Privacy policy
Last updated 28 September 2026
The short version
Lapsr is a daily photo app. This marketing site (lapsr.toistudios.io) only collects an email if you join the waitlist. In the app, your photos start on your device; if you sign in, we sync them to private cloud storage so Pro, restore, and lapse export can work. Payments for Pro go through Apple. We do not sell your data. We do not run advertising trackers on this site. The V1 app does not run product-analytics SDKs. You can delete your account from the Account screen in the app.
This marketing site
If you join the waitlist we store the email address you submit and the time you joined, so we can tell you when the app is available. We do not require an account on this site. We do not run advertising pixels on this site.
Your address is processed by Resend, our email provider, which handles it on our instructions. We use it for launch notice only, not for a marketing list, unless you later opt in separately. Resend’s privacy policy also applies to that processing. You can ask us to delete your waitlist address at any time at admin@toistudios.io.
The Lapsr app: what is stored
On your device
- Photos you capture for each day (local files)
- Project / lap state (name, sky, interval, reminder time, day keys) in on-device storage
- Reminder schedules via the device notification system (local only in V1; we do not yet send push for “lapse ready”)
- Firebase Auth session managed by the Firebase SDK (we do not separately persist your auth token)
When you are signed in and the service is reachable
- Day photos are uploaded to private Amazon S3 storage in the United States (
us-east-1), under a path tied to your account. Objects are not public; the app fetches them with time-limited links. - Lap / project metadata is also stored in our database (Amazon RDS Postgres in
us-east-1) via our API atapi.lapsr.toistudios.io. - Lapse exports are rendered on our servers from your synced frames. The output (video or zip) is stored in the same private S3 bucket; the app downloads it with a time-limited link for local share or keep.
Account identity
- Sign-in is through Firebase Authentication (Sign in with Apple, Google, or phone SMS). We identify you by the Firebase user id. There is no email/password sign-in in V1.
- Local capture can exist before you sign in. Cloud sync starts after you authenticate.
Purchases
- Lapsr Pro is intended to be sold through the Apple App Store and managed with RevenueCat, keyed to your Firebase user id. Apple processes payment; we never receive your card number. We may receive confirmation that a subscription is active so we can unlock Pro. Until plans and billing keys are live, treat in-app price placeholders as not final.
What is not stored
We do not sell personal data. We do not build advertising audiences. We do not ask for a postal address on the marketing site. Card numbers for App Store purchases never reach Toi Studios. The V1 app does not initialise Firebase Analytics, Amplitude, PostHog, or similar product-analytics SDKs, and we do not turn on Google advertising features for Lapsr.
Payments
Lapsr Pro is billed by Apple to your Apple Account. Apple’s and, when live, RevenueCat’s privacy policies also apply to their processing.
Retention and deletion
Waitlist emails are kept until launch notice is sent or you ask us to delete them.
App data: photos and metadata stay while your account and projects exist, subject to what the product supports.
To delete your app account: open Account in the app, choose Delete account, and confirm. That permanently deletes cloud photos and projects we hold for you, your database user row, and your Firebase Auth user, then erases projects and photo files on that device and signs you out. If the server call fails, your local data and session stay intact. You can also write to admin@toistudios.io for access or deletion help (include your waitlist address or enough detail to find the account).
Where it lives
Waitlist email processing: Resend.
App cloud storage and database: Amazon Web Services in us-east-1 (United States).
Sign-in: Google Firebase Authentication for project identity.
Site hosting: as configured for lapsr.toistudios.io (Vercel or equivalent), which may process ordinary request metadata to deliver and protect the site.
Children
Lapsr is not directed at children under 13 (or the higher age required where you live). Do not use it if you are under that age.
Contact
Questions or deletion requests: admin@toistudios.io.
Toi Studios LLC, 8425 Northwest 41st Street, Suite 331, Doral, Florida 33166, United States.