Privacy Policy
This Privacy Policy explains how personal data is handled when you use ImageSetta, the ImageSetta website, or contact ImageSetta support.
ImageSetta is designed around data minimization and local processing. Images are processed locally on your device, and ImageSetta does not maintain a server-side library of the images you edit.
1. Data Controller and Contact
The data controller for the processing described in this Privacy Policy is:
Johan Andersson
Email: jaappshelp@outlook.com
You may use this email address for privacy questions, data-protection requests, or support concerning ImageSetta.
2. Images and Files
Images that you open, edit, straighten, resize, fit, convert, export, print, share, or otherwise process in ImageSetta are processed locally on your device.
ImageSetta does not upload your images to its backend for image processing or storage.
ImageSetta does not maintain a server-side image library.
When you choose an image from Photos, Files, or another source, ImageSetta accesses the content necessary to perform the action you requested.
If you export, print, save, or share a file to another application, service, device, cloud-storage provider, printer, or destination, that destination may process the file under its own terms and privacy practices.
That processing is outside ImageSetta's control.
3. Photo Library and Files Access
ImageSetta may request access to Photos or Files when needed for functionality that you choose to use.
These permissions allow you to select, process, save, or export content.
You can manage system permissions through iOS Settings.
Granting Photo Library or Files access does not cause your image library to be uploaded to ImageSetta's servers.
ImageSetta does not use access to your Photo Library to create a remote copy of your library or to profile the contents of your images.
4. Purchases and Entitlement Verification
ImageSetta may offer paid functionality through Apple's In-App Purchase system, including a one-time Lifetime purchase.
Apple processes the purchase itself.
ImageSetta may process Apple-provided transaction, app-transaction, or entitlement information where necessary to:
- verify whether a purchase is genuine;
- identify the ImageSetta product that was purchased;
- determine whether an entitlement is valid;
- restore or recognize a purchase;
- recognize an existing Lifetime entitlement;
- prevent duplicate, manipulated, invalid, revoked, refunded, or fraudulent entitlement claims;
- diagnose purchase, restoration, or verification problems;
- protect the integrity of ImageSetta's paid functionality.
Where necessary, Apple-provided signed transaction, application, or entitlement information may be sent to ImageSetta's verification service.
Information used for purchase verification may include:
- identifiers associated with the transaction or entitlement;
- product information;
- entitlement status;
- verification timestamps;
- information provided by Apple concerning refund or revocation status;
- limited technical information needed to investigate failed or suspicious verification attempts.
Signed Apple transaction or application information may be processed where necessary for verification.
Raw signed payloads are not used for advertising, behavioral profiling, or unrelated analytics and are not intended to be retained longer than reasonably necessary for verification, security, fraud prevention, dispute resolution, or compliance with legal obligations.
ImageSetta does not receive your complete payment-card details.
Payment processing is handled by Apple.
5. Backend Infrastructure
ImageSetta uses Cloudflare Workers and Cloudflare D1 for limited backend functions, including purchase and entitlement verification.
The ImageSetta backend is not used to store your ImageSetta image library.
Where required for verification, entitlement maintenance, security, or fraud prevention, limited backend records may include information such as:
- product or entitlement identifiers;
- transaction-related identifiers supplied by Apple;
- entitlement or verification status;
- verification timestamps;
- information indicating whether a transaction has been refunded or revoked where supplied by Apple;
- limited technical or integrity information necessary to investigate verification failures, fraudulent requests, or abuse.
Network infrastructure may also process ordinary technical request information such as:
- IP address;
- request time;
- protocol and request metadata;
- security-related information;
- information generated when a request fails;
- diagnostic information needed to operate and secure the service.
ImageSetta does not use this information to build advertising profiles.
ImageSetta does not combine backend verification information with your images for profiling or advertising purposes.
6. Technical Logs and Retention
ImageSetta does not use server logs as a long-term behavioral history of individual users.
Where Cloudflare Workers Logs are enabled, Cloudflare currently states that such logs are retained for a limited period.
At the time this Privacy Policy was last updated, Cloudflare's standard retention was generally up to three days for Workers Free and up to seven days for Workers Paid.
These periods are determined by Cloudflare and may change if Cloudflare changes its platform, plans, or retention practices.
ImageSetta does not represent those platform-specific periods as permanently fixed.
Technical information retained separately from ordinary Workers Logs is kept only where reasonably necessary for purposes such as:
- security;
- debugging;
- fraud prevention;
- purchase verification;
- service integrity;
- investigating technical failures;
- resolving disputes;
- establishing, exercising, or defending legal claims.
Entitlement records may be retained for as long as reasonably necessary to recognize, maintain, restore, secure, or verify the relevant Lifetime or other purchase entitlement.
