Privacy Policy — Irida

Effective date: 28 August 2026 App: Irida (live & AI wallpapers) Developer / data controller: Kirill (independent developer), contact: [email protected]

1. Who we are

Irida is a mobile app that provides live, photo, and AI-generated wallpapers. This policy explains what data we handle and why. We designed Irida to be privacy-light: we do not ask for your name, email, phone number, or create an account.

2. What we collect

a) Device identifier. On first launch we generate a random token (a UUID) that identifies your installation so we can track your credit balance and unlocked content. It is not linked to your real identity. On our server we store only a one-way hash of this token, not the token itself.

b) Content you submit for AI features.

c) On-device preferences. Your chosen interests, language, favorites, and unlocked wallpapers are stored only on your device and are not sent to us.

d) Purchases (when available). If you buy credits or a subscription, the purchase is processed by Google Play Billing. We receive a purchase token to grant your entitlement — we never receive or store your card details.

e) Install attribution (Android). So we can tell which advertising campaign an install came from, the app uses Tenjin, a mobile measurement partner. Tenjin receives your device's Google Advertising ID (a resettable identifier you control in Android Settings → Privacy → Ads), together with basic install and app-version information, and the fact that a purchase of a given product occurred. It does not receive your prompts, your photos, your generated wallpapers, or any payment details. You can reset this identifier, or switch it off entirely, in your Android settings at any time; the app keeps working either way.

We do NOT collect: your name, email, phone, contacts, precise location, or biometric data. We do not use advertising SDKs and we show no ads. The only third-party measurement SDK in the app is the attribution partner named in (e) and §5.

3. AI processing & model training

Your prompts and photos are used only to generate the result you requested. We do not use your content to train our own AI models, and we do not sell it. Generation is performed by our processor fal.ai; we instruct them to process your content solely to return your result. See fal.ai's privacy policy for their handling.

4. How we use data

To provide the wallpapers and AI features, generate and deliver your results, manage your credit balance, prevent abuse/fraud, and comply with law. Where GDPR applies, our legal bases are performance of our service (to you) and legitimate interests (security and abuse prevention).

5. Who we share it with (processors)

We do not sell your data. We do not share your prompts, photos, or generated images with anyone for advertising. The advertising identifier described in §2(e) is shared only with our attribution partner, and only to measure where installs come from.

6. International transfers

Our backend is hosted in the United Kingdom (DigitalOcean, London). Our AI partner may process content on servers in other countries, including the United States. Where required, transfers rely on appropriate safeguards (such as the processors' standard contractual clauses).

7. Permissions we request

8. Data retention

Your device record and generation history are kept until you delete them (see §10) or your installation is inactive for 24 months, after which they are removed automatically. Input photos for stylization are not retained by us.

9. Children

Irida is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect data from children. If you believe a child provided us data, contact us and we will delete it.

10. Your rights & how to delete your data

You can delete all data tied to your device at any time, in the app: Settings → Legal → Delete my data. This immediately removes your device record, credit balance, premium status, and generation history from our server, and clears local data on your device.

You can also email [email protected] with the subject "Delete my data". We action email requests within 30 days. See also our Data deletion page.

Depending on your region (EEA/UK — GDPR, California — CCPA/CPRA), you may have additional rights (access, correction, portability, objection, and the right not to have personal information sold — which we do not do). Contact us to exercise them.

11. Security

Traffic between the app and our server is encrypted in transit (HTTPS/TLS). Your device token is stored in your device's secure keystore, and only a one-way hash of it is stored on our server. No method is 100% secure, but we use reasonable technical measures to protect your data.

12. Changes

We may update this policy; material changes will be reflected by a new effective date at this URL.

13. Contact

Kirill (independent developer) — [email protected]