Privacy Policy
Casalo is published by RA2 LAB COMPANY LIMITED ("Ra2Lab"). This page has two parts: a short summary of what Casalo specifically does with your data, and the full Ra2Lab Privacy Policy, which applies to Casalo and to this website.
Casalo at a glance
- No sign-up. Casalo creates an anonymous account on your device automatically. We don't ask for your name or email.
- Your photos and prompts. When you create a design, the photo you take or
pick, and any text you type, are sent to our backend (
api.ra2lab.io) and to AI model providers acting for us, such as Google Gemini, to generate the result. - Your designs stay on your device. Your design history is stored on your phone. You can delete designs in the Mine tab; deleting the app deletes them all.
- Purchases. Payments are handled by Apple or Google. We never see your card. RevenueCat tells the app whether you have Casalo Pro.
- Analytics and crash reports. We use Firebase Analytics to understand which features are used and Firebase Crashlytics to fix crashes.
- No ads and no tracking. Casalo has no advertising SDKs and does not track you across other companies' apps or websites, so it never shows the App Tracking Transparency prompt.
- Permissions. Camera, to take the photo you want to redesign. Photos, to pick an existing photo and to save designs to your library. Both are asked for only when you use them.
- This website doesn't set cookies and doesn't use analytics or advertising scripts.
- Questions or deletion requests: admin@ra2lab.io.
Ra2Lab Privacy Policy
Effective date: 16 August 2026 · Last updated: 16 August 2026
Ra2Lab ("Ra2Lab", "we", "us", or "our") builds and publishes mobile applications. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have.
If you have any question about this policy or want to exercise a privacy right, email us at admin@ra2lab.io.
1. Scope — which apps this covers
This policy applies to every mobile application published by Ra2Lab on the Apple
App Store and Google Play (including, but not limited to, apps whose bundle
identifier begins with io.ra2lab.), to our websites and landing pages, to our
backend services at api.ra2lab.io, and to any support or marketing
communication you exchange with us. We refer to all of these together as the
"Services".
Our apps differ from one another. A scanning app uses the camera; a media app does not. No app collects data for a feature it does not have. An app only requests a device permission when you use the feature that needs it, and the authoritative, per-app summary of what is collected is the privacy label shown on that app's App Store or Google Play listing. Section 3 explains, permission by permission, what we do with the data when an app does use it.
Where an individual app publishes its own privacy policy (for example, because a store listing requires app-specific detail), that app-specific policy governs for that app and this policy applies to everything it does not address.
2. Information we collect
2.1 Information you give us
- Account details. Most of our apps work with an anonymous account created automatically on your device, with no name or email required. If you choose to sign in — with email or a social provider such as Apple or Google — we receive your email address and, where the provider supplies it, your display name.
- Content and inputs. Anything you submit through a feature: photos and images, barcodes, audio recordings, text prompts, search queries, corrections, quiz and onboarding answers, saved preferences, favourites and lists.
- Purchases. Payments are processed by Apple or Google, never by us. We never see or store your card number. We receive your subscription status, product identifier, price, currency, and renewal or cancellation events from the stores and from our subscription provider.
- Support and feedback. Messages you send us by email, in-app feedback, app reviews you ask us to look at, and survey or promotion entries.
2.2 Information collected automatically
- Usage data. Screens viewed, features used, actions taken in the app, session length, onboarding and paywall events.
- Device and log data. Device model, operating system version, app version and build, language and region, time zone, mobile network type, IP address, access times, and a per-installation identifier.
- Diagnostics. Crash reports, stack traces, and performance data used to fix defects.
2.3 Information we generate
- Internal identifiers. A user ID linking your account to your data.
- Approximate location from IP address, used for regional pricing, content availability, and fraud prevention.
- Derived preferences. For example, categories you scan or watch most often, or the likelihood that a given screen is useful to you.
2.4 Information from other sources
App stores and our subscription provider (purchase and subscription state); social sign-in providers you choose to use; public or licensed content databases; and service providers acting on our behalf.
