Privacy Policy
Rabbit Hole by TMS Recording · Last updated August 3, 2026
The short version: Rabbit Hole processes a photo only after you capture it or choose it from your library and agree to AI analysis. A compressed copy is sent to Google Gemini through our proxy over an encrypted HTTPS connection. The transient analysis cache is replaced when you start a new scan, while up to five recent captures can remain on your device so you can revisit them. We do not sell your data, use it for ads, or track you across other companies' apps and websites.
1. What Rabbit Hole Does
Rabbit Hole is a curiosity engine. It analyzes a photo you capture or choose, identifies interesting details, and uses artificial intelligence to generate educational facts and optional follow-up paths.
2. Camera, Photos & Share Cards
Rabbit Hole asks for operating-system permission when a feature needs access. You can change those permissions later in your device's Settings app.
- Camera: Used for live captures. The camera is active only while the app is in the foreground and the camera view is in use.
- Photo picker: Used only when you choose to analyze an existing image. Rabbit Hole processes the image you select; the app does not enumerate your library for analysis.
- Add to Photos: When you create a share card, your device's share sheet may offer an option such as “Save Image” or “Add to Photos.” Rabbit Hole does not add the card to your library unless you explicitly choose that action, and the operating system may request add-only photo permission.
3. Photo Processing & On-Device Storage
When you capture a photo or choose one from your library:
- The app makes a temporary analysis frame in its sandboxed cache and sends a compressed version to our AI proxy over HTTPS.
- The transient analysis cache is replaced when you start a new scan. On launch, the app also purges stale orphaned analysis-cache files from prior sessions.
- Separately, Recent Captures keeps up to five recent analyzed photos on your device so you can revisit them. New captures replace the oldest.
- If a request cannot be processed while offline or during a retryable outage, the app can keep a durable local copy in its offline queue until it is processed, canceled, or its retry limit is exhausted. See Sections 5 and 12 for limits.
Rabbit Hole does not intentionally persist photos on its servers. Our proxy application relays image data for the requested analysis and does not intentionally log image bodies or write them to an application database. Hosting, AI, and diagnostic providers may process operational metadata under their configured settings and provider policies.
4. AI Analysis
Photo analysis, deep dives, and Ask requests use Google's Gemini API:
- A compressed JPEG, up to about 3072 pixels on its longest analysis dimension and approximately 2.7 MB, is sent over HTTPS to our proxy hosted by Vercel and then to Google Gemini. During detail enrichment, the app may also send up to three smaller crops from that same photo.
- The Gemini API credential stays on the proxy; it is not included in the app.
- Gemini returns structured text such as labels, facts, and coordinates. Rabbit Hole does not request a returned copy of your image.
- Follow-up personalization is enabled by default to preserve continuity between topics. When enabled, a compact text summary of recent topic labels may be included in deep-dive or Ask requests. You can turn it off at any time in Library → AI data controls. The full local memory database is not uploaded.
- Google's processing is governed by Google's Gemini API Terms of Service.
5. Data Stored on Your Device
Depending on which features you use, Rabbit Hole can store the following locally:
- Usage count: Your capture count for the current calendar month. Free use includes up to 20 successful scans per calendar month; the counter resets when the month changes.
- Preferences and state flags: Small records for AI consent, onboarding completion, a random per-install analytics identifier, telemetry delivery, first-use events, and related app preferences. The identifier is generated by Rabbit Hole and is not an advertising or vendor identifier.
- Entitlement cache: The last Rabbit Pass status verified with Apple StoreKit or Google Play Billing. A recently verified active entitlement may be reused during a store or network outage for up to seven days. If an expiration time is available, access is never extended more than 24 hours past that time. The earlier of those two limits applies.
- Rabbit Hole memory: Up to 500 recent memory nodes for up to 180 days, including labels, facts, prompts, timestamps, and relationships between dives.
- Saved rabbit holes: Up to 50 saved holes with their text, branches, history, tags, and save time.
- Recent captures: Up to five recent capture-history images and their analysis results.
- Offline captures: Up to 50 queued photos and queue metadata, retained until processed, canceled, or the retry limit is exhausted. If the queue exceeds its cap, the oldest pending item and its photo are removed.
- Telemetry outbox: Up to 500 pending operational events for no more than seven days when delivery is temporarily unavailable. Photo bodies are not part of these events.
- Session restoration: A bounded snapshot of the current app view may be used to restore an interrupted session for no more than five minutes.
- On-device model files: This release does not download or store a separate Memory model on Android. On supported Apple devices, local Memory insights use Apple's system-provided model; Rabbit Hole does not download its own model file.
6. Operational Data & Diagnostics
- No accounts: Rabbit Hole does not require an account, email address, or sign-in.
- No advertising or cross-app tracking: We do not provide data to advertising networks or use it to track you across other companies' services.
- Limited product telemetry: The app may send allowlisted events such as first capture, bubble open, paywall view, restore tap, and share tap to our backend for product reliability and aggregate usage analysis. These events are not tied to a Rabbit Hole account and do not contain photo bodies, object labels, generated facts, or free-text input. A random per-install identifier accompanies these events so we can count return usage; the backend stores only a keyed pseudonym of that identifier.
