Klarpix Privacy Policy
Last Updated: July 31, 2026
Public URL: https://klarpix.com/privacy
This Privacy Policy explains how Hangzhou Yangcongquan Cultural Innovation Co., Ltd. (Chinese registered name: 杭州洋匆圈文化创意有限公司), the operator of the Klarpix iOS application and related services (collectively, the “Services”) (“Klarpix,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects information and describes your choices and rights.
Privacy at a Glance
- Ordinary editing stays on your device. Importing, cropping, color adjustments, sharpening, noise reduction, presets, edit history, and exporting are performed locally on your device. We do not receive your photographs merely because you use those features.
- Each AI Restoration requires a separate upload. A selected photograph is sent to the identified service providers only after you choose the photograph, view the disclosure for that upload, and affirmatively tap “Agree and Restore.”
- Server-side photographs are processed briefly. Input and output copies used for AI Restoration are deleted from our proxy environment and the AI-processing environment within one hour after processing is completed. You control copies saved on your device.
- Use is strictly limited. We do not use AI photographs or results for advertising, cross-app tracking, identity recognition or authentication, creating databases of individuals, or training general-purpose or third-party AI models, and we do not permit service providers to use them for their own purposes.
- No sale or sharing for targeted advertising. We do not sell personal information, “share” personal information for cross-context behavioral advertising, or use targeted advertising.
- You may decline. You may cancel any AI upload and continue using local editing features that do not require uploading photographs.
1. Scope and Responsible Entity
This Policy applies to the Klarpix App, AI Restoration, purchase status, support communications, and processing related to the security of the Services.
The following third parties apply their own policies when independently determining the purposes and means of processing, and their processing is not controlled by this Policy:
- Apple’s processing in connection with the App Store, Apple ID, iCloud, iCloud Photos, iCloud Keychain, device backups, and payments (see the Apple Privacy Policy);
- Other applications or recipients you choose through system sharing features; and
- Third-party websites or services you choose to visit.
Klarpix is the entity responsible for the processing described in this Policy. Our contact information appears in Section 16.
2. Information We Process
The categories below identify the information, its source, processing purpose, potential recipients, and the retention period under our control.
On-Device Photographs, Editing Parameters, Edit History, and Exported Results
- Source: You and your device photo library
- Purpose: Perform local editing and exporting
- Potential recipients: Not sent to us; obtained only by system features or recipients you select
- Retention: Retained on your device until you delete them or clear App data, subject to Apple backup settings
AI Restoration Input Photographs and Server-Generated Results
- Source: A photograph you affirmatively select for each AI Restoration
- Purpose: Perform the requested AI Restoration, transmit data, and return the result to your device
- Potential recipients: Cloudflare, Inc.; Replicate, Inc.
- Retention: Server-side input and output copies deleted within one hour after processing is completed
Face-Related Visual Features
- Source: Pixels in a photograph you upload
- Purpose: Solely to improve clarity, color, texture, and visual detail
- Potential recipients: Same as the preceding category
- Retention: No identification template is created; if processing produces biometric information protected by law, it is permanently deleted within one hour after processing is completed
Network and Security Metadata
This may include an IP address, request time, random request ID, App version, device or operating-system type, response status, errors, and security events.
- Source: Automatically generated by the device, network, and proxy environment
- Purpose: Route requests, prevent fraud, enforce rate limits, troubleshoot, and maintain security and reliability
- Potential recipients: Cloudflare, Inc. and, where necessary, Replicate, Inc.
- Retention: Routine logs: no more than 30 days; confirmed security-incident records: no more than 12 months
Aggregated Operational Statistics
This may include daily request counts, success rates, and processing times.
- Source: Aggregated from operational data
- Purpose: Capacity, cost, reliability, and product planning
- Potential recipients: No external recipient; aggregated by us
- Retention: No more than 12 months, and only after the information cannot reasonably be linked to an individual
Apple Transaction and Entitlement Information
This may include product ID, transaction status, entitlement status, and Apple-generated transaction identifiers.
