Privacy Policy
1. Who the app is for
Wallnote Gallery is designed for parents and other adults. Accounts are adult-owned. We do not offer child logins. Information about children (such as a first name and age band you enter, and photos of artwork) is provided by the adult account holder and treated as personal information under laws such as COPPA (US) where applicable.
2. Information we collect
Depending on how you use the app, we may process:
- Account data: email / auth identifiers from Firebase Authentication (and Sign in with Apple if enabled).
- Family and profile data: family membership, invite codes, child display names and age bands you create, and (if you consent to AI notes) a record that you agreed to send artwork to our AI provider.
- Artwork content: photos you upload (stored as compressed JPEG images), captions/notes you write, and optional AI-generated notes you choose to create or keep.
- Viewing-link records: when an adult creates a share link, we store a hash of the secret token (not the raw token), the family/child scope, the creating parent, expiry, and a revoked flag. Opening a link may record coarse rate-limit counters (hashed IP / hashed token) to prevent guessing and abuse.
- Usage and security signals: daily upload counters, per-artwork AI generation counters, basic app diagnostics (for example crash reports via Sentry with default PII sending disabled).
- Product analytics (parent account): if you leave analytics on, PostHog (US cloud,
https://us.i.posthog.com) receives parent actions such as onboarding steps, sign-up and sign-in, creating a child profile, uploading artwork, choosing a frame, using rotate or crop, generating or viewing an AI note, saving a copy to Photos, creating or opening a grandparent viewing link, and toggling the by-age wall. Properties are counts and fixed labels (for example an age band or frame style). We identify the account with a hash of the Firebase user id only. We do not send artwork images, child names, birth months, AI note text, emails, or anything you type. Session replay is off, text-field autocapture is off, and we ask PostHog not to derive location from IP. This is on by default for the parent account. Turn it off in Family, then About this gallery. It is not linked to a child profile and is not used for advertising. - Push notifications (optional): if you allow notifications, OneSignal delivers them to this device. We ask only after you save a first drawing, not at launch. We register the device with your Firebase user id so a reminder can reach that parent account. Messages we send are an "on this day" memory (a drawing from a prior year) and, when someone opens a viewing link, a notice that the link was opened. The text says "your little artist" and does not include a child's name, a photo, or note text. A development build signed with a free Personal Team cannot register for push.
- Device permissions you grant: Camera, Photo Library (add-only where applicable), and Notifications if you allow them. They are used only to capture or save artwork you choose, or to deliver the reminders above.
A parent may enter a child's birth year and month, not the day, so we can calculate age.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use advertising trackers or cross-app tracking. Product analytics and push, when enabled, are for operating Wallnote Gallery for the parent account.
3. How we use information
- Provide the private family gallery, sync, export, and adult-created viewing-link features you request.
- Enforce abuse limits: 10 uploads per parent per calendar day (UTC), 2 successful AI museum notes per artwork, and 20 successful AI museum notes per parent per calendar day (UTC). Failed AI attempts do not count toward either AI cap.
- Generate an optional museum-style note only after you give a separate consent and tap generate. The consent screen names the active AI provider before you agree. Notes remain editable and are meant to stay in the family gallery.
- Maintain security, debug crashes, and operate the service.
- Comply with law and respond to valid requests from the adult account holder.
4. AI processing
Active provider: Cloudflare Workers AI (Google Gemma model). While this page is published, optional museum notes are sent only to Cloudflare Workers AI, not to Google Gemini, Alibaba Cloud Model Studio, or OpenRouter. Cloudflare processes those requests on its network to provide Workers AI and states that it does not use them to train the models on Workers AI, or to improve Cloudflare or third-party services, without separate consent. The in-app consent screen names Cloudflare Workers AI before you agree.
Museum notes are optional. We do not send a drawing to an AI provider when you upload it.
The first time you tap Generate museum note or Regenerate, the app asks for a separate consent. That consent is separate from creating your account, from product analytics, and from notifications. The consent screen names the AI provider that will receive the drawing before you agree. If the app cannot confirm that provider, it does not name one and does not send the drawing. You can skip and write your own note.
Only when a parent gives that consent and taps Generate do we send the selected artwork JPEG, the child's first name, and their age band to the one provider in the section below. We do not send that drawing to any other AI provider at the same time. The hosted copy of this policy includes only the section for the provider that is active when the page is published. The in-app copy shows the Cloudflare Workers AI section. The consent screen names the same provider.
Cloudflare Workers AI (Google Gemma model)
Used when Cloudflare is the active provider. We send the artwork JPEG, the child's first name, and their age band to Cloudflare Workers AI. The model is a Google Gemma model hosted on Workers AI. The default model id is @cf/google/gemma-4-26b-a4b-it. Cloudflare processes that request on its network to provide Workers AI.
