LEGAL

Privacy

Effective 28 September 2026. Huginn is made by The Forge.

The short version

Your photographs and your recipes are yours. They stay on your device and, if you use iCloud, in your own private iCloud storage, which we cannot read. Talking to your camera happens directly between your phone and the camera and never passes through us. The one exception is setting up a camera Huginn still needs to map for full feature functionality. Huginn reads the settings from the photos you take of your camera's setting screens, on your phone, and sends us those settings and a copy of the camera's settings so we can support that camera. The photos themselves never leave your phone. The details are below. The app does count how it is used, in aggregate and without any of your content, so we can tell a broken feature from an unloved one, and this website counts page views the same way. Both run on our own servers. There is no analytics company in the app. The one advertising component in the app is Meta’s SDK, used only to measure, in aggregate, whether one of our ads led to an install or a subscription. It runs with cross-app tracking and the advertising identifier turned off, so you are not tracked across apps and no advertising profile is built about you. It never receives your recipes, your photographs, your camera details, or anything you create. This website is the one place we advertise from, so it can carry a Meta pixel that measures whether an ad led to a subscription; in Europe and the UK it runs only if you allow it, and it is described in full under This website below. You can sign in with Apple if you want a subscription, and that is the only account there is.

What the app stores on your device

Recipes, Film Palettes, saved recipes, camera backups, and your profile details are stored on your device. If you are signed in to iCloud, the app mirrors them into your private iCloud database so they appear on your other devices. That storage belongs to your Apple account. It is not our server, we cannot read it, and deleting the app or turning off iCloud for Huginn removes it.

What the app sends us

Huginn records a small set of usage events and sends them to us. They are counts and labels, never content. Specifically:

How far people get. Whether the app was opened for the first time, whether onboarding finished, whether a camera was found, whether it connected, whether a recipe was written to it, and whether that write succeeded. This is how we tell a transport bug from someone who simply does not own a compatible camera. Those two look identical in a total and need completely different fixes.

Which cameras are nearby. When the app scans over Bluetooth and sees a camera advertise itself, we record the manufacturer and the model family, for example Fujifilm and X-T5. We record cameras we cannot yet support, including cameras from other manufacturers, because that is the only honest way to decide which brand to build for next. We never record a serial number, and the identifier your camera uses for pairing is never sent.

Camera compatibility. When the app meets a camera Huginn still needs to map for full feature functionality, it records what it needs in order to support that camera, and sends us that compatibility information. It describes the camera model and never your serial number. When the app sets up a camera Huginn still needs to map for full feature functionality, it asks you to photograph the camera's custom setting screens. The photos are read on your phone and never leave it. At the end of setup we receive the settings read from them (for example, Classic Chrome with weak grain) and a copy of the camera's settings. Before that settings data leaves your phone, the camera's serial number and every name stored in it are erased, including the names you gave your custom settings and any owner name the camera holds. It is stored privately, seen only by us, and used only to support that camera. We keep it, because it is what lets every later owner of that camera skip setup. We stop collecting it once enough owners of that camera have set it up.

Which features get used. A count when a tab is opened, when a recipe is created, forked, saved or shared, when an import or a shoot plan or a backup is made, when a locked Pro feature is reached for, when the paywall is shown, and when checkout is opened. Which feature, and nothing about it.

Which library recipe, when it is one of ours. When you view, save, install or build on a recipe from the public library, we record which one, by the same short name that appears in its web address. This is how we can tell which looks people actually carry to a camera rather than only look at. Recipes you made yourself have no such name and are only ever counted, never identified.

Which film simulation a new recipe starts from. One of the twenty names Fujifilm gives its film simulations, such as Classic Chrome or Acros. Nothing else about the recipe: not its name, not its settings, not its photographs. It tells us where the community's taste sits, which decides what the library should hold more of.

Whether a camera operation worked, and which step failed. Connecting, pushing a recipe, rendering and switching looks each report success or failure, how long connecting took, which step failed, and the numeric code the camera itself returned. We deliberately do not send the error message, because those are written for people to read and can mention a file name.

Whether you had a subscription at the time. Free or paid, on each event. Without it we cannot tell whether a feature is used by the people paying for it.

Contributions and creator pages. When a recipe is contributed to the public library or withdrawn, when a creator page is opened and how you got to it, and when one of a creator's own links is tapped. That last one exists so we can tell creators something true about what being in the library is worth to them.

Which build it came from. Whether the event came from a released build, a TestFlight build or a development build, so our own testing is never counted as customer behavior, plus the app version, the iOS version and the iPhone or iPad model (for example iPhone15,2, never the name you gave your device). Camera events also name the camera model and firmware version.

Crashes and freezes. When the app crashes or freezes, iOS gives the app a short technical report, and we send its type code, the system's reason and a fingerprint of where in the app it happened. Never a stack of your data, a file name or anything you typed. iOS provides these only if you share analytics with app developers.

Subscribing. When you subscribe or restore a purchase in the app, which plan and what led you to it (for example, the feature you reached for). Never the price paid, a receipt or a transaction number.

Whether an Apple ad led to the install. Once, the app asks Apple which Apple Search Ads campaign, if any, led to the install. This uses no advertising identifier, shows no tracking prompt, and the answer is kept with the random identifier described below.

Contact support. We count when Contact support is opened and from where. The email itself opens in your mail app with your app version, iOS version, device model and camera model already written in. You can edit or delete any of it, and nothing is sent unless you press Send.

Each event carries a random identifier the app generates on first run. It is not derived from your device, it is not an advertising identifier, and it is not connected to your name or your email. If you have signed in with Apple, the event also carries the identifier Apple gave us, so a subscription can be matched to the person who bought it.

