LEGAL
Privacy
Effective 13 August 2026. Huginn is made by The Forge, a division of Gatz Holdings LLC.
The short version
Your photographs and your recipes are yours. They stay on your device and, if you use iCloud, in your own private iCloud storage, which we cannot read. Talking to your camera happens directly between your phone and the camera and never passes through us. The app does count how it is used, in aggregate and without any of your content, so we can tell a broken feature from an unloved one, and this website counts page views the same way. Both run on our own servers. There is no advertising identifier in Huginn, no analytics company involved, and no cross-site tracking of any kind. You can sign in with Apple if you want a subscription, and that is the only account there is.
What the app stores on your device
Recipes, Film Palettes, favorites, camera backups, and your profile details are stored on your device. If you are signed in to iCloud, the app mirrors them into your private iCloud database so they appear on your other devices. That storage belongs to your Apple account. It is not our server, we cannot read it, and deleting the app or turning off iCloud for Huginn removes it.
What the app sends us
Huginn records a small set of usage events and sends them to us. They are counts and labels, never content. Specifically:
How far people get. Whether the app was opened for the first time, whether onboarding finished, whether a camera was found, whether it connected, whether a recipe was written to it, and whether that write succeeded. This is how we tell a transport bug from someone who simply does not own a compatible camera. Those two look identical in a total and need completely different fixes.
Which cameras are nearby. When the app scans over Bluetooth and sees a camera advertise itself, we record the manufacturer and the model family, for example Fujifilm and X-T5. We record cameras we cannot yet support, including cameras from other manufacturers, because that is the only honest way to decide which brand to build for next. We never record a serial number, and the identifier your camera uses for pairing is never sent.
Which features get used. A count when a tab is opened, when a recipe is created, forked, favorited or shared, when an import or a shoot plan or a backup is made, when a locked Pro feature is reached for, when the paywall is shown, and when checkout is opened. Which feature, and nothing about it.
Which library recipe, when it is one of ours. When you view, favorite, install or build on a recipe from the public library, we record which one, by the same short name that appears in its web address. This is how we can tell which looks people actually carry to a camera rather than only look at. Recipes you made yourself have no such name and are only ever counted, never identified.
Which film simulation a new recipe starts from. One of the twenty names Fujifilm gives its film simulations, such as Classic Chrome or Acros. Nothing else about the recipe: not its name, not its settings, not its photographs. It tells us where the community's taste sits, which decides what the library should hold more of.
Whether a camera operation worked, and which step failed. Connecting, pushing a recipe, rendering and switching looks each report success or failure, how long connecting took, which step failed, and the numeric code the camera itself returned. We deliberately do not send the error message, because those are written for people to read and can mention a file name.
Whether you had a subscription at the time. Free or paid, on each event. Without it we cannot tell whether a feature is used by the people paying for it.
Contributions and creator pages. When a recipe is contributed to the public library or withdrawn, when a creator page is opened and how you got to it, and when one of a creator's own links is tapped. That last one exists so we can tell creators something true about what being in the library is worth to them.
Which build it came from. Whether the event came from a released build, a TestFlight build or a development build, so our own testing is never counted as customer behaviour.
Each event carries a random identifier the app generates on first run. It is not derived from your device, it is not an advertising identifier, and it is not connected to your name or your email. If you have signed in with Apple, the event also carries the identifier Apple gave us, so a subscription can be matched to the person who bought it.
How far people get. Whether the app was opened for the first time, whether onboarding finished, whether a camera was found, whether it connected, whether a recipe was written to it, and whether that write succeeded. This is how we tell a transport bug from someone who simply does not own a compatible camera. Those two look identical in a total and need completely different fixes.
Which cameras are nearby. When the app scans over Bluetooth and sees a camera advertise itself, we record the manufacturer and the model family, for example Fujifilm and X-T5. We record cameras we cannot yet support, including cameras from other manufacturers, because that is the only honest way to decide which brand to build for next. We never record a serial number, and the identifier your camera uses for pairing is never sent.
Which features get used. A count when a tab is opened, when a recipe is created, forked, favorited or shared, when an import or a shoot plan or a backup is made, when a locked Pro feature is reached for, when the paywall is shown, and when checkout is opened. Which feature, and nothing about it.
Which library recipe, when it is one of ours. When you view, favorite, install or build on a recipe from the public library, we record which one, by the same short name that appears in its web address. This is how we can tell which looks people actually carry to a camera rather than only look at. Recipes you made yourself have no such name and are only ever counted, never identified.
Which film simulation a new recipe starts from. One of the twenty names Fujifilm gives its film simulations, such as Classic Chrome or Acros. Nothing else about the recipe: not its name, not its settings, not its photographs. It tells us where the community's taste sits, which decides what the library should hold more of.
Whether a camera operation worked, and which step failed. Connecting, pushing a recipe, rendering and switching looks each report success or failure, how long connecting took, which step failed, and the numeric code the camera itself returned. We deliberately do not send the error message, because those are written for people to read and can mention a file name.
Whether you had a subscription at the time. Free or paid, on each event. Without it we cannot tell whether a feature is used by the people paying for it.
Contributions and creator pages. When a recipe is contributed to the public library or withdrawn, when a creator page is opened and how you got to it, and when one of a creator's own links is tapped. That last one exists so we can tell creators something true about what being in the library is worth to them.