Cloudflare states that it does not use this content to train the models on Workers AI, or to improve Cloudflare or third-party services, unless you give separate consent. Cloudflare does not make that content available to other Cloudflare customers. Cloudflare does not create or train these models. The model is a third-party model hosted on Workers AI and may have its own license terms. Those statements are from Cloudflare's Workers AI data-usage terms, published at developers.cloudflare.com/workers-ai/platform/data-usage (page dated April 21, 2026).
While Cloudflare is active, that drawing is not sent to any other AI provider.
You can skip, write your own note, or edit or replace anything the model returns. You may later revoke that consent in Family, then About this gallery. We will ask again before the next generate.
Each artwork may receive 2 successful AI generations. Each parent may receive 20 successful AI generations per calendar day (UTC). Failed, empty, or timed-out drafts do not count. The first successful note uses Generate. One more successful note uses Regenerate. After two successful notes, AI generation is unavailable for that drawing and you can still write your own. Hitting a cap does not hide photos already in the gallery.
Do not tap Generate if you do not want that image and those child fields processed by the provider named on the consent screen.
5. Storage and processors
We use the following processors to run Wallnote Gallery:
- Google Firebase and Google Cloud (Authentication, Firestore, Cloud Functions, and Hosting): accounts, metadata, captions, business logic, and the read-only viewing page.
- Cloudflare R2: compressed artwork JPEG files.
- Cloudflare Workers AI (Google Gemma model): drafts the optional museum note when Cloudflare is the active provider, only after you consent and tap generate. Cloudflare processes the request on its network to provide Workers AI. Cloudflare states that it does not use those inputs or outputs to train the models on Workers AI, or to improve Cloudflare or third-party services, without separate consent, and does not make that content available to other Cloudflare customers.
- PostHog (US cloud): product analytics for the parent account, as described above. Not used for advertising and not linked to a child profile.
- OneSignal: push notification delivery to the parent's device, only if you allow notifications.
- Sentry: crash and error monitoring, configured to avoid sending default personal data, artwork, or child names.
Data is processed in regions configured for these services (our Functions are deployed in us-east1 unless changed).
6. Sharing
We share data with the processors above to run the app, and with other adults you invite into your family. An adult may also create an unlisted viewing link for one child's gallery. Anyone who has that exact URL can view that child's artwork and captions in a browser until the link expires or a parent revokes it. Viewing links are read-only (no upload, no AI generate, no family admin). Images are delivered through short-lived signed URLs, not long-lived public object links. This is not a public social feed. We do not list families or galleries for discovery. We may disclose information if required by law or to protect safety and the service.
We do not sell personal information. We do not share it for cross-context behavioral advertising.
7. Data retention
This is our written retention policy for personal information, including information about children.
We keep personal information only for the purpose it was collected, and only while that purpose still needs it. We do not keep children's personal information indefinitely.
- Account, family, and child profile. Purpose: run the private gallery the parent asked for. Kept while the adult account and that family gallery exist. Deleted when you delete the child album or delete the account, as described below. Business need: the gallery cannot show the family without this data.
- Artwork photos and notes, including an AI note you chose to keep. Purpose: show the drawing in the family gallery and on a viewing link you create. Kept while that drawing remains in the gallery. Deleted when you delete the drawing, the album, or, if you are the only parent, the account. We try to delete the stored photo at that time. If a storage delete times out, the file may remain until a later cleanup. Residual photo files after a timed-out delete are removed within 30 days. Business need: you asked us to keep the memory until you delete it.
- AI request sent to the active provider. Purpose: draft the note you asked for. We do not keep a separate copy of the prompt beyond the note you save in the gallery. The provider's own retention is described in the AI section for the active provider. Business need: one request to draft one note.
- Viewing-link records. Purpose: the read-only link you created. The link works until it expires or a parent revokes it. You choose 7, 30, or 90 days when you create it (90 days is the maximum). We store a hash of the token, not the raw token. The record is deleted with the family data it belongs to when that album or sole-parent account is deleted. Business need: open the link only for people you gave it to, and stop it when it expires or you revoke it.
- Rate-limit counters. Purpose: stop guessing and abuse. Link-open counters are kept for about 10 minutes. Counters for how many links a family creates are kept for about one day. They are hashes, not a profile of a child. Business need: protect the gallery.
- Upload tickets and signed URLs. Purpose: one upload or one read. An unused upload ticket expires after about 10 minutes. A signed read URL expires after about 15 minutes. Business need: move the photo without a long-lived public link.
