Privacy Policy
Last updated August 2026 · Appenvision Ltd, company number 12392130
Privacy Policy
Mobile applications, AI services and website
Last updated: August 2026
This Privacy Policy explains how APPENVISION LTD collects, uses, shares and protects personal data when you use an Appenvision mobile application, an associated online feature or appenvisions.com.
1. Who we are
APPENVISION LTD (company number 12392130) is registered in England and Wales. Our registered office is Office 34a, Business Centre, 9 Lydden Road, London SW18 4LT, United Kingdom. Appenvision is the controller for the processing described here unless an App or provider notice states otherwise.
Privacy and data-rights contact: support@appenvisions.com
2. Scope
This policy applies to Appenvision applications published on the Apple App Store or Google Play, including renamed or successor versions, and to appenvisions.com. The current catalogue is available at appenvisions.com/apps/. It includes AI assistants and generators, photo and avatar tools, document and PDF utilities, identification tools, network/VPN utilities, personalisation tools, music and time utilities, and puzzle or interactive-story applications.
3. Data we process
3.1 Data you choose to provide
- User content. Prompts, messages, documents, photos, videos, scans, signatures, notes, recipient details and other material selected for an App feature.
- Support information. Email address, app/platform/version, order or subscription ID, device details and the message or attachment you choose to send.
- Optional profile or account data. Most Apps do not require a general Appenvision account. If an App expressly offers an account or cloud history, it may process an email or sign-in identifier, profile settings and account activity as disclosed in that App.
3.2 Device, usage and transaction data
- Device and app data. Device model, operating-system and app version, language, region, time zone, screen/performance characteristics, carrier/network type, IP address and installation or app-instance identifiers.
- Usage and diagnostics. App launches, sessions, screens and features used, interactions, crashes, stack traces, error codes, performance and related technical events.
- Attribution and advertising. IDFA on Apple devices, Android advertising ID, installation/attribution data, ad requests, impressions, clicks, rewards, conversion events and consent status. IDFA is not accessed unless ATT is authorised.
- Purchases and subscriptions. Product, transaction or receipt identifier, entitlement/subscription status, price/currency information supplied by the store and anti-fraud signals. Appenvision does not receive full card or bank details.
- Permissions. Camera, photos, microphone, notifications, local network, location, VPN configuration or other protected resources only when required by a user-selected feature and authorised through the platform prompt. Current Apps do not integrate with HealthKit or Health Connect.
3.3 Feature-level processing schedule
The schedule below is the disclosure baseline. A listed category applies only when the corresponding feature is present and used in the relevant App build.
| Product group | Feature data | Typical processing and storage |
|---|---|---|
| AI chat, writing and generation | Prompts, messages, uploaded images or documents, requested output, locally held history and technical request metadata | When the user starts an AI feature, the selected input is sent through the OpenAI API. History stays on-device unless an App expressly identifies an online storage or synchronisation feature. |
| Plant, rock, food and object identification | Camera or library image, recognition request, optional notes and returned result | The selected image or input may be sent to the OpenAI API only after the user initiates identification. EXIF metadata is removed or minimised where technically supported. |
| Photo, avatar and creative tools | Photos, videos, face images, prompts, edits, effects and generated output | Editing occurs on-device or, for an AI function, through the OpenAI API. Face images are used to create the requested result, not to identify or authenticate a person. |
| Documents, OCR, signing and communication | Scans, imported files, OCR text, annotations, signatures, recipient details and delivery status where the selected feature requires them | Local editing stays on-device unless the user selects an OpenAI-powered, sharing, delivery or other online feature operated by Appenvision. |
| Network, Wi-Fi, VPN and remote control | Public IP, selected server, network characteristics, nearby/local-network devices, latency, connection timing, transferred-byte counts, error/security events and device-discovery data | Appenvision rents and operates the VPN/backend servers. Network traffic is processed in transit to route the user-requested connection; limited connection and security data may be processed to operate, secure and diagnose the service. |
| Personalisation, keyboards and utilities | Selected themes, widgets, fonts, timers, alarms, notification schedule and app preferences | Primarily stored on-device. A keyboard extension must not be used to enter passwords or other sensitive data unless the relevant field and platform permit it. |
| Analytics, diagnostics and advertising | App interactions, sessions, crashes, performance, installation/advertising identifiers, attribution and ad events | Applies only where the relevant SDK is active. Consent, ATT status, device settings and regional restrictions control tracking and personalised advertising. |
3.4 Website data
appenvisions.com uses Google Analytics and Google Consent Mode. Hosting/security logs may record IP address, request time, requested page, referrer, browser/user-agent and device information. Analytics may process page interaction events and online identifiers. Where storage consent is required, analytics cookies remain denied until the relevant choice; limited consent-mode measurement signals may operate without cookies where law and configuration permit. Website choices can be changed through the available consent control or browser settings.