- Source: Apple
- Purpose: Verify purchases; deduct or restore entitlements; address purchase issues; prevent fraud
- Potential recipients: Apple Inc.; no third-party purchase-status management provider currently used
- Retention: As required by Apple policies and applicable legal recordkeeping obligations
AI Consent Records
This may include the policy or notice version, consent timestamp, and randomly generated request number. It does not include any photograph or information that identifies you or your device.
- Source: Generated when you tap “Agree and Restore”
- Purpose: Demonstrate that the particular upload was lawfully authorized
- Potential recipients: A local copy remains on your device; the consent timestamp, policy version, and random request number are transmitted with the restoration request and recorded on our proxy server
- Retention: Device copy retained until you uninstall the App or clear App data; server record retained for five years, consistent with applicable limitation periods, and not used for any other purpose during that period
Support Information
This may include your email address, messages, attachments, transaction information, and diagnostic information you choose to provide.
- Source: You
- Purpose: Respond to requests, troubleshoot, protect the Services, and address legal rights
- Potential recipients: Processed by us ([email protected]); professional advisers where necessary
- Retention: 24 months after the support matter is closed, unless longer preservation is required for legal claims or disputes
We do not require you to create a Klarpix account and do not collect your name, telephone number, or email address for login purposes. We do not collect advertising identifiers for tracking.
3. On-Device Processing
The following features operate locally on your iPhone and do not, merely by being used, send photographs to our servers:
- Importing photographs from your photo library or the system photo picker and generating thumbnails;
- Adjusting exposure, contrast, color, sharpness, noise reduction, crop, rotation, presets, and automatic adjustment suggestions;
- Saving editing parameters, edit history, and versions; and
- Saving, exporting, or sharing results through system features.
Photo-library permissions are managed by iOS. We recommend requesting only the scope of photo access necessary for the feature you choose and using the system photo picker, where practicable, instead of requesting access to your entire photo library.
Local photographs, editing data, Keychain information, and related backups are controlled by your device, Apple ID, iCloud, and system settings. Uninstalling the App may not delete information stored in Keychain, iCloud Photos, or device backups.
4. How AI Restoration Works
When you initiate AI Restoration, the App processes your request as follows:
1. You select a photograph;
2. The App compresses it on-device so that its longest edge is no more than 512 pixels;
3. The App displays a disclosure on the preview screen identifying the data, purpose, actual proxy and AI service providers (Cloudflare, Inc. and Replicate, Inc.), retention period, and restrictions applicable to that upload;
4. The photograph is transmitted over encrypted HTTPS only after you affirmatively tap “Agree and Restore”;
5. Cloudflare, Inc. processes the data solely for routing, security, and request management and forwards the photograph to Replicate, Inc.;
6. Replicate, Inc. processes the photograph solely to generate the result you requested;
7. The result is returned to your device; and
8. Server-side input and output copies are deleted within one hour after processing is completed.
Our proxy layer does not write photographs to persistent storage. It retains only short-lived task metadata required to complete a request (excluding photographs, for approximately two hours at most) and anonymous daily request counts (for no more than 12 months).
“Processing is completed” means that Replicate has generated the result or has determined that the request failed and ended processing. The one-hour period applies to server-side copies of photographs in the Cloudflare proxy environment and Replicate processing environment, including temporary caches. We do not place photographs in routine logs, long-term backups, training datasets, or human-review queues.
Network failures or security controls may prevent a request from completing. Even if a request fails, any photograph copy that reached a server must be deleted within one hour after processing for that request ends.
5. Faces and Information Potentially Protected by Biometric Laws
A photograph may contain a face. AI Restoration may analyze pixels, contours, textures, or other visual features to reconstruct or improve the photograph. The feature is not intended to identify or verify any person. We do not:
- Compare photographs against identity databases;
- Create, retain, or use facial templates or profiles of individuals for identification;
- Infer a person’s name, identity, health, race, religion, emotion, or other personal characteristics from a photograph;
- Use face-related data to make decisions about individuals;
- Sell, lease, trade, or otherwise profit from face-related data itself; or
- Permit service providers to use it for their own purposes.
