FraudMax · LEGAL
Privacy Policy
Effective date: 21 August 2026 Last updated: 21 August 2026
FraudMax is an iOS application that allows users to upload portrait photographs and request AI-powered facial and photographic enhancements.
This Privacy Policy explains what personal information FraudMax collects, why it is used, how it is stored and shared, and the choices and privacy rights available to you.
FraudMax is operated by Arthur K. Cassidy, operating as FraudMax ("FraudMax", "we", "us" or "our"), based in the United Kingdom.
For data-protection purposes, FraudMax is the controller of personal information processed through the FraudMax service where applicable.
Contact: Contact@FraudMax.app Website: https://fraudmax.app
1. Information We Collect
The information FraudMax processes depends on how you use the app.
1.1 Photographs and Generated Images
FraudMax allows you to:
- select a photograph from your device; or
- take a photograph using your device's camera.
When you request an enhancement, the selected photograph is uploaded to FraudMax's Google Cloud-hosted infrastructure so that the requested enhancement can be processed.
The photograph, together with the instructions needed to perform the enhancement, is processed using Google Gemini.
The resulting enhanced image is then returned to the app.
Generated images may also be stored using Firebase Storage so that you can access previous images through FraudMax's image-history features.
Depending on the photograph and the way it was created, the image file may also contain technical or embedded metadata.
FraudMax currently sends the selected image file for processing without separately extracting or removing embedded image metadata. Any metadata contained in the submitted file may therefore be transmitted as part of that file, although FraudMax does not use such metadata to identify users or for advertising.
1.2 Anonymous Account Identifier
FraudMax uses Firebase Authentication to create an anonymous account identifier.
You do not necessarily need to provide your name, email address or create a traditional username and password account in order to use FraudMax.
Firebase assigns the installation or user account a unique identifier. Although Firebase refers to this as anonymous authentication, the identifier may still be considered personal information when it can be associated with your use of the service.
FraudMax may display or use this Firebase identifier as your Developer Key.
The Developer Key allows FraudMax support or authorised administrators to identify the corresponding FraudMax account, including for purposes such as adding promotional tokens.
1.3 Token and Account Information
FraudMax uses Firebase Firestore to store information associated with your account, which may include:
- your Firebase user identifier;
- your token balance;
- whether you are eligible for a free image or enhancement;
- promotional token adjustments;
- subscription-related account state;
- usage information required to determine whether an enhancement may be processed; and
- other technical account information necessary to operate the service.
FraudMax uses tokens to manage access to image enhancements. An enhancement may consume tokens unless a free enhancement, promotional allowance, subscription entitlement or another applicable entitlement covers it.
1.4 Subscription and Purchase Information
FraudMax uses RevenueCat to manage subscription status and purchase entitlements.
RevenueCat may process information such as:
- subscription status;
- purchase and transaction identifiers;
- product or subscription identifiers;
- entitlement status;
- renewal or expiration information;
- App Store receipt or transaction information; and
- identifiers required to associate an entitlement with a FraudMax account.
Payments made through the iOS application are processed by Apple through the App Store.
FraudMax does not directly receive or store your complete payment-card details when you purchase a subscription through Apple.
Apple may independently collect and process billing, payment and App Store account information in accordance with Apple's own privacy practices.
1.5 Technical, Usage and Security Information
FraudMax may process technical information reasonably necessary to provide, maintain, troubleshoot and secure the service.
This may include:
- device type and operating-system information;
- app version;
- Firebase identifiers;
- IP address;
- server request information;
- request and response timestamps;
- error information;
- server logs;
- authentication information;
- image-processing request information;
- subscription or entitlement checks; and
- information used to detect technical failures, misuse, abuse or security incidents.
FraudMax does not necessarily collect every item listed above during every use of the app.
1.6 Information You Send to Support
If you contact FraudMax, we may process the information you provide in your message, such as:
- your email address;
- your Developer Key;
- the contents of your support request;
- screenshots or attachments you choose to send; and
- information required to investigate and resolve the issue.