Where an entitlement ceases to be valid, related information may continue to be retained for a reasonable period where necessary for:
- fraud prevention;
- accounting or transaction reconciliation;
- dispute resolution;
- security;
- compliance with legal obligations;
- establishment, exercise, or defense of legal claims.
ImageSetta does not intentionally keep ordinary technical request logs indefinitely.
7. Advertising, Analytics and Tracking
The current version of ImageSetta does not use third-party advertising SDKs or third-party analytics SDKs.
ImageSetta does not use your activity in the app to track you across applications or websites owned by other companies.
We do not sell personal data.
We do not build advertising profiles from the images that you process in ImageSetta.
We do not use your images for targeted advertising.
We do not use your images to train an advertising profile.
8. Support Communications
If you contact ImageSetta support, we may receive personal data that you voluntarily provide, such as:
- your name;
- your email address;
- the contents of your message;
- diagnostic information you choose to provide;
- screenshots or files you choose to attach;
- purchase or transaction information relevant to a support problem;
- information concerning your device, app version, or operating-system version where relevant to troubleshooting.
Please do not send:
- passwords;
- complete payment-card details;
- identification documents;
- health information;
- unrelated sensitive personal data;
- private images or documents that are unnecessary for resolving the support issue.
Closed support communications are normally retained for up to 24 months after the most recent communication.
They may be retained longer where reasonably necessary to:
- resolve an ongoing support matter;
- resolve a dispute;
- investigate fraud or abuse;
- establish, exercise, or defend legal claims;
- comply with a legal obligation.
9. Website Data
When you visit the ImageSetta website, the hosting, networking, or security providers used to deliver the site may process ordinary technical information necessary to provide and secure the website.
This may include information such as:
- IP address;
- browser information;
- device information;
- requested page;
- request time;
- protocol information;
- security-related request metadata.
ImageSetta does not use its website to create cross-site advertising profiles.
If the website later introduces functionality that materially changes the processing described in this Privacy Policy, this Privacy Policy will be updated where required by applicable law.
10. Legal Bases for Processing
Where the GDPR applies, personal data is processed only where an appropriate legal basis exists.
Performance of a Contract
Processing may be necessary to:
- provide functionality that you requested;
- verify a purchase;
- restore or recognize an entitlement;
- maintain access to paid functionality;
- provide functionality associated with a valid purchase;
- respond to certain support requests connected with your purchase or use of ImageSetta.
Legitimate Interests
Limited personal data may be processed where reasonably necessary for legitimate interests such as:
- operating ImageSetta;
- securing ImageSetta;
- protecting purchase-verification systems;
- preventing fraud;
- preventing abuse;
- diagnosing technical problems;
- responding to support communications;
- maintaining service integrity;
- protecting ImageSetta against malicious or forged requests;
- establishing, exercising, or defending legal claims.
Where legitimate interests are relied upon, those interests are considered against the rights, freedoms, and reasonable expectations of affected users.
Legal Obligations
Information may be processed or retained where required by applicable law or a legally binding request.
Consent or User Choice
Some processing occurs only because you choose to perform an action or grant a system permission, such as selecting an image or granting access to Photos.
You can manage system permissions through iOS Settings.
Revoking a permission may prevent the corresponding feature from functioning.
11. Service Providers
ImageSetta uses a limited number of service providers where necessary to operate the app and related services.
Apple
Apple operates the App Store and In-App Purchase infrastructure and provides transaction, app-transaction, and entitlement information used by ImageSetta.
Apple processes information under its own applicable privacy and service terms.
Apple also provides operating-system functionality used by ImageSetta, including services related to Photos, Files, sharing, printing, and StoreKit.
Cloudflare
Cloudflare provides infrastructure used for ImageSetta's limited backend functions, including Cloudflare Workers and Cloudflare D1.
Cloudflare may also provide networking, security, or website-related infrastructure.
Where Cloudflare processes personal data on behalf of ImageSetta, that processing is governed by the applicable contractual and data-protection arrangements between ImageSetta and Cloudflare.
Service providers are not authorized by ImageSetta to use data processed on ImageSetta's behalf for unrelated advertising or profiling merely because they provide infrastructure.
12. International Data Transfers
Some service providers operate internationally.
As a result, limited personal data may be processed outside Sweden, the European Economic Area, or your country of residence.
For transfers involving Cloudflare, Cloudflare currently states that it relies, where applicable, on mechanisms including the EU-U.S. Data Privacy Framework and the European Commission's Standard Contractual Clauses for transfers requiring contractual safeguards.
Where a Data Privacy Framework mechanism cannot lawfully be relied upon for a particular transfer, contractual safeguards such as applicable Standard Contractual Clauses may be used where required.
Supplementary or additional safeguards may also apply where required by applicable data-protection law.
The specific transfer mechanism applicable to particular processing can depend on:
- the recipient;
- processing location;
- relevant Cloudflare entity;
- applicable law;
- the legal status of the relevant transfer mechanism at that time.
