Strum: Privacy Policy
Last updated: September 1, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy. This Privacy Policy has been created with the help of the Privacy Policy Generator.
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
For the purposes of this Privacy Policy:
Account means a unique account created for You to access our Service or parts of our Service.
Affiliate means an entity that controls, is controlled by or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
Application refers to Strum, the software program provided by the Company.
Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to Strum.
Country refers to: United Kingdom
Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
Personal Data is any information that relates to an identified or identifiable individual.
Service refers to the Application.
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit). This includes data in the form of text, video and audio.
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Our app uses Apple's ARKit framework and ARFaceTrackingConfiguration to provide features that track facial movement and expressions using the device's front-facing TrueDepth camera.
When you use the app's face-tracking features, ARKit provides the app with information about the detected face, which may include facial position, orientation, facial geometry/topology, and facial expressions. This information is used solely to provide the face-tracking functionality and features of the app.
Face-tracking data is processed locally on your device. We do not upload, transmit, or otherwise send face-tracking data to our servers or to any third party.
We do not use face-tracking data to identify you or any other person. We do not perform facial recognition or attempt to determine a person's identity from the information provided by ARKit.
We do not use face-tracking data for advertising, marketing, tracking, user profiling, authentication, or any other purpose unrelated to the functionality of the app.
We do not use face-tracking data to build or maintain a profile about you or any other individual.
Face-tracking data obtained through ARKit is used only while the relevant face-tracking functionality is being performed.
We do not retain face-tracking data on our servers. Face-tracking data is not uploaded to or stored by our servers.
When face tracking is no longer required by the app's functionality, the corresponding face-tracking data is discarded and is not retained by the app.
We do not sell, rent, share, disclose, or otherwise provide face-tracking data to third parties.
In particular, face-tracking data is not provided to our analytics provider, TelemetryDeck. TelemetryDeck receives only the app-usage analytics information described in the "Use of TelemetryDeck to Analyze App Usage" section below. Face-tracking data, facial geometry, facial expressions, camera frames, and other information obtained through ARKit face tracking are not included in that analytics data.
Face tracking uses the device's front-facing camera and TrueDepth system. Although ARKit uses camera information to perform face tracking, our app does not upload or transmit camera frames or video recordings to our servers.
No video or audio recordings are stored on or transmitted to our servers. Camera and face-tracking information is processed only as necessary to provide the app's functionality and is discarded when it is no longer required.
Before the app can use the camera for ARKit face tracking, iOS requests permission from the user. You can revoke camera access at any time through your device's Settings. If camera access is denied or revoked, features that require ARKit face tracking will not function.
Face-tracking data obtained through ARKit is processed only for as long as necessary to provide the relevant functionality and is not retained on our servers.
We do not maintain a database of face-tracking data or use face-tracking data to create user profiles.
Because we do not store face-tracking data on our servers, there is no server-side Face Data associated with a user that we can retrieve or delete.
If you have questions about personal data processed by the app or wish to request deletion of personal data that we may hold, please contact us using the contact information provided in this Privacy Policy. We will process such requests in accordance with applicable law.
We use the privacy-friendly analytics service TelemetryDeck (provider: TelemetryDeck GmbH, Von-der-Tann-Str. 54, 86159 Augsburg, Germany) to analyze usage data. The use is based on Art. 6 para. 1 lit. b GDPR, as we require reliable and efficient tools for collecting app usage data in order to fulfill the contract with you, our customer.
The data processed by TelemetryDeck is completely anonymized and does not allow any conclusions to be drawn about personal information.
The following data is collected, among other things:
an anonymized, untraceable user ID (per app installation),
actions defined by the app publisher (e.g., "app launched," "settings opened"),
a rounded timestamp (to the nearest hour),
device metadata (e.g., system version, app version, device type),
additional metadata defined by the app publisher (e.g., "number of items in the database").
What is not stored?
No IP addresses (not in logs, not in the database),
No cookies or tracking technologies,
no persistent identifiers that could be traced back to individuals.
The source code of the TelemetryDeck SDK is completely open source and available on GitHub: https://github.com/TelemetryDeck
Further information on the exact data processing by TelemetryDeck can be found at: telemetrydeck.com/privacy and at telemetrydeck.com/docs/guides/privacy-faq.
Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 13 without verification of parental consent, We take steps to remove that information from Our servers.
If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent's consent before We collect and use that information.
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.
We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
If you have any questions about this Privacy Policy, You can contact us: