Chupian Privacy Policy
Version 1.4 Published and effective: September 4, 2026
AI CORTEX NEXUS LIMITED ("we", "us", or the "Company") operates Chupian. This policy explains how the Chupian iOS app, websites, APIs, customer support, and related services collect, use, store, disclose, transfer, protect, and delete personal data.
Please read this policy before using Chupian. We provide a prominent notice and request explicit consent before a photo is first sent for AI processing. If cross-app tracking or an advertising identifier is involved, we separately request permission through Apple's App Tracking Transparency (ATT) framework. Refusing ATT does not affect login, retouching, saving, or purchases.
1. Scope
This policy applies to the Chupian app and the services directly required to operate it. A service provider acting on our instructions may process only the data necessary for its assigned service. If a third party independently determines a different purpose or method, its own terms and legal obligations apply.
2. Data we process
2.1 Account and identity data
We process your phone number and temporary verification code for registration, login, account recovery, security checks, and essential notices. If you choose Sign in with Apple, we receive the stable identifier and any email or relay address that Apple makes available with your authorization. We also process your Chupian user ID, account status, and authentication tokens. We never receive your Apple password.
2.2 Photos that may contain faces, editing instructions, and results
When you choose and submit a photo, we process the original photo and optional reference images; marks, normalized coordinates, quick prompts, text instructions, brush paths, removal masks, output ratio and size; task status and processing stage; generated result, thumbnail, and original/result relationship; and the history and continuation relationship for that task.
Photos may contain a person's face, body, surroundings, text, location clues, or camera metadata. In this policy, photos containing a face and their related editing information are called face-containing photos and related data.
Chupian does not access Face ID or TrueDepth data. We do not create face templates, biometric identifiers, facial feature vectors, face meshes, or identity profiles. We do not use a face to identify, authenticate, track, profile, or advertise to a person. Face-containing photos and related data are used only to perform the retouching or removal requested by the user, return and display the result, maintain the user's history, permit continued editing, recover a task, and investigate a service failure. We do not sell this data or use it to train general-purpose AI models.
Do not upload identification documents, bank cards, medical records, intimate images, sensitive images of minors, or any material you are not authorized to process.
2.3 Purchases and entitlements
We process Apple product and transaction identifiers, original transaction identifier, purchase and expiry times, subscription status, refund or revocation status, credit balance, expiry, and usage records. We do not receive your full card number or Apple payment password.
2.4 Device, network, interaction, and diagnostic data
We may process device model, OS and app version, language and region, a random app/device identifier, IDFV, IP address, network type, request time and path, task status, error code, crash or performance information, and security events. Minimal interaction events can include login method and new-user status, image source type, editing mode, number of quick prompts or marks, whether a custom request was entered, success/failure category, duration band, save action, membership-page view, product identifier, price, currency, and a hashed transaction identifier.
IDFA is accessed only after ATT permission. We do not send Google or Meta any photo pixels, face data, reference images, marks, masks, prompt text, phone number, email address, Chupian user ID, task ID, or image/result URL.
2.5 Support data and permissions
If you contact support, we process the issue, contact details, relevant task ID, screenshots or attachments, and communications. Photo read access is used only when you choose an image; photo add access is used only when you save a result. We do not scan your entire photo library.
3. Purposes
We use data to create and secure accounts; process and deliver AI edits; calculate, deduct, refund, and display credits; validate Apple purchases; provide history and continued editing; respond to support; prevent fraud and abuse; monitor reliability; analyze product use and conversion; measure our own Google and Meta advertising after the required consent; comply with accounting, legal, audit, and dispute obligations; and protect users and the service.
We do not sell personal data, use face-containing photos for advertising or profiling, or make a solely automated decision that has a significant legal or similarly serious effect on a user.
4. AI processing and explicit consent
Before the first AI task, Chupian explains that the original photo, optional reference images, marks, masks, text instructions, and output settings required for the task will be transmitted over an encrypted connection to necessary third-party AI image-processing providers, and asks for explicit consent. Without consent, no AI task is submitted. Consent can be withdrawn for future tasks; withdrawal does not undo processing already lawfully completed.
Providers are authorized only to process the data necessary to complete the requested task, maintain security, and meet legal obligations. We do not authorize identity recognition, advertising, data brokerage, unrelated profiling, or general-purpose AI training. Providers and routes may change for quality, availability, and regional operation, but we require equivalent purpose limitation and data protection. We update this policy and obtain any required new consent before a material change.
