The paperwork
Privacy Policy
Effective date: July 5, 2026
1. Who we are
Fable ("the app", "we", "us", "our") is an iOS application, an App Clip, and a web experience for shared, disposable-camera event rolls.
Fable is built and maintained by Jakub Zitko, an independent solo developer. Fable is not operated by a company and does not maintain a physical office.
If you have any questions about this policy or how your data is handled, please contact us at jakub.zitko@icloud.com.
2. The short version
Fable was built with a simple privacy principle: collect the minimum data required to make a shared camera roll work, and keep it out of the hands of advertisers.
- No email or phone number is required to use Fable. Sign in with Apple is optional and reveals only what Apple lets you share.
- No analytics SDKs, no advertising identifiers, no third-party trackers are integrated.
- Your photos are stored in our Cloudflare R2 bucket so guests of your event can view them. They are not indexed, mined, or used to train any model.
- Photos are held back from other guests until the event's reveal time. Photos are only visible to the guests and host of the specific event you shared them with.
- You can delete your account and all associated photos from Settings inside the app at any time.
3. What data Fable collects
Fable collects two categories of data: things you enter, and small pieces of technical data required to route your data to the right event.
Data you enter:
- Event name, host name, reveal time, late-night cutoff, timeline schedule, and cover color.
- Guest names as you type them when joining an event.
- Photos you capture in the Fable camera. Photos are stored in our Cloudflare R2 bucket in a per-event folder. Full-resolution frames and 512px thumbnails are stored separately.
- Emoji reactions you tap on other guests' photos.
- Optional Sign in with Apple identifiers: your opaque Apple user id, and, if you shared them the first time you signed in, your name and Apple relay email.
Data collected automatically:
- A randomly generated guest ID stored on your device (in UserDefaults and in the App Group shared with the App Clip). This is not tied to your identity in any way.
- An APNs device token, if you enable notifications. The token is stored on our Convex backend so the reveal-time push and late-night moderation ping can reach you.
- Short-lived server logs from our backend (Convex) recording request paths, response codes, and coarse timing for debugging and abuse detection. These logs do not include your uploaded photos.
Fable does not collect:
- Your precise or coarse location.
- Your contacts, calendar, reminders, or health information.
- Advertising identifiers (IDFA).
- Data about your usage of other apps or websites.
- Analytics events (no Firebase, no Amplitude, no Mixpanel, no Sentry, no third-party crash reporter).
4. Where your data lives
Fable uses the following storage:
- Your device — Local UserDefaults holds your guest ID, plan preference, and settings toggles. A JSON file in the app's Documents directory holds your local copy of your events and media. Photo bytes are also cached locally for offline access.
- Convex, our backend provider — All event metadata (event names, guest lists, reveal times, photo metadata, timeline blocks, reactions) is stored in a Convex deployment operated by us.
- Cloudflare R2 — Photo bytes (both full-resolution and 512px thumbnails) are stored in an R2 bucket operated by us.
- Apple — If you use Sign in with Apple, Apple holds your identity and forwards a stable subject id to us.
- Apple Push Notification Service — Your APNs device token flows through Apple to reach your device when we send a reveal push.
Data in transit is protected with TLS. Photos in R2 are stored encrypted at rest. Access to the R2 bucket is granted only to Fable's Convex backend.
5. How we use the data
Fable uses your data only to operate the shared-camera experience:
- Event metadata and guest lists are used to route your photos to the right event and show the right feed to the right guest.
- Photos are stored so that after the reveal time, every guest and the host of that specific event can view them.
- APNs device tokens are used to send reveal-time reminders, late-night moderation pings, and "someone joined your event" notifications to the relevant host.
- Sign in with Apple identifiers are used to link your local guest ID to a stable Apple identity, so if you reinstall Fable on a new device and sign in again, your past events return.
- Server logs are used to debug outages and detect abuse.
We do not use your data for advertising, profiling, cross-app tracking, or model training. Your uploaded photos are never used to train image models.
6. Who your data is shared with
Within Fable, your photos are shared only with the guests and host of the specific event you uploaded them to, and only after the reveal time has passed (or, for the uploader and host, immediately).
The following third parties process your data on our behalf:
- Apple, to distribute the App, process in-app purchases, and deliver push notifications through APNs.
- Convex, to host and serve event metadata.
- Cloudflare, to host the web experience and store photo bytes in R2.
These providers act as processors: they may only handle your data to run the service and may not use it for their own purposes. Their terms are available at apple.com/legal, convex.dev/legal, and cloudflare.com/legal respectively.
We do not sell, rent, or lend your data to any third party. We do not share your data with data brokers, ad networks, or list resellers, and we have never done so.
7. Storage and retention
Retention depends on the event's tier at the time it was created:
- Free tier: 30 days from event creation.
- Party tier: 90 days from event creation.
- Event tier: 1 year from event creation.
- Wedding tier: 7 years from event creation.
After the retention window ends, photo bytes are removed from R2 and event metadata is anonymized in Convex. You can shorten retention by deleting the event yourself from the host dashboard at any time.
You can also delete individual photos, wipe your local cache, or delete your entire account from Settings inside the app. Deleting your account removes your user row, memberships, hosted events, uploaded media, reactions, and device tokens from our backend.
8. Your rights
Depending on where you live, you may have rights under laws like the GDPR (EU/UK), the CCPA/CPRA (California), or similar frameworks. To exercise any of these rights:
- Right to access: All of your Fable data is visible inside the app. To request a machine-readable export, email jakub.zitko@icloud.com.
- Right to delete: Use Settings → Danger → Delete account inside Fable to remove all of your data, or email us for individual event deletions.
- Right to correct: Every event and photo in Fable can be edited or deleted by the host or the uploader.
- Right to portability: Email us to request a machine-readable export of your events and photos.
- Right to object / opt out of "sale" of personal information: Fable does not sell personal information and has no mechanism to do so.
If you would like additional help exercising any right, email jakub.zitko@icloud.com.
9. Children
Fable is intended for people aged 12 and up. Fable is not directed at children under 13. If you are the parent or guardian of a user under 13 and believe they have created events or uploaded photos, contact jakub.zitko@icloud.com and we will help you erase that data.
10. International transfers
Fable is operated from where Jakub Zitko lives. Our Convex backend and Cloudflare R2 bucket may store data in the United States or Europe. By using Fable from outside those regions, you understand and consent to your data being transferred there. Where the GDPR applies to you, the transfer is made under Standard Contractual Clauses as offered by our providers.
11. Security
We use industry-standard security practices to protect your data. This includes TLS for all data in transit, encryption at rest for photos in R2, and least-privilege access controls for our backend. No system is perfectly secure; if we discover a data breach that affects you, we will notify you through the app and by email (if you have signed in with Apple) as required by applicable law.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date above and publish the new version at fable-web.pages.dev/privacy. For material changes we will present an in-app notice on your next launch.
13. Contact
For any question, concern, or request related to your privacy, please contact Jakub Zitko at jakub.zitko@icloud.com. We will do our best to respond within a reasonable time.