THESIS: Zup begins with the blank-caption problem and proves its photo-to-caption workflow immediately; cross-posting is the finish, not the headline. OWN-WORLD: Porcelain editorial fields alternate with graphite proof stages; gold marks the brand while real iPhone captures carry every product claim. STORY: Choose photos, receive a voice-matched caption, tune it, preview each destination, then post only when ready. FIRST VIEWPORT: A large caption-first promise and App Store action sit beside one live iPhone screen with a tactile twelve-screen reel. FORM: Device-as-stage, established Zup marketing world, seed e65ccae8. FINISH: unreviewed and undocumented is unfinished; this build ends with the finish review, the verdict, DESIGN.md, and every shipping raster carrying its provenance.
Zup

Privacy policy

Effective August 11, 2026

Zup is an iPhone app that turns photos you choose into captions and share-ready posts. For posts you create yourself, you select photos with Apple’s system photo picker and Zup does not need access to the rest of your library. Venue context is off by default and can be turned on under Your Voice → Personalization. When it is on and a selected photo contains GPS metadata available through that selection, Zup combines Apple’s reverse-geocoding and nearby-place services with a live venue search. To identify a company, office, campus, or other venue that Apple does not list, Zup’s App Attest-protected service may transiently send the exact coordinates, reverse-geocoded address, and country code to Bright Data for a live Google place search. The selected photo and caption are not sent to Bright Data for this lookup. When Venue context is off, Zup does not start venue searches and excludes saved venue labels from caption prompts. Zup does not show a separate location confirmation, and neither Zup nor its database persists the raw coordinates or search response. Only a specifically resolved venue label may be saved with a favorite and supplied to the activated caption provider; a city or region alone is not supplied as caption context when no venue can be verified. The optional Daily suggestions feature is the only part of Zup that requests access to photos you allow so it can find pictures taken today.

Privacy-friendly app analytics

Zup uses Apple App Store Connect analytics and TelemetryDeck to understand aggregate product use, such as whether onboarding was completed, how many photos were selected, which destination was chosen, whether caption generation or publishing succeeded, and which app version or device type was involved. TelemetryDeck receives a one-way anonymized identifier for this app installation, an event name, a timestamp rounded to the nearest hour, ordinary app and device metadata, and the limited non-content properties needed to group that event. TelemetryDeck does not store IP addresses.

Zup does not send selected photos, captions, photo-edit instructions, names, mentions, email addresses, social-account identifiers, access tokens, or raw error messages to analytics. Analytics data is not used for advertising, is not combined with data from other companies to track you across apps or websites, and is not linked by Zup to your identity. Learn more in TelemetryDeck’s privacy documentation.

On-device processing

Zup performs private photo analysis on-device for features such as Daily suggestions and the optional profile reference. Apple’s on-device Foundation Model remains available for the separately configured Daily suggestion flow, while Generate uses the hosted model you selected and activated. Data used only by an on-device model stays on your iPhone.

Optional Daily suggestions

Daily suggestions is off until you choose to set it up. Zup explains the feature before asking for Apple Photos permission, and you may give access to selected photos or your full library using Apple’s system control. When enabled, Zup checks photo creation dates on your iPhone when you open the app, considers only photos available to Zup that were taken today, skips screenshots, and prepares no more than three suggestions with up to four photos each. Zup does not continuously scan your library or run this check in the background.

You review each suggestion before keeping it. Swiping left dismisses only Zup’s suggestion and never deletes, edits, or hides the original photo in Apple Photos. Swiping right saves the proposed post and protected copies of its photos to Zup Favorites on this iPhone. Closing the review without swiping leaves the suggestion available for a later review. Creating or saving a suggestion does not publish it to any social network.