Please avoid sending unnecessary sensitive information when contacting support.
2. How We Use Your Information
FraudMax may use personal information to:
- provide the image-enhancement service you request;
- upload, process and return photographs;
- operate AI image-processing functionality;
- provide image-history functionality;
- authenticate anonymous FraudMax accounts;
- maintain token balances and free-image eligibility;
- determine subscription and entitlement status;
- apply promotional tokens or other authorised account adjustments;
- provide customer support;
- troubleshoot crashes, errors and failed image-processing requests;
- maintain the security and integrity of FraudMax;
- detect or prevent abuse, unauthorised access and fraudulent use;
- maintain necessary operational records;
- comply with applicable legal requirements; and
- establish, exercise or defend legal rights where necessary.
FraudMax will not use personal information for materially unrelated purposes without an appropriate legal basis and, where required, additional notice to you.
3. Portrait Photographs, Facial Information and Sensitive Information
Portrait photographs are personal information and should be treated carefully because they contain an image of a person's face and appearance.
Photographs may also reveal or appear to reveal sensitive characteristics about a person.
Under UK data-protection law, however, an ordinary digital photograph is not automatically considered biometric or special-category data merely because it contains a person's face. Facial information generally becomes biometric data for these purposes when specific technical processing is used to uniquely identify or authenticate an individual.
FraudMax's described purpose for processing photographs is to perform user-requested image enhancements, not to establish a person's identity.
FraudMax does not use uploaded or generated photographs for facial recognition, biometric identification or authentication, the creation of biometric identity templates, advertising profiles, or the sale of personal information.
FraudMax may use automated systems to analyse visual information to produce the image enhancement you request. That image processing is different from using facial information to determine who a person is.
4. AI Image Processing
FraudMax uses Google Gemini to perform AI image processing.
When an enhancement is requested, information necessary to complete that request may be sent to Google, including:
- the photograph being enhanced;
- instructions describing the requested enhancement; and
- technical information necessary to submit and receive the processing request.
Google processes this information as part of providing the AI-processing service used by FraudMax.
FraudMax uses the Gemini Developer API. Google's processing of submitted content is governed by the terms, data-handling practices and account settings applicable to that service.
FraudMax's AI enhancement feature is intended to edit or generate images. It is not intended to make decisions about your employment, education, credit, insurance, legal rights or other matters that produce legal or similarly significant effects.
AI systems may produce unexpected, inaccurate or imperfect results. The output should not be treated as a factual assessment of a person's health, identity or other personal characteristics.
5. Legal Bases for Processing
Where the UK GDPR applies, FraudMax must have a lawful basis for processing personal information.
Depending on the circumstances, FraudMax may rely on the following bases.
Performance of a Contract
FraudMax may process information where it is necessary to provide the service you request, including:
- processing photographs;
- generating enhanced images;
- maintaining your FraudMax account;
- managing tokens and entitlements;
- providing image history; and
- providing subscription functionality.
Legitimate Interests
FraudMax may process information where necessary for legitimate interests such as:
- securing the service;
- preventing abuse and unauthorised access;
- maintaining reliable infrastructure;
- investigating technical failures;
- responding to support requests; and
- protecting FraudMax's legal rights.
Where FraudMax relies on legitimate interests, those interests must be balanced against the rights and interests of affected individuals.
Legal Obligations
FraudMax may process or retain information where necessary to comply with a legal obligation.
Consent
Where applicable law requires consent for a particular type of processing, FraudMax will rely on consent and you may withdraw that consent as permitted by applicable law.
Your device may also request permission before allowing FraudMax to use functions such as your camera or photo library. These permissions can generally be managed through iOS settings.
6. Photographs of Other People
You should only upload photographs that you have the legal right or appropriate permission to use.
If you upload an image containing another identifiable person, information relating to that person may also be processed by FraudMax and its service providers for the purpose of completing the enhancement you requested.
You should consider the other person's privacy before uploading or modifying their photograph.
7. Service Providers and Other Recipients
FraudMax uses third-party services to operate the application.
