About this Policy and the Data Controller
This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use the Service, and how you can exercise your related rights. This Policy is a privacy notice; merely downloading, opening, or continuing to use the Service does not constitute your blanket consent to all processing activities. For processing that legally requires consent, we will provide a clear explanation separately and obtain your affirmative choice.
Age Requirements
The Service is intended only for users who are 18 years of age or older. We do not knowingly provide the Service to, or collect personal information from, anyone under 18. If we discover that a person under 18 has provided us with personal information, we will take reasonable steps to delete the related account and information as soon as practicable, except where retention is required by law.
Parents or guardians who believe a minor has used the Service should contact us through the privacy email above. We may need reasonable information to locate the relevant account, but we will not ask for information unrelated to verification.
Information We Process, Purposes, Legal Bases, and Retention
The table below reflects the App’s actual practices. For optional features you do not use, we do not collect the corresponding information.
| Category | Details | Source | Primary purposes | Legal basis (e.g. GDPR, where applicable) | Typical retention |
|---|---|---|---|---|---|
| Account & identity | Email, user ID, account credentials, password, Google sign-in identifier | You or Google sign-in | Registration, login, account management, and cross-device sync | Contract performance; legitimate interests for security | While the account is active; after deletion, handled under Section 9 |
| User-uploaded content | Original images you actively select, plus prompts or other creative inputs you enter | You | Complete the AI animation generation you request | Contract performance | Deleted from generation systems within 48 hours after success or failure; backups under Section 9 |
| Generation & creation data | Animation parameters, outputs, project records, favorites and regeneration history, generation ID, timestamp, model version, and job status | You and the Service | Generate and deliver animations, show creation history, sync projects, troubleshoot issues | Contract performance; legitimate interests for service reliability | Outputs and project records kept until you delete them or delete your account; diagnostic metadata follows log retention |
| In-app purchases & subscriptions | Google Play order ID / purchase token, product or plan, transaction time, currency, subscription and refund status | Google Play | Verify purchases, unlock entitlements, restore purchases, refunds, and financial reconciliation | Contract performance; legal obligation; legitimate interests for fraud prevention | As required for tax, finance, and dispute handling — typically no more than one year |
| Device & app information | Device model, OS and app version, language, time zone, app instance or advertising identifier | Your device and SDKs used | Compatibility, diagnostics, security, and anti-abuse | Contract performance; legitimate interests for security and stability | Typically no more than 7 days; then deleted or irreversibly anonymized |
| Network & approximate region | IP address, country or region inferred from IP, network request time and status | Network connection, servers, and providers | Establish connections, deliver content, security, regionalization, and troubleshooting | Contract performance; legitimate interests for security and fraud prevention | Raw network logs typically no more than 7 days |
| Notification information | Push tokens and notification preferences | Device | Send generation-complete, service, or subscription notices; marketing notices only after separate consent | Contract performance; marketing based on consent | Deleted after you disable notifications, the token expires, or you delete your account — typically no more than 30 days |
| Support & rights requests | Email content, account identifiers, screenshots, attachments, and request/handling records | You | Customer support, complaints and rights requests, dispute resolution | Contract performance; legal obligation; legitimate interests for dispute resolution | Typically 1 month after the matter closes; longer if needed for disputes or legal requirements |
| Security & content governance | Abnormal requests, account risk signals, reported content, and account expiry signals | You, other users, or systems | Prevent fraud, abuse, unlawful content, or rule violations | Legitimate interests for user and service safety; legal obligation | Typically no more than 7 days, except for major security incidents or legal retention |
If certain information is necessary to provide a specific feature, refusing to provide it may make that feature unavailable. Optional analytics, marketing, or model-improvement processing is not a condition of using core animation features.
Device Features and Permissions
We request permissions only when needed for the relevant feature, and we explain the purpose around the system permission prompt. Actual permissions are governed by the App’s Android Manifest and runtime requests.
- Image selection: We preferentially use the Android system photo picker so you grant the App only temporary access to the images you select. If a legacy Android compatibility path truly requires media-read permission, it should be requested only when you actively choose an image, with the actual permission name and applicable OS versions stated.
- Saving generated works: We may request broader external storage management permission to save outputs.
- Notifications (optional): Used to send generation-complete, service-status, or subscription-related reminders. Disabling notifications does not affect core animation features.
- Network access: Used to upload materials you select, return generated results, sync account information, and verify subscriptions. Network access is an operational capability of the App, not an Android runtime sensitive permission.
You may withdraw granted permissions in your device settings. After withdrawal, features that depend on that permission may become unavailable. Granting a permission does not mean we automatically browse or upload local content unrelated to what you actively select.
Photos, Animation, and AI Processing
When you start an animation job, the image you selected, generation parameters, and necessary technical metadata are transmitted over an encrypted connection to our servers and to infrastructure or AI processing providers acting on our behalf. After processing, the result is returned to you, and source images are deleted according to the timelines in Section 9.
