Privacy Policy
Effective date: September 27, 2026
Filmode — published on Google Play as Filmode: Film Presets & Editor, package app.filmode.presetseditor — is a photo editor for Android published by FightTech VN. In short: your photos are edited and stored on your phone, they are never uploaded, and there is no account. The app uses the internet for two things of its own: downloading looks from the Presets Store, and sending anonymous usage counts and crash reports, which you can switch off in Settings. It also talks to Google Play for purchases. There are no ads, and we do not sell any data.
What the app does
Filmode applies film looks and edits to photos you choose, keeps them in a library inside the app, and exports finished pictures to your own storage. Every edit, look, suggestion and export is computed on your device's own processor and graphics chip. There is no cloud processing, no user account and no sign-in, and nothing the app sends over the internet contains your photos or anything taken from them.
Permissions the app declares
These are all the permissions in the app's final manifest, including the ones Google's libraries add to it. Android asks you for the runtime ones (camera, microphone, location) at the moment each is first needed, and you can revoke them later in Settings → Apps → Filmode → Permissions. Everything except the built-in camera works without any of them.
- Camera (
CAMERA) — used only by the optional built-in camera, and asked for the first time you open it. The camera feed is shown on screen and written to the photo or video you take; it is never streamed anywhere. Scanning a preset QR code does not use this permission (see below). The camera is declared optional, so the app also installs on devices without one. - Microphone, optional (
RECORD_AUDIO) — used only to record sound with a video in the built-in camera, and asked for the first time you record a clip with sound on. The sound is written into your video file on the device and never transmitted. Deny it and videos record without sound. - Location, optional (
ACCESS_FINE_LOCATION,ACCESS_COARSE_LOCATION) — used for one purpose only: writing GPS coordinates into the EXIF metadata of photos you take with the built-in camera, on the device. It is requested only if you switch on saving location in the camera's settings, which is off by default. The coordinates are stored inside your own files and are not transmitted to us or anyone else. Leave the setting off and the app never asks for the permission and never reads your location. - Internet (
INTERNET,ACCESS_NETWORK_STATE) — used for the Presets Store and for anonymous usage and crash reports, both described below. The second lets the app and Google's libraries check whether the phone is online before trying. Neither is a runtime permission. - Google Play billing (
com.android.vending.BILLING) — added by Google's Play Billing library for the optional Filmode Pro purchase. It lets the app hand a purchase to the Google Play app on your phone. - Background upload and install source (
WAKE_LOCK,com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE) — added by the Firebase SDKs. The first lets a usage or crash report that is already queued finish sending if the screen turns off; the second lets the analytics SDK read, once, which Google Play listing the app was installed from, used only for aggregate install counts and never for advertising. Neither is a runtime permission, and both stop being used when you switch the reports off. - Storage, on Android 9 and earlier only (
WRITE_EXTERNAL_STORAGE, declared withmaxSdkVersion="28") — needed on Android 8 and 9 to save your exports into the sharedPicturesfolder. On Android 10 and newer the app saves through the system MediaStore and this permission is neither declared nor requested. - App-internal (
app.filmode.presetseditor.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION) — added automatically by Google's AndroidX library. Only Filmode itself holds it; it makes sure no other app can send messages to Filmode's internal components. It gives access to no data.
No photo-library permission. The app does not declare READ_MEDIA_IMAGES, READ_MEDIA_VIDEO or READ_EXTERNAL_STORAGE, and cannot browse your gallery. Photos come in through Android's photo picker (or, on older Android versions without it, the system file picker), or when you share or send a photo to Filmode from another app; either way Android hands the app only the photos you chose. .cube and .xmp files come in the same way, through the system file picker.
The app declares no contacts, phone, calendar, SMS or background-location permission, and no "all files access". It also declares no advertising permission: AD_ID and the Android Ad Services permissions are explicitly removed from the build, and advertising-ID collection is switched off in the analytics SDK, so the app cannot read your advertising identifier.
Your photos: import, Studio and export
Import. When you bring a photo into Filmode, the app copies it into its own private storage on your device, which other apps cannot read. The photo in your gallery is not changed, moved or deleted. Next to the copy, the app keeps a small settings file with your edit, a cached preview, any tags, projects and versions you create, and a short summary of the camera details read from the photo's EXIF (for example camera model, lens and exposure) to show in the photo's info. All of this stays on the device.
