Legal

PhotoFill
Privacy Policy

Effective: August 23, 2026  ·  Last updated: August 23, 2026

The short version: PhotoFill finds contacts on your device that have no photo and fills them in with a simple, colored initial-avatar — generated entirely on your device from the contact's name. No photo, image, or biometric data is ever uploaded to generate it. The app has no backend server and no accounts; reading your contacts and writing the generated avatar back both happen locally on your phone. Contact data is never sold or shared with third parties.

1. Introduction

PhotoFill ("the App") is an Android app developed by Bhoomin Naik ("we", "us", "our") that scans the contacts stored on your device to find ones with no photo, and fills each in with a simple generated avatar — a colored circle with the contact's first initial.

All of the App's core functionality — reading your contacts, generating avatars, and writing them back — happens entirely on your device. The App has no backend server of its own and no user accounts or login.

This Privacy Policy explains what information the App accesses, how it's used, and what the App's third-party services collect. By using the App, you agree to this policy. If you do not agree, please do not use the App.

2. Information We Access (Device Permissions)

The App requests two Android permissions to do its job:

READ_CONTACTS — used to scan the contacts stored on your device and identify which ones have no photo.

WRITE_CONTACTS — used to write the generated avatar back to a contact, via RawContacts.DisplayPhoto, once you choose to fill it in.

Reading and writing your contacts happens entirely on your device. Your contact names, phone numbers, emails, and photos are never transmitted off your device, sold, or shared with third parties — including the third-party SDKs described in Section 4 below.

3. How Avatars Are Generated

For each contact without a photo, the App draws a simple avatar image locally on your device — a colored circle with that contact's first initial. This image is generated programmatically from the contact's name; no photo, image, or biometric data is uploaded anywhere to create it, and no external service is involved in generating it.

4. Third-Party Services

The App integrates three third-party SDKs, all provided by Google. None of them receive your contact data (names, phone numbers, emails, or photos) — only the usage, diagnostic, and advertising data described below.

Firebase Analytics

Collects standard app usage and event data — screen views, button taps, session length, and app opens — along with device and advertising identifiers, to help us understand how features are used. Does not receive contact data.

Firebase Crashlytics

Collects crash reports and diagnostic logs — stack traces, device model, OS version, and app version — to help us find and fix bugs. Not used to collect contact data.

Google AdMob

Shows ads within the App. Collects advertising identifiers (the Android Advertising ID), device information, approximate IP-based location, and ad interaction data to serve and measure ads, and may use this data for personalized advertising unless you opt out via your device's ad settings.

For each of these services: the vendor is Google, data may be transmitted to and processed by Google, and you can review Google's privacy policy at policies.google.com/privacy. You can opt out of personalized ads at any time via your device's Google Ads Settings.

5. Data Sharing

The App has no backend server of its own and no user accounts or login. Contact reading, avatar generation, and photo writing all happen entirely on-device — none of that data is transmitted off your device, sold, or shared with third parties.

The only data that leaves your device is the non-contact usage, diagnostic, and advertising data described in Section 4, sent to Google via Firebase Analytics, Firebase Crashlytics, and Google AdMob.

6. Data Retention & Your Control

Because the App has no backend and no accounts, there is no server-side copy of your contact data for us to retain or delete. Writing an avatar to a contact is a device-local, reversible action — you can remove or replace it at any time using your phone's own Contacts app.

You can revoke the App's Contacts permission at any time from Android Settings → Apps → PhotoFill → Permissions. Uninstalling the App removes it and any of its local data from your device, though avatars already written to your Contacts Provider will remain until you edit or remove them yourself.

7. Children's Privacy

The App is not directed at children under 13, and we do not knowingly collect data from children under 13. If you believe a child has provided us with personal information, please contact us at bhoominn@gmail.com so we can take appropriate action.

8. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect the most recent revision. Continued use of the App after changes are posted constitutes your acceptance of the updated policy.

9. Contact Us

If you have questions about this Privacy Policy or the App, please reach out: