FujiShare has no ads, no third-party trackers, and no interest in who you are. You can use the app without ever giving us your name or email address. What you choose to post is public, and before it goes live it is screened by two automated services, named below. Your photographs and your camera's contents stay on your device. What we collect is a technical record of how your camera behaved and the ordinary private state of your account, both described below.
FujiShare is made by BrayLabs LLC, an Oregon limited liability company, and we are the ones responsible for the data described here. You can reach us at support@fujishare.com.
The website at fujishare.com sets no cookies and runs no analytics. Cloudflare serves it and keeps the usual short-lived request logs.
FujiShare uses anonymous accounts. There is no sign-up, no password and nothing to remember. The first time you open the app, it creates a random identifier for you. When you first post, we ask only for a display name and a picture you choose, both of which are public. We never ask for your phone number or your real name, and we do not sign you in through any other service.
You can add your Instagram handle on the Profile screen. It is optional, it is public, and you can remove it there at any time.
We ask for your email address twice, and it is optional both times: once at the end of the first-run walkthrough, and again if something goes wrong with your camera and you choose to send us a problem report. You can skip both and use the whole app. It is covered below.
Recipes, photographs, tips, packs, and your chosen display name are public - that is the point of the app. Public means anyone on the internet with the link, not only people using the app, and search engines may index it. Photographs you post may include camera capture data (the settings the photo was taken with), which is shown alongside the photo as part of the recipe. Location data is not published.
A credit on a post may name another person's Instagram handle, placed there by the poster to say where a look came from. If that is your handle and you would rather it were not there, write to us and we will remove it.
Posts to the Discover feed can also be reshared on FujiShare's own social media accounts to promote the app, credited to your display name. The terms set out exactly what we may and may not do with them, and asking us to stop is enough to stop us using them again.
When you pick a photograph to post or to use as your profile picture, iOS asks your permission and hands us the one file you chose. We never scan or index your library, and nothing leaves your phone until you publish. The photographs you do publish are uploaded and stored so the app can show them.
Nothing is screened until you tap post. When you do, every photograph, profile picture, post text, pack description and display name is sent to OpenAI's moderation service, which returns a score, does not store what it was sent, and does not train on it. Every image is also sent to Arachnid Shield, run by the Canadian Centre for Child Protection, which compares it against known child sexual abuse material and tells us whether it matched.
A match is preserved and reported to the National Center for Missing and Exploited Children, as United States law requires of us. Posts that score in the uncertain band wait for a human to look before they go live.
Over USB, FujiShare reads and writes your camera's custom settings banks directly from your phone. Over Bluetooth and the camera's own Wi-Fi it pairs with the camera and copies photographs across, and writes no settings. Either way the camera's contents are processed on your device. We do not upload your camera roll or your camera's photographs.
Fujifilm has said that its cameras may keep their own record of connections by software it has not licensed, which includes FujiShare. If that record exists, it lives on the camera under Fujifilm's control. FujiShare neither reads nor writes it, and we do not know what it contains. The terms explain what Fujifilm has said this means for your warranty.
When the app talks to a camera, it sends us a short technical record of how that went: the model and firmware version, whether each step worked, and the settings ranges the camera reports about itself. These records are how the app comes to work on camera models we do not own and cannot test ourselves.
The record carries no photographs, no bank names, and never your camera's settings file. It does carry the values the app wrote and what the camera reported back for them, which is how a failed write becomes a fix. It never carries your camera's serial number, in whole or in part. Each record is tied to your anonymous identifier and to nothing else, which lets us tell twenty reports from one person apart from twenty people hitting the same problem.
Sending these records is part of connecting a camera, not an optional extra. If you would rather not send them, do not connect a camera. Everything else in the app still works.
Our legal basis is legitimate interest: making the app work on cameras we cannot test. If you want the records tied to your identifier deleted, ask us and we will delete them. Your rights below cover how.
There are two places the app offers to take an email address, and both are optional. The last screen of the first-run walkthrough asks for one, with a skip button on the same screen. A problem report can carry one if you choose to add it. You can decline both and nothing about the app closes off.
