Privacy Policy
Last updated: July 2, 2026
On this page
- 1. Overview
- 2. What we collect
- 3. What stays on your device
- 4. Why we collect it
- 5. Storage and retention
- 6. Who we share it with
- 7. The public portfolio
- 8. Client testimonials and consent
- 9. Payments
- 10. No ad tracking
- 11. Security
- 12. Your rights and choices
- 13. Children's privacy
- 14. International users
- 15. Changes to this policy
- 16. Contact
1. Overview
This Privacy Policy explains what data Befora (the iOS app and the befora.pro website, operated by Gokazu) collects, why, how it's stored, and how you can control or delete it. Befora is built local-first and account-optional at the capture layer: the camera, alignment, and file organization work entirely on your device before you ever sign in.
2. What we collect
What we collect depends on how far you use the Service:
| Category | Examples | When |
|---|---|---|
| Account identity | Sign in with Apple identifier, email if you provide one | When you create an account |
| Business profile | Business name, logo, colors, bio, phone, WhatsApp, email, social links, Google Place ID | When you fill in Settings / onboarding |
| Job content | Job titles, locations, categories, client names/phone/email/notes, angle labels | As you use the app |
| Photos and videos | Before & after shots, loose shots, client testimonial clips | When you capture them, if you turn on cloud sync |
| Testimonial consent | Whether a client agreed to public sharing of their quote/clip, and their attribution text | When you record a testimonial |
| Generated outputs | Collages, PDFs, reel video files | When you generate them, if cloud sync is on |
| Subscription status | Whether your account is subscribed, and through which channel (Apple or Stripe) | When you subscribe |
| Feedback | Whatever you type or attach when you submit in-app feedback | When you choose to send feedback |
We do not ask for or collect government ID, precise real-time location tracking, contacts-list access, or biometric identifiers.
3. What stays on your device
If you never create an account, Befora works entirely offline: your jobs, photos, and generated outputs are stored only in the app's local database on your phone. Nothing is sent to us. Signing in adds cloud backup and multi-device sync — from that point, the content listed above is copied to our database and file storage so it can follow you across devices and survive a lost or replaced phone.
AI-assisted features that run in the app (like transcribing a testimonial's audio) run on-device using Apple's on-device speech recognition where available — that audio isn't sent to a third-party AI service to be processed.
4. Why we collect it
- To operate the core product: aligning before & after shots, generating collages/PDFs/reels, and organizing jobs and clients.
- To back up and sync your account: so your data survives a device loss and stays consistent across your devices.
- To run the subscription: to know whether your account is entitled to Pro features and to bill you through Apple or Stripe.
- To operate your public portfolio, if you turn it on: serving your published jobs and consented testimonials at befora.pro/yourhandle and through the embed script.
- To respond to feedback you choose to send us.
- To keep the Service secure and working — basic operational logs on our infrastructure (e.g., error logs, request logs) that are not used for tracking or advertising.
5. Storage and retention
Cloud data (once you sign in and sync) is stored in Supabase-hosted Postgres and file storage. We keep your account data for as long as your account exists. If you delete a job, client, or piece of content in the app while signed in, that deletion is intended to propagate to the cloud copy and to remove it from your public portfolio; if you delete your account entirely, we remove your cloud-stored data and unpublish your portfolio. Content stored only on-device (never synced) is deleted the moment you delete it in the app, or if you uninstall the app.
Backups of our production database may retain deleted data for a limited operational window before they age out, as is standard for database backup systems — we don't use backups to keep data alive that you asked us to delete.
6. Who we share it with
We don't sell your data, and we don't share it with data brokers or advertisers. We share data only with the service providers that make Befora work, each acting on our behalf:
- Supabase — database, authentication, and file storage for your account and synced content.
- Apple — Sign in with Apple, StoreKit subscription billing, on-device speech transcription, and push notifications.
- Stripe — payment processing for web-based subscriptions. We don't see or store your full card number; Stripe handles that directly.
We may also disclose information if required by law, to protect the rights or safety of Gokazu, our users, or the public, or in connection with a merger, acquisition, or sale of assets — in which case this policy would continue to govern how your data is handled.
7. The public portfolio
The public portfolio is opt-in and controlled entirely by you. If you turn on publishing (globally in Settings, and per job), the following becomes visible to anyone who has your befora.pro/yourhandle link or finds it via search: your business name, logo, colors, bio, and contact links you chose to add; your published jobs' before & after images; and any testimonial quote or clip you marked as OK to share publicly. Client phone numbers, emails, private notes, and any testimonial not marked shareable are never included on the public portfolio, regardless of the publish switch.
If you use the embed script on your own website, it pulls the exact same public data your portfolio page shows — nothing additional.
8. Client testimonials and consent
When you record a client testimonial in the app, you confirm whether the client agreed to have their quote and/or clip shared publicly. That flag is stored with the testimonial and gates whether it can ever appear on your portfolio or in an exported reel. If a testimonial isn't marked shareable, its content is excluded from anything public. You (the provider) are responsible for actually obtaining your client's consent before marking a testimonial shareable — see the Terms of Use §5 for the full allocation of that responsibility.
A client who wants a testimonial about them removed should contact the provider who recorded it (you), or reach us directly at support@befora.pro and we'll help route the request.
9. Payments
Subscriptions are billed either through Apple's In-App Purchase system (StoreKit) or through Stripe for web checkout. In both cases, payment card details are handled entirely by Apple or Stripe — we never receive or store your full card number. We do store whether your account is subscribed, through which channel, and a Stripe customer reference (for the web rail) so we can manage your subscription and support requests.
10. No ad tracking
Befora does not run advertising, does not include third-party ad SDKs, and does not use your content or activity to build an advertising profile of you or your clients. We don't sell data to data brokers.
11. Security
Data in transit to our cloud services is encrypted (HTTPS/TLS). Cloud data access is governed by row-level security tied to your account, so one account's data isn't readable by another. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable measures to protect your data and to limit what's exposed by any single credential.
12. Your rights and choices
- Access and export: your jobs and content are visible in the app at any time; client PDFs and reels can be exported and shared from the app.
- Correction: edit any job, client, or profile field directly in the app.
- Deletion: delete individual jobs, clients, or testimonials from the app; delete your entire account (and its cloud data) from Settings, or by contacting us.
- Unpublish: turn off the global publish switch or an individual job's visibility at any time to remove it from your public portfolio.
- Depending on where you live (for example under the GDPR or California's CPRA), you may have additional rights to access, correct, delete, or port your data, or to object to certain processing. Contact us at the address below to exercise these rights — we'll respond within the time required by applicable law.
13. Children's privacy
Befora is a tool for professionals running a business and is not directed at children. We don't knowingly collect data from anyone under 13 (or the relevant minimum age in your region). If you believe a child has provided us data, contact us and we'll delete it.
14. International users
Our service providers (Supabase, Apple, Stripe) operate infrastructure in multiple regions, which may mean your data is processed outside the country you're in. We rely on our providers' standard safeguards for cross-border transfers where applicable.
15. Changes to this policy
We may update this Privacy Policy as the product changes. If we make a material change, we'll update the "Last updated" date above and, where required, notify you in the app.
16. Contact
Questions about this policy, or to exercise a data right described above: support@befora.pro.
See also our Terms of Use.