ImageRecipe Privacy Policy

Effective date: September 21, 2026 · Last updated: September 21, 2026
Applies to the ImageRecipe (ImageFlow) Android application and to the ImageRecipe website.

In one sentence: your photos are processed only on your own device and are never uploaded — not by us, not by any third party. Network access exists for exactly two things: Google's ads in the free version, and verifying your Pro purchase. This page explains precisely what those two services can and cannot see.

1. Who we are (data controller)

This policy is issued by xiaoniubuniu, an individual developer and publisher of the ImageRecipe Android application ("the App", "we"). For the on-device functionality of the App we act as data controller under the EU General Data Protection Regulation (GDPR), the UK GDPR and comparable laws; "personal data" and "personal information" follow the GDPR/UK GDPR and the California Consumer Privacy Act as amended by the CPRA ("CCPA") definitions. For advertising and purchase data, Google acts as an independent controller / service provider under its own privacy terms (see the links in §3).

Contact us any time by email: xiaoniubuniu@gmail.com

2. What we do not collect, and what our SDKs do

By ourselves: we operate no servers and collect nothing directly — there is no account, no analytics or crash-reporting SDK, no email list. Your photos, their metadata, your workflows, your history and your settings never leave the device and are never visible to any advertising or billing component; the image-processing engine is pure local computation.

The App integrates two Google services, which process the following categories of data on our behalf or as independent controllers:

  • Google Mobile Ads (AdMob) — delivers ads in the free version and may process: the Android advertising ID (GAID/AAID), device model, OS and app version, IP-address-derived approximate location (country/city level), and ad/launch interactions (impressions, clicks). It can influence which ads you see; nothing from your gallery ever enters this pipeline. See Google Privacy Policy and How Google uses information from sites or apps that use its services.
  • Google Play Billing — handles the Pro purchase: Google processes your payment details; we receive only purchase confirmation (product, order/purchase identifiers) to unlock Pro and restore purchases.
  • If further ad networks or mediation partners are enabled, this policy will be updated with their names, data categories and opt-out links before release.

3. Device permissions

PermissionPurposeNotes
INTERNET Used solely by the two Google SDKs above: to fetch ads and to verify/restore the Pro purchase. The App transmits no image, filename, workflow or history content over the network. Nothing else in the App talks to the network.
Read photos
(READ_MEDIA_IMAGES;
READ_EXTERNAL_STORAGE on Android 12 and below)
Used only when you tap Repeat on a record in the History screen, to re-load the exact photos from that past run via the media URIs stored with the record. Requested lazily, after you explicitly trigger Repeat. Everyday image picking uses the system Photo Picker, which requires no permission at all. Declining this permission affects no other feature.

4. Legal basis (GDPR / UK GDPR)

For users in the EEA and UK:

  • Advertising (personalised ads and ad measurement) is shown only on the basis of consent (Art. 6(1)(a)), requested through Google's User Messaging Platform consent flow on first launch. Consent can be withdrawn or changed at any time in the App's settings and in Google's ad settings; declining consent still shows non-personalised ads.
  • Purchase verification relies on Art. 6(1)(b) (performance of the contract you enter by buying Pro).
  • On-device processing of your own photos is performed entirely for you, on your device, under your control.

Elsewhere, advertising is delivered on the basis of the legitimate interests of Google and of us in monetising the free version, subject to the opt-outs in §6.

5. International data transfers

App feature data (photos, workflows, history) never leaves the device, so it is never transferred. Advertising and purchase data processed by Google may be transferred to and processed in the United States and other countries, under Google's safeguards — the EU-U.S. Data Privacy Framework, Standard Contractual Clauses and the UK Extension — as described in Google's privacy terms.

6. Your rights and privacy controls

  • Access, rectification, erasure, portability, objection (GDPR/UK GDPR) — email us. Because we hold no server-side profile of you, we can only confirm the categories in §3; data we genuinely cannot link to you is also data we cannot disclose.
  • Delete local data — remove entries in the App, or uninstall it, which erases the App's private database immediately.
  • Opt out of personalised advertising — turn on "Opt out of Ads Personalization" or reset the advertising ID under Android Settings → Google → Ads, or at myadcenter.google.com; EEA/UK users can also change consent in the App's settings. Buying Pro removes all ads.
  • CCPA/CPRA (California) — we do not sell personal information for money. Under the CPRA, disclosure of the advertising ID to ad partners for cross-context behavioural advertising may qualify as "sharing"; you have the right to opt out, which the controls in the bullet above exercise, and we do not discriminate in price or service against you for doing so. The App does not knowingly "sell or share" personal information of consumers under 16.
  • Global Privacy Control / Do Not Track — this website runs no scripts and honours the absence of tracking by design; in the App, the ad personalisation toggle above is the equivalent control.

We respond to and fulfil valid requests within 30 days.

7. What is stored locally, and for how long

  • Output images: processed results are saved to the Pictures/ImageFlow folder on your device, fully under your control;
  • App database: workflows, run history (including the media URIs referenced in §3) and preferences are kept in the app's private on-device database, which other apps cannot read;
  • Original photos: processing only ever reads your originals; it never modifies or deletes them.

Retention. Local data is retained until you delete it or uninstall the App. Advertising and purchase logs are retained by Google under its own retention practices. If you enabled Android's OS-level backup (the App allows allowBackup), your device vendor's backup service may store a copy of the app database in your personal cloud backup; that processing is governed by your OS vendor's privacy terms.

8. Cookies and similar technologies

This website is fully static. It sets no cookies, uses no local-storage scripts, no tracking pixels, no fingerprinting and no third-party requests (no web fonts, CDNs or analytics are loaded — all assets are self-hosted). Tracking technologies therefore appear only inside the App, via the Google SDKs described in §2.

9. Children's privacy

The App is a general-purpose utility, is not directed at children, and its ads are not configured for child-directed targeting. It collects no personal information from anyone under 13 as required by the U.S. COPPA. In the EU/UK, in line with GDPR Article 8, users under 14 (or the applicable local threshold, up to 16) should use the App only under parental guidance. Teen accounts on Google Play receive age-appropriate ad settings enforced by Google.

10. Changes to this policy

If this policy changes, this page will be updated and the dates above revised; material changes (for example new SDKs or ad partners) will also be announced in the app's release notes.

11. Contact and data deletion requests

To exercise any right or ask any privacy question, contact the developer at xiaoniubuniu@gmail.com. Per Google Play's Data Deletion policy: uninstalling the App erases all app-held data; sideloaded installs and Pro purchase records can additionally be cleared by emailing the same address (purchases are managed by Google and refundable/cancellable through your Google Play account).