3.5 Sensitive and high-risk data
Current Apps do not integrate with HealthKit or Health Connect, and Appenvision does not collect or store health data as an App data category. Photos showing a face are used to create the requested image or effect and are not used by Appenvision to identify or authenticate a person. Network traffic routed through an Appenvision-operated VPN is used to provide and secure the requested connection and not to build an advertising profile from browsing content. Do not submit passwords, payment-card details, government identifiers, confidential documents or another person’s sensitive information unless the feature clearly requires it and you are authorised to do so.
4. Why we use data and legal bases
- Contract. Provide the requested App, AI output, identification, document conversion, subscription, purchase, delivery, VPN/network or support function.
- Consent. Access protected device resources, send push notifications, deploy non-essential website tags, access IDFA or provide personalised advertising where consent is required.
- Legitimate interests. Maintain stability and security, diagnose faults, prevent fraud/abuse, measure aggregate performance and administer the business where those interests are not overridden by user rights.
- Legal obligations and claims. Keep accounting records, respond to lawful requests and establish, exercise or defend legal claims.
5. Advertising, attribution and consent
Some Apps display contextual or personalised advertising and use attribution. The common portfolio stack includes AppsFlyer, AppMetrica, Firebase and Unity LevelPlay (formerly ironSource); each SDK processes data only in builds and configurations where the relevant function is active. OpenAI API is used for AI-enabled features across much of the portfolio.
- Where consent is required, consent-dependent analytics, attribution or personalised-advertising components do not initialise or transmit data until the required choice is recorded. Strictly necessary security, fraud-prevention and permitted contextual-ad components may operate where law allows.
- On iOS, ATT controls access to IDFA and tracking across apps and websites owned by other companies. Refusing ATT does not prevent contextual ads or privacy-preserving measurement such as SKAdNetwork.
- The in-app consent interface identifies relevant purposes and available advertising partners. Where required, it can be reopened through Privacy Choices or an equivalent settings control.
- Under some US state laws, disclosure of identifiers or usage/ad data for cross-context behavioural advertising may be considered a sale, sharing or targeted advertising even though Appenvision does not sell personal information for money.
6. Service providers and recipients
We disclose only data reasonably needed for the purposes above. A provider may act as our processor/service provider, an independent controller/business, or both depending on the service and jurisdiction. The current in-app disclosure and provider notice control where a provider is enabled only in particular Apps.