Google Cloud and Firebase
Google services are used for infrastructure and backend functionality, including:
- Google Cloud server infrastructure;
- Firebase Authentication;
- Firebase Firestore;
- Firebase Storage; and
- related backend services.
Depending on the service, Google may process account identifiers, technical information, stored images and other information necessary to provide the relevant infrastructure.
Google Gemini
Google Gemini processes photographs and enhancement instructions required to perform AI image enhancements.
RevenueCat
RevenueCat is used to manage subscription status, purchase information and entitlements.
Apple
Apple processes purchases and subscriptions made through the App Store.
Apple operates its own services and may act independently in relation to information associated with your Apple account, App Store transactions and payment methods.
Legal and Security Disclosures
FraudMax may disclose information where reasonably necessary to:
- comply with applicable law or a valid legal process;
- respond to lawful requests from public authorities;
- investigate fraud, abuse or security incidents;
- protect the rights, property or safety of FraudMax, users or others; or
- establish, exercise or defend legal claims.
FraudMax does not give service providers permission to use information for unrelated purposes merely because they provide infrastructure to FraudMax. Their processing is also subject to their applicable agreements, configurations and legal obligations.
8. Sale, Sharing and Advertising Use of Personal Information
FraudMax does not sell personal information for money and does not share personal information for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act. FraudMax does not use uploaded portrait photographs to create advertising profiles.
FraudMax does not sell personal information for money and does not share personal information for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act. FraudMax does not use uploaded portrait photographs to create advertising profiles.
9. How Long We Keep Information
FraudMax should retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including providing the service, maintaining security, resolving disputes and complying with legal obligations.
FraudMax applies the retention periods set out below. These periods may be extended where reasonably necessary to comply with law, investigate security incidents, prevent abuse, resolve disputes, or establish, exercise or defend legal claims.
Information may need to be retained for longer where reasonably necessary to comply with applicable law, investigate security incidents, resolve disputes, prevent abuse or establish, exercise or defend legal claims.
Apple, Google and RevenueCat may maintain information under their own retention policies where they act independently or are legally required to retain information.
10. Deleting Images and Your FraudMax Data
Deleting Individual Images
FraudMax allows you to delete stored images from within the app.
When you delete an image, FraudMax will remove the corresponding image from the user-accessible image history and initiate deletion from FraudMax-controlled storage as applicable.
When deletion is requested, FraudMax removes the image from user-accessible history and active FraudMax-controlled storage. Residual copies in backups, caches or disaster-recovery systems may remain for up to 90 days before being deleted or overwritten.
Deleting the FraudMax App
Deleting FraudMax from your iPhone does not, by itself, constitute a request to delete information stored in the cloud.
Cloud information associated with your Firebase identifier may remain after the app is removed from your device, subject to FraudMax's retention periods.
If you want your FraudMax data deleted completely, you should make a separate deletion request.
Requesting Complete Account and Data Deletion
To request deletion of your FraudMax account information and associated personal data, contact:
Use a subject such as "Data Deletion Request" and, where possible, include your Developer Key so FraudMax can identify the relevant anonymous Firebase account.
Because FraudMax uses anonymous authentication, the Developer Key may be necessary to locate the correct account.
FraudMax may request information reasonably necessary to verify that you are authorised to request deletion of the account.
Deletion requests will be handled in accordance with applicable law. Certain information may be retained where FraudMax is legally permitted or required to do so, including information necessary for security, fraud prevention, legal claims or compliance obligations.
Deleting FraudMax data does not automatically cancel an App Store subscription. App Store subscriptions must be cancelled separately through Apple.
FraudMax does not currently provide a complete in-app account-deletion function. Complete account and data deletion can be requested using the email process described above.
11. International Data Transfers
FraudMax is operated from the United Kingdom, but some service providers used to operate the app are international organisations.
As a result, personal information may be processed or stored outside the United Kingdom and, where applicable, outside the European Economic Area.
This may include processing by Google, RevenueCat, Apple or their infrastructure providers in countries in which they operate.
