Privacy Policy
The short version
- Retro Palette collects no personal data about you: no account, no profile, no tracking.
- Your photos are converted entirely on your device and are never uploaded to us or anyone else.
- There is no account, no login, no email address and no user database.
- There is no analytics SDK and no advertising SDK in the app.
- The app does send crash reports, so we can fix what breaks. They describe the failure, not you — see section 5.
- Outbound network traffic is limited to two things: the purchase check for the optional Pro unlock, and those crash reports.
1. Who we are
Retro Palette is developed and published by Software First, a software studio based in Athens, Greece. Where this policy describes processing of personal data, Software First is the data controller for the purposes of Regulation (EU) 2016/679 (the GDPR).
You can reach us at info@softwarefirst.gr for any question about this policy or about the app. We do not have a statutory Data Protection Officer, because the scale and nature of our processing does not require one; the address above reaches the people who actually wrote the app.
2. Your images and how they are processed
Retro Palette converts an image you choose into a retro console colour palette. Every step of that conversion — reading the image, matching colours, dithering, scaling and writing the result — happens locally on your device, using the device's own processor.
- Your images are never uploaded to Software First or to any third party.
- There is no server, no backend and no cloud processing behind this app.
- There is no AI or machine-learning service involved; the conversion is deterministic local computation.
- We never see your images, and we have no technical means of doing so.
- The app reads only the single image you pick, at the moment you pick it. It does not scan, index or browse your photo library.
When you save a converted image, it is written to your device's own photo gallery. From that point it is an ordinary photo on your device, governed by your device and by whatever backup or sync settings you have configured with Apple or Google — not by us.
3. What we do not collect
To be explicit, because “we care about your privacy” is worth nothing without a list. The app does not collect, request, generate or transmit any of the following:
| Category | Collected? | Notes |
|---|---|---|
| Name, email, phone number | No | There is no account and no sign-up form. |
| Photos or videos | No | Processed on device only; never transmitted. |
| Location data | No | The app never requests location permission. |
| Contacts, calendar, microphone, camera roll browsing | No | None of these permissions are requested. |
| Advertising identifiers (IDFA / AAID) | No | No ad SDK is present, so nothing reads them. |
| Analytics or usage events | No | No analytics SDK is bundled in the app. Nothing records which palettes you pick, how many images you convert, or what you do in the app. |
| Crash reports | Yes | The app reports its own crashes and errors, so we can fix them. See section 5 for exactly what a report contains — no images, and nothing that identifies you. |
| Cookies or web tracking inside the app | No | The app has no embedded web content that tracks you. |
Because we hold no personal data about you, there is nothing about you for us to sell, share, profile or hand over. We do not sell or share personal data, and we never have.
4. Purchases and the Pro unlock
Retro Palette is free to use. It offers one optional in-app purchase, Retro Palette Pro
(retropalette.pro), a one-time non-consumable unlock for the additional palettes and the
higher export resolution.
4.1 Apple and Google process the payment
The purchase itself is handled entirely by the Apple App Store or Google Play, depending on where you installed the app. Your payment details are entered into, and held by, that store. We never see and never receive your card details, billing address or store account credentials. Their handling of your data is governed by Apple's Privacy Policy and Google's Privacy Policy.
4.2 RevenueCat validates the receipt
To know whether you own the Pro unlock — including on a new device after you tap “Restore purchases” —
the app uses RevenueCat, Inc., a purchase-infrastructure provider. When the app starts
or when you make or restore a purchase, it contacts RevenueCat, which validates the store receipt and
returns whether the pro entitlement is active.
What is involved in that exchange:
- An anonymous app user identifier generated by the RevenueCat SDK. We do not set it from any identity of yours, because we do not have one.
- The store receipt or purchase token issued by Apple or Google.
- Basic technical context needed to validate it, such as the platform, the app version, the store country and device/OS information collected by the SDK.
No name, no email address, no photo and no content from your device is sent. The purpose of this processing is to deliver the product you paid for and to let you restore it; the legal basis under Article 6(1)(b) GDPR is performance of a contract with you. RevenueCat acts as our processor — see the RevenueCat Privacy Policy.
