Privacy Policy — Saccade

Effective Date: March 17, 2026

1. Introduction

This Privacy Policy describes how Saccade (“we,” “us,” or “our”) handles information when you use our eye-gaze-tracked image preference ranking application (“App”) and our website at saccadeapp.com (“Website”). We are committed to protecting your privacy and being transparent about our practices.

We do not sell, rent, share, or trade your personal information to or with any third party. We never have, and we never will.

Saccade is designed from the ground up with a privacy-first architecture. The App has no backend servers, no user accounts, no analytics, and no cloud storage. All data stays on your device, under your control, at all times.

2. Definitions

For the purposes of this Privacy Policy:

  • “App” means the Saccade iOS application available on the Apple App Store.
  • “Website” means saccadeapp.com and all associated subdomains.
  • “Service” means the App and Website collectively.
  • “Personal Information” means any information that identifies, relates to, describes, or could reasonably be linked to a particular individual.
  • “Device” means the iPhone or other Apple device on which you install and use the App.
  • “Blend Shape Values” means the numerical coefficients provided by Apple’s ARKit framework that represent the position and movement of facial features, including eye direction.
  • “You” or “User” means any individual who accesses or uses the Service.

3. Information We Collect

Saccade is designed to operate without collecting personal information. We do not require an account, email address, name, or any form of registration.

3.1 Camera and Face Tracking Data

Saccade uses your device’s TrueDepth camera and Apple’s ARKit framework to perform real-time face tracking during image comparison sessions. This is used solely to detect which of two displayed images you are looking at.

Specifically, the App reads numerical blend shape values from ARKit — small floating-point numbers indicating eye direction (e.g., eyeLookUpLeft, eyeLookDownRight). These values are:

  • Processed entirely on your device in real-time
  • Used only to determine gaze direction during active comparison sessions
  • Never stored, recorded, logged, or saved to any persistent storage
  • Never transmitted to any server, third party, or external service
  • Discarded from memory immediately after each pairwise comparison ends

We do not capture, record, or store any photos or video of your face. The TrueDepth camera feed is processed by ARKit on-device and is never accessed as raw imagery by the App.

3.2 Images You Import

When you create a project, you may import images from your device’s photo library or camera. These images are:

  • Stored locally on your device in the App’s sandboxed storage directory
  • Never uploaded, transmitted, or shared with any server or third party
  • Accessible only by the Saccade App on your device
  • Deleted when you remove the project or uninstall the App

3.3 Comparison Results

The results of your gaze-tracked comparisons (which image received more gaze time in each pair) are stored locally on your device using Apple’s SwiftData framework. This data:

  • Remains entirely on your device
  • Is never transmitted anywhere
  • Can be exported by you as a shareable results card, at your discretion
  • Is deleted when you remove the project or uninstall the App

3.4 What We Do NOT Collect

To be explicit, Saccade does not collect any of the following:

  • Names, email addresses, or contact information
  • Account credentials or passwords
  • Location data or GPS coordinates
  • Device identifiers, advertising IDs, or fingerprints
  • Usage analytics, crash reports, or telemetry
  • Photos or video of your face
  • Biometric identifiers or biometric templates
  • Browsing history, search queries, or interaction logs
  • Any data from other apps on your device
  • Health, financial, or demographic data

4. How We Use Information

The only processing Saccade performs is:

  • Real-time gaze detection: Reading ARKit blend shape values during active comparison sessions to determine which image you are looking at, then immediately discarding those values from memory.
  • Local data storage: Saving your project images and comparison results on your device so you can view them later.
  • Results generation: Computing preference rankings from pairwise comparison outcomes, entirely on-device.

We do not use your information for advertising, profiling, marketing, analytics, or any purpose other than the core functionality of the App as described above.

5. Cookies and Tracking Technologies

The Saccade App does not use cookies, web beacons, pixels, local storage tokens, or any other tracking technologies.

The Saccade Website (saccadeapp.com) does not use cookies, tracking pixels, analytics services, or any third-party scripts that collect visitor data. We do not use Google Analytics, Facebook Pixel, Hotjar, or any similar service. The Website is a static informational site with no visitor tracking whatsoever.

6. Data Storage and Security

All data created or imported within Saccade is stored exclusively on your device:

  • Images: Stored as JPEG files in the App’s sandboxed Documents directory.
  • Comparison results: Stored via Apple’s SwiftData framework in an on-device database.
  • Face tracking data: Exists only in volatile memory during active sessions and is never written to disk.

Because we have no servers, no backend, and no cloud infrastructure, there is no remote storage of your data. Your data is protected by your device’s built-in security measures, including:

  • iOS app sandboxing (other apps cannot access Saccade’s data)
  • Hardware-level encryption on all modern iPhones
  • Your device passcode, Face ID, or Touch ID
  • Apple’s Data Protection file encryption

7. Information Sharing and Disclosure

We do not share, sell, rent, trade, or otherwise disclose any user information to any third party, for any reason. This includes:

  • No sharing with advertisers or marketing partners
  • No sharing with analytics or data-mining services
  • No sharing with social media platforms
  • No sharing with data brokers
  • No sharing with affiliated or unaffiliated companies
  • No sharing with government entities (we have no data to share)

Because Saccade has no backend and collects no data on our end, we are technically incapable of sharing your information even if we wanted to or were compelled to do so. We cannot produce data we do not have.