It exists so a person can write back to you about a problem your camera hit, and once in a while so we can tell you when the thing you reported is fixed or when something about the beta needs saying. That is the whole list. We do not use it for marketing, we do not sell or share it, and every message we send carries a way to tell us to stop.
If you gave us an address, it is attached to the automatic crash reports described below, so that a crash we can see is also a person we can apologise to. It is never shown on your profile or anywhere else in the app, and no other user can see it.
You can change it or remove it at any time from the Profile screen in the app, and removing it there deletes it. You can also write to us and ask.
When something fails - a write your camera refuses, settings we cannot read back, a connection that will not hold - the app offers to send us a report. It is always your choice. The report carries what went wrong technically, your iPhone's iOS version, anything you type into it, and your email address if you decide to include one.
If the app crashes, a report goes to Sentry, an error-tracking service that handles it on our behalf and does not use it for anything of their own. It carries the crash, your camera's model and firmware, standard device details such as your iPhone model, iOS version and app version, your anonymous identifier, and your email address if you gave us one. There are no screenshots, no session recordings, no advertising identifiers, and the app is configured so that your IP address is not recorded with the report.
While FujiShare is in beta it is distributed through Apple's TestFlight. Apple collects tester feedback, screenshots you choose to send, and crash data under its own privacy policy, and passes them to us.
Like every internet service, the servers that answer the app keep short-lived logs of requests, which include your IP address. They exist for security and debugging, they age out on their own, and we do not use them for anything else. When the app checks for an update it asks Expo's servers, which see your IP address, the app version and the platform, and nothing else.
Posts, account state, camera records and problem reports are held in our database, run for us by Supabase. Crash reports are held by Sentry. Screening is done by OpenAI and the Canadian Centre for Child Protection. Each processes data on our instructions and for nothing else.
Our database sits in Amazon's Oregon region, a few hours' drive from where the app is written. Crash reports sit with Sentry in the United States. Screening happens with OpenAI in the United States and with the Canadian Centre for Child Protection in Canada. If you are reading this from outside those countries, that means your data is handled there, under their law, by the companies named above and nobody else.
Everything travels encrypted. The database enforces row-level security, so one account cannot read another's private rows, and the tables that carry camera records and reports accept new rows without letting anyone read them back. No system is perfect. If something happens that affects you, we will tell you rather than wait to be asked.
We disclose data when the law requires it, in response to valid legal process, to protect someone from harm, or to make the child-safety reports described above. We tell you when we are allowed to. If the business changes hands, the data goes with it, under this policy.
Different countries grant different rights over personal data. Rather than work out which set you fall under, we give everyone the same ones. You can ask us what we hold about your identifier, ask for a copy of it, ask us to correct it, ask us to delete it, and object to the camera records described above. Write to support@fujishare.com and we will answer within thirty days. It is free, and we will not treat you differently for asking. For a request that comes from outside the app we may ask for your account ID, to be sure the account is yours.
If you are in the UK, the EU, or somewhere else with a data-protection regulator, you can complain to them about how we have handled your data. We would rather you told us first so we can fix it, but that route is yours and we will not stand in the way of it.
You can delete your posts in the app at any time, and you can remove your email address yourself on the Profile screen. To delete the whole account, or an address you added to a problem report, write to support@fujishare.com and include your account ID, which the app shows you on your profile screen.
We ask for the ID because there is often nothing else to ask for. An account here has no password attached to it, and may have no email address either, so that ID is the only thing that reliably identifies which account is yours. Acting on a request without it would mean deleting a stranger's photographs on someone else's say-so. Until the in-app delete flow ships, email is the route, and the Profile screen prefills the message for you.
FujiShare is not for people under 16 and we do not knowingly collect anything from them. If we find out that we have, we delete it. If you are a parent and think we hold something of your child's, write to us and we will sort it out.
If we change something here that matters, we will tell you before it takes effect rather than quietly editing this page: during the beta through TestFlight's release notes, and by email if you gave us an address; once the app is on the App Store, in the app itself. The date at the top tells you which version you are reading. If you do not agree with a change, stop using the app and ask us to delete your account.
Write to support@fujishare.com. A human reads it.