What we never collect

We do not collect your photographs. We do not collect the contents of your recipes, their names, or anything you have written in them. We do not collect your location, your contacts, your file names, your camera serial numbers, or any free text you type into the app. There is no analytics company and no cross-site or cross-app tracking. The one advertising component in the app is Meta’s SDK, used only to measure, in aggregate, whether one of our ads led to an install or a subscription. It runs with cross-app tracking and the advertising identifier turned off, so you are not tracked across apps and no advertising profile is built about you. It never receives your recipes, your photographs, your camera details, or anything you create. Nothing the app collects is sold or rented, and none of it is used to build a profile of you or to follow you anywhere else. Beyond that one aggregate measurement, the only advertising measurement we do is on this website, and it is described under This website below.

Your camera and your photos

Connecting over Bluetooth or USB-C is a direct link between your device and your camera. Recipe pushes, slot reads, camera backups, renders, and the remote shutter all happen on that link. The settings we read from your camera, and the backups you take of it, stay on your device. The one exception is setting up a camera Huginn still needs to map for full feature functionality, described above, when a copy of the camera's settings with its serial number and every name erased is sent to us. Photos you take during setup are read on your phone and never uploaded. If you import RAW files from a camera or a memory card, the app asks for permission to read and write your photo library. Photos are read and written on your device only. We never upload them and we never see them.

Where it goes, and how long we keep it

Usage events are sent over an encrypted connection to our own servers at huginnfilm.app and stored in our own database. They are not shared with an analytics company, because we do not use one. We keep the individual events for twelve months, which is long enough to see whether something people did in their first week predicted whether they stayed. After that they are deleted. Summary counts, which carry no identifier at all, are kept indefinitely.

This website

The site counts page views so we can tell which pages are worth keeping. It runs on Umami, which is analytics software we host ourselves on our own infrastructure rather than a service we send visitors to. It sets no cookies, it does not fingerprint your browser, and it stores no identifier for you: a visit is counted as a page, a referring site and a country, and nothing that could be traced back to a person or followed to another site. It is the same standard as the app: counts, never content, never a profile.

Advertising measurement. We run ads for Huginn on Meta platforms (Facebook and Instagram), and to know whether those ads lead to subscriptions rather than to clicks, this website can carry a Meta pixel. When it runs, Meta receives the pages you view here, whether you started a checkout, and whether a checkout completed, together with the usual browser signals (your IP address and browser type). When a subscription is bought, our server also tells Meta that a purchase happened, with the amount and a one-way hash of the email you gave Stripe, so the two reports can be matched as one purchase. Meta uses this under its own privacy policy, which includes matching it to a Facebook or Instagram account you may have. If you are in the European Union, the wider European Economic Area, the United Kingdom or Switzerland, the pixel does not run until you choose Allow on the notice at the bottom of the page, and Decline is remembered. Everywhere else it runs by default, and a browser tracking blocker stops it. This applies to huginnfilm.app only. The Huginn app itself carries no advertising code and never reports anything to Meta.

Accounts and payments

Signing in with Apple is optional and is needed in exactly one place: connecting a subscription to you. We store the identifier Apple gives us and, if you choose to share it, your email address. Apple's private relay address is fine and is all we need. We use it to unlock Pro on your devices and to hold the recipes you save on the web.

Subscriptions are processed by Stripe. We never receive or store your card details. We keep a record of whether your subscription is active, which plan it is, and when it renews, because that is what unlocks paid features.

This website

The public recipe library is readable without signing in.

Newsletter. If you subscribe, we store your email address with our email provider, Resend, and use it only to send Huginn updates. Every message has an unsubscribe link, and unsubscribing removes you.

Contact form. Your message and the address you give us are relayed to our support inbox so a person can reply. We keep the correspondence only as long as it takes to resolve it.

Children

Huginn is not directed at children and we do not knowingly collect information from anyone under 13.

Deleting your account

You can delete your account from inside the app, under More, then Account and billing. You can also do it here on the web from your account page. It takes effect immediately, and you do not have to ask anyone.

Deleting removes your sign-in, your creator page and everything on it (your name, handle, biography, avatar and links), your saved recipes and ratings, any contributions still waiting for review, and any reports or blocks you made. If you have a subscription it is canceled at the same time, so nothing is charged again. Your usage events stop being connected to you.

Recipes you already published to the library stay in the library, with your name removed from them. We say this when you contribute a recipe, and again before you confirm the deletion, because it should never be a surprise afterwards. Publishing puts a recipe in other people's hands: they have saved it, it has a public address, and withdrawing it would take something away from them rather than from us. What comes off is every trace of who made it.

Your own recipes, palettes and photographs are not ours to delete. They live on your device and in your own iCloud, and they stay there. Remove them by deleting them in the app, deleting the app, or turning off iCloud for Huginn.

Your other choices

You can unsubscribe from email at any time using the link in any message. If you would rather not use the in-app button, or you want something we have not listed here, write to the address below and we will do it.

Changes

If this policy changes in a way that affects what we collect, we will update the effective date above and describe the change here. This page was revised on 28 September 2026 to describe what version 1.0.11 adds: the settings data sent when setting up a camera Huginn still needs to map (never the photos), crash and device diagnostics, in-app subscription events, Apple Search Ads attribution and Contact support. It was revised on 21 September 2026 to describe the aggregate advertising measurement added to the app in version 1.0.5. Earlier versions of this page said the app contained no advertising component; from 1.0.5 it contains the one described above, and nothing else. It was revised before that, on 13 August 2026, to describe deleting your account.

Contact

Questions about your data, or a deletion request: support@huginnfilm.app.

Who we are

Huginn is published by The Forge, the app development division of Gatz Holdings LLC, a limited liability company registered in Washington, USA. Gatz Holdings LLC is the legal entity responsible for Huginn and for this policy.