Zup first tries to create Daily suggestion captions on-device. If on-device captioning is unavailable, Zup may use Mistral automatically only after you separately grant the current automatic hosted-caption permission for Daily suggestions. Before you enable that option, Zup identifies Mistral and the service that relays each request, explains that resized copies of today’s candidate photos and the same caption context described below may be sent automatically when Zup opens, and asks for explicit permission. Zup may then make up to four sequential requests for the same suggestion to prepare platform-specific drafts in this order: X, Instagram, TikTok, then LinkedIn. Daily automatic use is recorded and checked separately in addition to the normal Mistral hosted-caption permission. Enabling Daily automatic use also allows Mistral for hosted captions on manually created posts; turning off Daily automatic use leaves the manual permission unchanged. Neither OpenRouter nor TokenRouter is silently switched to Mistral.

You can turn off Daily suggestions or automatic hosted captions under Your Voice. You can also limit or revoke Zup’s Photos access at any time in iOS Settings. Turning either option off prevents future Daily suggestion access or hosted requests but cannot retract a request already delivered.

Optional hosted captions with OpenRouter, TokenRouter, or Mistral

TokenRouter’s Google Gemini 3.7 Flash is the default for Generate, with OpenRouter vision and Mistral available as alternatives under Your Voice → Hosted intelligence. TokenRouter shows its current compatible vision-caption models in a dropdown, including GPT-5.4 Image 2 and other models available through TokenRouter. OpenRouter offers a choice among Google Gemini 3.5 Flash, Google Gemini 3.7 Flash, and the Ox Alpha preview model. Selecting a provider or model does not upload anything. Before the first request to a hosted model, Zup identifies that model, explains what will be shared and why, and asks for explicit model-specific photo-sharing permission. Once you activate a provider and model, Generate uses only that selection. Daily suggestions retain the separately permissioned on-device/Mistral flow described above.

Every hosted provider may receive resized copies of up to twelve photos selected for the post; text from the post editor, details you enter for LinkedIn Professional Writer, and any follow-up answer you enter; the destination platform and caption preferences; a specifically resolved venue or point-of-interest label derived from available photo GPS metadata when Venue context is on, but not the raw coordinates; verified brand handles matched from original-photo evidence; an optional text hint that you may appear in particular selected photos; the structured voice fingerprint for the destination; and up to six captions you previously copied, shared, or successfully published, with @mentions and hashtags replaced. Other text in those saved examples is sent so the model can match your writing style. When Zup prepares four Daily suggestion drafts through Mistral, the selected photos and applicable context may be included in each sequential request, with the destination platform changing for each request. Zup never sends your entire photo library or your profile reference photo.

For OpenRouter, the request is relayed through Zup’s Vercel-hosted, Apple App Attest-protected service to OpenRouter, which routes it to the provider serving the model you selected. Zup requests providers that deny data collection for the Gemini models. Ox Alpha is an optional preview from an anonymous provider that retains prompts and completions but states that it does not use them for training. Zup’s relay validates and forwards the request without writing selected photos, the prompt, or the generated caption to its database. OpenRouter retains request metadata, and downstream handling remains subject to the selected model provider’s policy. See OpenRouter’s Ox Alpha page, OpenRouter’s privacy policy, and provider logging documentation.

For TokenRouter, the request is relayed through Zup’s Vercel-hosted, Apple App Attest-protected service to TokenRouter, which routes it to the provider serving the vision model you selected solely to generate the caption you requested. Zup shows the selected model name, checks it against TokenRouter’s current catalog and supports only models compatible with Zup’s photo-caption flow. Zup’s relay validates and forwards the request without writing the selected photos, prompt, or generated caption to its database. TokenRouter and the selected model provider process the request under their applicable terms and data practices. See TokenRouter’s privacy policy.

For Mistral, the request is relayed through the same protected Zup service directly to Mistral AI. Mistral’s current API policy states that API inputs and outputs are not used for model training. Mistral may retain API inputs and outputs for up to 30 days for abuse monitoring unless zero data retention is enabled, and may retain information longer when legally required. Mistral processes this information under its commercial terms, data-processing terms, and privacy policy.