8. Sub-Processors

Sub-Processor Purpose Data Shared
None. Saccade has no backend, no third-party services, and no sub-processors.

9. Data Retention

Saccade retains data only on your device and only for as long as you choose to keep it:

  • Project images and results persist on your device until you delete the project within the App or uninstall the App entirely.
  • Face tracking data (blend shape values) exists only in volatile memory during active comparison sessions and is never persisted to disk. It is discarded the moment each comparison ends.

When you delete the App from your device, all associated data — including images, projects, and results — is permanently removed by iOS. We retain no copies, backups, or records of your data anywhere.

10. Your Privacy Rights

Regardless of where you live, we believe everyone deserves strong privacy protections. Because Saccade collects no personal data on our end, many traditional privacy rights are satisfied by design:

  • Right to Know / Access: We have no personal data about you. All your data lives on your device and is directly accessible to you within the App.
  • Right to Deletion: You can delete any project within the App, or delete the App entirely to remove all data. We have nothing to delete on our end.
  • Right to Correction: Your data is on your device; you can modify or re-run any comparison session at any time.
  • Right to Data Portability: You can export your results as shareable cards directly from the App.
  • Right to Opt Out of Sale: We do not sell personal information. There is nothing to opt out of.
  • Right to Non-Discrimination: We do not and cannot discriminate based on the exercise of privacy rights, as we do not collect identifying information.

If you have any questions about your privacy rights or wish to make a request, please contact us at marc@marchoag.com.

11. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information.

11.1 Categories of Personal Information

Under the CCPA/CPRA, we are required to disclose the categories of personal information we collect. Saccade does not collect any personal information in any category, including but not limited to:

  • Identifiers (name, email, IP address, etc.)
  • Commercial information
  • Biometric information
  • Internet or network activity
  • Geolocation data
  • Sensory data (audio, visual, etc.)
  • Professional or employment information
  • Education information
  • Inferences drawn from any of the above
  • Sensitive personal information

11.2 Your CCPA/CPRA Rights

As a California resident, you have the right to:

  • Know what personal information is collected, used, shared, or sold — we collect none.
  • Delete personal information held by a business — we hold none.
  • Opt out of the sale or sharing of personal information — we do not sell or share any.
  • Correct inaccurate personal information — we hold none.
  • Limit the use and disclosure of sensitive personal information — we collect none.
  • Non-discrimination for exercising your rights.

11.3 Sale of Personal Information

Saccade does not sell personal information. We have not sold personal information in the preceding 12 months. We do not engage in targeted advertising, cross-context behavioral advertising, or profiling.

11.4 Shine the Light (California Civil Code § 1798.83)

California’s “Shine the Light” law permits California residents to request information about disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for direct marketing purposes.

12. Other U.S. State Privacy Rights

Several U.S. states have enacted comprehensive privacy legislation. While Saccade’s privacy-first design means we comply with these laws by default (since we collect no personal data), we acknowledge the following:

12.1 Virginia Consumer Data Protection Act (VCDPA)

Virginia residents have rights to access, correct, delete, and obtain a copy of personal data, as well as the right to opt out of targeted advertising, sale of personal data, and profiling. Saccade does not engage in any of these activities and collects no personal data.

12.2 Colorado Privacy Act (CPA)

Colorado residents have similar rights to access, correct, delete, and port personal data, and may opt out of targeted advertising, sale of personal data, and certain profiling. Saccade does not collect personal data and does not engage in any of these activities.

12.3 Connecticut Data Privacy Act (CTDPA)

Connecticut residents have rights to access, correct, delete, and obtain a copy of personal data, and may opt out of targeted advertising, sale of personal data, and profiling. Saccade does not collect personal data or engage in any of these activities.

12.4 Utah Consumer Privacy Act (UCPA)

Utah residents have rights to access and delete personal data and may opt out of the sale of personal data and targeted advertising. Saccade does not collect, sell, or use personal data for targeted advertising.

13. European & UK Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and the UK GDPR provide you with additional rights.

13.1 Legal Basis for Processing

Saccade performs only on-device processing and does not transmit personal data to us or any third party. To the extent that any on-device processing constitutes “processing” under the GDPR, our legal basis is:

  • Consent: You affirmatively grant camera access through iOS system permissions before any face tracking occurs.
  • Legitimate interest: On-device processing of gaze direction is necessary for the core functionality of the App you have chosen to use.

13.2 Your GDPR Rights

Under the GDPR, you have the right to:

  • Access your personal data — all data is on your device and accessible to you.
  • Rectification of inaccurate data — you control all data on your device.
  • Erasure (“right to be forgotten”) — delete projects or uninstall the App.
  • Restriction of processing — you can stop using the App at any time.
  • Data portability — export results from within the App.
  • Object to processing — you can revoke camera permissions or stop using the App.
  • Withdraw consent at any time by revoking camera permissions in iOS Settings.
  • Lodge a complaint with your local data protection authority.