- Product analytics. Purpose: understand how the parent account uses the app, if you leave analytics on. We stop sending new events when you turn analytics off or delete the account. We do not use these events for advertising. Business need: operate the parent experience. Events already stored at PostHog follow that processor's schedule. We do not ask PostHog to keep them for advertising.
- Push registration. Purpose: deliver a notification you allowed. Kept while this device is registered and you allow notifications. We stop sending when you turn notifications off. The message text does not include a child's name, photo, or note. Business need: the reminder you allowed.
- Crash diagnostics. Purpose: fix failures. Sentry is configured not to send default personal data, artwork, or child names. Business need: keep the app working.
After you delete an account or album, we delete or anonymize the related account data, and we delete residual photos within the cleanup period marked above, except where the law requires us to keep something or we need it for security or fraud.
You may export artwork copies from the iOS app: a single JPEG (share sheet or save to Photos), Save for frame (a JPEG in Photos for a digital photo frame, with the drawing's frame baked in when it has one, up to 50 at a time), or a gallery Export ZIP of up to 50 JPEG copies. Failed downloads are skipped. Frame JPEGs and the ZIP are built on your device. We do not send artwork to digital-frame companies.
You can delete a child's album in the app: open Family, tap the child, then Delete [name]'s album. After you confirm, we delete that child profile, their artwork metadata, and we try to delete their stored photos on R2. Other children's albums stay.
Account deletion is available in the app (not email-only): open Family, then About this gallery, then Delete Account. If you have not joined a family yet, open About and Delete Account on the family setup screen. You confirm with a warning, then type DELETE.
- If other parents remain in your family, we remove your membership and profile. The shared family gallery and artwork stay with them (including pieces you uploaded). If you are the current family owner, ownership transfers automatically to another remaining parent so the family can still manage invites and members.
- If you are the only parent, we dissolve that family: child profiles and artwork metadata are deleted, and we try to delete the stored photos. Some photo files may remain until the cleanup period above if storage deletion times out.
- We then delete your profile and Firebase Authentication user and sign you out on this device. If you signed in with Apple, we revoke the Sign in with Apple token for this account when that revocation is configured and we still have the token from sign-in. We also delete the product analytics record for this parent and the push notification user for this account when those services are on. If they are off, nothing is sent to them.
For help, email support@wallnoteapp.com. For privacy or COPPA/parent requests, email privacy@wallnoteapp.com. We delete or anonymize remaining account data within a reasonable period except where retention is required by law or for security/fraud.
8. Children's privacy
Wallnote Gallery is a parent tool. We collect information about children from the adult account holder, not through a child-directed login. Under COPPA, that information (first name, age band, and photos of artwork that may include a child) is treated as personal information.
Separate parental consent for non-essential disclosure. Creating an account lets us store the gallery with service providers that only run the feature you asked for (Google Firebase and Google Cloud for the account and metadata, and Cloudflare R2 for the photos you upload).
Sending a child's artwork, first name, and age band to an AI provider is not required to store the drawing. We ask for a separate parental consent on the consent screen before the first Generate or Regenerate. That screen names the provider before you agree. You can refuse and write your own note. Product analytics and push notifications are separate choices. Agreeing to an AI note does not agree to analytics or push. Leaving analytics on does not agree to send a drawing to an AI provider.
We do not disclose children's personal information to third parties for those parties' own advertising, for sale, or for those parties to train their models. The AI provider named on the consent screen may process the one request as described in the AI section. A further, separate consent would be required before that content is used to train a model.
Parents and guardians may review, export, or delete child-related gallery content through the adult account: delete a single drawing, delete a child's entire album, or delete the adult account. You may also contact us at privacy@wallnoteapp.com.
Product analytics and push notifications describe how the parent uses the app. We do not create child accounts, and we do not send children's names, birth dates, photos, or notes to PostHog or OneSignal. Analytics may include a fixed label such as an age band or frame style, tied to a hash of the parent account, not to a child profile.
9. Information security program
We maintain a written information security program for personal information, including children's information. It is scaled to a small family gallery.
The program includes: the Wallnote privacy team, reachable at privacy@wallnoteapp.com, who coordinates it; access limited to signed-in adult accounts; server-side checks so one family cannot read another's gallery; hashed viewing-link tokens; rate limits; short-lived signed URLs for upload and read; crash reports configured not to attach artwork or default personal data; and terms with the processors above that limit their use of the data to providing the service. We review the safeguards when we add a processor or change what we collect.
A viewing link is unguessable but works like a password: only share it with people you trust. No method of transmission or storage is perfectly secure.
10. Your choices
- Turn off product analytics in Family, then About this gallery. It is on by default for the parent account.
- Decline notification permission when asked after the first saved drawing, or turn notifications off in iOS Settings.