Which build it came from. Whether the event came from a released build, a TestFlight build or a development build, so our own testing is never counted as customer behaviour.
Each event carries a random identifier the app generates on first run. It is not derived from your device, it is not an advertising identifier, and it is not connected to your name or your email. If you have signed in with Apple, the event also carries the identifier Apple gave us, so a subscription can be matched to the person who bought it.
What we never collect
We do not collect your photographs. We do not collect the contents of your recipes, their names, or anything you have written in them. We do not collect your location, your contacts, your file names, your camera serial numbers, or any free text you type into the app. There is no advertising identifier, no advertising SDK, no analytics company, and no cross-site or cross-app tracking. Nothing we collect is sold, rented, or shared for advertising, and none of it is used to build a profile of you or to follow you anywhere else.
Your camera and your photos
Connecting over Bluetooth or USB-C is a direct link between your device and your camera. Recipe pushes, slot reads, camera backups, renders, and the remote shutter all happen on that link. The settings we read from your camera, and the backups you take of it, stay on your device. If you import RAW files from a camera or a memory card, the app asks for permission to read and write your photo library. Photos are read and written on your device only. We never upload them and we never see them.
Where it goes, and how long we keep it
Usage events are sent over an encrypted connection to our own servers at huginnfilm.app and stored in our own database. They are not shared with an analytics company, because we do not use one. We keep the individual events for twelve months, which is long enough to see whether something people did in their first week predicted whether they stayed. After that they are deleted. Summary counts, which carry no identifier at all, are kept indefinitely.
This website
The site counts page views so we can tell which pages are worth keeping. It runs on Umami, which is analytics software we host ourselves on our own infrastructure rather than a service we send visitors to. It sets no cookies, it does not fingerprint your browser, and it stores no identifier for you: a visit is counted as a page, a referring site and a country, and nothing that could be traced back to a person or followed to another site. It is the same standard as the app: counts, never content, never a profile.
Accounts and payments
Signing in with Apple is optional and is needed in exactly one place: connecting a subscription to you. We store the identifier Apple gives us and, if you choose to share it, your email address. Apple's private relay address is fine and is all we need. We use it to unlock Pro on your devices and to hold favorites you save on the web.
Subscriptions are processed by Stripe. We never receive or store your card details. We keep a record of whether your subscription is active, which plan it is, and when it renews, because that is what unlocks paid features.
Subscriptions are processed by Stripe. We never receive or store your card details. We keep a record of whether your subscription is active, which plan it is, and when it renews, because that is what unlocks paid features.
This website
The public recipe library is readable without signing in.
Newsletter. If you subscribe, we store your email address with our email provider, Resend, and use it only to send Huginn updates. Every message has an unsubscribe link, and unsubscribing removes you.
Contact form. Your message and the address you give us are relayed to our support inbox so a person can reply. We keep the correspondence only as long as it takes to resolve it.
Newsletter. If you subscribe, we store your email address with our email provider, Resend, and use it only to send Huginn updates. Every message has an unsubscribe link, and unsubscribing removes you.
Contact form. Your message and the address you give us are relayed to our support inbox so a person can reply. We keep the correspondence only as long as it takes to resolve it.
Children
Huginn is not directed at children and we do not knowingly collect information from anyone under 13.
Deleting your account
You can delete your account from inside the app, under More, then Account and billing. You can also do it here on the web from your account page. It takes effect immediately, and you do not have to ask anyone.
Deleting removes your sign-in, your creator page and everything on it (your name, handle, biography, avatar and links), your favorites and ratings, any contributions still waiting for review, and any reports or blocks you made. If you have a subscription it is cancelled at the same time, so nothing is charged again. Your usage events stop being connected to you.
Recipes you already published to the library stay in the library, with your name removed from them. We say this when you contribute a recipe, and again before you confirm the deletion, because it should never be a surprise afterwards. Publishing puts a recipe in other people's hands: they have saved it, it has a public address, and withdrawing it would take something away from them rather than from us. What comes off is every trace of who made it.
Your own recipes, palettes and photographs are not ours to delete. They live on your device and in your own iCloud, and they stay there. Remove them by deleting them in the app, deleting the app, or turning off iCloud for Huginn.
Deleting removes your sign-in, your creator page and everything on it (your name, handle, biography, avatar and links), your favorites and ratings, any contributions still waiting for review, and any reports or blocks you made. If you have a subscription it is cancelled at the same time, so nothing is charged again. Your usage events stop being connected to you.
Recipes you already published to the library stay in the library, with your name removed from them. We say this when you contribute a recipe, and again before you confirm the deletion, because it should never be a surprise afterwards. Publishing puts a recipe in other people's hands: they have saved it, it has a public address, and withdrawing it would take something away from them rather than from us. What comes off is every trace of who made it.
Your own recipes, palettes and photographs are not ours to delete. They live on your device and in your own iCloud, and they stay there. Remove them by deleting them in the app, deleting the app, or turning off iCloud for Huginn.
Your other choices
You can unsubscribe from email at any time using the link in any message. If you would rather not use the in-app button, or you want something we have not listed here, write to the address below and we will do it.
Changes
If this policy changes in a way that affects what we collect, we will update the effective date above and describe the change here. This page was revised on 13 August 2026 to describe deleting your account, including what happens to recipes you have already published, which the earlier version did not cover.
Contact
Questions about your data, or a deletion request: support@huginnfilm.app.