| Provider or category | Purpose and typical data | Privacy information |
|---|---|---|
| AppsFlyer | Install attribution and campaign measurement; device/installation identifiers, IP address, app/device data, events and consent status. IDFA is available only after ATT authorisation. | Provider policy |
| Google Firebase | Analytics, app-instance and device/app data; Crashlytics crash/diagnostic data; Remote Config requests; Cloud Messaging push tokens and delivery data. | Provider policy |
| AppMetrica | Product analytics and attribution; app/device information, installation identifiers, sessions, events, diagnostics, IP address and approximate region. | Provider policy |
| Unity LevelPlay / ironSource | Advertising mediation and delivery; device and advertising identifiers, IP address, app/device data, ad requests, impressions, clicks, reward events, fraud signals and consent choices. | Provider policy |
| OpenAI API | AI chat, writing, generation, image/document analysis and identification; prompts, selected images or files, requested output and limited request metadata needed to provide and secure the feature. | OpenAI privacy |
| Appenvision-operated infrastructure | App backends, internal diagnostics and VPN/network functionality. Appenvision rents and operates the servers; hosting companies provide infrastructure and may process IP addresses, server requests, connection/security events and encrypted traffic in transit as technically necessary. | Provider policy |
| Apple and Google | App distribution, permissions, purchases, subscriptions, refunds, store fraud prevention and store-provided analytics under their own terms. | Apple privacy Google privacy |
| Website analytics | Google Analytics and Consent Mode on appenvisions.com; page URL, referrer, browser/device data, IP-derived region, interactions and cookie/online identifiers where permitted. | Provider policy |
Appenvision rents and operates the servers used for its custom backends and VPN/network functions. Hosting companies supply server infrastructure but do not independently determine the purposes of Appenvision’s App processing. Appenvision also operates internal diagnostic services. The active server location, configuration and data flow must be reflected in the relevant in-app disclosure and store declaration before release. We may disclose limited information to professional advisers, auditors, insurers, law enforcement or regulators where necessary, or in connection with a merger, financing, reorganisation or sale subject to required safeguards and notice.
7. International data transfers
OpenAI, the common SDK providers and Appenvision’s contracted server hosts may process data in the United Kingdom, EEA, United States and other countries where the relevant infrastructure operates. Where UK or EEA personal data is transferred without an applicable adequacy decision, we use an approved mechanism such as the EU Standard Contractual Clauses and, for UK transfers, the UK International Data Transfer Addendum or International Data Transfer Agreement, together with transfer-risk review and supplementary safeguards where appropriate. Use of an App is not treated as consent to otherwise unlawful international transfers.
8. How long we keep data
Retention varies by feature, provider configuration and legal requirement. The periods below are intended maximums or deletion criteria unless a shorter period applies. Limited records may be kept longer for security, fraud prevention, disputes or legal obligations.
| Data | Typical retention or deletion criterion |
|---|---|
| Local content and preferences | Stored on the device until the user deletes the item, clears app data or removes the App, subject to supported backups and platform synchronisation. |
| AI prompts, files and cloud requests | Sent through the OpenAI API when the user starts the relevant feature and kept only as needed to return the requested result, prevent abuse and meet provider or legal requirements. App history is local unless the App expressly identifies online storage. |
| Documents, scans and photos | Local unless the user selects an OpenAI-powered, delivery, sharing or other online feature. Temporary Appenvision server copies are deleted after processing or a short operational/recovery window. |
| VPN and backend data | Network traffic is processed in transit for the requested connection. Connection, error and security records, if generated by the active server configuration, are rotated or deleted when no longer needed for operation, security, abuse prevention or a legal obligation. |
| Crash and diagnostic data | Normally up to 90 days, subject to provider configuration and a longer period only for security, incident or legal needs. |
| Analytics and product events | Normally no longer than 14 months in identifiable or pseudonymous form, then deleted or aggregated unless a shorter setting applies. |
| Attribution and advertising data | Only for measurement, fraud prevention and compliance; provider limits apply and attribution data is not intended to be retained longer than 24 months. |
| Support correspondence | Up to 24 months after closure, longer only if needed for a dispute, safety issue or legal obligation. |
| Purchases and tax records | For the statutory accounting period, generally six years in the United Kingdom. |
| Website data | Website measurement data normally no longer than 14 months; security logs for a short rolling period unless required to investigate an incident. |
9. Your choices and controls
- Tracking and advertising. Use Privacy Choices, iOS Settings → Privacy & Security → Tracking, or Android advertising/privacy settings.
- Permissions. Review camera, photos, microphone, location, local-network, notification, VPN and other permissions in device settings. Removing a permission may disable the related feature.
- Content and local data. Delete content through the App where available or remove local data through platform settings. Keep any supported backup before uninstalling.
- AI and online processing. Do not submit content to an AI feature if you do not want the selected input sent through the OpenAI API. On-device functions can be used without that transfer where the App offers such an option.
- Subscriptions and notifications. Manage subscriptions through the purchasing store and notifications through device settings.