Where UK data-protection law restricts an international transfer, a valid transfer mechanism must be used where required. Depending on the circumstances, this may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses;
- another recognised safeguard; or
- another lawful transfer mechanism available under applicable data-protection law.
FraudMax relies on the contractual and organisational safeguards made available by its service providers for restricted international transfers, which may include adequacy regulations, standard contractual clauses and the UK International Data Transfer Addendum where applicable.
Where the EU GDPR applies, equivalent appropriate safeguards must be used for restricted transfers from the EEA where required.
12. Security
FraudMax uses technical and organisational measures intended to protect information against unauthorised access, alteration, disclosure, loss or destruction.
FraudMax uses Google Cloud-hosted infrastructure and limits access to systems and information to the extent reasonably necessary to operate and support the service.
Measures used by FraudMax include encrypted HTTPS connections, Google Cloud and Firebase security controls, Firebase authentication, restricted administrator access, server-side secret storage, and access rules intended to limit users to their own account data. Google Cloud and Firebase also provide encryption at rest for relevant managed storage services.
No internet transmission, cloud platform or storage system can be guaranteed to be completely secure. FraudMax therefore cannot guarantee absolute security.
If you believe your FraudMax account or data may have been compromised, contact Contact@FraudMax.app.
13. Your Privacy Rights
Your rights depend on where you live and which privacy laws apply.
These rights are not absolute and may be subject to legal conditions or exceptions.
UK GDPR Rights
If the UK GDPR applies to your personal information, you may have the right to:
- Access — ask whether FraudMax processes your personal information and request a copy of it.
- Rectification — ask FraudMax to correct inaccurate or incomplete personal information.
- Erasure — ask FraudMax to delete personal information in certain circumstances.
- Restriction — ask FraudMax to restrict the processing of personal information in certain circumstances.
- Data portability — receive certain information you provided to FraudMax in a structured, commonly used and machine-readable format where the legal requirements for portability are met.
- Object — object to certain processing based on legitimate interests.
- Withdraw consent — where FraudMax relies on consent, withdraw that consent without affecting processing that was lawful before withdrawal.
- Complain to a supervisory authority — raise a concern with the UK Information Commissioner's Office ("ICO").
You may exercise these rights by contacting Contact@FraudMax.app.
FraudMax may need to verify your identity or your connection with a particular Developer Key before fulfilling a request.
European Economic Area
If you are located in the EEA and the EU GDPR applies to FraudMax's processing of your personal information, you may have equivalent GDPR rights and may also have the right to complain to the data-protection supervisory authority in your country.
Users in the EEA may contact FraudMax directly at Contact@FraudMax.app regarding EU data-protection questions or requests.
14. California Privacy Rights
This section applies only to the extent that the California Consumer Privacy Act, as amended ("CCPA"), applies to FraudMax and to the relevant personal information.
Depending on how you use FraudMax, categories of personal information processed may include:
- Identifiers, such as your Firebase identifier, Developer Key and IP address;
- Commercial information, such as subscription, transaction and entitlement information;
- Internet or electronic network activity information, such as request data and technical logs;
- Visual information, including uploaded photographs and generated images; and
- Other account or service information necessary to provide FraudMax.
This information is generally collected directly from you, your device, Apple, Firebase, RevenueCat or through your interaction with the FraudMax service.
The purposes for collecting these categories are described in the How We Use Your Information section above.
The categories of service providers to which information may be disclosed are described in the Service Providers and Other Recipients section above.
FraudMax has not sold personal information or shared personal information for cross-context behavioural advertising during the preceding 12 months.
Where the CCPA applies, California residents may have rights including:
- the right to know what personal information is collected, used and disclosed;
- the right to access specific pieces of personal information;
- the right to delete qualifying personal information;
- the right to correct inaccurate personal information;
- the right to opt out of sale or sharing of personal information, if FraudMax engages in activity legally defined as a sale or sharing;
- the right to limit certain uses or disclosures of sensitive personal information, where applicable; and
- the right to non-discrimination for exercising applicable CCPA rights.
