1. Introduction
Welcome to iOS Wallpapers, operated by Creativebilly (“we,” “us,” or “our”). We operate the website ioswallpapers.pro (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services, including browsing wallpapers, generating AI wallpapers, and making purchases.
This policy is designed to comply with applicable data protection laws worldwide, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), Brazil's Lei Geral de Proteção de Dados (LGPD), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Australia's Privacy Act 1988.
2. Data Controller
For the purposes of the GDPR and other applicable data protection laws, the data controller responsible for your personal data is:
Creativebilly
Email: hello@ioswallpapers.pro
3. Information We Collect
3.1 Information You Provide
- Payment Information: When you purchase wallpapers or use paid features, payment is processed securely through Stripe. We do not store your credit card details on our servers. Stripe acts as an independent data controller for payment data.
- AI Generation Prompts: Text prompts you submit to our AI wallpaper generator may be stored to improve service quality and prevent abuse.
3.2 Information Collected Automatically
- Device Fingerprint: To enforce free-tier usage limits and prevent abuse, we generate a hashed device identifier from browser signals (screen dimensions, timezone, language, hardware concurrency, canvas rendering, and WebGL renderer). This hash is combined with your IP address on our server and stored as a one-way hash — we cannot reverse it to identify you personally. The fingerprint is used solely for usage tracking and is not shared with third parties.
- Usage Analytics: We use Umami, a privacy-focused analytics tool, to collect anonymous usage data such as page views, referral sources, and device type. Umami does not use cookies and does not collect personally identifiable information.
- Log Data: Our servers and hosting provider (Netlify) may automatically record information such as your IP address, browser type, operating system, and the pages you visit. IP addresses are anonymized where required by law.
- Local Storage: We use your browser's localStorage to save your theme preference (light/dark mode). This data stays on your device and is not transmitted to our servers.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases:
- Contract Performance: Processing necessary to fulfill purchases and deliver our services to you (Art. 6(1)(b) GDPR).
- Legitimate Interests: Processing for analytics, fraud prevention, and service improvement, where our interests do not override your fundamental rights (Art. 6(1)(f) GDPR).
- Consent: Where you have given explicit consent, such as for personalized advertising via third-party cookies (Art. 6(1)(a) GDPR). You may withdraw consent at any time.
- Legal Obligation: Processing required to comply with applicable laws (Art. 6(1)(c) GDPR).
5. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain our website and services
- Process transactions and send related information (receipts, confirmations)
- Generate AI wallpapers based on your prompts
- Improve and personalize your experience
- Monitor and analyze usage trends to enhance our Service
- Detect, prevent, and address technical issues or abuse
- Comply with legal obligations
6. Third-Party Services
We use the following third-party services that may process your data. Where these services transfer data outside the EEA, appropriate safeguards (such as Standard Contractual Clauses) are in place:
- Stripe: For secure payment processing. Stripe acts as an independent data controller and may collect your IP address, browser information, and device identifiers for fraud prevention in addition to payment details. Stripe's privacy policy is available at stripe.com/privacy.
- Supabase: For data storage, backend services, and serverless edge functions. Supabase's privacy policy is available at supabase.com/privacy.
- OpenAI: For standard AI wallpaper generation. Your text prompts are sent to OpenAI's API to generate images. OpenAI's privacy policy is available at openai.com/privacy.
- Google Gemini: For premium (“Beast Mode”) AI wallpaper generation. When you use Beast Mode, your text prompts are sent to Google's Gemini API. Google's privacy policy is available at policies.google.com/privacy.
- Google AdSense: For displaying advertisements. Google may use cookies and tracking technologies. Google's advertising privacy policy is available at policies.google.com/technologies/ads.
- Netlify: For website hosting and serverless functions. Netlify may process request data including IP addresses. Netlify's privacy policy is available at netlify.com/privacy.
- Cloudflare: For content delivery (CDN) and performance optimization. Cloudflare's privacy policy is available at cloudflare.com/privacypolicy.
- Discord: We may send generation event data (prompt text, wallpaper category, and generation mode) to a private Discord channel via webhook for operational monitoring. No personally identifiable information is included. Discord's privacy policy is available at discord.com/privacy.
