Privacy Policy
Effective date: August 20, 2026
FreshGreet (the "App") is operated by Anini, an independent app developer based in Malaysia ("we", "our", or "us"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our App. You can reach us at any time at aniniwtf@gmail.com.
1. Information We Collect
Account Information. When you sign in with Google or Apple, we receive your name, email address, and profile photo as provided by the sign-in provider. If you use the App as a guest, no account information is collected.
User-Generated Content. When you create custom greetings or edit AI prompts, we store your text inputs and the generated images in your account to enable access across sessions. Your prompt text — and the image you are editing — are sent to our AI providers to render the result. See section 4.
Contacts Data. If you enable contact sync, we access your device's address book to retrieve birthday dates for personalized greeting suggestions. Contact names and birthdays are stored in your account to generate timely greetings. No other contact information (phone numbers, emails, addresses) is transmitted to our servers. When we generate an automatic birthday greeting, the person's name is included in the prompt sent to our AI provider so it can be rendered into the image.
Usage Data. We collect usage analytics including app opens, features used, images shared, and error reports. We do not attach your name or email address to these events. Analytics and crash reporting services assign a pseudonymous app-instance identifier to your installation.
Device Information. We may collect device type, operating system version, and language settings to optimize your experience.
Purchase Information. Subscription and credit pack purchases are processed by Apple (App Store) or Google (Google Play). We receive a transaction identifier and entitlement status but do not have access to your payment details such as credit card numbers.
Photo Library. If you save a greeting to your device gallery, the App writes the image to your photo library. We do not read your existing photos and nothing from your photo library is sent to us.
2. How We Use Your Information
- To provide, maintain, and improve the App and its features
- To generate personalized greeting images based on your preferences
- To manage your account, subscriptions, and credit balance
- To send you notifications about new greetings, holidays, or app updates (with your permission)
- To analyze usage patterns and fix bugs
- To comply with legal obligations
3. Third-Party Services and Processors
We use the following third-party services, which may receive or process your information:
- Supabase — backend database, authentication, and image storage
- Amazon Web Services (AWS) — server functions in the Asia Pacific (Singapore) region that build prompts, call our AI providers, and write the resulting image to storage
- Google Gemini API — AI image generation (see section 4)
- OpenAI API — AI image generation and image editing (see section 4)
- RevenueCat — subscription and in-app purchase management
- Google AdMob — advertising for free-tier users (AdMob may use advertising identifiers; see Google's privacy policy for details)
- Firebase Analytics — usage analytics including app opens, features used, and user engagement
- Firebase Crashlytics — crash reporting including device information, stack traces, and diagnostic data to help us identify and fix bugs
- Google Sign-In / Apple Sign-In — authentication
Each third-party service operates under its own privacy policy. We encourage you to review their policies.
4. AI Image Generation and Your Prompts
Greeting images are created by third-party AI providers. Which provider handles a request depends on the language and on whether you are editing an existing image:
- Google Gemini API — English generations
- OpenAI API — non-English generations, and all image edits
What is sent. We send the greeting text, the style and category of the card, and — for custom greetings and edits — the prompt text you typed. For an edit, the image being edited is also sent. For an automatic birthday greeting, the name you synced or entered for that person is included in the greeting text. We do not send your email address, your account identifier, your contact list, or your device identifiers to these providers.
Training. We do not use your data to train AI models. We use the paid tiers of both providers. Google states that it does not use paid-tier prompts or responses to improve its products. OpenAI states that data sent to its API is not used to train or improve its models unless the customer opts in; we have not opted in.
Retention by the providers. Both providers log prompts and responses for a limited period to detect abuse and to meet legal obligations — up to 30 days by default in each case — after which they are deleted. This retention is controlled by the provider, not by us.
Human review. Google does not apply human review to paid-tier API prompts. OpenAI may have staff review content that its automated systems flag for abuse. Neither provider reviews your prompts for any other purpose.
These statements reflect the providers' published API data policies as of August 20, 2026. Provider policies can change; we will update this section when they do.
