Privacy Policy
Last updated: August 11, 2026
This Privacy Policy explains how MlemStick (“we”, “the app”) handles information when you use our iOS and Android applications. English is the controlling language of this policy.
1. Information we process
- Photos you upload. Images you choose for sticker generation are sent to our servers and to third-party AI image processors (see section 3) only to create your stickers. Before the first upload, the app asks for your explicit permission and names those AI processors. We do not use your photos for ads or for training models for third parties.
- Anonymous device identifier. The app creates a random device token stored on your device. It authenticates API requests and associates credit balance with that device. It is not your name, email, or phone number.
- Purchase data. In-app purchases are processed by Apple or Google. We and our payment partner (RevenueCat) receive purchase tokens / transaction identifiers needed to verify payment and grant credits. We do not receive your full payment card details.
- Generated stickers. Stickers you save stay on your device (and, if you export them, in apps you choose such as Messages or WhatsApp).
2. How we use information
- Provide sticker generation and credit balances
- Verify and fulfill in-app purchases
- Prevent abuse and keep the service reliable
- Comply with law and store policies when required
3. Storage and processors
API traffic is handled by our cloud proxy on Cloudflare Workers, with key-value storage for credit balances and short-lived job metadata (not your photo files). Image generation is performed by third-party AI processors acting on our behalf:
- OpenAI (image edit / generation APIs)
- GPTI2 (image edit / generation APIs)
Depending on configuration and availability, one or both of these processors may receive your uploaded portrait solely to produce sticker artwork. Purchase validation may involve Apple, Google, and RevenueCat.
4. Sharing
We do not sell your personal information. We share data only with service providers that help us run the app (Cloudflare hosting, OpenAI and/or GPTI2 for AI generation, RevenueCat / Apple / Google for purchase validation), or when required by law.
5. Retention
Face photos are forwarded to the AI processor for the generation job and are not stored in our Cloudflare object storage. Temporary processing and provider-side retention are typically on the order of about one hour (provider policies may vary). Job metadata on our proxy expires within about 24 hours. Credit balances tied to your device token remain until you clear local app data or request deletion. Store purchase records follow Apple / Google retention rules.
6. Your choices
- You can decline photo access; generation will not work without a photo.
- You can decline the AI upload consent dialog; no photo is sent until you agree.
- You can delete stickers and clear local app data from the device (this also resets AI upload consent on the device).
- To request deletion of server-side credit data associated with your device token, contact us at privacy@mlemstick.app and include enough detail to identify the request (for example the approximate purchase date).
7. Children
MlemStick is not directed to children under 13 (or the equivalent minimum age in your country). We do not knowingly collect personal information from children.
8. Changes
We may update this policy. The “Last updated” date at the top will change when we do. Continued use of the app after changes means you accept the updated policy.
9. Contact
Questions about privacy: privacy@mlemstick.app
Short version: with your consent we send your photo to OpenAI and/or GPTI2 to make stickers, keep an anonymous device id for credits, and never sell your data.