- Umami Analytics: For privacy-focused, cookie-free website analytics. Umami does not collect personally identifiable information.
7. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from your jurisdiction. When we transfer personal data outside the EEA, UK, or Switzerland, we ensure appropriate safeguards are in place, including:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Agreements (IDTAs) where applicable
- Adequacy decisions by relevant data protection authorities
- Other legally recognized transfer mechanisms
8. Cookies, Local Storage & Device Fingerprinting
Our website does not set first-party cookies for tracking purposes. We use the following client-side technologies:
- localStorage: Used solely to store your theme preference (light/dark mode). This data remains on your device.
- Device Fingerprinting: We collect browser signals (screen size, timezone, language, canvas rendering, WebGL renderer) and hash them with your IP address to create an anonymous device identifier. This is used exclusively to enforce free-tier usage limits (3 free AI generations per device). Under the EU ePrivacy Directive, device fingerprinting is treated similarly to cookies; our legal basis for this processing is legitimate interest in preventing abuse (Art. 6(1)(f) GDPR).
- Third-Party Cookies: Google AdSense may use cookies to serve personalized ads. In accordance with the EU ePrivacy Directive and similar laws, we will obtain your consent before non-essential cookies are placed on your device.
You can manage cookie preferences through your browser settings or visit aboutads.info/choices or youronlinechoices.eu to opt out of personalized advertising.
9. Data Security
We implement appropriate technical and organizational security measures to protect your information, including encryption in transit (TLS/SSL) and at rest where applicable. However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.
10. Data Retention
We retain your information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:
- Transaction records: Retained for the period required by applicable tax and financial regulations.
- AI prompts: Retained for up to 12 months for abuse prevention, then deleted or anonymized.
- Device fingerprint hashes: Retained for the duration needed to enforce usage limits. These are one-way hashes and cannot be used to identify you.
- Analytics data: Anonymized and may be retained indefinitely.
11. Your Rights
Depending on your location, you have specific rights under applicable data protection laws:
11.1 Rights Under the GDPR (EEA, UK, Switzerland)
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data (“right to be forgotten”).
- Right to Restriction: Request that we restrict processing of your data.
- Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
- Right to Lodge a Complaint: File a complaint with your local data protection authority (e.g., the ICO in the UK, CNIL in France, or the relevant supervisory authority in your EU member state).
11.2 Rights Under the CCPA / CPRA (California, USA)
If you are a California resident, you have the right to:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to Delete: Request deletion of your personal information.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not sell your personal information. If this changes, we will provide a “Do Not Sell or Share My Personal Information” link.
- Right to Non-Discrimination: You will not be discriminated against for exercising your privacy rights.
11.3 Rights Under the LGPD (Brazil)
If you are located in Brazil, you have the right to:
- Confirmation of the existence of processing
- Access to your data
- Correction of incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion of unnecessary or excessive data
- Data portability
- Information about public and private entities with which your data is shared
- Revocation of consent
11.4 Rights Under PIPEDA (Canada)
If you are located in Canada, you have the right to access your personal information, challenge its accuracy, and withdraw consent for its collection, use, or disclosure, subject to legal or contractual restrictions.
11.5 Rights Under the Privacy Act 1988 (Australia)
If you are located in Australia, you have the right to access and correct your personal information, and to make a complaint to the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached.
To exercise any of these rights, please contact us at hello@ioswallpapers.pro. We will respond to your request within the timeframe required by applicable law (typically 30 days for GDPR, 45 days for CCPA).
12. Do Not Track Signals
Some browsers transmit “Do Not Track” (DNT) signals. Since we use privacy-focused analytics (Umami) that does not track individual users, our Service inherently respects DNT signals. Third-party services embedded on our site may respond to DNT signals differently; please refer to their respective privacy policies.
13. Children's Privacy
Our Service is not directed to children under the age of 16 (or the applicable age of digital consent in your jurisdiction, e.g., 13 in the US under COPPA, 16 in the EU under GDPR). We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child below the applicable age, we will take steps to delete that information promptly.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Last updated” date. Where required by law, we will obtain your consent for material changes. You are advised to review this Privacy Policy periodically.
15. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:
Creativebilly
Email: hello@ioswallpapers.pro
If you are located in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.