- Stability diagnostics: Release builds may send crash, performance, and related technical context to Sentry so we can diagnose failures.
- No location or contacts: Rabbit Hole does not request precise location or access your address book.
7. Sharing
- Short links: If you create one, Rabbit Hole stores the shared label, fact, thread, branches, and history with a random share ID. Short-link payloads do not include your photo and automatically expire after 90 days.
- Share cards: A share card is an image created on your device and handed to the operating system's share sheet. It is sent to another app or added to Photos only when you choose a destination or save action.
- Identity: Shared links are not associated with a Rabbit Hole account or payment account. Anyone who receives a link can view its content, so share only material you are comfortable making available to the recipient.
8. In-App Purchases & Subscriptions
Rabbit Hole may offer:
- Tip Jar: A one-time consumable tip at the price shown by your device's storefront at purchase time.
- Rabbit Pass: A monthly auto-renewing subscription that provides up to 500 successful scans per calendar month and full reader access at the displayed storefront price.
Payment is charged to your Apple App Store or Google Play account when you confirm the purchase. Rabbit Pass renews automatically each month unless you cancel before the next renewal under your storefront's rules. You can manage or cancel on iPhone or iPad in Settings → your name → Subscriptions, or on Android in Google Play → profile → Payments & subscriptions → Subscriptions. Cancellation normally takes effect at the end of the current paid period; refunds and exceptions are controlled by the applicable storefront. Rabbit Hole can restore eligible purchases, but TMS Recording does not process or receive your payment-card details.
Store terms also apply. See Apple's Standard End User License Agreement and the Google Play Terms of Service.
9. Third-Party Services
Rabbit Hole uses service providers for specific functions:
- Google Gemini API for AI image analysis and text generation — Google Privacy Policy.
- Vercel for API and short-link hosting — Vercel Privacy Policy.
- Expo Updates for approved app-code updates — Expo Privacy Policy.
- Sentry for crash and performance diagnostics — Sentry Privacy Policy.
- Apple StoreKit and Google Play Billing for purchases, subscriptions, and entitlement restoration on their respective platforms.
10. External Links
Rabbit Hole may show topic or hashtag links that open another app or website. We do not send your photo to that destination. Once you leave Rabbit Hole, the destination's own privacy policy applies.
11. Children's Privacy
Rabbit Hole is a general-audience app and is not directed to children. We do not knowingly collect personal information from children. The app uses content-safety controls intended to reduce harmful or inappropriate AI-generated content.
12. Security & Retention
Communication between the app, our proxy, and service providers uses HTTPS/TLS. No system is perfectly secure, but we use bounded local storage, input validation, and access controls appropriate to the data processed.
- Transient analysis cache: Replaced when a new scan starts; stale orphaned cache files are purged on launch.
- Recent captures: Limited to five; new captures replace the oldest.
- Offline captures: Limited to 50 and deleted after processing, cancellation, retry exhaustion, or oldest-item eviction at the cap.
- Memory and saved content: Memory is limited to 500 nodes and 180 days; saved rabbit holes are limited to 50.
- Telemetry outbox: Limited to 500 events and seven days; delivered or expired entries are removed.
- Aggregate product metrics: Daily funnel counters and keyed per-install pseudonyms used for first-seen and day-1/day-7 return measurement expire after 180 days. They do not contain photos, labels, generated facts, or free text.
- Session restoration: A snapshot is eligible for use for no more than five minutes.
- Entitlement cache: A verified active result can be reused for up to seven days, but no more than 24 hours past a known subscription expiration.
- Short links: Automatically expire after 90 days.
- Provider operational metadata: Hosting, AI, storefront, update, and diagnostic providers may retain request or diagnostic metadata according to our configured settings and their policies. Rabbit Hole's application code does not intentionally log image bodies.
13. Your Choices & Rights
You can decline AI analysis, camera, or photo access; turn off recent-topic personalization or withdraw AI consent under Library → AI data controls; cancel a queued offline capture; remove individual saved items; or use Library → Clear Local Data to permanently remove saved rabbit holes, recent capture images, personal memory, queued scans, and restorable session content from the device. This control does not reset AI settings, purchases, or the monthly scan allowance. It also does not reset the random analytics install identifier or once-only analytics flags. Uninstalling Rabbit Hole also deletes that remaining local app data. Short links use random IDs and are not tied to an account; they expire automatically after 90 days. If you contact us about a specific link, include its full URL, but understand that we cannot use an account record to verify who created it.
Privacy rights differ by location. To ask a question or make a privacy request, contact us using the address below. We may need enough information to understand the request, but we will not ask you to create a Rabbit Hole account.
14. Changes to This Policy
We may update this policy as the app changes. We will revise the “Last updated” date on this page and provide additional notice or request consent when applicable law requires it.
15. Contact
Questions about this policy or Rabbit Hole's data practices can be sent to:
Email: support@tmsrecording.com
Developer: TMS Recording