Sticker Awesome — Privacy Policy
Draft. Not reviewed by a lawyer. Every claim here was checked against the code and the database schema, and each one says where it is enforced so it can be re-checked rather than taken on trust. Anything in double brackets is a blank only the company can fill.
Last updated: 6 October 2026 Operator: Digiposs LLC registered address Contact: support email
The short version
We collect an email address only if you choose to give us one — to sign in, or to be replied to if you report a concern about artwork. We count which stickers people keep, with nothing attached that could identify you. That is all. There is no advertising, no tracking across apps or websites, and nothing is sold or shared with data brokers.
What we collect, and why
An email address — only if you link one
The app works fully without an account. If you link an email we store the address and a session token for each device you sign in on.
We use it for exactly two things: signing you in, and attaching anything we give you directly to an account that is yours. We do not send marketing.
Anonymous sticker counts
When a sticker is kept or unkept we increment a counter. The row we write contains:
| the sticker's reference | AAA0-07 |
| what happened | kept or unkept |
| the date | not the time |
| a count | a number |
There is no identifier of any kind — no account, no device id, no session, no IP address, no advertising identifier, and no timestamp finer than the day. This is a property of the table rather than a promise about our behaviour: there is nothing in it to join to a person, including for us. It is enforced in server/schema.sql (sticker_signals).
We use it to see what people like, so we know what to license next.
A report about artwork — only what you type
If you use *Account → Art & licensing → Report a concern*, we store what you wrote, the art reference if you gave one, and an email address only if you chose to leave one. If you happened to be signed in, the report is linked to your account so we can reply; if you were not, it is not linked to anything.
Contact details are optional on that form on purpose: somebody raising a rights concern should not have to identify themselves to be heard.
We keep reports so we can act on them and show what we did about them, and we do not use them for anything else.
What we deliberately do not collect
- We do not know which stickers you send. iOS does not tell us. The Messages extension uses Apple's own sticker view, which handles the tap internally and reports nothing back. We could have replaced it to find out and chose not to, because it would have cost the drag-to-peel gesture and it is not ours to know.
- We do not read your messages. The extension cannot see your conversations, and it has no network access at all.
- No advertising identifiers, no cross-app or cross-site tracking, and therefore no App Tracking Transparency prompt — there is nothing to ask about.
- No analytics SDKs. Nothing third-party is embedded in the app.
What stays on your device
Your kept stickers, the sticker images themselves, your followed tags, and your free-allowance ledger all live on your iPhone, in the app's shared container. They are not uploaded. The session token, if you have one, is in the Keychain.
Deleting the app deletes all of it.
Purchases
Subscriptions are sold by Apple, and Apple handles the payment. We never see your card, your name, or your billing address.
Apple tells our server when a subscription starts, renews, lapses or is refunded. Those notifications identify the transaction, not you: we store the transaction identifier, the product, the status and the dates. Apple's own privacy policy covers what Apple collects.
Who we share it with
Nobody, other than the services that run the app:
| Apple | purchases and subscription status |
| Cloudflare | hosting, storage and the database |
| Amazon SES | sending sign-in codes |
Each is a processor acting on our instructions. We do not sell personal information, we do not share it for advertising, and we have no data brokers.
How long we keep it
- Account and email: until you ask us to delete it.
- Session tokens: until you sign out on that device.
- Sign-in codes: 10 minutes, then they are deleted. A used one is deleted immediately.
- Artwork reports: kept as a record of what was raised and what we did. Tell us if you want your contact details removed from one.
- Sticker counts: indefinitely — they are already anonymous, so there is no one for retention to protect.
- Purchase records: as long as needed for support and for tax and accounting obligations.
Your rights
Write to support email and we will:
- tell you what we hold for your address,
- correct it,
- delete it.
Deleting your account removes the email, the sessions and any membership we gave you directly. It cannot remove the anonymous counts, because there is nothing in them that points to you — that is the trade transparency makes.
Depending on where you live you may have rights under the GDPR or the CCPA/CPRA. We do not sell or share personal information as those laws define it. An EU representative may be required if the app is offered in the EU — for the company to determine.
Children
The app is not directed at children under 13 and we do not knowingly collect anything from them. If you believe a child has given us an email address, tell us and we will delete it.
Changes
If we start collecting something new we will say so in the app before it begins. We will not quietly broaden this.