Your provider- and model-specific permission choices are saved on your iPhone. Zup remembers each model you approve, so switching back to a previously approved model does not ask again. You can turn off future OpenRouter, TokenRouter, or Mistral sharing separately under Your Voice → Hosted intelligence. Turning off a provider prevents future requests to that provider but cannot retract a request already delivered. Zup asks again before first using a newly selected model or when the recipient, purpose, categories of shared data, or permission terms change.

Optional social voice matching

Instagram style matching is optional. If you turn it on under Your Voice and provide a public Instagram username, Zup’s protected service validates and sends that username to Bright Data, which retrieves recent public posts from the selected account. Zup’s configured hosted AI provider transiently analyzes the post text to derive an aggregate voice profile covering tone, diction, sentence rhythm, openings, formatting, and structure. Zup does not send your selected photos, draft caption, personal direction, profile reference, voice fingerprint, or saved caption examples to Bright Data. Source posts are not returned to your iPhone or saved in Zup’s database, and the analysis is instructed not to quote them or copy their facts. Zup saves only the entered username, aggregate style profile, and refresh metadata so later Instagram captions can use the learned voice immediately. Providing another username replaces that saved profile.

Optional Zup AI photo editing

Photo editing is separate from caption generation. Before the first AI photo edit, Zup asks whether it may send a resized copy of the selected photo and the edit request you typed. If you allow it, Zup saves that choice on your iPhone so it does not ask again for later edits. Zup relays only that copy and request through its Apple App Attest-protected service to xAI’s Grok Imagine Image model to create the edit. Zup’s relay does not write the submitted photo, request, or returned image to its database. The returned image becomes a reversible working copy in Zup; the original Photos-library asset remains untouched, and you can undo the edit or restore the original before sharing.

xAI states that API inputs and outputs are not used to train its models without explicit permission and are ordinarily retained for up to 30 days for abuse and misuse monitoring unless zero-data-retention terms apply. xAI processes the request under its applicable terms and data practices. See xAI’s API security guidance.

Sharing and social accounts

Caption generation creates drafts only and never publishes them. X, Instagram, Facebook Pages, LinkedIn, and TikTok offer direct publishing after you connect a supported account and explicitly confirm the final post in Zup. Instagram direct publishing is available only for supported professional accounts: Feed sends all selected photos and the reviewed caption. The optional native Instagram handoff opens Instagram’s own available destination choices with the photo currently in view and places the reviewed caption on the short-lived iOS pasteboard for the user to paste before publishing or sending. Personal Instagram accounts can use this native handoff or Apple’s share sheet. Facebook direct publishing is available only for Pages the connected person manages and cannot publish to personal profiles. TikTok also lets you explicitly send the reviewed content to your TikTok inbox as a draft and retains an optional native Share Kit fallback. WhatsApp uses a native share handoff because its business API does not publish a person’s Status or operate their personal chats. The applicable selected content is sent through Zup’s protected publishing service only to the direct-publishing network you chose. Zup never receives your social account password and never publishes in the background or without your final confirmation.

Instagram’s native handoff and TikTok’s Share Kit fallback require a Photos-library asset identifier. If a camera capture, edited image, or restored Zup post does not have one, Zup asks for add-only Photos permission and saves the prepared image as a new photo so the selected app can receive the version you chose to share. Zup remembers that prepared photo for later retries and does not edit or delete existing photos in your library.

Connected social accounts

When you connect X, Instagram, Facebook Pages, LinkedIn, or TikTok, Zup stores the account or selected Page identifiers and display names needed to show connection status, along with the OAuth access tokens and any refresh token returned by that network. If your Facebook account manages more than one eligible Page, Zup temporarily stores the available Page names, identifiers, and Page access tokens as one encrypted selection record for no more than ten minutes while you choose all Pages or a checked subset. Only the chosen Page credentials move into the encrypted connection record; unselected credentials are deleted with the temporary selection record. Access and refresh tokens are encrypted at rest with AES-GCM on Zup’s server and are used only to maintain the connection or carry out a publish action you confirm. Zup keeps the chosen connection record until you disconnect the account in Zup or ask Zup to delete it. Disconnecting or completing a verified deletion request deletes the stored connection record and encrypted tokens; for TikTok, Zup also asks TikTok to revoke the access token.