13. Data Retention
ImageSetta keeps personal data only for as long as reasonably necessary for the purpose for which it is processed.
In particular:
- images processed locally are not retained on the ImageSetta backend;
- ordinary Cloudflare Workers Logs, where enabled, are subject to Cloudflare's platform retention practices described above;
- support communications are normally retained for up to 24 months after the most recent communication;
- entitlement information may be retained for as long as reasonably necessary to recognize, maintain, restore, secure, or verify the relevant purchase;
- security information may be retained for the period reasonably necessary to investigate or protect against the relevant security issue;
- diagnostic information is retained only for a period appropriate to the relevant troubleshooting purpose;
- fraud-prevention records may be retained where reasonably necessary to detect repeated fraudulent or manipulated entitlement claims;
- information may be retained longer where required by law or reasonably necessary for accounting, dispute resolution, fraud prevention, or legal claims.
When information is no longer required, it may be:
- deleted;
- anonymized;
- allowed to expire;
- otherwise removed in accordance with the relevant system's retention process.
14. Your Privacy Rights
Depending on where you live, you may have rights relating to your personal data.
Under the GDPR, these may include the right to:
- request access to personal data concerning you;
- request correction of inaccurate personal data;
- request deletion where the applicable legal requirements are met;
- request restriction of processing;
- object to certain processing based on legitimate interests;
- receive certain personal data in a portable format where the requirements for data portability are met;
- withdraw consent where processing relies on consent;
- lodge a complaint with a competent supervisory authority.
These rights are subject to the conditions, limitations, and exceptions provided by applicable law.
Because ImageSetta processes images locally and does not maintain a server-side image library, ImageSetta normally cannot retrieve or delete images stored only on your own device.
You control those files through your device and through any locations where you choose to save them.
To exercise a right concerning personal data held by ImageSetta, contact:
We may request enough information to:
- locate the relevant records;
- understand your request;
- protect personal information from unauthorized disclosure;
- verify that a request is legitimate where verification is reasonably necessary.
If you are located in the European Economic Area, you may also lodge a complaint with the competent data-protection supervisory authority.
In Sweden, the supervisory authority is Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection.
You may also have the right to complain to the supervisory authority in another EEA country where you live, work, or where an alleged infringement occurred.
15. Security
ImageSetta uses reasonable technical and organizational measures appropriate to the nature, amount, and sensitivity of the information processed.
These measures are intended to reduce risks such as:
- unauthorized access;
- unauthorized disclosure;
- misuse;
- alteration;
- loss;
- fraudulent entitlement manipulation;
- compromise of backend verification systems.
No computer system, network, storage service, or method of transmission can be guaranteed to be completely secure.
You remain responsible for protecting:
- your device;
- device passcode;
- Apple Account;
- backups;
- copies of files that you create or export;
- credentials for services to which you choose to export content.
16. Children
ImageSetta is not designed to:
- profile children;
- serve targeted advertising to children;
- create advertising profiles concerning children;
- maintain a server-side collection of children's photographs.
ImageSetta does not impose an artificial age threshold through this Privacy Policy solely because younger users may be capable of using image-processing functionality.
Where personal data relating to a child is processed and applicable law imposes additional protections, those protections apply.
If ImageSetta becomes aware of personal data being processed in a way that requires action under applicable child-privacy law, appropriate steps will be taken.
17. Legal Requests, Fraud and Abuse
Limited information may be preserved or disclosed where reasonably necessary to:
- comply with applicable law;
- respond to a valid and binding legal request;
- establish, exercise, or defend legal claims;
- investigate attempted fraud;
- investigate manipulation of purchase or entitlement verification;
- investigate deliberately falsified transaction information;
- protect ImageSetta's systems against abuse, attack, or malicious activity;
- protect the integrity of paid entitlements.
ImageSetta will not treat a legitimate privacy request, consumer complaint, refund request, or exercise of a statutory right as fraudulent merely because the user and developer disagree.
This section does not limit rights that cannot lawfully be restricted under applicable consumer or data-protection law.
18. Changes to this Privacy Policy
This Privacy Policy may be updated where ImageSetta, its infrastructure, service providers, legal obligations, or data-processing practices change.
This may include changes resulting from:
- new functionality;
- changes to backend infrastructure;
- changes to service providers;
- changes to Cloudflare's platform or retention practices;
- changes to Apple services;
- changes to applicable law.
If a change materially affects how personal data is handled, notice will be provided where required by applicable law.
The date at the beginning of this Privacy Policy identifies the current version.
19. Contact
For privacy questions, data-protection requests, or complaints concerning ImageSetta, contact:
Johan Andersson
Email: jaappshelp@outlook.com
The same email address may also be used for ImageSetta support.