Certain U.S. state laws distinguish ordinary photographs from a “scan of face geometry,” a “biometric identifier,” or biometric information used to identify an individual. We do not assume that every photograph constitutes biometric information. Nevertheless, as a heightened safeguard, if processing produces a biometric identifier or biometric information protected by applicable law, we apply the following publicly stated retention-and-destruction policy:
1. Purpose: Solely to complete the single AI Restoration expressly requested by the user;
2. Notice and consent: Provide written electronic notice and obtain affirmative electronic consent before each upload;
3. Disclosure: Disclose the information only to the service providers identified in the upload interface and Section 13, and solely to complete the request;
4. Retention: Process it only for the shortest period necessary to complete the request;
5. Destruction: Permanently delete server-side copies within one hour after processing is completed, and no later than when the original purpose has been satisfied;
6. Protection: Apply reasonable standards of care at least as protective as those applied to other confidential and sensitive information; and
7. Prohibitions: Do not sell, lease, trade, advertise with, train on, identify or authenticate with, or use it to create a database.
You may upload a photograph containing someone other than yourself. Before each upload, you must confirm that you are the relevant individual or that you have lawful authority and have obtained any consent required by applicable law. Your confirmation does not relieve us of any direct obligation we may have to that individual under applicable law. That individual or a lawful representative may contact us under Section 16.
Before each upload, the App uses a separate interface to disclose the purpose, recipients, one-hour deletion period, and use restrictions and requires you to affirmatively tap “Agree and Restore.” Consent must not be preselected, and consent given for an earlier upload must not replace consent for the current upload.
6. How We Use Information
We use the information identified in Section 2 only to:
- Provide the local or AI functionality you request;
- Route requests, return results, and verify purchases;
- Maintain reliability, troubleshoot errors, limit abuse, and protect security;
- Respond to support, privacy, and legal requests;
- Generate aggregated statistics that cannot reasonably be linked to an individual;
- Comply with applicable law and valid legal process and establish, exercise, or defend legal claims; and
- Pursue a materially different new purpose only after providing a separate, clear notice and obtaining new consent where required by law.
We do not use information obtained for one purpose in a manner incompatible with that purpose.
7. Activities We Do Not Conduct
Under the business practices described in this Policy, we do not:
- Sell personal information;
- “Share” personal information for cross-context behavioral advertising;
- Use targeted advertising or third-party advertising SDKs;
- Use advertising identifiers for tracking;
- Use photographs, results, or face-related information to train general-purpose AI models for Klarpix, a service provider, or a third party;
- Use that data for identification, authentication, profiling, or high-impact automated decision-making; or
- Permit service providers to use that data for their independent purposes.
If we propose to conduct any of these activities in the future, we must first update this Policy, reassess the applicable legal basis, and provide a separate consent or opt-out mechanism where required by law.
8. When We Disclose Information
We disclose information only in the following circumstances:
- Service providers. We disclose information necessary to perform a specified service to the proxy, AI-processing, purchase-status, support, and security providers identified in Section 13. Contracts should limit purpose and duration; prohibit sale, advertising, training, identification, and independent use; require reasonable security measures and assistance with rights requests; require notice if a provider can no longer comply; and permit audits or remedial action.
- Apple. Apple independently processes App Store purchases, refunds, system permissions, iCloud, and device services. We may exchange transaction and entitlement status with Apple.
- Professional advisers. We may disclose limited information where reasonably necessary to obtain legal, audit, financial, insurance, or security advice and where the recipient is subject to confidentiality obligations.
- Law and safety. We may disclose information where necessary and proportionate to comply with valid legal process or protect users, the public, the Services, or rights against fraud, unlawful conduct, or imminent harm. Unless expressly required by a valid legal obligation, we will not extend the one-hour operational retention period for AI photographs in response to a general legal request.