Editing is non-destructive: nothing is baked into a picture until you export it, and you can change or undo an edit at any time.
Export. Exported pictures are written as new JPEG or PNG files into Pictures/Filmode on your device's shared storage and registered with the media library, so your gallery and other apps can see them. With Keep EXIF on (it is on unless you switch it off in the export settings), the exported file carries metadata copied from the original — the date and time, camera and lens details and exposure settings, and GPS coordinates only if the original photo already had them. That metadata travels inside the file when you share it; switch Keep EXIF off to export without it. It is written locally; we never see it.
Deleting. Removing a photo from Studio deletes the app's copy and its edit. Uninstalling the app, or clearing its storage in Android's settings, deletes the whole Studio library. Your original photos and anything you exported are yours and are not affected.
The built-in camera
The optional camera shows your chosen look live in the viewfinder and saves the photos and videos you take to your device's own storage, where your gallery can see them. Video can include sound only if you allowed the microphone. Photos include GPS coordinates only if you switched on saving location, as described above. Nothing the camera records is uploaded.
Looks, presets and QR codes
Your presets, favourites, custom categories and the .cube and .xmp files you import are stored in the app's private storage on your device.
Sharing a preset as a QR code. The code is generated on your phone and contains only the preset's name and its adjustment numbers (and, if the preset uses a built-in or Presets Store look, that look's catalogue ID; a look you imported yourself is left out). It contains no photo, no account or device identifier and no location. Anyone who can see the code can read those numbers; where you show or send it is your choice, and the app sends it nowhere by itself.
The code is written as a web link, https://filmode.app/p#…, with the preset after the #. If someone scans it with an ordinary camera app instead of Filmode, their browser opens that address: the browser keeps the part after the # to itself and does not send it to the server, so our server sees only an ordinary page request, like any website visit, and never the preset.
Scanning a preset QR code. Scanning uses Google's code scanner, which is part of Google Play services on your phone. It opens its own camera screen, processes the camera image on the device and returns to Filmode only the decoded text; Filmode never receives the camera image and needs no camera permission to scan. Google Play services may download the scanner module ahead of your first scan, and Google may receive diagnostic information about the scanner itself, under the Google Privacy Policy. A scanned code that is not a Filmode preset is ignored.
Features that read your photo
Some features look at the content of a photo to do their job: the looks matched to your photo, Magic Filter (automatic adjustment, Pro) and Replica Filter (Pro), which reads the colours of a reference photo you pick and builds a look from them. All of this analysis runs on your phone. No photo, reference photo or anything derived from them is uploaded, to us or to anyone else.
The Presets Store
The Presets Store's catalogue, its before-and-after sample pictures and, when you pick a look, that look's file come from our content server at filmode.app, which is delivered through Cloudflare's network. These are plain file downloads over HTTPS: like any web request they reveal your IP address and a standard app user-agent to that server and to Cloudflare, which may keep them briefly in routine server logs. They carry no account, no device identifier and nothing from your photos. The app talks to this server only to fetch the Store's catalogue and files — for example when you browse the Store, download a look, or add a shared preset whose look comes from the Store. If you preview a look on your own photo, the preview is rendered on your phone; the photo is never uploaded. Looks you download are kept on your phone.
Analytics and crash reporting
The app uses Google Analytics for Firebase and Firebase Crashlytics, both provided by Google, to learn which features get used and to fix crashes. Both are on by default and both stop when you switch off Settings → Send usage and crash reports; the choice is remembered across launches.
- Usage counts — which screens and tools are used (for example that a look was applied, with the catalogue ID of a built-in or Presets Store look; that a preset was saved, imported, shared or scanned, with the file type of an import but never its name; that an export was made, and its pixel size; or that the paywall was opened and a purchase started, finished or was cancelled; Google Analytics also records a completed Google Play purchase automatically, with the product ID, product name, price and currency), the app version, the phone model, Android version, language and country, and a random app-instance ID that Firebase creates on install. Country is derived by Google from the connection; Google Analytics does not log or store IP addresses.
- Crash reports — when the app fails, or hits an error it recovers from, the stack trace and the part of the app where it happened, the phone model, Android version, free memory and disk space, orientation, a random Crashlytics installation ID, and the list of app events that led up to it.