If you never buy anything, the app still contacts RevenueCat once at startup to confirm that no entitlement is active. That check carries the anonymous identifier described above and nothing else. The app is fully usable offline; if the check fails, Retro Palette simply keeps working with its locally cached entitlement state.
5. Crash and error reports
When Retro Palette crashes or hits an unexpected error, it sends a report so we can find and fix the fault. This is the one place where the app tells us something without you asking it to, so it is worth being precise about what a report is.
The reports are processed by Sentry (Functional Software, Inc., trading as Sentry), a US error-monitoring provider acting as our processor. They are sent to a project used only by this app.
5.1 What a report contains
- The error itself — its type, its message and the stack trace showing which code failed.
- The app version and build number, and whether it was a store build or a development one.
- Device and operating-system information: model, OS version, language, available memory and storage, and whether the device was low on either.
- A short trail of the actions leading up to the failure — for example that a button was tapped or a screen was opened. The text on those controls is deliberately excluded, so the trail records that something was tapped, never what it said.
- A random identifier generated when the app is first installed. It lets us tell "one person crashed forty times" apart from "forty people crashed once", which changes how urgent a bug is. It is not derived from you, your device's hardware ids, or any account; it is created on the device, and reinstalling the app replaces it with a new one.
5.2 What a report never contains
- No images. Not the photo you picked, not the converted result, not a thumbnail. Automatic screenshot attachment is a feature of the reporting SDK and it is switched off in this app, deliberately and permanently — the screen almost always shows one of your own photos.
- No IP address. The SDK is configured not to send one, and the receiving project is additionally set to discard IP addresses before storage.
- No name, email address, account or advertising identifier — the app has none of these to send.
- Nothing about which palettes you use, how many images you convert, or how often you open the app. Crash reporting is not analytics, and there is no analytics SDK in the app.
5.3 Why we are allowed to do this
The legal basis under Article 6(1)(f) GDPR is our legitimate interest in keeping the app working and fixing defects that would otherwise be invisible to us. We consider this proportionate because the reports are stripped of the things that would identify you, and because the alternative — shipping updates without knowing what is broken on real devices — produces a worse app for everyone. If you would rather not send them, see 5.5.
5.4 Storage, retention and transfers
Reports are transmitted over HTTPS and stored on Sentry's infrastructure in the United States, which is a transfer outside the EEA. It is covered by the Standard Contractual Clauses incorporated into our agreement with Sentry. Reports are kept only for a limited retention period and are then deleted automatically; we do not archive them elsewhere.
5.5 If you would rather not send crash reports
The app has no in-app switch for this in the current version. If you object to this processing, write to info@softwarefirst.gr — under Article 21 GDPR you have the right to object to processing based on legitimate interests, and we will tell you how to stop it. We are considering an opt-out toggle in a future version.
6. Device permissions
| Permission | Platform | Why it is needed |
|---|---|---|
| Photo library — read | iOS | To let you pick the one image you want to convert. Requested at the moment you tap to choose a photo. |
| Photo library — add | iOS | To save the converted image back to your gallery. Requested when you tap save. |
| Photo picker / media store | Android | Android 10 and later let the app receive the picked photo and write the export through the system media store without broad storage permissions, so the app does not request any. |
INTERNET, ACCESS_NETWORK_STATE | Android | Used for the purchase/entitlement check in section 4 and the crash reports in section 5, and nothing else. Image conversion never uses the network. |
You can withdraw photo access at any time in your device settings. The app will simply be unable to open or save pictures until you grant it again.
7. Data stored on your device
Retro Palette keeps a very small amount of state locally, in the app's own private storage:
- Whether you have completed the onboarding screen, so it is not shown to you again.
- A cached flag recording whether the
proentitlement is active, so the app starts instantly and works offline.
Neither of these identifies you. They never leave the device, and uninstalling the app removes them.
8. Advertising
This version of Retro Palette contains no advertising. No advertising SDK is bundled in the app, no ads are displayed, and no advertising identifier is read.
