iOS app

Privacy Policy for iOS

Last updated: July 27, 2026

How CREATEAWITY.art collects, uses, and protects your information in the iOS app. It mirrors our main policy, with the differences that are specific to iOS — in-app purchases and device permissions — called out below.

1. Information We Collect

Account Information

When you register or sign in, we collect your name, email address, and authentication credentials. If you sign in via Google Sign-In, we receive your public Google profile information (name, email, profile picture) as permitted by your Google account settings.

Usage Data

We automatically collect information about how you interact with the app, including the AI services you use, images you process, prompts you create, and features you access. This helps us improve our services.

Payment Information — iOS

In-app purchases on iOS are processed entirely by Apple through the App Store and StoreKit. When you buy a credit pack, your payment method, billing details, and transaction are handled by Apple under Apple's own Privacy Policy — we never see or store your card details. We receive a signed transaction receipt from Apple, which we verify with Apple's servers to confirm your purchase and credit your account. We retain only the transaction identifier, product purchased, amount, and credit balance change necessary for billing records and support. This app does not use Razorpay or Google Play Billing — those apply to our web and Android platforms respectively.

Device & App Permissions

The app may request the following permissions, only at the point you use a feature that needs them. Camera — to take a new photo directly within the app for editing. Photo Library (Add Photos) — to save your edited or generated results back to your Photos app. Photo Library (Select Photos) — to choose an existing photo to edit; this uses Apple's limited, out-of-process photo picker, which does not give the app access to your full photo library, only the specific photos you select. Notifications — to send you updates about job completion, offers, or account activity, if you opt in. You can review or revoke any of these at any time in iOS Settings → CREATEAWITY.art.

Device & Technical Data

We collect device model, operating system version, app version, IP address, a device or installation identifier, and crash diagnostics, for security, analytics, debugging, and to ensure compatibility.

Push Notifications & Crash Reporting

The app uses Firebase Cloud Messaging to deliver push notifications and Firebase Crashlytics to collect crash reports and diagnostic logs if the app crashes, so we can fix bugs. Crash reports may include device information and a snapshot of app state at the time of the crash; they do not intentionally include your photos or prompt content.

2. How We Use Your Information

Service Delivery

We use your information to provide, maintain, and improve our AI image editing services, process your requests, and manage your account and purchases.

Communications

We may send transactional notifications (job completion, purchase confirmations, service updates) via push notification or email. You can opt out of non-essential notifications in iOS Settings or the app's Settings tab.

Security & Fraud Prevention

We analyse usage patterns to detect and prevent abuse, fraudulent purchases, and unauthorised account access.

Analytics & Improvement

We use Firebase Analytics to understand aggregated, anonymised app usage — which features are used, how often, and general engagement trends — so we can improve the app. This is in-app analytics, distinct from the cookie-based Google Analytics used on our website.

3. Your Images & Content

Ownership

You retain full ownership of all images you upload and outputs you generate. We do not claim any intellectual property rights over your content.

How We Store Your Images

Your uploaded inputs and generated outputs are stored on a secure content-delivery network so you can access them from your History and, if applicable, so your organization members can collaborate on shared work. Storage continues for as long as your account is active, unless you delete the image yourself from your History or your organization administrator deletes it on your team's behalf.

Processing by AI Providers

To generate or transform your image, your input image (if any) and prompt are sent to a trusted third-party AI service provider. Which provider serves a given request depends on the service you choose and our internal routing rules. Inputs are sent under each provider's data-processing terms and are not retained by them beyond the duration of the request, per their published API policies. A current list of named subprocessors is available on written request to our Grievance Officer (see Section 11).

No Training on Your Data

We do not use your uploaded images or generated outputs to train our or any third-party AI models.

Authorized Staff Access

Our authorized staff (Platform Administrators and Super Administrators) may access your uploaded and generated images when necessary for customer support, investigation of reported abuse or policy violations, diagnosing bugs you have reported, or complying with a valid legal request. Every such access is recorded in an internal audit log. You may request a report of any staff access to your data by contacting our Grievance Officer (see Section 11).

History

Your generation history is stored to provide the History feature. You can delete individual outputs or entire jobs from your History at any time.

4. Data Sharing & Third Parties

We Do Not Sell Your Data

We never sell, rent, or trade your personal information to third parties for their marketing purposes.

Categories of Subprocessors

We rely on a small number of trusted service providers: cloud infrastructure and a managed database, a content-delivery network for image storage, third-party AI providers for image generation and editing, an email-delivery provider, and Firebase (Google) for authentication, push notifications, crash reporting, and in-app analytics.

Payment Processor — Apple

Payments made through the iOS app are processed by Apple via the App Store and StoreKit. Apple's handling of your payment data is governed by Apple's Privacy Policy, not ours.

Full Subprocessor List on Request

A current and complete list of our named subprocessors is available on written request to our Grievance Officer (see Section 11).

Cross-Border Data Transfers

Some of our subprocessors process data outside India (primarily the United States and the European Union). For users in the EU or UK, these transfers rely on applicable safeguards such as Standard Contractual Clauses. For users in India, transfers comply with the Digital Personal Data Protection Act, 2023.

Legal Requirements

We may disclose information when required by law, court order, or to protect the rights, property, or safety of our users or the public.

5. Data Retention

Account Data

Retained while your account is active; up to 90 days after closure for billing reconciliation and abuse investigation, then anonymized or deleted.

Uploaded Inputs & Generated Outputs

Retained while your account is active, unless deleted by you or your organization administrator; deleted within 90 days of account closure.

Agent Conversations

Retained while active. You can archive or delete individual conversations at any time.

Transaction Records

Retained for 7 years as required by applicable financial and tax regulations. We never store your card details; those are held exclusively by Apple.

Crash Reports & Diagnostics

Retained per Firebase Crashlytics' standard retention (typically 90 days), then deleted.

Audit Logs

Retained for 3 years.

6. Security

Safeguards

We implement industry-standard security measures including HTTPS/TLS encryption in transit, secure credential storage (iOS Keychain on-device, encrypted storage server-side), access controls, and regular security reviews.

Breach Notification

In the event of a data breach affecting your personal information, we will notify you and the relevant authorities within the timeframes required by applicable law.

7. Your Rights

Access, Correction, Deletion & Portability

You have the right to access the personal information we hold about you, request corrections, request deletion of your account and data, request a portable export of your data, and opt out of non-essential communications. Contact us at support@createawity.art — we aim to respond within 7 business days, and process deletion requests within 30 days.

8. Children's Privacy

Age Requirement

Our app is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact our Grievance Officer (see Section 11) and we will delete it.

9. Organization Workspaces

Shared Workspace Data

If you use the app as part of an Organization workspace, your work within that workspace (generated images, prompts, Agent conversations attributed to the organization, and credits consumed from the organization's pool) is visible to your Organization Owner and Administrators. If you leave an organization, your prior organization-attributed work remains in the organization's records.

10. Changes to This Policy

Updates

We may update this Privacy Policy from time to time. We will notify you of material changes by email, push notification, or a prominent in-app notice at least 14 days before the change takes effect. Continued use of the app after changes constitutes acceptance of the updated policy.

11. Contact Us & Grievance Officer

Grievance Officer

For privacy concerns, data-access or deletion requests, complaints, or to exercise your rights under applicable data-protection law, contact our Grievance Officer at support@createawity.art.

Using CREATEAWITY.art on the web or Android?

Those platforms are covered by our main privacy policy, which also documents cookie preferences and the payment processors used outside iOS.

Read the main Privacy Policy

Have questions about your privacy?

Contact Us