising ID, vendor ID, install source, ad campaign, ad group, keyword, and interaction or conversion events.
Communications. If you contact us, we collect your email address, message, attachments, and the information needed to answer or verify a privacy request.
3. Why we use information
- Provide the Service: authenticate users, process photos, generate tutorials and feedback, restore projects, manage credits, and deliver purchases and subscriptions.
- Operate and protect the Service: prevent fraud and abuse, enforce our Terms, secure accounts, debug failures, and maintain reliability.
- Measure and improve: understand feature use, diagnose crashes, evaluate performance, and improve the product.
- Attribution and advertising: measure whether an ad led to an install or purchase and improve our campaigns, subject to consent and opt-out rights.
- Communicate and comply: answer requests, send service messages, keep required records, and comply with law or valid legal process.
Where European or UK data-protection law applies, our legal bases are: performing our contract with you; our legitimate interests in operating, securing, measuring, and improving the Service; your consent for tracking or other processing where required; and compliance with legal obligations. You may withdraw consent at any time, without affecting earlier lawful processing.
4. Photo transfer and third-party AI processing
Your photos leave your device. A reference photo is sent through our Google Firebase backend to Google Cloud Vertex AI (Gemini) for subject classification and to fal — Features & Labels, Inc. — for AI image generation. A photo of your drawing attempt is sent to Google Cloud Vertex AI for AI feedback. fal may use an underlying model partner to complete a request.
These providers process the photo and related instructions to provide the requested feature, maintain security, and prevent abuse. We do not sell your photos or use them to train our own AI models. Google states that it does not use customer data to train or fine-tune AI models without the customer’s permission or instruction. fal may create de-identified or aggregated usage data as described in its terms and privacy notice.
Maximum seven-day AI retention. We configure fal request data and media used for normal AI processing to be deleted no later than seven (7) days after processing, and we disable fal request input/output history storage. Google Cloud may temporarily cache AI input and output in memory for up to 24 hours. A provider may preserve limited information for longer only when the law requires it, to investigate abuse or a security incident, or as otherwise stated in its binding terms. We do not control those exceptional copies and cannot always delete them early.
Photos sent to AI providers may be processed in the United States or other countries. Do not upload a photo unless you have the right and permission to do so. Avoid photos containing government IDs, financial information, health records, intimate content, confidential information, or a child unless you are the parent or legal guardian and the upload is lawful.
Provider information: Google Cloud Privacy Notice and fal Privacy Policy.
5. Storage, service providers, and other disclosures
We disclose information to these categories of recipients:
- Google Firebase and Google Cloud for authentication, databases, file storage, cloud functions, AI processing, analytics, and crash reporting.
- fal and model providers for AI image generation.
- RevenueCat, Apple, and Google Play for purchases, subscriptions, entitlements, and app distribution.
- AppsFlyer, Meta, TikTok, and Apple AdServices for advertising attribution, campaign measurement, and related analytics.
- Vercel and communications providers for website hosting and support communications.
- Advisers and authorities when reasonably necessary to obtain legal, accounting, security, or insurance support; comply with valid legal process; or protect rights, safety, and the Service.
- A business successor in a merger, financing, reorganization, bankruptcy, or sale, subject to applicable law and this policy.
Service providers may collect information directly through their SDKs and process it under our instructions and their own legal obligations. Their handling is also governed by their contracts and privacy notices.
6. Advertising, tracking, sale, and sharing
We do not sell personal information for money. Our use of advertising and attribution partners can involve sending device identifiers and app-event data to measure ads. Some US state laws may call this “sharing”, “targeted advertising”, or a “sale” even when no money changes hands.
You can deny or revoke app-tracking permission in iOS or Android settings, reset or limit your advertising ID, and email privacy@howtodraw.app with the subject “Do not sell or share”. We will not discriminate against you for exercising a privacy right. Disabling tracking does not stop analytics needed for security, basic operation, or non-personal measurement.
7. How long we retain information
- AI processing copies: no more than seven (7) days in the normal fal processing flow; Google Cloud temporary AI cache may last up to 24 hours, subject to the limited exceptions in section 4.
- Photos, attempts, and generated tutorials in Firebase: stored so projects can survive a reinstall and retained until you delete your account or we complete a verified deletion request, unless a longer period is legally required.
- Local app files: retained on your device until you delete them, clear app data, or uninstall the app.
- Account, project, credit, and subscription records: retained while the account is active and then deleted or de-identified, except for transaction, tax, fraud, or legal records we must keep.
- Operational analytics: our server-side operational event records expire after 180 days. Analytics, attribution, and crash providers retain their records under our account settings and their documented schedules.
- Support and privacy requests: retained as long as needed to answer the request, document compliance, resolve disputes, and meet legal obligations.
Deletion from active systems may not immediately remove encrypted backups. Backup copies are isolated, expire on their normal cycle, and are not used for ordinary product activity.
8. International transfers
We and our providers may process information outside your country, including in the United States and the United Kingdom. Those countries may have different privacy laws. Where required, we use an adequacy decision, data-processing agreement, standard contractual clauses, or another lawful transfer safeguard. You may contact us for more information about the safeguard relevant to your data.
9. Your privacy rights
Depending on where you live, you may have the right to know or access the information we hold; correct it; receive a portable copy; delete it; restrict or object to processing; withdraw consent; opt out of sale, sharing, or targeted advertising; limit certain uses of sensitive information; and appeal a denied request. You may also use an authorized agent where local law allows.
Use the in-app Settings → Delete Account action, visit our deletion instructions, or email privacy@howtodraw.app. State the right you want to exercise and your country or state. We may ask for information needed to verify your identity or authority. We will respond within the period required by applicable law.
You may complain to your local data-protection authority. In the UK, this is the Information Commissioner’s Office. EEA residents may contact the authority where they live, work, or believe a violation occurred.
10. Security
We use measures designed to protect information, including encryption in transit, authenticated storage rules, access controls, app attestation, secret management, and provider review. No system is perfectly secure, so we cannot guarantee absolute security. Tell us promptly if you believe your account or information has been compromised.
11. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. A parent or guardian who believes a child provided information can contact us so we can investigate and delete it. Users under 18 should use the Service only with a parent or guardian’s permission and must not upload another child’s photo without lawful authority.
12. Changes to this policy
We may update this policy as the Service, providers, or law changes. We will change the date above and provide additional notice when required. If a change needs consent, we will ask before applying it.
13. Contact
Privacy questions and requests: privacy@howtodraw.app. Postal address: Jesse Deng, 13 The Hoe, Watford WD19 5AY, United Kingdom.