Last Updated: September 21, 2026
Likeness uses Apple's system photo picker. The app receives only the photographs you choose. It reads the selected image on your device to detect and align faces, restore detail, upscale the image, and compare the result with the source for possible identity drift.
The restoration models are included with the app and run using Apple's on-device Core ML framework. Photographs, face crops, feature representations, restoration results, and related metadata are not transmitted to Zebel or any third party.
When you choose Save, Likeness requests add-only Photos permission and writes a new JPEG to your library. It does not overwrite or delete the selected original.
Restoring a photograph of a person necessarily means processing the faces in it, so this section states exactly what happens to face data, in the terms Apple uses.
Collection. Likeness does not collect face data. No face data — and no data of any kind — is ever transmitted off your device. The app contains no networking code, so it is not merely a promise: the app is technically incapable of sending anything anywhere.
Use. When you restore a photograph, the app locates faces in it using Apple's Vision framework, aligns a crop of each face, restores that crop with the machine-learning models bundled inside the app (run locally by Apple's Core ML framework), and compares the restored face with the original to measure how much it changed. All of this serves one purpose only: restoring the photograph you selected. Face data is not used to identify, recognize, or authenticate anyone, is not used for advertising or profiling, and is not used to train any model.
Storage. Face crops, alignment coordinates, feature representations, and comparison values exist only in your device's working memory (RAM) while a restoration is in progress. They are never written to disk, never placed in any database, and never leave the device. No faceprint or biometric template is created or kept. The only thing that persists is the restored photograph itself, and only if you tap Save — it is then written to your own Photos library as a new item, under your control like any other photo.
Sharing. Face data is shared with no one. There are no third parties involved in restoration: no cloud services, no analytics providers, no SDKs from other companies.
Retention and deletion. Face data is retained only for the duration of the restoration in progress and is automatically freed when the restoration finishes, when you leave the result screen, or when the app closes — whichever comes first. Because nothing is ever collected or stored by Zebel, there is nothing for Zebel to delete, and no retention period beyond the seconds of processing.
Likeness stores only a small amount of app state on the device, such as whether onboarding is complete, how many free restorations remain, restoration preferences, and whether a review prompt has been shown. Draft image data is temporary and is discarded when the restoration session ends. Deleting the app removes this local app state.
The one-time lifetime unlock is processed by Apple through the App Store. Zebel does not receive or store payment-card details. The app reads Apple's signed transaction status to determine whether paid features are unlocked. Apple's handling of App Store transactions is covered by Apple's Privacy Policy.
Likeness contains links to this policy, support, the model acknowledgements page, and Apple's standard terms. Opening one of those links leaves the app and is handled by your browser under the destination site's privacy practices. Photo restoration itself does not use a network connection.
Likeness is not directed at children and Zebel collects no data from users of any age.
If this policy changes, the date above will be updated. A material change will be reflected in the App Store privacy information before an updated app is released.
Questions about privacy: likeness [at] zebel.ai