- Business transactions. In connection with a merger, financing, acquisition, reorganization, bankruptcy, or related transfer of assets, we may disclose necessary information to participants subject to confidentiality obligations. A successor must remain subject to this Policy and applicable law. If processing purposes materially change, we will provide separate notice and obtain consent where required.
- At your direction. We disclose information when you use system sharing functionality or expressly direct us to send information to a designated recipient.
9. Retention and Deletion
We apply data minimization and retain different categories of information according to the periods or criteria stated in the table in Section 2.
For AI Restoration:
- Server-side input and output copies are deleted within one hour after processing is completed;
- Photographs must not be placed in long-term logs, backups, training datasets, or human-review queues;
- We may retain only the minimum consent record, transaction record, and security metadata that does not contain a photograph or face-related data; and
- You delete originals and results stored on your device. We cannot remotely delete copies on your device, in iCloud, or already shared with third parties.
For other information, we may lawfully retain limited records for longer where necessary to complete transactions, comply with tax or recordkeeping obligations, address security incidents, or establish, exercise, or defend legal claims. Any exception will be limited to necessary information, access will be restricted, and the information will be deleted or de-identified when the relevant purpose ends.
10. Security
We use administrative, technical, and organizational safeguards appropriate to the nature of the information and the relevant risks, which are intended to include:
- Encryption in transit;
- Data minimization and short-lived processing of photographs;
- Prohibitions against writing photographs to routine logs or long-term backups;
- Access controls for production environments and service-provider access;
- Contractual restrictions on providers and deletion verification;
- Security-incident response and vulnerability management; and
- Periodic verification of data flows across the App, proxy, and service providers.
No system can be guaranteed to be completely secure. If a personal-information security incident occurs for which applicable law requires notice, we will notify affected individuals and relevant authorities as required by law.
You are responsible for protecting your device, Apple ID, photo library, iCloud account, and device-unlock credentials.
11. Your Choices and Privacy Rights
You may:
- Cancel any AI upload and continue using local editing;
- Control photo permissions through iOS;
- Delete photographs, results, and editing data stored on your device;
- Uninstall the App, although information in Keychain, iCloud Photos, or backups may remain under your Apple settings;
- Manage purchases, refunds, iCloud, backups, and synchronization through Apple; and
- Refrain from sending photographs or unnecessary sensitive information through support channels.
Subject to your place of residence, applicable law, and statutory exceptions, you may have the right to:
- Know or confirm whether we process your personal information;
- Access personal information or obtain a copy;
- Correct inaccurate personal information;
- Delete personal information;
- Obtain a portable copy;
- Opt out of sale, targeted advertising, sharing for cross-context behavioral advertising, or profiling that produces legal or similarly significant effects;
- Withdraw consent for future processing that relies on consent;
- Limit certain uses of sensitive information;
- Appeal our denial of a request;
- Submit a request through a legally authorized agent; and
- Exercise your rights without discrimination.
We currently do not engage in sale, targeted advertising, sharing for cross-context behavioral advertising, or high-impact profiling, so the related opt-out rights generally do not apply to the activities described in this Policy. If our practices change, we will provide any legally required mechanism before beginning the activity and recognize applicable universal opt-out preference signals.
How to Submit a Request
Email [email protected] with the subject line “Privacy Request” and describe the type of request and relevant activity. To appeal, use the subject line “Privacy Appeal.”
We may request information proportionate to the risk of the request to verify your identity or an agent’s authority, but we will not collect unnecessary government-issued identification or photographs solely for verification. Because the Services do not use accounts, photographs are deleted quickly, and most data remains on-device, we may be unable to reasonably locate information associated with you. We will explain the result rather than create a new, long-term identity profile for that purpose.
We will respond within the period required by applicable law. If we deny a request, we will explain the reason and available appeal process to the extent required by law. You may also complain to your state attorney general or another competent regulatory authority.