5. Disclosure and service providers
We disclose only the minimum necessary data to:
- Apple and its affiliates for app distribution, Sign in with Apple, in-app purchases, subscriptions, permissions, and privacy-preserving attribution;
- NetEase Yunxin and configured messaging providers for login verification;
- Alibaba Cloud OSS or another configured infrastructure provider for object storage, delivery, databases, queues, logs, backup, and recovery;
- necessary third-party AI image-processing providers for the retouching, removal, or generation task you submit;
- Google Firebase Analytics for product analytics and Google campaign attribution; and Meta App Events for Meta campaign attribution and optimization;
- professional advisers, transaction participants, or competent authorities when legally necessary.
Photos and face data are not disclosed to Google or Meta for analytics or advertising. We use contractual terms, published processing rules, encryption, access control, minimization, and audit measures appropriate to each provider.
6. International transfers and storage location
Chupian is currently offered in Hong Kong, Macao, Taiwan, Singapore, Japan, South Korea, and the United States. During the current transitional deployment, account data, task records, original and reference photos, masks, results, and history under our control are transmitted to and primarily stored on servers, databases, and object storage located in mainland China. For users outside mainland China, this is a cross-border transfer.
Necessary task data may also be transmitted to the infrastructure used by the selected AI provider. Google and Meta may process minimal device, interaction, and purchase events on their global infrastructure, but they do not receive face-containing photos or related editing data.
We plan to migrate services and data for regions outside mainland China to a Japan region when operationally ready. Until migration is completed, Japan is a plan rather than the current storage location. Before a material change to the actual location or transfer path, we will update this policy and provide any legally required notice or consent.
7. Retention and deletion
- Account data is kept while the account exists. After an account-deletion request, and absent a legal hold or dispute, we normally delete or anonymize the account and files under our control within 15 business days.
- Verification codes are valid for five minutes. Delivery and security logs are retained only as needed for fraud prevention, audit, and law.
- Original photos, reference images, masks, results, thumbnails, and task history for a successful task are retained while required to provide history, continued editing, and re-download, up to account deletion or a verified image-deletion request.
- Not tapping “Save to Photos” only means no extra copy was written to the device. If the task remains in Chupian history, its images may remain on our server.
- Deleting a history item removes it from the history interface. To request deletion of associated server files, email us. We normally complete a verified request within 15 business days. Account deletion triggers deletion of account-associated images.
- A copy saved to Apple Photos is independently controlled by your device and any iCloud Photos settings. Removing a Chupian record does not remove that local copy.
- Purchase and accounting records are kept as necessary for tax, fraud, refund, and dispute obligations. Operational and security logs are kept for the shortest necessary period and normally contain task identifiers and error data, not the original face photo.
- Firebase user-level event retention is configured to two months with reset-on-new-activity disabled. Aggregated or de-identified reports and data required by a provider for security or law follow the applicable provider rules. We do not separately store IDFA in our business database.
8. Security
We use HTTPS, authentication, role-based access, database isolation, protected credentials, encryption where appropriate, rate limiting, monitoring, audit logs, backups, and confidentiality obligations. No internet service can guarantee absolute security. If an incident may materially affect users, we will investigate, mitigate, notify affected users and authorities when required, and provide practical protective steps.
9. Your choices and rights
Subject to applicable law, you may request access, a copy, correction, deletion, restriction, or an explanation; withdraw a revocable consent; object to unnecessary processing; delete an individual record; delete your account in Profile — Settings — Delete Account; or make a complaint. We may verify identity and normally respond within 15 business days.
Photo and tracking permissions can be changed in iOS Settings. Withdrawing ATT permission does not affect core functionality. Deleting a Chupian account does not cancel an Apple subscription; manage or cancel it in your Apple account subscriptions.
10. Children
Chupian is not directed to children. Users under 18 should use it with a guardian's guidance, and processing of a child's personal data requires the consent required by applicable law. A guardian may contact us to request access, correction, or deletion.
11. Analytics and advertising attribution
Chupian does not display third-party ads. Firebase Analytics and Meta App Events help us understand product performance and measure advertising for Chupian. Without ATT permission, the app does not access IDFA or perform IDFA-based cross-app tracking, although privacy-preserving attribution and non-photo basic analytics may still operate. After ATT permission, permitted identifiers, product interactions, and purchase events may be used for attribution and optimization. You can withdraw ATT permission at any time.
12. Policy updates
We may update this policy for legal, operational, technical, provider, or product changes. Before a material change to purposes, data categories, sharing, location, or rights takes effect, we provide a prominent notice and obtain renewed consent where required. The online page shows the current version.
13. Contact
Controller and operator: AI CORTEX NEXUS LIMITED Product: Chupian Privacy email: aotemanai2023@163.com
We normally respond to a complete request within 15 business days, subject to any mandatory local deadline.