IslandWidgetStudio Privacy Policy
IslandWidgetStudio (“the app,” “we,” “us”) is an AI-powered iOS personalization studio. This policy explains what information we process, why we use it, and who processes generation requests.
1. Information We Process
- Account information: The user identifier provided by Sign in with Apple and, if you choose to share them, your name and possibly relayed email address. We do not receive your Apple ID password.
- Generation input and results: The text prompt, style, and material type you choose, plus generated wallpapers, widgets, and Dynamic Island materials.
- App data: Favorites, generation task records, subscription status, and quota.
- Operational information: Request time, task status, error codes, and—after notification permission—the device push token used for generation-complete notices.
- On-device data: Applied materials and thumbnail caches remain in the App Group container and are not uploaded merely because you use those local features.
2. Purposes
We use this information to sign you in and sync your account, generate and save materials, provide the catalog and personalized recommendations, manage subscriptions and quota, send necessary service notices, troubleshoot failures, and moderate prompts and results to block prohibited content. We do not sell your personal information.
3. AI Data Sharing and Current Processors
When you start a generation request, we process the prompt, selected style, and material type you provide. They first go to NewAPI, our self-hosted gateway at https://newapi.zweiteng.tk, and are then routed through our self-hosted CLIProxyAPI protocol adapter and Gemini Balance Google request adapter.
The external AI processors that may currently receive that generation input are:
- OpenAI — currently used for text planning with
gpt-5.6-luna/gpt-5.6-terraand image generation withgpt-image-2. - Google LLC — currently used for image safety review with
gemini-3.5-flash; it can also serve as a conditional text fallback when the OpenAI text route is unavailable. Google requests normally use the Google AI API; an enabled conditional route may also use Google Cloud Vertex AI.
We do not include your Sign in with Apple name, email, or payment-card details in the AI generation input sent to OpenAI or Google. Before you consent to enable AI generation, your prompt, style, and material type are not sent to those AI processors. You can turn sharing off anytime in App Settings → AI Data Sharing; new generation requests stop while it is off.
We do not make unsupported promises about an external processor’s exact retention period or model-training practices. Each processor handles received data under its own terms:
- OpenAI: Privacy Policy · Data Processing Addendum · Sub-processor List
- Google: Privacy Policy · Gemini API Additional Terms · Google APIs Terms of Service
- Configured Vertex AI conditional route: Google Cloud Data Processing Addendum · Subprocessors
If we change a processor or route that can receive user generation input, we will update this section and the in-app consent disclosure before the new route is used. Where renewed consent is required, no input will be sent until consent is obtained.
4. Data Storage and Security
Account records, generation tasks, favorites, and generated materials are stored in Supabase cloud database and object storage and transferred over TLS. Server-side row-level security isolates data by user; generated materials are visible only to their owning account by default and are not publicly listed.
5. Subscriptions and Purchases
Subscriptions are processed through Apple StoreKit 2 and RevenueCat. Apple and RevenueCat manage purchase receipts and subscription status; we do not handle your payment-card details.
6. Content Safety
We review prompts and generated results for content safety. Requests assessed as unlawful, infringing, sexual, violent, hateful, or harassing may be rejected. Related task status and moderation results are used to protect the service.
7. Push Notifications
If you allow notifications, we use Apple Push Notification service (APNs) for service notices such as generation completion. You can disable notifications anytime in iOS Settings.
8. Retention and Deletion
Account and cloud data are retained while needed to provide the service. You can request deletion in App Settings → Delete Account; the server deletes the account and associated generation tasks, favorites, and materials. Uninstalling the app removes its device caches.
9. Other Services
- Supabase — authentication, database, and material storage
- RevenueCat / Apple StoreKit 2 — subscription and purchase management
- Sign in with Apple / APNs — sign-in and push notifications
10. Children’s Privacy
The app is not directed to children under 13, and we do not knowingly collect their personal information.
11. Policy Changes
We may update this policy. We will provide in-app notice of material changes. A new AI recipient or purpose follows the before-use update and consent rule in Section 3.
12. Contact Us
For privacy questions, contact: support@sanva.tk
For questions about this document, contact support@sanva.tk.