We may introduce advertising in a future version. If we do, we will update this policy before that version is released, describe exactly which advertising provider is used and what it processes, and — for users in the EEA, the UK and Switzerland — present a consent dialogue through a certified consent management platform before any ad is loaded. Owners of the Pro unlock would not see ads.
9. Children
Retro Palette is a general-audience utility. It is not directed at children, and we do not knowingly collect personal data from anyone, including children — the app collects no personal data at all. If you believe a child has somehow provided us with personal data, contact us and we will look into it, though in practice there is no channel through which that could happen.
10. This website
This policy covers the app. Separately, the marketing pages on softwarefirst.gr — including
the Retro Palette overview page — use Google Analytics to
count visits. That is a website measurement tool and is entirely unconnected to the app; nothing it
records is linked to anything in Retro Palette.
This privacy policy page, the terms of use and the support page deliberately load no analytics and no third-party scripts. Reading our policy should not be a tracked event.
11. Your rights under the GDPR
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the rights of access, rectification, erasure, restriction, data portability and objection, as well as the right not to be subject to solely automated decision-making, in respect of personal data a controller holds about you.
In our case the honest answer is that we hold nothing that identifies you — no name, no email address, no account. There are two records connected to your use of the app, and neither is tied to your identity: the purchase record described in section 4 sits with Apple, Google and RevenueCat against an anonymous identifier and your store account, and the crash reports described in section 5 sit with Sentry against a random per-install identifier.
The practical consequence cuts both ways. It means there is almost nothing about you for anyone to retrieve, profile or leak — but it also means that, given only your name or email address, we have no way to find records relating to you, because no such link exists for us to follow. Where we cannot identify you from the data we hold, Article 11 GDPR does not require us to acquire more information purely to be able to.
You can still write to info@softwarefirst.gr to exercise any of these rights, including your right to object under Article 21 to the crash reporting described in section 5. We will respond within one month. If you give us the anonymous app user id shown by our support team's instructions, or your store transaction id, we can ask RevenueCat to delete the associated purchase record on your behalf — bear in mind that doing so may prevent you from restoring a purchase you have paid for.
You also have the right to lodge a complaint with a supervisory authority. In Greece that is the Hellenic Data Protection Authority; if you live elsewhere in the EEA, you may complain to your own national authority.
12. Retention, deletion and international transfers
12.1 Retention
We hold no personal data about you, so for the most part there is nothing to retain. The two exceptions are both described above: purchase records held by RevenueCat on our behalf are kept for as long as the app is operated, so that you can restore a purchase you paid for, and are deleted when they are no longer needed for that purpose; crash reports are kept by Sentry for a limited retention period and then deleted automatically (section 5.4).
12.2 Deleting your data
Uninstalling Retro Palette removes everything the app stored on your device. Because there is no account, there is no account to delete. For the purchase record, see section 11.
12.3 International transfers
Two of our processors are based in the United States, so both exchanges involve a transfer outside the EEA: RevenueCat, Inc. for the receipt validation described in section 4, and Sentry for the crash reports described in section 5. Both transfers are covered by the Standard Contractual Clauses incorporated into our agreements with them. Apple and Google likewise operate globally under their own published transfer safeguards.
13. Security
The strongest security property of this app is architectural: your images stay on your device, so there is no server for anyone to breach and no database of user content to leak. Both outbound channels — the purchase check and the crash reports — use HTTPS. The app's local storage is the operating system's private per-app storage, protected by the device's own sandboxing and encryption.
14. Changes to this policy
If we change how the app handles data, we will update this page and change the version and effective date at the top. Material changes — in particular, introducing advertising or analytics — will be published here before the version that makes them is released to the stores. Previous versions are available on request.
14.1 What changed in version 1.1
28 August 2026. Retro Palette now sends crash and error reports, which version 1.0 of this policy said it did not. The new section 5 describes what a report contains and what it excludes, and sections 6, 12 and 13 were corrected to match. This page was updated before the change reached a public store release, as promised above. No other processing changed: images are still converted entirely on your device, and there is still no analytics SDK and no advertising in the app.
15. Contact
Questions, requests or corrections about this policy:
Software First — Athens, Greece
info@softwarefirst.gr
For help using the app, the support page is the faster route.