The Service does not use facial recognition to confirm your identity and does not build biometric templates for identifying or verifying individuals.
Staff generally do not view your uploaded content except where: you actively request support and provide relevant content; review is necessary to investigate a security incident, abuse, or unlawful activity; or the law requires us to process it.
You are responsible for ensuring you have the right to upload the images and materials you provide. Rules on user-content licenses, prohibited content, and intellectual property are set out in the User Agreement; those rules do not change the data-processing commitments in this Privacy Policy.
Cookies and Website Technologies
The native Android app does not use browser cookies. Our website or in-app web pages may use necessary cookies, local storage, server logs, and security technologies to load pages, prevent abuse, and store essential preferences.
How We Use Information
We process personal information only for the following purposes:
- Create and manage accounts, verify logins, and sync account settings;
- Receive the images and parameters you select, generate animations, and deliver results;
- Store projects, works, favorites, and creation history that you choose to keep;
- Verify Google Play purchases and subscriptions, restore entitlements, handle refunds, and reconcile accounts;
- Send service notices you request and handle support requests;
- Protect accounts, users, and the Service; detect fraud, bot traffic, abuse, and security incidents;
- Diagnose crashes, assess performance, and improve the product where legally permitted and with any required choice mechanisms in place;
- Comply with applicable law, enforce agreements, handle disputes, and respond to valid legal process;
- Send marketing messages or conduct other optional processing only after obtaining separate consent.
Where processing is based on legitimate interests, we assess whether those interests are overridden by your rights and reasonable expectations. You may object under Section 11. Where processing is based on consent, you may withdraw consent at any time; withdrawal does not affect the lawfulness of processing before withdrawal.
We do not make decisions that produce legal or similarly significant effects solely based on automated processing.
Disclosure, Service Providers, and Sale / Sharing
8.1 We do not sell personal information
We do not sell your personal information for money or other valuable consideration, and we do not “share” your personal information for cross-context behavioral advertising.
8.2 Limited disclosure situations
We may disclose information in the following limited circumstances:
- Google Play: to complete purchases, verify subscriptions, process refunds, prevent fraud, and meet platform requirements by exchanging necessary order and app information. Google may also process some information as an independent controller under its own privacy policy.
- Recipients you designate: when you actively use the system share sheet, relevant content is sent to the app or person you choose. Subsequent processing is governed by the recipient’s rules.
- Legal and safety: when we in good faith believe disclosure is necessary to comply with law, a court order, or a valid government request, or to protect the rights, safety, and property of users, the public, the Service, or others.
- Business changes: in a merger, acquisition, financing, reorganization, bankruptcy, or asset transfer, to necessary participants, while taking reasonable measures to protect the information and providing notice required by law if the controller or purposes materially change.
Retention, Deletion, and Account Closure
We set retention periods based on service needs, sensitivity, security and dispute risk, and legal obligations. When a period ends, we delete the information or irreversibly anonymize it.
- Source images: deleted from online generation systems within 48 hours after generation succeeds or fails.
- Generated works and project history: retained until you delete the relevant works or delete your account. If a work is saved only on your device, we do not retain a cloud copy.
- Basic account information: retained while the account is active. After a verified deletion request, it is deleted from active systems or de-identified.
- Backup copies: may remain in restricted backups for up to 7 days solely for disaster recovery, not for day-to-day operations, and are overwritten on the backup cycle.
- Logs, support, and order records: retained according to the periods in Section 3. Information retained for legal, security, anti-fraud, refund, tax, or dispute purposes is isolated from active accounts, used only for those purposes, and deleted when the period expires.
If the App allows account creation, you may start deletion in either of these ways:
- In the App: Personal Center → Delete Account;
- On the web: https://aianimate.xyz/delete_account.html
Deleting your account does not automatically cancel a Google Play subscription (if any). To avoid future charges, cancel the subscription separately in the Google Play subscription center. We will not require you to reinstall the App solely to submit a web deletion request. To prevent malicious deletions, we perform identity verification proportionate to the risk, but we will not ask for passwords, full payment details, or materials unrelated to verification.
International Transfers
For personal information subject to the GDPR that is transferred outside the European Economic Area, we use applicable adequacy decisions, European Commission Standard Contractual Clauses (SCCs), or other legally recognized safeguards, and complete transfer impact assessments and supplementary measures where needed. Transfers of UK and Swiss data use the mechanisms applicable in those jurisdictions. You may contact us to learn about the safeguards or request an available copy; copies may be redacted as needed to protect trade secrets and others’ information.
We rely on SCCs as a transfer basis only when the relevant contracts have been signed and apply to the actual data flows.