Zup may identify likely people or organization names in your caption on your iPhone. Zup does not guess which X account belongs to a suggested name. Only after you tap a suggestion or Find does Zup send that name to X through its protected service and show possible search results. No result is selected by default, and no handle is added to your caption unless you choose the exact account and confirm it.

After you connect X or a supported Instagram Creator or Business account, Zup automatically and transiently retrieves up to ten recent posts or captions authored by that account. When LinkedIn grants the required member-post permission, the same automatic import applies there; otherwise the LinkedIn connection and publishing features continue to work without it. Zup’s service does not save the retrieved text. The posts are analyzed on-device, the raw text is discarded after analysis, and only a structured writing fingerprint for that destination is saved on your iPhone. Facebook and TikTok connections do not currently expose recent writing to this import. For every destination, captions you copy, share, or successfully publish through Zup are stored locally as approved examples and can build the destination’s fingerprint after five examples.

During a confirmed X or LinkedIn publish, Zup’s service transiently processes the selected photos and caption without saving them in its hosted database. Instagram and TikTok require their services to fetch images from public URLs. For Instagram, Zup stores compressed copies behind long, unguessable URLs only while Meta creates the media containers, deletes them after the confirmed publish succeeds or fails, and makes interrupted copies expire within one hour. For TikTok, those URLs expire within 24 hours and are normally deleted earlier when TikTok reports a completed post, inbox delivery, or failure. Zup sends only the confirmed caption when the chosen destination accepts one, temporary photo URLs, and provider-required publishing settings to the selected network. Resulting posts and drafts are stored by that network under its terms and privacy practices; deleting a Zup connection does not delete content already delivered there.

Profile reference

Your optional profile reference photo stays protected on your iPhone. Face comparison happens on-device. The reference photo is never uploaded by Zup.

Security and service records

Zup assigns a random installation identifier and stores an App Attest public key, request counter, and one-way credential hash to verify genuine app requests, prevent replay, and limit abuse. These records are not used for advertising or cross-app tracking. Zup’s hosting infrastructure may process ordinary network metadata such as an IP address, timestamp, and request status for security and service operation.

Local preferences

Your voice settings, social voice-matching preference, per-platform structured voice fingerprints, favorites and their resolved photo-location labels, profile reference, Daily suggestions settings and dismissed-photo identifiers, provider-specific OpenRouter, TokenRouter, and Mistral permission choices, AI photo-edit permission, and captions you copy, share, or successfully publish for local voice memory are stored on your iPhone. Zup automatically uses verified brand evidence from selected photos when a matching handle is available and automatically learns from those approved caption actions. Raw photo coordinates are not stored by Zup. You can remove favorites, remove the profile reference, turn off Instagram style matching, Daily suggestions, or future hosted sharing, or disconnect X, Instagram, Facebook, LinkedIn, or TikTok at any time. Deleting Zup removes its locally stored voice memory and every writing fingerprint. Removing a favorite deletes Zup’s saved copies of its photos and their resolved location labels but does not delete the original from Apple Photos.

Protection, retention, and deletion

Zup requires service providers that process user data to protect it consistently with this policy and applicable privacy requirements. Zup retains the security records described above for as long as needed to protect its hosted services and retains each encrypted social connection until it is disconnected or deleted on request. Instagram’s temporary photo URLs stop working within one hour; TikTok’s stop working within 24 hours. Their copies are normally deleted earlier when the provider reports a terminal status. Deleting the app removes local preferences and content but does not by itself notify Zup to delete a hosted connection. Disconnect X, Instagram, Facebook, LinkedIn, and TikTok before uninstalling, revoke Zup in the network’s connected-app settings, or send a deletion request using the address below.

Contact

Questions, consent requests, and deletion requests can be sent to privacy@samkarri.com. General product help is available from Zup support.

Back to Zup