3. Device permissions
An app asks for a permission only when you invoke the feature that needs it, and you can revoke any permission at any time in your device settings — the rest of the app keeps working.
| Permission | Why an app asks for it | What leaves your device |
|---|---|---|
| Camera | Scanning barcodes, labels, objects, or taking a photo the feature works on | The captured image or barcode is sent to our servers and to our AI/recognition providers to produce the result |
| Photo library | Choosing an existing photo instead of taking one | Only the images you explicitly pick |
| Microphone / speech | Recording or transcribing audio for a feature that analyses or converts sound | The recording or its transcript, for as long as needed to return the result |
| Location | Features that depend on where you are, such as finding nearby places | Approximate or precise location while you use that feature; we do not track location in the background |
| Notifications | Reminders, results that finish later, and occasional product news | The notification token, which is not linked to your identity outside our systems |
| Contacts | Only when you choose to share or invite a specific person from a share sheet | The contact you pick, used solely to address that one message; we do not upload your address book |
| Tracking (iOS ATT) | Measuring advertising in apps that show ads | Only if you tap "Allow" on the system prompt; declining does not limit app functionality |
4. AI processing
Several Ra2Lab apps produce results using AI models — for example turning a photo of a label into an explanation, recognising an object, generating an image, or transcribing speech. To do that, the input you submit (image, audio, or text) is sent to our backend and to model providers acting as our processors, such as Google (Gemini) and comparable model APIs.
- We use these inputs to return your result, to debug failures, and to improve the accuracy of our own matching, scoring, and prompts.
- We may retain de-identified or aggregated inputs for quality assurance and measurement.
- AI results are informational only. They are not medical, veterinary, legal, financial, or professional advice, and they can be wrong. Do not rely on them for decisions that affect health, safety, money, or legal standing.
- We do not use AI to make decisions that produce legal or similarly significant effects about you.
5. How we use information
We use the information described above to:
- provide, operate, and maintain the Services and the features you request;
- create and secure your account, and sync your data across your devices;
- process purchases, manage subscriptions, and honour restores and refunds;
- personalise content, recommendations, and the order in which we show things;
- send transactional messages (subscription changes, support replies) and, where you have opted in or we are otherwise permitted, product news;
- measure and improve the Services, including analysing usage trends, testing variants, and fixing crashes;
- market our apps, including measuring advertising campaigns;
- detect, investigate, and prevent fraud, abuse, and security incidents; and
- comply with legal obligations and enforce our terms.
Legal bases (EEA / UK / Switzerland). We rely on: performance of a contract for providing the Services and handling purchases; our legitimate interests for security, fraud prevention, analytics, and product improvement; your consent for device permissions, personalised advertising, and marketing messages where consent is required; and legal obligation where the law requires processing.
6. How we share information
We do not sell your personal information for money. We share it only as follows.
- Service providers who process data on our behalf under contract: cloud hosting and storage, authentication, crash reporting and analytics, subscription management, AI and content processing, email and support tooling, and security and anti-fraud services.
- App stores and payment processors — Apple and Google — for purchases, subscriptions, and refunds.
- Advertising and attribution partners, in apps that show ads or run paid acquisition, subject to Section 7.
- Professional advisers (lawyers, accountants, auditors) bound by confidentiality.
- Authorities, when required by law or valid legal process, or to protect the rights, property, or safety of Ra2Lab, our users, or the public.
- A successor entity, if Ra2Lab is involved in a merger, acquisition, or sale of assets — the same commitments continue to apply.
- Anyone you direct us to, including when you use a share feature.
We may also publish or share aggregated or de-identified information that cannot reasonably be used to identify you.
Third parties commonly used across our apps
Depending on the app, these providers may process data:
- Google Firebase — authentication, analytics, crash reporting, messaging.
- Google Gemini and comparable AI model APIs — generating results from your inputs.
- RevenueCat — subscription state management.
- Apple App Store / Google Play — purchases and subscriptions.
- Google AdMob — advertising, in apps that show ads.
- Google Maps Platform — maps and place search, in apps with location features.
- Public and licensed content databases — reference data shown in the app.
These providers handle data under their own privacy policies as well; we encourage you to read them.