- Decline AI generation, write notes yourself, or revoke AI consent in About this gallery. AI consent is separate from account creation.
- Export a single JPEG, save JPEGs to Photos for a digital frame, or export a gallery ZIP of up to 50 copies from the iOS app.
- Create, expire, or revoke viewing links from Family in the app.
- Delete a child's album from Family, then that child's settings.
- Limit Photo or Camera permissions in iOS Settings (some features will not work).
- Delete your account in the app from Family, then About this gallery, then Delete Account (not email-only).
- Send a Global Privacy Control signal from your browser when you visit our website. We treat it as an opt-out of sale and sharing. See the California section.
- Review this policy when we update it (the date above will change).
11. California privacy rights (CCPA / CPRA)
This section applies to California residents. It supplements the rest of this policy.
Categories we collect. In the 12 months before the date above, we collect these categories for the purposes in this policy:
- Identifiers, such as an email address, a Firebase account id, a hash of that id for analytics, and a push token if you allow notifications.
- Customer records, such as family membership, a child's first name, birth year and month, and age band.
- Visual information, the photos of artwork you upload.
- Internet or network activity, parent actions if analytics is on, and coarse rate-limit counters (hashed IP or hashed token) when a viewing link is opened.
- Inferences, the optional AI note, only if you choose to keep it.
- Sensitive personal information, information about a known child (first name, age, and artwork photos).
We do not collect precise geolocation, payment card numbers, or government identification numbers. We ask PostHog not to derive a location from IP.
We do not sell or share. We do not sell personal information. We do not share personal information for cross-context behavioral advertising. "Share" in this section has that California meaning, not the family viewing link you choose to create.
Global Privacy Control. If your browser sends a Global Privacy Control signal (Sec-GPC) to our website, we honor it as a request to opt out of sale and sharing. Because we do not sell or share, the signal does not switch on a sale. You can also turn off product analytics in the app. The iOS app itself does not receive a browser GPC signal.
Your requests. You, or someone you authorize, may ask us to:
- Know and access the categories and specific pieces of personal information we have about you.
- Delete personal information, using the in-app delete tools or a request to the privacy contact.
- Correct inaccurate personal information (for example a child's first name or birth month, which you can also edit in the app).
- Opt out of sale or sharing. We will confirm we do not sell or share.
- Limit the use of sensitive personal information to what is necessary to provide the gallery you asked for, and to the optional AI note only after the separate consent above.
- Not be discriminated against for exercising these rights. The app does not charge a different price or change the gallery because you make a request.
Send requests to privacy@wallnoteapp.com, or use the in-app delete and edit tools. We will confirm we received the request and respond within 45 days. If a request is complex or you have sent several, we may extend that once by another 45 days, and we will tell you why within the first 45 days. We may need to verify that you are the adult account holder before we complete a request. We will not ask you to pay a fee for a request unless the law allows it because the request is manifestly unfounded or excessive.
12. Other US state privacy laws
If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another US state with a consumer privacy law, you may have similar rights to access, correct, delete, and obtain a copy of your personal information, and to opt out of sale, targeted advertising, and certain profiling. We do not sell personal information and we do not use it for targeted advertising or for profiling that produces a legal or similarly significant effect.
Children's data is sensitive. Information about a known child is sensitive personal information under these laws. We process it to provide the family gallery the parent requested. We send it to an AI provider only after the separate parental consent described above. We do not sell it.
Appeal. If we deny a privacy request, you may appeal by replying to that decision through the privacy contact. Tell us you are appealing and include the date of the denial. We will respond to the appeal within 45 days. Where the state's law allows up to 60 days to decide an appeal, we may use that longer period if we need it, and we will tell you. If we deny the appeal, we will explain how to contact your state attorney general when the law gives you that right.
13. International users
If you access the service from outside the United States, you understand your information may be processed in the US or other countries where our processors operate.
14. Changes
We may update this policy. Continued use after an update means you accept the revised policy, unless applicable law requires otherwise. If a change materially reduces how we protect children's information, we will ask for consent again where the law requires it.
15. Contact
Questions, COPPA or parent requests, and privacy rights requests: privacy@wallnoteapp.com Help: support@wallnoteapp.com
Operator: FengShui Master AI Inc. Mailing address: FengShui Master AI Inc., 13740 N Highway 183 Ste L2 #409, Austin, TX 78750
Retention schedule
- Gallery data is kept while the gallery exists.
- Residual photos are removed within 30 days.
- Share-link records are kept for 30 days after expiry or revocation.
- Rate-limit counters are kept for 7 days.
- PostHog data is kept for 12 months.
- Sentry data is kept for 90 days.
- A gallery that stays inactive for 3 years is deleted after a 30-day email notice.