Privacy Policy
Effective 2026-09-04. Last updated 2026-09-04.
ULMOX is a video-sharing app. You record a short video and our server delivers it to one eligible recipient chosen at random. Only a recipient may choose to share a video they received to the public Global feed.
ULMOX is operated by Ferdi Gülseren. For any privacy question, contact ulmoxapp@outlook.com.
1. Who can use ULMOX
ULMOX is an 18+ service. It is not intended for children, and we do not knowingly collect data from anyone under 18.
2. What we collect
Account and authentication
- Email address and display name.
- Account and sign-in provider identifiers.
- A supported sign-in provider is used to create and access your account. Where an account is linked with Sign in with Apple and uses Apple’s Hide My Email, we receive a relay address rather than your real one.
Content you create
- Videos you record and their generated thumbnails.
- Your profile photo and profile details.
- Global content, when a recipient shares a video publicly.
- Reports you submit, and the optional free-text details you add to them.
Camera, microphone and photos
- Camera and microphone. ULMOX asks for these so you can record a video moment with sound, and take a profile photo. Recording starts only when you start it.
- Choosing a photo. When you set a profile photo, ULMOX opens a photo picker and receives the image you pick. On a current Android version that is the system photo picker, so ULMOX asks for no permission to your wider photo library. On iOS, ULMOX asks for photo access for the flows that genuinely need it, and iOS lets you grant access to selected photos rather than to your whole library.
- Saving to your device. If you choose to save a moment to your phone, ULMOX asks for permission to add it to your photo library. That permission adds a file rather than reading your library.
Media you create is uploaded; it does not stay only on your device. Videos, their generated thumbnails and your profile photo are uploaded to and stored in Firebase Cloud Storage so they can be delivered and displayed. Saving your own copy to your phone is a separate and optional step.
On Android, ULMOX no longer declares the broad photo and video access permissions that Android 13 and later use, because the system photo picker replaces them. Two older storage permissions are still declared, both inherited from components ULMOX builds on, and both capped so that a modern Android version cannot grant them:
- A legacy read storage permission, declared for compatibility with Android 12 and earlier only.
- A legacy write storage permission, declared for compatibility with Android 9 and earlier only. This is the older, pre-scoped-storage way of writing a file to shared storage. It is not a modern photo or video library permission, and it is not one of the Android 13+ media permissions described above.
Each cap is part of the declaration itself, so on a newer Android version the permission is not granted, is not requested and has no effect. ULMOX never asks you for either of them. On a current Android version, choosing an image goes through the system photo picker, which needs no storage permission at all.
ULMOX requests no advertising identifier. The advertising and ad attribution permissions are absent from the Android app we build, so there is nothing for an advertiser or an ad network to read.
Location
With your permission, ULMOX uses your device location to show the city and country where a moment was recorded, and to place content on the world map. If you decline, the app continues to work without it.
Location is read only while you are using the app, as a single reading taken at the moment you record. ULMOX does not follow your location in the background, does not track it continuously, and does not read it while the app is closed.
ULMOX asks only for while-in-use location. It does not use background location, continuous monitoring, significant-change monitoring or geofencing, and the app declares no permission that would let it do any of them.
Message translation (Google ML Kit)
ULMOX offers optional translation of a Connections message you have received. It runs only when you choose Translate with Google on a single message, and the original message stays on screen and remains the authoritative one. Connections and optional message translation are being introduced gradually and may not yet be available for every account or installed app version. See Translation information.
| Part | What happens |
|---|---|
| The message and its translation | Handled on your device by Google ML Kit. ULMOX does not send either of them anywhere to be translated, and does not store the translation on our servers, in a report, in moderation evidence, in a notification, in analytics or in our logs. |
| Language packs | Downloaded to your device when a language is first translated. ULMOX asks first and downloads over Wi-Fi unless you explicitly choose mobile data. You can view and delete them in the app; removing ULMOX removes them in the ordinary way your operating system removes an app’s files. |
| Translation and language metadata | Which languages are configured, and which language was identified, are used to pick a model and label the result. They are not written against a message, an account or a Connection. |
| Google ML Kit’s own network use | Google’s component can use the network for its own purposes: delivering language packs, reading its remote configuration, and reporting diagnostics and usage analytics about the component. Google documents that it collects app and device information, a per-installation identifier, performance data, API configuration, feature events, error codes, the configured translation languages and the identified language. |
| ULMOX server data | Unchanged. Our servers hold the original message only, exactly as described elsewhere in this policy. |
Three things we will not claim. We do not claim that Google receives the text of your messages — Google’s documentation for this feature does not say that it is uploaded. And we do not claim that nothing ever leaves your device: Google’s component makes its own network connections for the purposes listed above. And we do not claim to have ruled the question out — Google’s privacy declaration for its machine-learning kit covers every feature in that kit, including ones that do handle user content, and the component is not open source, so we cannot inspect it ourselves. We tell you what we can verify rather than filling the gap with a reassurance.
Translation data is never used for advertising or profiling, by us or on our behalf. A translation never becomes moderation evidence: reports and the people who review them use the original message.
Device and technical information
- Device and installation identifiers, app version and platform.
- Push notification tokens, so we can deliver notifications.
- Signals used to protect the service against abuse, such as whether several accounts share one device.
Usage and diagnostics
- Firebase Analytics: aggregate product usage.
- Firebase Crashlytics: crash reports.
- Firebase Performance Monitoring: performance measurements.
- Operational server logs, used to run and secure the service.
Age assurance
To confirm you are 18 or older, ULMOX uses the age signal your platform provides where that is available, and otherwise asks you for your date of birth.