An authorised agent may make a request on your behalf where permitted by California law. FraudMax may request appropriate verification of the request and the agent's authority.
California privacy requests may be submitted to:
FraudMax will respond within the timeframes required by applicable law.
15. Children's Privacy
FraudMax is intended only for users aged 16 or older.
You must be at least 16 years old to use FraudMax. If local law requires a higher minimum age or parental authorisation for a particular activity, that requirement also applies.
FraudMax should not be used by anyone below the applicable minimum age unless the use is permitted under applicable law and any required parental or guardian involvement has been obtained.
Because FraudMax processes portrait photographs, special care should be taken before uploading photographs of children.
If you are a parent or guardian and believe that FraudMax holds personal information relating to a child in circumstances where it should not, contact:
FraudMax will review the request and take action as required by applicable law.
16. Website Privacy
This Privacy Policy is intended to be published at:
The information provided above describes the FraudMax iOS application and its supporting services.
The FraudMax website does not currently use advertising pixels, behavioural advertising, marketing cookies, analytics tools or public contact forms. Its hosting provider may process limited request and security-log information, such as IP addresses and request timestamps, to deliver and protect the website.
17. Changes to This Privacy Policy
FraudMax may update this Privacy Policy from time to time to reflect:
- changes to the app;
- new features;
- changes to service providers;
- changes to data-processing practices;
- security or operational changes; or
- changes in applicable law.
When this Privacy Policy is updated, the Last updated date at the top of the policy will be changed.
Where required by law, FraudMax will provide additional notice of material changes.
You should review this Privacy Policy periodically to understand how FraudMax handles personal information.
18. Contact FraudMax
Questions, privacy requests, account-deletion requests or concerns about this Privacy Policy can be sent to:
FraudMax Operated by Arthur K. Cassidy, operating as FraudMax United Kingdom
Email: Contact@FraudMax.app Website: https://fraudmax.app
If you are in the United Kingdom and are dissatisfied with FraudMax's handling of your personal information, you may also have the right to complain to the Information Commissioner's Office (ICO).
19. Summary
In simple terms:
FraudMax processes the photograph you choose in order to create the enhancement you request. The photograph is uploaded to cloud infrastructure and processed using Google Gemini.
Firebase is used to operate anonymous accounts, token balances, eligibility and image-history features. RevenueCat manages subscription entitlements, while Apple processes App Store payments.
Deleting an individual image through FraudMax can remove it from your image history, but deleting the FraudMax app from your iPhone does not automatically delete information stored in FraudMax's cloud systems.
To request complete deletion of your FraudMax data, contact Contact@FraudMax.app and include your Developer Key where possible.
FraudMax should collect and retain only the information reasonably necessary to operate, secure and support the service, subject to the more detailed terms of this Privacy Policy.
| Information | Retention |
|---|---|
| Original photographs uploaded for enhancement | Processed for the duration of the enhancement request and not intentionally retained by FraudMax after processing. Copies temporarily held by service providers are governed by their applicable service terms and retention practices. |
| Generated images stored in image history | Until deleted by the user or until the associated FraudMax account is deleted. |
| Firebase account identifier / Developer Key | Until the associated FraudMax account is deleted, unless longer retention is required for security, fraud prevention or legal compliance. |
| Token balance and free-image eligibility records | Until the associated FraudMax account is deleted, unless longer retention is required for security, fraud prevention or legal compliance. |
| Subscription and entitlement records controlled by FraudMax | For the life of the account and for up to 24 months afterward where reasonably required for support, accounting, disputes or legal compliance. |
| Technical, security and server logs | Normally up to 30 days, unless longer retention is reasonably necessary to investigate abuse, security incidents or technical failures. |
| Support communications | Up to 24 months after the support request is resolved, unless longer retention is reasonably necessary for an ongoing dispute or legal obligation. |
| Deleted information remaining in backups, caches or disaster-recovery systems | Deleted or overwritten within 90 days. |