What we collect
- Account details. Your email address and, if you use a password, a salted hash of it (never the password itself). If you sign in with Google or Apple, we receive your email address and an account identifier from them. With Apple, that may be a private relay address.
- Billing records. Your balance and a ledger of top-ups and AI requests: the amount, time, model used and token counts. Stripe gives us a customer ID and confirms each payment. Card details go straight to Stripe and never reach us.
- API keys. A hash and short prefix of each key, when it was made and when it was last used.
- Session cookie. One cookie that keeps you signed in, plus a short-lived cookie during Google or Apple sign-in. We use no advertising or analytics cookies.
- Request logs. Like most websites, our hosting provider records technical details such as IP address, browser, and the time and path of each request, for security and debugging.
What you send to the AI
When a Shortcut calls our API, it sends the text, image or audio you chose to our servers, which pass it to an AI model and return the result. We do not store the content of your requests or the AI's replies in our database. We keep only the billing record described above. Our providers may keep request data briefly, as described below.
Who we share it with
We share data only with the companies that run the service for us:
- Cloudflare hosts the site and database and runs most AI models (Workers AI) and the AI Gateway that routes image requests. See Cloudflare's privacy policy.
- OpenAI generates images for the Make an Image block. OpenAI says it does not train on API data by default and may keep it for up to 30 days to monitor abuse. See OpenAI's privacy policy.
- Stripe processes payments. See Stripe's privacy policy.
- Google and Apple, only if you choose to sign in with them.
We may also disclose data when the law requires it, to protect people or the service from harm, or as part of a sale or merger of the service (in which case this policy keeps applying).
How we use it
To run your account, answer your requests, charge the right amount, prevent fraud and abuse, keep the service secure, and reply when you contact us. We do not sell your personal information, share it for advertising, or use your requests to train AI models.
How long we keep it
We keep account and billing records while your account is open. After you delete your account, we remove your account details, keys and sessions, but may keep payment records for as long as tax and accounting law requires. Sessions expire on their own, and our hosting provider's logs are kept for a limited time.
Your choices and rights
You can see your balance, history and API keys on your account page, and revoke keys there. To get a copy of your data, correct it, or delete your account, email support@iphoneadvanced.com. Depending on where you live (for example, in the EU, UK or California), you may have further rights, such as to object to processing or to complain to a data protection authority. We will not treat you differently for using them.
Security
Traffic is encrypted with HTTPS, passwords and keys are stored only as hashes, and access to production systems is limited. No system is perfectly secure, so please use a strong, unique password.
Children
The service is not meant for children under 13, and we do not knowingly collect their data. If you think a child has given us data, email support@iphoneadvanced.com and we will delete it.
International users
We and our providers may process data in the United States and other countries, which may have different data protection laws from yours.
Changes
If we change this policy in a meaningful way, we will update the date above and say so on the site.
Contact
Privacy questions or requests: support@iphoneadvanced.com. See also our Terms of Service.