Privacy Policy

Last updated: May 12, 2026

1. Who we are

Striply ("we", "our", "us") is an AI-powered journaling app for iOS that turns your day into a 4-panel comic strip starring you. This Privacy Policy explains what we collect, why, and the controls you have. We are the data controller for your account data.

2. Information we collect

  • Account data: your Apple ID identifier, email (if you choose to share), and display name. We do not store your Apple password.
  • Selfie: a single photo you upload at onboarding to become your comic-strip character. Used as a reference image for AI generation. You can replace or delete it any time in Profile → My Character.
  • Daily entries: the text (or voice transcript) you write describing your day. We process this to generate a comic script.
  • Generated comics: the panel images, script, narration, and video your account produces. Stored to your library.
  • Cast members: photos of family/friends you optionally add as supporting characters. Same controls as your own selfie.
  • Subscription state: entitlement status from RevenueCat / Apple. We do not see your card details.
  • Diagnostics: anonymous usage events and crash logs (you can opt out in Settings).

3. How we use your data

  • Generate your daily comics — script, panel illustrations, narration, music.
  • Maintain your character's visual consistency across comics.
  • Send transactional push notifications you've opted into (daily reminder, streak warnings, comic-ready alerts).
  • Enforce subscription entitlements and prevent abuse.
  • Improve generation quality and prompt safety.
  • Provide customer support when you contact us.

We do not sell your data, share it with advertisers, or train third-party AI models on your selfies, photos, or journal entries.

4. Sub-processors

  • Google (Gemini API) — script generation and comic panel image generation. Inputs are not stored by Google for training under our enterprise terms.
  • ElevenLabs — narration text-to-speech. Voice samples used only for synthesis, not retained for training.
  • OpenAI (Whisper) — voice-to-text transcription for spoken entries (used only when Apple's on-device STT is unavailable).
  • Cloudflare R2 — generated comic image and video storage.
  • RevenueCat — subscription receipt validation.
  • Apple (APNs) — push notification delivery.
  • Hetzner Cloud (EU) — application servers and database hosting.

5. Where your data is stored

Our primary database is hosted in the European Union (Hetzner, Germany). Image and video objects are stored on Cloudflare R2 (multi-region). AI generation occurs on Google Cloud and ElevenLabs servers (region varies). Your data may therefore be transferred outside your country of residence; where required, we rely on Standard Contractual Clauses.

6. How long we keep it

  • Account, selfies, comics, journal entries: kept while your account is active.
  • Generation input photos before processing: deleted within 24 hours after the comic is rendered.
  • Diagnostic events: 90 days, then aggregated.
  • Backups: encrypted database snapshots retained for 30 days.
  • Deleted accounts: erased within 30 days, except where law requires us to retain receipts.

7. Your rights (GDPR, UK GDPR, CCPA)

You can exercise the following rights at any time, directly inside the app under Profile → Privacy:

  • Access & portability: tap "Export my data" to receive a JSON archive with your comics, scripts, and account info.
  • Erasure ("right to be forgotten"): tap "Delete account" — your data is hard-deleted within 30 days.
  • Rectification: edit your profile, character photo, or cast entries directly in-app.
  • Object / restrict: contact us at the email below.
  • Lodge a complaint with your local supervisory authority.

8. Children

Striply is rated 12+ and is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with information, contact us and we will delete it.

9. Content safety

Generated comics pass through safety filters to block sexual, violent, or otherwise inappropriate output. Your journal entries are scanned by content moderation models before generation. Users who repeatedly attempt to bypass these filters may be suspended.

10. Security

Data in transit is encrypted with TLS 1.3. Database backups and stored images are encrypted at rest. Refresh tokens are stored as salted hashes. We follow OWASP top-10 mitigations and rotate secrets quarterly.

11. Changes

We may update this policy. Material changes will be announced in-app at least 14 days before they take effect.

12. Contact

Questions or rights requests: support@purifyos.app