5. Advertising
Free-tier users may see banner, interstitial, and rewarded ads served by Google AdMob. AdMob may collect device identifiers and usage data to serve personalized or non-personalized ads based on your device settings. Paid-tier users (Plus and Pro) do not see ads.
6. Data Storage and Security
Your account data and images are stored on Supabase infrastructure with row-level security enabled. On-demand and custom-generated images are stored in a private storage bucket accessible only to your account. Image generation runs on AWS server functions in the Asia Pacific (Singapore) region; these functions process your request in transit and do not keep a copy of it after the image is written to storage. We use commercially reasonable security measures to protect your data, but no method of transmission or storage is completely secure.
7. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data and generated images within 30 days, except where retention is required by law. Prompts held by our AI providers for abuse monitoring are deleted on their schedule, described in section 4.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete your personal data
- Export your data in a portable format
- Object to or restrict how we process your data
- Limit our use and disclosure of your data
- Opt out of personalized advertising
- Withdraw consent for data processing
- Lodge a complaint with a data protection authority
We do not sell your personal information, and we have not sold it in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16. If you use the free tier with personalized ads enabled, sharing your advertising identifier with Google AdMob for personalized advertising may count as "sharing" for cross-context behavioural advertising under California law. You can stop this at any time by turning off personalized ads in your device settings (iOS: Settings → Privacy & Security → Tracking; Android: Settings → Google → Ads), or by subscribing to a paid tier, which removes ads entirely.
To exercise these rights or delete your account, visit our account deletion page or contact us at aniniwtf@gmail.com.
9. Notice for Malaysian Users (PDPA)
This section is given under the Personal Data Protection Act 2010 (Malaysia).
- Personal data we process: your name, email address, and profile photo from your sign-in provider; the greeting text and prompts you write; the contact names and birthdays you choose to sync; your purchase entitlement status; and device and usage data.
- Source: directly from you, from your device (with your permission), and from your Google or Apple sign-in provider.
- Purpose: the purposes listed in section 2. Providing your name, email, and prompt text is necessary to create and store greetings; if you do not provide them, you cannot use the generation features. Contact sync is optional.
- Classes of parties we may disclose to: cloud hosting and database providers, AI image generation providers, payment and subscription processors, analytics and crash reporting providers, advertising providers, and authentication providers. These are named in section 3. We may also disclose data where required by law or by a regulator.
- Transfer outside Malaysia: your data is processed outside Malaysia. See section 11.
- Your choices: you may request access to or correction of your personal data, limit our processing of it, or withdraw your consent, by writing to aniniwtf@gmail.com. Withdrawing consent may stop you using parts of the App.
This notice is issued in English. If you would prefer it in Bahasa Malaysia, write to us at aniniwtf@gmail.com and we will provide it.
10. Children's Privacy
FreshGreet is not directed at children. You must be at least 13 years old to use the App. In the European Economic Area and the United Kingdom, you must be at least 16 years old, or the minimum age set by your country's law, unless a parent or guardian consents on your behalf. We do not knowingly collect personal information from children below these ages. If we become aware that we have collected such data, we will delete it promptly. Contact us at aniniwtf@gmail.com if you believe a child has given us personal data.
11. International Data Transfers
Your data is processed outside your country. Our server functions run on AWS in the Asia Pacific (Singapore) region. Our database, authentication, and image storage run on Supabase infrastructure. Our AI providers (Google and OpenAI) and our analytics, advertising, and subscription providers process data in the United States and in other countries where they operate. Where a transfer leaves the European Economic Area or the United Kingdom, we rely on the receiving provider's Standard Contractual Clauses or an equivalent approved safeguard.
12. Data Breach Notification
If a breach of personal data occurs that is likely to cause you significant harm, we will notify you and the relevant data protection authority without undue delay, and within the time limit set by applicable law.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy in the App or by other means, and we will update the effective date at the top of this page. If a change means we will use your existing personal data for a genuinely new purpose — for example, sending your data to a new category of provider — we will ask for your consent before we do so, rather than rely on your continued use of the App.
14. Contact Us
If you have questions about this Privacy Policy, or wish to exercise any right described above, contact us at:
Email: aniniwtf@gmail.com