What is never sent: your photographs or any part of one, thumbnails, file names, the names or contents of your presets and imported files, what a QR code contains, your location or the GPS data in your photos, your advertising identifier, your name, email or any account identifier.
This data is processed by Google on our behalf, under the Firebase privacy and security terms. It is used only to improve the app, never for advertising, never combined with other data to identify you, and never sold.
No advertising. The app contains no ads and no ad SDK.
Data we collect
Only the anonymous usage counts and crash reports described above, which we see as totals and individual crash reports in the Firebase console. We — FightTech VN — hold no database of users, and we never see your photos, your edits, your presets or your settings. There is no account system and no newsletter. If you email us, we receive what you choose to write, and use it only to answer you.
Purchases
Filmode Pro (Pro looks and presets, Magic Filter, Replica Filter, and full-resolution and custom-size export) is sold as a monthly or yearly subscription or a one-time lifetime purchase through Google Play Billing. Google processes the payment under the Google Privacy Policy; your card details and billing address are never given to us or to the app. As the seller, Google Play Console shows us the order record for each purchase — order ID, product, date, price and country — which we use only for refunds, tax and support, and not to identify or contact you. The app checks the purchase on your phone against Google's signature and remembers the result locally; it sends nothing about it to us, apart from the anonymous purchase event in the usage counts described above. Everything outside Pro is free and needs no purchase.
Data shared with third parties
None is sold or shared for advertising. The only other companies involved are service providers doing a specific job:
- Google — runs Firebase (the usage counts and crash reports, as our processor), Google Play Billing (any Pro purchase, as described above) and the code scanner in Google Play services.
- Cloudflare — delivers the Presets Store's files.
None of them receives your photos.
Android backup
If you use Android's own backup or move to a new phone with Android's transfer tool, Android may include Filmode's private data — your settings, presets and, within the size limits Android sets, the Studio library — in a backup stored in your Google account or copied to your new phone. That is done by Android and Google under your account and its settings; we have no access to it.
Data retention and deletion
Your library, edits, presets, settings and downloaded looks live on your device and are removed when you uninstall the app or clear its storage. Photos you exported are yours and stay in Pictures/Filmode until you delete them.
Firebase Crashlytics keeps crash reports for 90 days. Google Analytics keeps user-level event data for the retention period set in our project, at most 14 months, after which only aggregated totals remain. Switching off Send usage and crash reports stops any new data; clearing the app's data or reinstalling it creates a new random app-instance ID, so earlier data can no longer be linked to your phone. You can also write to us at the address below with any request about your data. You can cancel a subscription or ask for a refund in the Google Play app under Payments & subscriptions.
To delete your Filmode data:
- Export any photos you want to keep. Everything already in
Pictures/Filmodestays where it is. - In Filmode, open Settings and switch off Send usage and crash reports, so nothing new is sent.
- Uninstall Filmode, or clear its storage in Android's Settings → Apps → Filmode → Storage → Clear storage. This deletes your library, edits, presets, settings and downloaded looks from the phone, and resets the random app-instance ID.
- To have the usage counts and crash reports already sent deleted too, email trunghieu4121993@gmail.com with the subject "Filmode data deletion". We will delete them from Firebase within 30 days and reply to confirm. Otherwise they are removed automatically after the retention periods above.
Google Play keeps its own order records for purchases under the Google Privacy Policy. We keep nothing else about you.
Security
Your library and presets sit in the app's private storage, which Android keeps out of reach of other apps. Presets Store downloads use HTTPS. Purchases are verified with Google's signature on the device. No system is perfectly secure, but because your photos never leave the phone, there is no copy of them on any server of ours to leak.
Children
The app is not directed at children under 13 and does not knowingly collect personal information from children.
Your responsibility
You are responsible for the photos you edit and share, including the consent of the people in them, and for what you share inside a preset's name.
Changes to this policy
If the app's data practices change, this page will be updated and the date above revised before the new version is released. If a future version adds a permission or an SDK, it will be listed here first. Written on September 27, 2026 for the first release of Filmode: Film Presets & Editor.
Contact
FightTech VN, Vietnam. Questions about this policy, or a request about your data? Email trunghieu4121993@gmail.com.