- Rights requests. Email support@appenvisions.com with the App name, platform and only the identifier or order information reasonably needed to locate a record.
10. UK and EEA data-protection rights
Subject to legal conditions and exceptions, users may have rights to access, correct, erase, restrict or object to processing, receive certain data in portable form and withdraw consent. Users may complain to the UK Information Commissioner’s Office or their local EEA supervisory authority. Withdrawing consent does not terminate the general licence to use features that do not require the withdrawn processing.
To exercise a right, email support@appenvisions.com. We normally respond within one month and may request proportionate information to verify the request.
ICO complaints: ico.org.uk/make-a-complaint/
10.1 ADDENDUM FOR EEA RESIDENTS (EU GDPR REPRESENTATIVE):
If you are a resident of the European Union, the EU General Data Protection Regulation (EU GDPR) applies to the processing of your personal data.
APPENVISION LTD, a company organised and existing under the laws of England and Wales (the Data Controller), has appointed its affiliated EU entity as its designated representative in the European Union in accordance with Article 27 of the EU GDPR.
If you have any questions about how we handle your personal data, or if you wish to exercise your data subject rights (such as the right to access, delete, or restrict your data), you can contact our EU Representative directly:
EU Representative Name: JMH DEVELOPERS OÜ
Postal Address: Vesivärava tn 50-212, Kesklinna linnaosa, Tallinn 10152, Harju maakond, Estonia
Dedicated Email Address: support@jmhdevelopers.com
Our EU Representative is authorized to act on our behalf and serve as a direct point of contact for EU users regarding all matters related to EU GDPR compliance.
11. California and other US state rights
Depending on residence and whether a law applies, users may have rights to know/access, correct, delete, obtain a portable copy, opt out of targeted advertising or sale/sharing, limit certain sensitive-data uses and appeal a refusal. We do not discriminate for exercising a right.
- To opt out of eligible future sale/sharing or targeted advertising, use Privacy Choices or email support@appenvisions.com with the subject “US Privacy Opt-Out” and identify the App, platform and installation identifier.
- Website visitors can use the cookie/consent control. Where legally required and technically applicable, we honour Global Privacy Control for browser-based sale/sharing or targeted advertising.
- We do not knowingly sell or share personal information of users under 16 for cross-context behavioural advertising.
- An authorised agent may submit a request where law permits. We verify requests using proportionate information already associated with the device, content, support request or transaction.
12. Accounts and deletion
Most current Apps do not require a general Appenvision account. If an App allows account creation, it must provide an in-app deletion path and a web method to request deletion of the account and associated data. A request may be sent to support@appenvisions.com. Deletion does not require erasure of records that must be retained for purchases, fraud prevention, legal obligations or claims, and it does not automatically cancel a store subscription.
13. Children and teenagers
Our Apps are general-audience products and are not intended for the App Store Kids Category or Google Play Designed for Families unless a particular store page expressly states otherwise. They are not directed to children under 13, and we do not knowingly collect personal data from a child under 13 without legally valid parental authorisation. A 4+ or similar store age rating describes content suitability and does not mean the App is directed to children. Users below the age of legal majority should use the Apps with a parent or guardian’s involvement.
We do not knowingly use personal information of users under 16 for personalised or cross-context behavioural advertising. If we learn that a child has supplied personal data without required authorisation, we apply the required restriction and delete the data where required. Parents or guardians may contact us for review or deletion.
14. Security
We use reasonable technical and organisational measures appropriate to the data and risk, including access controls, encryption in transit, data minimisation, provider review and incident-response procedures. No transmission or storage method is completely secure. We notify affected users and regulators when law requires.
15. Changes to this policy
We may update this policy when Apps, providers, features or legal obligations change. The cover date shows the latest version. Material changes affecting rights or relying on new consent receive additional notice and consent where required. Earlier versions may be requested from support.
16. Contact
APPENVISION LTD
Company number 12392130
Office 34a, Business Centre
9 Lydden Road
London SW18 4LT
United Kingdom
Email: support@appenvisions.com


