Your Privacy Rights
Depending on where you live and applicable law, you may have the right to:
- Limit, where applicable, the use and disclosure of sensitive personal information beyond what is necessary;
- Not be unlawfully discriminated against for exercising privacy rights;
- Appeal a denied request (by contacting us by email);
- Lodge a complaint with a competent data-protection authority where you live or where jurisdiction otherwise lies.
These rights are not absolute in every case. For example, data portability usually applies only to data you provided that is processed by automated means based on consent or contract; deletion rights may also be limited by tax, anti-fraud, legal process, and claims exceptions.
You may submit requests by email to [email protected]. Please state the type of request and the information needed to locate your account. We may require reasonable identity verification; authorized agents must also provide valid proof of authorization. Please do not send passwords, full payment-card numbers, or unnecessary identity documents by email.
Where the GDPR applies, we usually respond within one month of receiving the request; for complex or numerous requests we may lawfully extend by up to two months and will explain within the first month. Where CCPA/CPRA applies, we confirm and handle verifiable requests within the statutory period — typically 45 days — and explain any permitted extension. Other regions are handled under local statutory timelines.
Exercising the right to deletion may make features that depend on an account and cloud history unavailable; that is not discrimination for exercising rights. If we refuse or limit a request based on a legal exception, we will explain the reason and available appeal or complaint channels.
11.1 European Economic Area, United Kingdom, and Switzerland
You may complain to a supervisory authority in your habitual residence, place of work, or place of the alleged infringement. A list of EEA authorities is available via the European Data Protection Board website. If we have appointed an EU or UK representative, their details appear in Section 1.
11.2 California, United States
To the extent CCPA/CPRA applies to us, California residents may request to know the categories and specific pieces of personal information we collected, used, disclosed, sold, or shared during the statutory lookback period; request correction or deletion; and exercise applicable opt-out and limitation rights. Categories collected, sources, purposes, recipients, and retention criteria over the past 12 months are described in Sections 3, 7, 8, and 9.
11.3 Virginia, Colorado, Connecticut, and other applicable states
To the extent the relevant state laws apply to us, residents may exercise rights to access, correct, delete, obtain a copy, and opt out of targeted advertising, sale of personal information, or profiling that produces legal or similarly significant effects. If we deny a request, you may submit a “privacy rights appeal” through the privacy contact email after receiving our decision. We will respond as required by applicable law and tell you how to complain to a state attorney general or other competent authority.
Information Security and Incident Response
We use technical and organizational measures proportionate to the nature of the information and the risks involved, including encryption in transit, access controls, least privilege, authentication, audit logging, backup protection, vendor management, and incident-response procedures.
No system can guarantee absolute security. If a security incident affects your personal information, we will investigate, contain, and remediate it, and notify affected users and competent authorities within the timelines required by applicable law.
If you suspect unauthorized use of your account or information, contact [email protected] immediately.
Third-Party Services and External Links
The Service may link to Google Play, social platforms, or other third-party services. After you leave the Service or share content to a third party, that party processes information under its own terms and privacy policy. We encourage you to read those policies before use.
We do not rely solely on the fact that a third party has its own privacy policy to avoid our duties to review, contractually bind, and disclose our chosen service providers and SDKs.
Google Play Purchases, Subscriptions, and Refunds
Google Play handles billing for purchases completed through its billing system. We do not directly receive or store full bank-card numbers, but we receive purchase tokens, order details, and subscription status needed to verify entitlements and process orders.
Subscriptions automatically renew at the price and interval shown on the purchase page until canceled. The next renewal date is shown on the Google Play subscription page or purchase receipt. In Google Play, go to profile picture → Payments & subscriptions → Subscriptions, select AI Sweeter, and manage or cancel. Cancellation usually takes effect after the current paid period ends; uninstalling the App does not automatically cancel a subscription.
Refund eligibility is determined by Google Play rules, our refund policy, and applicable law. Users may contact Google Play or us. Where Play Console supports it and law or policy requires, we may be able to process full or partial refunds. Accordingly, we do not state that “refund authority belongs entirely to Google Play and developers cannot issue refunds.”
Complete commercial terms for purchases, renewals, cancellations, and refunds belong on the purchase page and in the User Service Agreement or separate subscription terms, and should not rely solely on this Privacy Policy.
Updates to this Policy
We may update this Policy from time to time. Updated versions will be published at the current URL with a revised “Last updated” date. For material updates that significantly affect your rights or change how information is used, we will provide prominent notice before they take effect through in-app notice, account email, or another conspicuous method.
Continued use of the Service does not replace consent required by law. If an update involves new processing that legally requires consent, we will obtain your affirmative consent separately before starting that processing.
Contact, Complaints, and Supervisory Authorities
If you have questions or complaints about this Policy, our processing of personal information, or a rights request, please contact:
If you are not satisfied with our response, you may complain to a competent data protection, consumer protection, or state supervisory authority. We encourage you to contact us first so we can investigate and resolve the issue promptly, but that does not limit your right to complain directly to a regulator.