13.3 Data Controller

For the purposes of the GDPR, the data controller is:

Marc Hoag
Saccade
Marin County, California, United States
marc@marchoag.com

13.4 Data Protection Officer

Given the nature of Saccade (no personal data collection, no backend processing), we have not appointed a Data Protection Officer. For all privacy inquiries, please contact us at marc@marchoag.com.

14. International Data Transfers

Saccade does not transfer data internationally — or at all. All data remains on your physical device. There are no servers, no cloud storage, and no cross-border data flows. Accordingly, no Standard Contractual Clauses, Binding Corporate Rules, or other transfer mechanisms are required.

15. Data Breach Notification

Because Saccade has no backend servers, no databases, and no cloud infrastructure, the risk of a data breach on our end is effectively zero — we have no data to breach.

Nevertheless, we commit to the following: in the unlikely event that we become aware of any security incident affecting the App or its distribution (for example, a compromise of the App binary), we will:

  • Investigate the incident promptly and thoroughly
  • Notify affected users through the App Store and our Website within 72 hours of confirming the incident
  • Provide clear information about the nature of the incident and any recommended protective actions
  • Cooperate with relevant data protection authorities as required by applicable law

16. Use of Artificial Intelligence

Saccade does not use artificial intelligence or machine learning. The App does not employ neural networks, large language models, predictive algorithms, or any form of AI-driven decision-making.

The App uses Apple’s ARKit framework for face tracking, which runs entirely on-device. ARKit is a system framework provided by Apple as part of iOS; it is not an AI or machine learning feature of the Saccade App itself. The gaze direction determination is based on a straightforward mathematical formula applied to blend shape values — not on trained models or probabilistic inference.

17. Do Not Track Signals

Some web browsers transmit “Do Not Track” (DNT) signals to websites. Because the Saccade Website does not track visitors in any way, we effectively honor DNT signals by default. There is no tracking to disable.

The Saccade App does not access or respond to DNT signals, as it does not perform any tracking whatsoever.

18. Biometric Data

This section addresses the important distinction between Saccade’s use of face tracking technology and the collection of biometric data.

18.1 What Saccade Does

Saccade uses Apple’s ARKit framework to read real-time blend shape values from the TrueDepth camera. These values are numerical coefficients (floating-point numbers between 0.0 and 1.0) that represent the current position of facial features, including eye direction. The App reads approximately 30 values per frame to determine whether you are looking at the top or bottom image on screen.

18.2 Why This Is NOT Biometric Data

Blend shape values as used by Saccade are not biometric identifiers under applicable privacy laws (including BIPA, CCPA/CPRA, GDPR, and other regulations) for the following reasons:

  • No identification capability: Blend shape values cannot be used to identify a specific individual. They represent the momentary position of facial features, not a unique biometric template or faceprint.
  • No storage: Values exist only in volatile memory during active use and are immediately discarded. Nothing is written to disk or transmitted.
  • No template creation: Saccade does not create, store, or compare facial geometry templates, faceprints, or any biometric identifier.
  • Transient and non-unique: The same person produces different blend shape values moment to moment depending on where they look. These values cannot distinguish one person from another.
  • No facial recognition: Saccade does not perform facial recognition, face matching, or identity verification of any kind.

18.3 Illinois Biometric Information Privacy Act (BIPA)

Under Illinois BIPA, a “biometric identifier” includes a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Saccade does not capture, collect, store, or disseminate any scan of face geometry. The blend shape values read by ARKit are transient directional indicators processed in real-time and immediately discarded — they do not constitute a scan of face geometry under BIPA.

19. Children’s Privacy

Saccade does not collect personal information from anyone, including children under the age of 13 (or under the age of 16 in the EEA/UK). Because the App collects no personal data, creates no accounts, and requires no registration, it does not knowingly collect information from children in violation of the Children’s Online Privacy Protection Act (COPPA), the UK Age Appropriate Design Code, or similar laws.

The App requires a device with a TrueDepth camera and uses no age-restricted content. If you are a parent or guardian and believe your child has somehow provided personal information to us, please contact us at marc@marchoag.com — though we are confident no such data exists on our end.

20. Third-Party Links

The Saccade Website may contain links to third-party websites or services (such as the Apple App Store, social media profiles, or external resources). We are not responsible for the privacy practices or content of these third-party sites. We encourage you to review the privacy policies of any third-party sites you visit.

The Saccade App does not contain third-party links, third-party SDKs, or embedded web content.

21. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will:

  • Post the updated Privacy Policy on our Website with a new “Effective Date”
  • Provide at least 30 days’ notice before material changes take effect
  • Update the Privacy Policy link within the App

Your continued use of the Service after the updated Privacy Policy becomes effective constitutes your acceptance of the changes. If you do not agree with the updated policy, you should discontinue use of the Service.

22. Contact