Your date of birth is not stored. It is used only while the request is being processed, to work out whether you are 18 or older. We keep the outcome — whether you are eligible — and not the date itself, not your exact age and not an age band.
Age information is never used for advertising, profiling, ranking or analytics.
Reporting, moderation and blocking
- Reports about content and about users, including a dedicated child safety category.
- Moderation records created when a report is reviewed.
- Blocks you create. Blocking is a private safety action; the person you block is not told.
Reported content may be placed in a reversible quarantine while a human reviews it. Reports do not ban accounts. Only an authorised ULMOX administrator can ban an account, and only after human review.
ULMOX does not automatically analyse video frames, audio or transcripts.
3. Deactivation and deletion
Deactivation
Deactivation is reversible: you restore the account by signing back in and choosing Reactivate, which signing in alone does not do. Your profile and Global content are hidden and your account is not selected for new deliveries. Your data is retained so the account can be restored. Videos you already sent may remain with the people who received them for their normal retention period.
Deactivation is not an erasure and it does not clear safety records. Reports, moderation decisions, blocks and other safety evidence are unaffected by deactivating and by reactivating. Reactivation restores your access; it does not undo a moderation decision, does not bring back content that was removed or hidden by moderation, and does not reopen a Connection that was ended. Ending a Connection is final for that pair. Blocking works differently: a block ends the Connection you have now and stops contact in both directions while it stands. Removing a block does not restore the old Connection either — the two accounts would have to qualify again from the beginning, through two fresh qualifying video exchanges and a fresh approval from each person.
Deletion
Deletion is permanent. Access and discoverability are removed as soon as deletion is successfully started, and physical erasure continues in the background, targeted for completion within 30 days unless a justified safety or legal obligation requires limited retention. Your username is held for 90 days before it can be reused. See Delete your ULMOX account.
If your account is linked with Sign in with Apple, permanent deletion on an Apple device asks you to confirm once more directly with Apple, so that ULMOX can revoke its own Sign in with Apple authorisation before the account is deleted. We do not receive your Apple password. If that step does not finish, nothing is deleted. An Apple-linked account cannot complete this step on an Android device; ULMOX stops before removing anything and asks you to finish on an Apple device.
Deleting your ULMOX account does not delete your Apple ID or your Google Account. ULMOX cannot delete either of them. Revoking ULMOX’s Sign in with Apple authorisation is also a different action from deleting your account, and on its own it does not erase your ULMOX data.
Deleting your account removes your data. It does not remove another person’s: a Connection has two people in it, and the messages, videos and records belonging to the other participant stay with them. Where safety evidence has to be kept for a justified reason, the links that tie it to your identity are scrubbed as part of the erasure, so what remains is a record of what happened rather than a record of you.
4. How long we keep things
| Data | How long |
|---|---|
| Account profile and settings | While your account exists. |
| Videos that were never opened | Removed about 7 days after they were sent. |
| Videos that were opened but not shared to Global | Removed about 15 days after they were sent. |
| Global content | Kept while it remains available, until its owner deletes it or moderation removes it. We do not delete Global content on a fixed timer. |
| Unfinished uploads | Cleaned up about 24 hours after they are abandoned. |
| Push tokens and device records | While registered; removed on deactivation and deletion. |
| Age eligibility result | While your account exists. Your date of birth is never stored. |
| Username reservation after deletion | 90 days. |
| Internal deletion record | 90 days, kept so a deletion can be audited. |
| Connection messages | An ordinary message in a Connection is treated as expiring about seven days after it is sent, and stops being part of the conversation then. That is a rule about the message, not a promise about a timer: automatic expiry of the stored record is not currently switched on, so removal happens through routine cleanup rather than at a fixed moment. |
| Reports, moderation records, blocks and safety events | Kept as safety evidence, including after an account is deleted, for as long as there is a justified safety or legal reason. Safety evidence is not ordinary message history: once a message is attached to a report, seven-day expiry no longer governs it, and it is kept while a review is open and afterwards where the outcome justifies keeping it. |
| Analytics, crash and performance data | Retained according to the retention setting configured in the relevant Google service. |
5. Who processes data for us
ULMOX uses the following services:
- Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions and Cloud Messaging (Google).
- Firebase Analytics, Crashlytics and Performance Monitoring (Google).
- Firebase App Check, a device-integrity check used, where the platform supports it, to reduce automated abuse of the service.
- Google Sign-In, and Sign in with Apple for accounts linked with it, for authentication.
- Google ML Kit Translation and Language Identification, which run message translation on your device and may use the network as described under “Message translation” above.
- Firebase Remote Config and Firebase Installations, which ML Kit uses for its own configuration and for the per-installation identifier described above.
- Platform age signals from Google Play and Apple, where the platform makes them available and you choose to share them.
We do not sell personal information, and we do not use it for advertising or cross-app tracking.
6. International processing
ULMOX is available worldwide and our providers operate data centres in several countries, so your data may be processed outside the country where you live. We rely on the safeguards our providers offer for those transfers.
7. Your rights
Depending on where you live, you may have the right to access, correct or delete your data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. You can delete your account yourself in the app, and you can exercise other rights by writing to ulmoxapp@outlook.com.
If you are not satisfied with our response, you may complain to your local data protection authority.
8. Security
Data is transmitted over encrypted connections and stored using our providers’ managed infrastructure. Access to moderation evidence is limited to authorised reviewers. No online service can promise perfect security, and we do not claim to.
9. Changes
We will update this page when our practices change and will update the effective date above. Material changes may require you to accept updated Terms in the app.
10. Related pages
Delete your account · Terms of Service · Child Safety Standards · Support