Masks On
Privacy Policy
This Privacy Policy explains how Crayon Labs (“Crayon Labs,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use the mobile application Masks On (the “App”), including related backend services we operate for the App.
By creating an account, completing onboarding, or otherwise using the App, you acknowledge this Policy. If you do not agree, do not use the App.
This Policy is intended to be clear and protective of both users and Crayon Labs. It is not legal advice to you. Privacy laws vary by place; where a law gives you stronger rights, we will honor those rights to the extent they apply.
1. Who we are
Masks On is operated by Crayon Labs. For privacy questions, requests, or complaints related to the App, contact us at info@crayonlabs.ca.
2. Scope
This Policy applies to:
- the Masks On iOS application;
- our servers and cloud infrastructure that power the App; and
- communications with us about the App at the contact address above.
It does not apply to third-party websites, stores, or services that we do not control (for example, Apple’s App Store or Sign in with Apple), which have their own privacy terms.
3. Age requirement
Masks On is intended only for adults. You must be at least 18 years old to create an account or use the App. We do not knowingly collect personal information from anyone under 18. If you believe a minor has used the App, contact us and we will take appropriate steps, which may include deleting related account information.
4. Information we collect
Depending on how you use the App, we may process the following categories:
4.1 Account and profile
- Authentication. The App uses Firebase Authentication. You may start with a device session and may optionally link or restore an account with Sign in with Apple. We do not require you to publish your legal name or Apple email on your public profile.
- Profile you choose. Nickname, age, avatar selection (from our bundled avatar set—not a custom photo upload to your profile), interests, ring style, and similar presentation choices you set in the App.
- Verification status. Whether you have completed voice verification and related badge information (for example, verified status and badge gender category where applicable). Badge fields are maintained by our verification systems and are not freely editable as ordinary profile text.
- Discover preferences. Settings such as hiding your card from Discover, blocked users, favorites, and similar controls you operate in the App.
4.2 Communications and social features
- Chat threads, invitations, and related metadata (participants, timestamps, delivery and read signals, expiry timers).
- Content you post to shared surfaces in the App (for example, daily prompt answers and reactions), subject to moderation.
- Presence signals (online / last active style heartbeats) used to show availability.
4.3 Device, security, and diagnostics
- Push notification tokens when you enable chat notifications.
- App integrity and abuse-prevention signals (for example, App Check / device attestation where enabled).
- Technical logs needed to operate, secure, and debug the App (which may include identifiers, error reports, and limited request metadata).
4.4 Information we do not sell
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
5. Voice verification
Voice verification exists to support a safer, more trustworthy community (including gender-related badge integrity) and to reduce abuse. If you choose to verify:
- Your device captures a short voice sample and related challenge data needed to complete the check (for example, challenge identifiers and limited sensor / capture-context signals used to detect spoofing or replay).
- That audio is transmitted securely to our verification service for analysis.
- We do not keep the voice recording as a lasting media library. After analysis, the temporary audio file is deleted from the verification service.
- We may retain non-audio records needed for security and integrity—such as a cryptographic fingerprint (hash) of the sample, challenge outcome, rate-limit history, and your resulting verification badge status—so we can prevent replay abuse, investigate fraud, and keep badge results consistent.
Declining verification may limit access to features that require a verified badge. Verification is optional where the App allows unverified use.
6. Messages, encryption, and deletion
Masks On is designed around short-lived, discreet conversations—not permanent archives.
- Encryption. Once a conversation is eligible for sealing, message text and chat media are encrypted on your device before they are sent. Sealed content is stored in a form that is not readable by us as ordinary plaintext. Cryptographic keys are managed so that participants can decrypt content intended for them.
- Safety review of openers. Early messages that open a conversation may be processed in a form our moderation systems can evaluate, so we can block abusive or prohibited first contact. After a conversation is sealed, subsequent content follows the encryption model above.
- Burn timers and deletion. Conversations are intended to expire. When a chat ends, is deleted by you, or reaches its burn deadline, associated message content is purged through our deletion processes. Extending a timer (where offered) only delays that deletion window; it does not create a permanent archive on our side.
- Metadata. Even when message bodies are sealed or deleted, limited operational metadata may exist for delivery, security, billing of infrastructure, or abuse prevention, and may be retained for shorter or longer periods as needed for those purposes.
No security system is perfect. Encryption reduces risk; it does not guarantee that compromised devices, screenshots, or someone you chat with cannot disclose what they can see.
7. Photos, video, and captures
Masks On is not a photo-backup or permanent media host. We treat media as transient and protected.
- My Captures (on-device vault). Captures you keep in the App’s vault remain on your device for your use in composing messages. They are stored in the App’s private storage (not as a lasting copy in your system Photos library through this vault), are protected by device file protections, and are automatically purged after a short retention window. Vault items are not uploaded to our servers merely because they sit in My Captures.
