Privacy policy
Effective and last updated: October 8, 2026
NoArm sends the working copy of the photo you choose to its server and OpenAI when you agree to create an AI edit. Server photo storage is temporary. Operational records and OpenAI's retention are separate from photo deletion.
What this policy covers
This policy covers the NoArm iPhone app, its photo editing service, and this website. For questions about how NoArm handles your data, contact noarm@bulse.ai.
Photos and permissions
You choose a photo through Apple's photo picker or take a photo using the camera. NoArm processes a working copy for editing; it does not upload your entire photo library. The app prepares the working image without the original file's location metadata. The photo itself may still reveal people, places, or other personal information.
NoArm asks you to agree to cloud processing before uploading a photo for an edit. You can decline and keep the preview on your device. Please use only photos you have the right to edit and permission from the people pictured.
Cloud AI processing
Your working photo is sent over HTTPS to NoArm's hosted server and then to OpenAI's image editing API to generate a result. The server is hosted on Railway. These providers process data to deliver, protect, and operate the service. Processing may take place outside your country.
Under OpenAI's default API policy, API inputs and outputs are not used to train its models unless the API customer opts in. OpenAI may retain abuse monitoring data for up to 30 days, with exceptions for safety or legal requirements. NoArm's photo deletion does not remove copies held by OpenAI. See OpenAI's API data controls for the provider's details.
AI edits may change people or other details. Newly exposed areas are generated reconstructions. Compare the result with your original before saving or sharing.
Other data used by the service
NoArm creates a random app session identifier and access credential without asking you to register an account. The service stores a hash of that credential. It records edit request identifiers, photo fingerprints, consent version, attempt counts, status, timestamps, dimensions, model and configuration versions, processing time, and usage information. If you provide feedback or save or share a result, the service can also record that action or feedback.
These records help operate the service, enforce usage limits, prevent duplicate requests, investigate failures, and assess edit quality. A photo fingerprint is a hash of image data; it is not a facial recognition profile. Short-lived hashed network address buckets help limit session creation. Hosting providers also receive connection information such as IP addresses when serving requests.
NoArm does not include advertising or tracking SDKs, and does not sell photo data or use it for cross-app advertising. Operational data is linked to the random app session.
How long data is kept
- Server input photos: scheduled for deletion when processing ends, fails, or is cancelled.
- Server output photos: expire 24 hours after the edit request is created, or are removed earlier following a deletion request.
- Deletion: deleted or expired jobs lose download access immediately. File cleanup normally follows promptly; temporary storage failures can delay physical removal while the service retries.
- Operational edit records: normally retained for up to 30 days after request creation, including records that a job was deleted. Cleanup must finish before the job record can be removed.
- Session access records: random session identifiers and credential hashes remain until removed or revoked; they are not covered by the 24-hour photo expiry.
- Local working files: excluded from device backups and cleared when you discard the edit or on the next app launch after 24 hours.
- Photos you save or share: remain in your Photos library or with the app or person you share them with. You control those copies separately.
- Support messages: remain in the support inbox as needed to respond and maintain a record of the request; you can ask for deletion.
Your choices and requests
You can decline cloud processing, discard an edit, and manage camera and Photos permissions in iOS Settings. Discarding an edit queues deletion of its server jobs; an internet connection is needed to deliver those requests. Automatic server expiry still applies. Delete saved photos in Apple's Photos app if you no longer want them.
To request information, correction, deletion, or another privacy action, email noarm@bulse.ai with the subject “NoArm privacy request.” Include only the minimum information needed to identify your request, such as an edit request identifier if available. Never send access credentials. Because NoArm does not require a named account, we may need more information to locate a particular session. Requests are handled subject to applicable law and necessary security or legal obligations.
This website
This website is hosted by Cloudflare Pages. It does not add advertising, analytics scripts, or a contact form. Cloudflare processes connection and request information to deliver and protect the site. See Cloudflare's privacy policy. Emailing support sends your email address, message, and any attachments to the support mailbox and its email providers; please do not attach private photos unless needed for your request.
Policy updates
We will publish changes on this page and update the date above. If the app's cloud processing disclosure changes, NoArm asks you to agree to the updated disclosure before further edits.