Privacy Policy
Last Updated: June 2026
Welcome to Wondershot (the “App” or “we”). We understand the importance of your personal information and are committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal information, and how you can manage your information.
Please read and understand this Privacy Policy carefully before using the App.
1. Information We Collect
1.1 Information You Provide
- Account Information: When you sign in with Apple ID, we receive a unique user identifier provided by Apple. We do not receive your Apple ID email address unless you choose to share it.
- User Content: Photos you upload for AI processing and the generated result images.
- Feedback Information: Information you provide when contacting us via email or community channels.
1.2 Information Collected Automatically
- Device Information: Device model, operating system version, unique device identifiers.
- Usage Data: App feature usage frequency, preference settings.
- Log Information: App crash logs, error reports (excluding personally identifiable information).
1.3 Information We Do Not Collect
- We do not collect your contacts, messages, or call history.
- We do not collect your precise geographic location.
- We do not access your photo library without your knowledge.
2. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Provide AI image generation services | Contract performance |
| Process your credits and membership orders | Contract performance |
| Improve and optimize app features | Legitimate interests |
| Send service-related notifications | Contract performance |
| Prevent fraud and abuse | Legitimate interests |
| Comply with legal requirements | Legal obligation |
3. Data Storage and Security
3.1 Storage Location
Your data is stored on secure cloud servers provided by trusted cloud service providers. For users located in mainland China, data is stored within China. For users in other regions, data may be processed on servers located in the United States or other regions where our service providers operate.
3.2 Retention Period
We retain your personal information only for the minimum period necessary to fulfill the purposes described in this Policy and as required by applicable laws and regulations. Unless otherwise required by law, we generally follow these retention rules:
- Account Information: Retained during your account’s existence, deleted within 30 days after account deletion.
- Uploaded Photos: Deleted from our servers immediately after processing; we do not retain permanent copies.
- Generated Images: Stored only on your local device; we do not keep copies.
- Log Data: Automatically deleted after 90 days.
- Order and Transaction Information: We retain necessary transaction information as required by law for purposes including contract performance, reconciliation, taxation, and dispute resolution. The retention of such information does not change the nature of credits and membership services as virtual usage entitlements rather than stored-value funds.
3.3 Security Measures
We implement the following measures to protect your data:
- Transport Encryption: All data transmission uses TLS 1.3 encryption.
- Storage Encryption: Sensitive data is encrypted using AES-256.
- Access Control: Strict employee data access permission management.
- Security Audits: Regular security vulnerability scans and penetration testing.
4. Information Sharing and Disclosure
We commit to never selling your personal information. We may share your information in the following circumstances:
4.1 Service Providers
We may share only the information reasonably necessary for the Service with third-party service providers. Because AI model routing, availability, pricing, and safety requirements may change, we may use different providers from time to time. These providers act only for the purposes described below and are not permitted to use your information for their own independent purposes unless their own terms and applicable law allow it and you have separately agreed.
| Provider Category | Purpose | Data Shared |
|---|---|---|
| Apple and App Store services | Authentication, payment processing, subscription management | Apple-provided user identifier, transaction and subscription information |
| AI model, image generation, safety, and moderation providers, which may include providers such as Google, OpenRouter and model providers available through it, BytePlus/Seedream, Cloudflare, Zhipu AI, or other equivalent providers | AI image generation, prompt/image processing, model routing, safety review, abuse prevention, and service reliability | Photos you upload, prompts or template parameters, generated results, request metadata, and limited account or device identifiers where necessary to provide, secure, or troubleshoot the Service |
| Cloud infrastructure, storage, content delivery, and security providers, including Cloudflare | Hosting, object storage, content delivery, security protection, logging, and abuse prevention | Access logs, security logs, generated image URLs or files where stored for the Service, device and request metadata |
We review our service provider categories periodically and may replace or add providers when reasonably necessary to operate, secure, improve, or scale the Service. Material changes in how we use or share personal information will be handled as described in the “Changes to This Privacy Policy” section.
4.2 Legal Requirements
We may disclose your information when required by law, government investigation, or to protect our or others’ legitimate interests.
4.3 Business Transfers
In the event of a merger, acquisition, or asset sale, your information may be transferred as part of the transaction assets. We will notify you before any such transfer.
5. Your Rights
Under applicable data protection laws, including GDPR (for EU residents) and CCPA (for California residents), you have the following rights:
5.1 Right of Access
You have the right to view the personal information we hold about you. Please check through the “Account Center” in the app or contact us.
5.2 Right to Rectification
If you find that information we hold is inaccurate, you have the right to request correction.
5.3 Right to Erasure
You have the right to request deletion of your personal information. You can:
- Delete your generation history within the app
- Request account deletion to remove all data
5.4 Right to Withdraw Consent
You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
5.5 Right to Data Portability
You have the right to receive your personal information in a structured, commonly used format.
5.6 Right to Lodge a Complaint
If you believe our processing activities infringe your rights, you have the right to lodge a complaint with the relevant supervisory authority.
6. Cookies and Similar Technologies
This App does not use cookies. We may use the following technologies:
- Local Storage: To save your app settings and preferences.
- Device Identifiers: To prevent fraud and abuse.
7. Children’s Privacy
This App is not intended for children under 13 (or the higher age specified in your jurisdiction). We do not knowingly collect personal information from children. If you are a parent or guardian and discover that your child has provided us with personal information, please contact us, and we will promptly delete such information.
8. International Data Transfers
If you are located outside of mainland China, your data may be processed on servers in the United States or other regions where our service providers operate. We ensure such transfers comply with applicable data protection laws and implement appropriate safeguards.
For EU residents: We rely on Standard Contractual Clauses approved by the European Commission for international data transfers.
If you are located in mainland China, your data will be stored within China unless otherwise required by law.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Updated policies will be posted in the App with the update date noted.
For significant changes, we will notify you in advance through in-app notifications or other appropriate means. Continued use of the App constitutes your acceptance of the updated Privacy Policy.
10. Contact Us
If you have any questions, comments, or complaints about this Privacy Policy, please contact us:
- Email: support@wondershot.art
- Response Time: We will respond to your request within 15 business days
For EU Residents
If you are located in the European Union and have concerns about our data processing practices, you may contact your local Data Protection Authority.
For California Residents
California residents have additional rights under the CCPA, including the right to know what personal information is collected and the right to opt-out of the sale of personal information. As stated above, we do not sell personal information.
Privacy Contact / Data Controller Contact: Shanghai Chenxing HuiKe Technology Co., Ltd.
Email: support@wondershot.art
This Privacy Policy is effective as of June 2026.