Privacy Policy – Drag Selfie
This Privacy Policy explains how the mobile application Drag Selfie ("the App") collects, uses, and shares information. Last updated: 18 August 2026.
Data controller
The entity responsible for processing your data in connection with the App is:
- Company
- Sesang, Inhaber Wonyoung Seo
- Address
- Limburger Str. 15, 65520 Bad Camberg, Germany
- hello@sesang.de
- Phone
- +49 177 267 1468
- VAT ID
- DE457318871
Camera and photos
The App uses your device camera to take photos and stores them in an app-owned DragSelfie album. It does not read or browse your general photo library. Photos you take are processed and stored locally on your device only; they are not uploaded to us or shared with third parties by the App. You can delete photos at any time using your device. The App does not request broad photo or video permission. On iOS, it may request add-only Photos permission to export a captured photo; older Android versions may show only the limited permissions needed for local storage compatibility.
Data collected by third-party services
The following services are platform- and release-dependent; a service is used only when the relevant feature is active in the applicable app version and the required consent has been given:
- Google AdMob (Google Ireland Ltd / Google LLC): On Android versions where advertising is active, advertising, measurement, and fraud prevention may appear only on the non-camera Gallery, Photo Detail, and Settings surfaces after UMP confirms that ads are allowed. If advertising consent is denied or UMP returns an error, no ads are requested or shown. The camera preview, countdown, and capture flow show no ads. Depending on choices, Google may process the Advertising ID, IP address (which may be used to estimate general location), app interactions, diagnostics, device or account identifiers, and ad interactions. Remove Ads bypasses all remaining ad placements. On iOS, AdMob and UMP are linked but not initialized: no ad request is made, no ads are shown, no ATT prompt is displayed, and no IDFA is used. Any future activation of iOS advertising requires a renewed privacy review and an update to this Policy. UMP advertising consent is separate from product analytics.
- PostHog: product analytics only after explicit opt-in; consent is OFF by default and can be revoked in Settings. While consent is OFF, no analytics event is sent, kept in memory, or written to device storage; a later opt-in never replays past events. After opt-in, it processes only approved events and a random, app-specific pseudonymous identifier. Approved analytics may include whether the optional Remove Ads entitlement is active; payment details, tokens, order numbers, and timestamps are not sent. This identifier is not an account ID, Advertising ID, or hardware identifier. Photos and files are not sent. Over HTTPS, the provider can see the request source IP; DragSelfie sends no location property and sets `$geoip_disable=true` and `$process_person_profile=false`. The production project currently has an external provider-side setting to discard client IP data; it is rechecked at every release and is not a permanent guarantee of the App. That check is a separate release gate.
- Sentry: On iOS, Sentry starts only after explicit “Share diagnostics” consent in Settings; consent is OFF by default and can be revoked independently. With consent, Sentry processes crash data and other diagnostic data to support App Functionality. `sendDefaultPii=false` is configured; the App sends no account identity, photos, files, location data, Advertising ID, or hardware identifier. The provider may receive the request source IP; the current Sentry project scrubs IP addresses and removes IP-derived `user.geo` at ingest. This provider-side configuration is rechecked at each release and is not a permanent guarantee of the App. Without consent, Sentry is not initialized and no diagnostic request is made.
Purposes and legal bases (GDPR)
- Providing the App's core features (camera and DragSelfie gallery): performance of our service at your request, Art. 6(1)(b) GDPR.
- Advertising: on Android versions where advertising is active, ads may appear only in Gallery, Photo Detail, and Settings after UMP provides proof that ads are allowed; if consent is denied or UMP errors, no ads are requested or shown. The camera preview, countdown, and capture flow contain no ads. On iOS, AdMob and UMP are linked but not initialized: no ad request is made, no ads are shown, no ATT prompt is displayed, and no IDFA is used. Any future activation of iOS advertising requires a renewed privacy review and an update to this Policy. Remove Ads bypasses all remaining ad placements. UMP advertising consent is separate from analytics consent.
- Product analytics (PostHog): your explicit consent, OFF by default and revocable at any time in Settings, Art. 6(1)(a) GDPR. Without consent, analytics is not initialized.
- Crash and other diagnostic data collected by Sentry on iOS: your explicit “Share diagnostics” consent, OFF by default and revocable at any time, Art. 6(1)(a) GDPR. Without consent, Sentry is not initialized; with consent, the processing supports App Functionality.
Advertising choices
On Android versions where advertising is active, ads may appear only in Gallery, Photo Detail, and Settings after UMP confirms that ads are allowed; if advertising consent is denied or UMP errors, no ads are requested or shown. The camera preview, countdown, and capture flow contain no ads. UMP advertising consent and UMP privacy options can be managed in Settings for those Android versions. On iOS, AdMob and UMP are linked but not initialized: no ad request is made, no ads are shown, no ATT prompt is displayed, and no IDFA is used; these UMP advertising and privacy options are unavailable there. Product analytics has its own separate consent, OFF by default. Remove Ads bypasses all remaining ad placements.
Data sharing and international transfers
We share information only with the service providers listed above, where the relevant feature is active and the required consent has been given. The App does not transmit photos, files, or location properties. For PostHog, the provider can see the source IP of an HTTPS request; the production project currently has an external provider-side setting to discard client IP data. This setting is rechecked at every release, is outside the App, and is not a permanent App guarantee. Some providers may process data outside the European Economic Area; appropriate safeguards such as EU Standard Contractual Clauses are used. We do not sell your personal data.
Data retention
Photos remain on your device until you delete them. While analytics consent is OFF, no analytics event is sent, kept in memory, or written to device storage; a later opt-in never replays past events. After consent is revoked, future PostHog events stop and local analytics state is cleared; this does not automatically delete data already transmitted. Data processed by third-party providers is retained according to their respective policies and for as long as necessary for the purposes described above. On iOS, Sentry starts only after explicit consent; after consent is revoked, future diagnostic data is no longer delivered and local diagnostic state is cleared. This does not automatically delete data already transmitted.
Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability. You may withdraw consent at any time. To exercise these rights, contact hello@sesang.de. You also have the right to lodge a complaint with a data protection supervisory authority.
Children
The App is not directed to children under the age of 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us.
Changes and contact
We may update this Privacy Policy from time to time; the "Last updated" date above reflects the current version. For questions about this policy or your data, contact us at hello@sesang.de.