Gnocchi Privacy Policy
Effective date: July 28, 2026
Gnocchi creates playful image transformations from photos that you choose. This policy describes the information the app processes, why it is used, and the choices available to you.
Information Gnocchi processes
- Photos and generated images. The app accesses only the individual photos you explicitly select through the system photo picker; it has no access to the rest of your photo library. Selected photos are copied into the app and uploaded to private Cloudflare R2 storage. A selected photo is uploaded to WaveSpeedAI for automated safety screening and, only if it passes, editing by Google’s Gemini image model. The result is safety-screened before delivery. Source and generated images are associated with an anonymous account identifier issued by Firebase Authentication so the app can retrieve the correct images.
- Subscription information. The app sends Apple-signed transaction data and the current time-zone identifier to the service to confirm access and schedule the daily image. Purchases and billing are handled by Apple; Gnocchi does not receive your payment-card details.
- Push tokens. If Apple supplies a widget push token, the app sends it to the service so the widget can be notified that a new image is available. If you allow notifications, the app also sends an Apple notification device token so the service can deliver a short “ready” notification when the daily image has arrived. Allowing notifications is optional; declining only means the ready notification is not sent.
- Service and network information. Cloudflare automatically processes network information such as an IP address. The Worker logs request details — a request identifier, endpoint path, response status, duration, and error messages — and may log the anonymous account identifier, photo identifiers, and image-safety screening outcomes for security, reliability, and troubleshooting. Photo contents are not written to these logs.
- On-device preferences and files. The app and widget share onboarding state, subscription status, the widget push token, selected photos, and recent generated images in their private App Group container. The anonymous account identifier is stored in the device keychain.
Gnocchi does not use this information for third-party advertising, does not sell it, and does not track you across other companies’ apps or websites.
How information is used
Information is used only to provide the app: upload photos you select, generate and deliver prank images, maintain subscription access, schedule the daily drop, support the widget, prevent unauthorized access, and troubleshoot service errors.
Service providers
- Apple provides App Store purchases, StoreKit transaction data, photo-picker APIs, widget delivery, and Apple Push Notification service.
- Cloudflare provides the Worker API, private R2 object storage, and KV storage.
- WaveSpeedAI provides temporary inference media hosting, automated image safety screening, and access to the Gemini image-editing model.
- Google provides the Gemini image-editing model, anonymous Firebase authentication, and App Check device attestation used to block unauthorized clients. Google receives the selected photo through WaveSpeedAI for the requested image edit.
These providers process information under their own terms and privacy policies.
Retention and deletion
Generated cloud images are configured for automatic deletion after one day. Selected source photos remain in private cloud storage while needed to provide daily generation. Subscription state, time zone, the anonymous account identifier, and push tokens remain while the service is active for that installation. WaveSpeedAI documents that media uploaded for inference is retained for seven days and then automatically deleted.
Use Settings > Delete all my photos & data to request deletion of selected source photos, generated cloud images, subscription state, time zone, and push tokens for the current installation, and to remove the app’s local photo and image data. A record linking the App Store subscription transaction to the anonymous account identifier persists until shortly after the current subscription period ends, then expires automatically. Deleting the app removes its local container but may not itself send the cloud-deletion request, so use the in-app control first. Apple retains App Store purchase records under Apple’s policies. Cloudflare and WaveSpeedAI may retain limited security and operational records under their service configurations and policies.
Security and international processing
Gnocchi uses HTTPS for network transfers and private cloud storage. No security method is guaranteed to prevent every incident. Cloudflare, WaveSpeedAI, or Apple may process information in countries other than the one where you live.
Children and photo permissions
Gnocchi is not directed to children below the minimum age required to consent to data processing in their country. Only upload photos that you have the right and permission to use, especially photos of another person or a child.
Changes and contact
Material changes will be reflected by updating the effective date. Questions or privacy requests, including data-deletion requests, can be sent to shubhamapadia@gmail.com.