7. Advertising, analytics, and tracking
Some Ra2Lab apps are ad-supported, and we advertise our apps on third-party platforms. Advertising and analytics partners may use device identifiers, cookies, and similar technologies to measure and target ads.
- On iOS, ad tracking happens only if you allow it at the App Tracking Transparency prompt. You can change your answer in Settings → Privacy & Security → Tracking.
- On Android, you can reset or delete your advertising ID in Settings → Google → Ads.
- Under some laws, sharing identifiers for cross-context behavioural advertising counts as a "sale" or "share". You can opt out at any time by emailing admin@ra2lab.io.
- We honour the Global Privacy Control (GPC) signal on our websites where applicable law requires it.
Paid subscriptions do not require you to accept advertising tracking.
8. Data retention
We keep personal information only as long as we need it:
- Account data — while your account exists, then deleted or anonymised.
- Content and AI inputs — for the period needed to deliver and support the feature, after which it is deleted or de-identified.
- Purchase records — for as long as tax, accounting, and audit law requires.
- Diagnostics and analytics — typically retained in de-identified or aggregated form.
When you delete your account we delete or anonymise the personal information associated with it, except what we must retain by law or to resolve a dispute.
9. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and least-privilege access for our systems. No system is perfectly secure, so we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant authorities as applicable law requires.
10. International transfers
We and our providers operate globally, so your information may be processed in countries other than your own, including the United States. Where the law requires it, we protect those transfers with an adequacy decision, Standard Contractual Clauses, or your explicit consent.
11. Your rights and choices
Subject to your local law, you may have the right to: know what personal information we hold; access it or receive a portable copy; correct it; delete it; object to or restrict processing; withdraw consent at any time; opt out of the sale or sharing of personal information for targeted advertising; and limit the use of sensitive personal information.
How to exercise a right. Email admin@ra2lab.io from the address linked to your account, or use the in-app account-deletion option where the app provides one. We may need to verify your identity before we act, and you may use an authorised agent. We do not discriminate against you for exercising a right. If we decline a request, you may appeal by replying to our decision at the same address.
Marketing. Unsubscribe using the link in any marketing email. We will still send you transactional messages about your account and purchases.
Push notifications. Turn them off in your device settings at any time.
Subscriptions. Manage or cancel a subscription in your App Store or Google Play account settings; we cannot cancel it for you.
12. Children
Our apps are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, email admin@ra2lab.io and we will delete it. Where an app carries a higher age rating on a store, that rating applies. We do not knowingly sell or share the personal information of anyone under 16.
13. Additional information for California residents
This section supplements the policy for California residents under the CCPA/CPRA.
Categories of personal information we collect: identifiers (account ID, email, device and advertising identifiers, IP address); commercial information (subscriptions and purchase history); internet or network activity (app usage and interactions); geolocation data (approximate from IP; precise only for location features you use); audio, electronic, or visual information (photos, recordings, and messages you submit); and inferences drawn from the above.
Sources: you; your device and use of the Services; app stores and our subscription provider; social sign-in providers you choose; public sources; and our service providers.
Business purposes: those listed in Section 5.
Disclosures: to the categories of recipients listed in Section 6. We do not sell personal information for money. Sharing identifiers with advertising partners may qualify as "sharing" for cross-context behavioural advertising; opt out by emailing admin@ra2lab.io or by enabling GPC.
Sensitive personal information: we do not use or disclose it for purposes beyond those permitted without an option to limit under the CCPA.
14. Additional information for the EEA, UK, and Switzerland
Ra2Lab is the data controller for personal data processed through the Services. Our legal bases are described in Section 5. In addition to the rights in Section 11, you may lodge a complaint with your local supervisory authority — for example via edpb.europa.eu, ico.org.uk, or edoeb.admin.ch.
15. Changes to this policy
We may update this policy. When we do, we change the "Last updated" date above and, for material changes, give additional notice in the app or by email before the change takes effect. Continuing to use the Services after a change means you accept the updated policy.
16. Contact
Ra2Lab — privacy questions, requests, and appeals: admin@ra2lab.io
© 2026 Ra2Lab. All rights reserved.