- Media sent in chat. If you send a photo, video, or voice note in a conversation, it is encrypted on your device before upload. What we receive and temporarily hold is ciphertext—not an open, browsable gallery of your originals. Encrypted chat media is automatically deleted after a short retention period (on the order of days), and may be deleted sooner when a message is spent (for example, view-once), a chat is purged, or related cleanup jobs run.
- What we are not doing. We do not operate a permanent public photo feed of your media, we do not use your chat media to train public generative models as part of ordinary App operation described here, and we do not sell your media.
Because deletion and encryption depend on systems operating correctly, and because recipients may capture what appears on their screens, you should treat any media you send as potentially sensitive and send only what you are comfortable sharing under those limits.
8. Location
Distance on Discover is optional. If you enable location sharing:
- We publish only a coarse location cell (a rounded grid area), not a precise street-level track of your movements.
- Others see approximate distance buckets—not live GPS breadcrumbs.
- You can turn Distance in Discover off in Settings, which clears the published cell from your public profile card.
Device permission is controlled by iOS. If you revoke permission in system Settings, the App cannot continue sharing a cell until you allow it again.
9. How we use information
We use information to:
- provide, operate, and improve the App;
- authenticate you and maintain your profile and preferences;
- perform voice verification and maintain badge integrity;
- enable messaging, Discover, presence, and related features;
- moderate prohibited content and reduce fraud, spam, and abuse;
- send push notifications you have enabled;
- secure our systems, enforce our terms, and protect users and Crayon Labs;
- comply with law and respond to lawful requests; and
- communicate with you about the App when you contact us.
10. How we share information
We may share information only as follows:
- With other users, according to what you choose to show (profile card, presence, distance if enabled, messages and media you send, shared-wall posts, and similar).
- With service providers that process data on our behalf to run the App—most notably Google Firebase and related Google Cloud infrastructure (authentication, database, file storage for encrypted payloads, functions, messaging, and security tooling). These providers act as processors under our instructions and their applicable terms.
- For legal and safety reasons, if we believe disclosure is reasonably necessary to comply with law, enforce our rights, investigate abuse, or protect the safety of users or the public.
- Business transfers. If Crayon Labs is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to appropriate confidentiality and this Policy’s purposes.
Other users you interact with are independently responsible for how they handle information you share with them. We cannot control screenshots, forwarding outside the App, or disclosure by a recipient.
11. Retention
We keep information only as long as needed for the purposes above, including security and legal obligations. In particular:
- profile and account data generally last for the life of the account;
- chat content is designed to be short-lived and subject to burn / purge;
- encrypted chat media is retained only briefly, then deleted;
- on-device vault captures auto-expire after a short local window;
- voice recordings used for verification are deleted after analysis; limited verification records (such as hashes and outcomes) may be kept longer for abuse prevention;
- logs and security records may be kept for operational and investigative periods.
After account deletion, residual copies may persist for a limited time in encrypted backups, logs, or disaster-recovery systems until those systems rotate, and some records may be retained where we must keep them for legal, security, or fraud-prevention reasons.
12. Security
We use administrative, technical, and organizational measures appropriate to the nature of the App, including transport encryption, device-side encryption for sealed chat content and media, access controls, and integrity checks. No method of transmission or storage is completely secure. You are responsible for protecting your device, passcode, and Apple account.
13. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or restrict certain personal information, or to object to certain processing. In the App you can typically:
- edit profile fields the App allows you to change;
- turn location sharing and chat notifications on or off;
- hide from Discover and block users;
- delete conversations and clear history where the App provides those controls;
- delete your account from Settings (which removes your profile and authentication identity from the App’s account systems).
To exercise privacy rights or ask a question, email info@crayonlabs.ca. We may need to verify your request. We will not discriminate against you for exercising rights available under applicable law.
14. Children
The App is not directed to children under 18, and we do not knowingly collect personal information from them. See Section 3.
15. International processing
We and our infrastructure providers may process information in countries other than where you live (including the United States). Those countries may have different data-protection laws. Where we transfer personal information internationally, we take steps designed to protect it in line with this Policy and applicable law.
16. Changes
We may update this Policy from time to time. When we do, we will change the “Last updated” date above and, where appropriate, provide additional notice in the App or on this page. Continued use after an update means you accept the revised Policy, except where applicable law requires a different form of consent.
17. Contact
Crayon Labs
Privacy — Masks On
Email: info@crayonlabs.ca
Web: https://crayonlabs.ca
If you have an unresolved privacy concern that we have not addressed satisfactorily, you may have the right to contact a data-protection or consumer-protection authority in your jurisdiction.