LITTLE TOMORROW · BEAUTY AND BYTES, LLC
App privacy policy
Beauty and Bytes, LLC operates Little Tomorrow. This policy covers our iPhone app and its account and portrait services. The app is for adults aged 18 or older living in the United States. It is not a service for children to use themselves. Our website privacy notice covers visits to this site. Contact support@getlittletomorrow.com with privacy questions or requests.
Information we use
- Account: your chosen name, email address, account identifier, adult/US eligibility declaration, photo permission, welcome trials, credit balance and account status. We use these to authenticate you and operate your account.
- Photos and creative details: the photos you select, your portrait options and optional creative instructions. We use these only for the requested portrait, delivery, safety and related support. Photo metadata is removed before upload. Do not put private contact details, medical information or unrelated sensitive information in a creative prompt.
- Apple purchases and signup verification: Apple-signed app and purchase identifiers, product and transaction identifiers, purchase/refund status and our account link. We use these to prevent duplicate grants, reconcile credits and refunds, and limit abuse of account creation and welcome trials. We do not receive your Apple password or payment-card details.
- Service and security: request addresses, times, job status, error information and protected anti-abuse identifiers. Hosting and email providers may retain delivery and technical logs. Our application does not intentionally log photo contents, raw creative prompts or sign-in codes.
- Support: the messages and attachments you choose to send. Please do not email children's photos or verification codes.
Information that stays on your iPhone
Saved keepsakes, birth details, parents' heights, growth-journal measurements and optional growth estimates are stored locally for the signed-in account. We do not send growth measurements or parent heights to our server or AI processor, or use them to train shared models. The app excludes this storage from device backups. Deleting the app can lose this data. Saving or sharing an export creates a separate copy controlled by you and the receiving app, which may use cloud storage.
AI photo processing and your permission
Before your first AI upload, we ask for explicit photo permission for your account. When you tap Create, selected photos, portrait options and creative instructions pass through our server to Google, our third-party AI image processor. Original uploads and creative details are processed in server memory and are not intentionally saved in our account database. The portrait is an artistic interpretation, not identity recognition or a reliable prediction of appearance, health or future size.
We use the paid AI service. Its terms state that prompts, images and responses are not used to improve its products. Google nevertheless retains prompts, context and outputs for 55 days for abuse monitoring and required disclosures; authorized staff may review flagged content. Its processing may occur where it or its agents operate. Withdrawing permission prevents new uploads and does not undo earlier processing. See AI processor data terms ↗ (external website) and AI processor safety retention ↗ (external website).
Service providers and sharing
Render hosts our account service and encrypted storage. Cloudflare hosts this website and stores private encrypted account backups. Resend delivers verification emails. Apple processes app purchases and refunds. Zoho hosts our business support mailbox and processes correspondence. These providers receive the information needed for their functions. We may also disclose information when legally required, to address fraud or security threats, or as part of a business transfer subject to applicable protections. We do not sell personal information or share it for cross-context behavioral advertising. The app has no advertising, cross-app tracking or public photo gallery.
Retention and backups
- Live portrait recovery: generated portraits are encrypted until your device acknowledges delivery, or for up to 24 hours. The live result is then removed. Journal data and original uploads are not included in this recovery store.
- Account records: profile and consent records stay while your account is active. Deletion removes your name, email, eligibility and consent from the active account record and ends its sessions. We retain limited transaction, credit and audit records as needed to honor credits, prevent duplicate refunds, resolve disputes and meet legal recordkeeping duties. Protected email/Apple entitlement claim records remain to prevent repeated promotional signups; they are not a copy of your photo.
- Encrypted account backups: separate recovery copies contain account, consent, purchase, credit and audit records, but exclude photos, sign-in codes and login sessions. A seven-day expiration rule applies; storage-provider lifecycle deletion can take additional processing time. Copies are restricted to recovery, not ordinary account access.
- Hosting disk snapshots: Render also takes encrypted disk snapshots. They may contain an earlier account record or encrypted temporary portrait result, even after deletion from the live service. Render currently makes snapshots available for at least seven days. This is separate from our seven-day account-backup rule. We do not promise that all provider copies disappear immediately.
- Authentication and technical records: verification codes expire after ten minutes and work once. Sessions normally expire after 30 days or sooner on logout/deletion. Temporary application abuse counters are cleaned after roughly one day; providers apply their own operational-log retention.
- Support: correspondence is retained as needed to handle the issue, related disputes and legal obligations. Ask us to remove correspondence that is no longer needed.
If recovery from a backup is necessary, we reconcile later account deletions and credit/refund events before reopening the restored service. Access is limited to authorized operators. We use encryption and access controls, but cannot guarantee absolute security.
Your choices and requests
In Settings, choose Privacy & photo use to review this information, Withdraw AI photo permission to stop new uploads, or Delete all local keepsakes & measurements. To delete your account, open Your account → Delete account. We may require a fresh emailed code and completion of any pending portrait. Deleting an account is not a request for an Apple refund; contact Apple separately. Local data on another device or exported copies may need to be deleted there too.
You can email support to request access, correction or deletion, or to report an unauthorized photo. We verify account ownership without asking for your password or verification code. Depending on applicable law, you may have additional privacy rights, including an appeal of a declined request. We do not discriminate for exercising applicable rights. If a legal retention requirement limits deletion, we explain the limitation.
Authorized family photos only
Only submit photos you have the right to use. Obtain permission from both adults in parent-photo mode, and be the child's parent/legal guardian or have their authorization for a child's photo. We do not knowingly offer accounts to under-18 users. Contact support if you believe a child is using the service or a photo was uploaded without authorization.
Policy changes
We update the effective date when this policy changes. Material changes will be communicated in the app or through the account contact where appropriate. If a change needs new permission for photo sharing, we will request it before the changed processing.