12. Children’s Privacy
The Services are not directed to children under 13, and we do not knowingly collect their personal information. Users between age 13 and the age of majority where they reside should use the Services only with permission and supervision from a parent or legal guardian.
If we obtain actual knowledge that a child under 13 submitted personal information through AI Restoration or a support channel, we will stop the relevant processing, investigate, and delete the information as required by law. A parent or guardian may contact us under Section 16.
We do not collect facial images or government-issued identification to verify age. Before introducing any age-verification process, we must separately evaluate and update the relevant notices, consents, providers, security measures, and deletion practices.
13. Service Providers and Processing Locations
Apple Inc. (App Store, Payments, iCloud, and System Services)
- Privacy Policy: Apple Privacy Policy
- Information received: Payment, transaction, device, and iCloud information independently collected by Apple; we receive only necessary transaction status
- Processing location: As described in Apple’s policies
- Key restrictions: Apple processes independently and does not provide us with your complete payment-card number
Cloudflare, Inc. (Proxy Infrastructure)
- Privacy Policy: Cloudflare Privacy Policy
- Information received: AI photographs, results, requests, and security metadata
- Processing location: United States and global edge locations
- Key restrictions: No persistent photo storage; no training, advertising, identification, or independent use; photo copies deleted within one hour
Replicate, Inc. (AI Processing)
- Privacy Policy: Replicate Privacy Policy
- Information received: AI photographs, generated results, and minimum request information
- Processing location: United States
- Key restrictions: Restoration only; no training, advertising, identification, or independent use; input and output deleted within one hour
Purchase-Status Management
- No third-party provider currently used. Entitlements are managed by Apple Inc. and the device Keychain.
Support and Email
- Processor: Hangzhou Yangcongquan Cultural Innovation Co., Ltd.; handled internally without a third-party customer-support SaaS provider
- Information received: Email address, messages, and attachments you voluntarily provide
- Processing location: China, where the operator is located
- Key restrictions: Support and rights requests only
Error and Security Monitoring
- No independent third party currently used. Cloudflare edge logs may contain IP addresses, request IDs, and similar metadata, but not photographs.
- Processing location: As described in Cloudflare’s policies; United States and global edge locations
- Key restrictions: Must not receive photographs; routine logs retained no more than 30 days
Before replacing or adding a service provider that receives AI photographs, we will assess its privacy, security, contractual safeguards, and deletion capabilities; update this list and the upload interface; and obtain new consent where required by applicable law.
14. Cross-Border Processing
The Services are initially offered in the United States, but the operator is located in China, and service providers and technical infrastructure may be located in other countries or regions. Your information may be processed in the locations identified in Section 13, where data-protection rules may differ from those in your place of residence.
We conduct cross-border processing only as described in this Policy and in accordance with applicable law. We use service-provider contracts, access restrictions, data minimization, and short retention periods to reduce associated risks.
15. Changes to This Policy
We may update this Policy to reflect changes in features, service providers, law, security, or business practices, and we will update the date at the top.
We will provide advance notice of material changes through an in-app notice or another reasonable method. If a change involves a new category of data, a materially different purpose, a new recipient of AI photographs, a longer photo-retention period, or a circumstance in which law requires renewed consent, we will obtain new affirmative consent before beginning the relevant processing.
Prior versions should remain available for reference. If you do not agree to a change, you may stop using the affected functionality before it takes effect.
16. Contact Us
Responsible Entity: Hangzhou Yangcongquan Cultural Innovation Co., Ltd.
Chinese Registered Name: 杭州洋匆圈文化创意有限公司
Registered Address: Room 42, Room 707, Building 2, No. 217 Wujiang Road, Shangcheng District, Hangzhou 310000, China
Privacy Contact: Privacy matters are handled through [email protected]; no separate Data Protection Officer has been appointed.
Telephone: No public customer-service telephone number; please contact us by email.
Privacy and Support Email: [email protected]
Public Webpage: https://klarpix.com/privacy