Privacy Policy
Boxpop is an on-device Zine creation app. Choose photos to generate an initial layout, continue editing, and export finished pages or other supported media formats to Photos.
Data we collect
After you accept the privacy notice, Boxpop collects basic analytics and diagnostics, such as device identifiers, app launches, activity, version, distribution channel, feature usage, crashes, and performance data. We use this information to understand organic growth, stability, usage trends, and reliability issues. Boxpop does not collect advertising identifiers for tracking across apps or websites.
After you accept this version of the policy, Boxpop uses the Tencent Cloud CLS SDK to report play entries, editor opens, export starts, and save results for Zine, free collage, receipt diary, film roll, style, outline, halftone, imprint, tracking, and fingerprint; actions and results involving membership; the identifier of the published template you apply; template loading stages and durations; bytes transferred; cache results and HTTP status codes; app version and build number; iOS version, language, region format, and device time zone; and random identifiers for events, sessions, membership page visits, and purchase attempts. This helps us understand feature usage, stability, content planning, and membership conversions. We do not upload media, text in your creations, file paths, payment accounts, receipts, transaction IDs, or specific purchase amounts to CLS.
To measure installation activity, retention, and conversions across launches, Boxpop generates a random installation identifier when you first consent, saves it locally, and records when it was first recognized. The identifier is reused for later launches of that installation. It contains no name, does not use IDFA, and is not used for advertising tracking across other companies' apps or websites. Deleting and reinstalling the app usually creates a new identifier; restoring a system backup may preserve it. The first-recognized time is not the actual download time, and an installation does not necessarily represent one person.
To count how many installations have used each template, Boxpop sends the template identifier and a deduplication key derived from the installation identifier above to the Boxpop template server over HTTPS when you apply a published template. The server stores only the SHA-256 digest of that key to count unique usage per template. It does not store the original value, does not store your creations, and does not use it to identify you. The derived key is not the same value as the installation identifier in analytics logs. Only one persistent installation identifier is kept on the device; a separate template-usage identifier saved by older versions is deleted after you upgrade.
To understand the audience's approximate geographic distribution, Tencent Cloud CLS records the source IP address of log uploads and infers the country, province or region, and city. We do not request GPS access, read location coordinates, or use photo locations for this purpose. Mobile networks, proxies, VPNs, travel, and delayed offline uploads can affect these estimates. They are not your precise location or home address. Installation identifiers, activity logs, and source IP addresses are stored in Tencent Cloud's Guangzhou region for 30 days: 29 days in standard storage and one day in infrequent-access storage. They are then deleted under the log topic's retention rules. When we add a new data category or a new recipient, we request consent again in the app and do not enable these analytics reports before you agree; extending already-disclosed event categories to more plays does not prompt again. If you decline, Boxpop stops reporting and deletes the events still queued on your device along with the installation identifier above.
Optional notifications
Boxpop subscribes you to new template, feature update, and member offer notifications only when you turn on “Template updates & offers” in the app's Notifications settings and allow notifications in iOS. You can turn off the subscription in the app or block notifications in iOS Settings at any time. Creating and exporting do not require a subscription to notifications.
To deliver notifications, Boxpop sends the push token assigned by Apple, installation identifier, push environment, and subscription status to the Boxpop server over HTTPS. The server delivers notifications through Apple Push Notification service (APNs). Push tokens are not written to CLS. Authorization results, foreground receipt, and notification taps are recorded under the analytics rules above; notification message contents are not included in analytics logs. Once a subscription cancellation syncs successfully, the server removes the push token and retains only the minimum subscription version and authentication digest needed to prevent older requests from reactivating it. Subscription records that have not been updated for more than 90 days are periodically removed. Delivery status records are kept for up to 30 days. If you turn off the subscription while offline, the app retries synchronization the next time you open it with a connection. Notifications already delivered to iOS or in transit may still appear.
Feedback
When you submit feedback in the app, Boxpop sends your message, contact details (if provided), app version, build number, and iOS version to the Boxpop feedback server. We use these to investigate issues, reply when contact details are provided, and improve the app. Please do not include sensitive personal information in feedback.
Photos, videos, and Live Photos
Photos, videos, and Live Photos you select in Boxpop are processed on your device. Except for images you explicitly submit for review, Boxpop does not upload your original media or exported creations to a server. Zine pages and other export results are saved to Photos only when you choose to export.
Permissions
Boxpop requests photo access so you can choose media for Zines or other visual creations and save exports. Access is limited by the permissions you grant through iOS and is used only for actions you choose to perform.
Purchases
Boxpop offers an auto-renewing monthly membership and a one-time lifetime purchase to unlock member-only editing features. Apple handles purchases and payment information through the App Store purchase system. After you accept the in-app privacy notice, Boxpop sends an anonymous app user identifier and App Store purchase, transaction, and subscription status data to RevenueCat. RevenueCat verifies purchases, synchronizes renewals, restores purchases, manages refunds and membership access after reinstallation, and provides subscription analytics. Boxpop does not receive your bank card details or require a Boxpop account.
Retention and deletion
Except for images you explicitly submit for review, Boxpop does not store your original media or exported creations on its servers. Feedback is retained for as long as needed to address and fix reported issues. Contact details in feedback are used only for support replies. You manage and delete exports in Photos. You can also revoke Boxpop's photo access in iOS Settings or delete the app to remove its local data.
Third-party services
Boxpop uses the Umeng Analytics SDK and Umeng U-APM SDK for analytics and application performance monitoring. These tools measure launches, activity, versions, distribution channels, feature usage, crashes, and performance. They may collect device identifiers, product interaction data, crash data, and performance data. See the Umeng privacy policy.
Boxpop uses RevenueCat for purchase verification, membership entitlement management, and subscription analytics. Data may include an anonymous app user identifier, App Store purchase history, transaction and subscription status, and basic app or device information. RevenueCat processes this data as Boxpop's service provider and does not receive bank card information from Boxpop. See the RevenueCat privacy policy.
The Tencent Cloud CLS logging SDK is developed and operated by Tencent Cloud Computing (Beijing) Co., Ltd. It provides log collection and behavior analytics for the events and technical fields described above. See the CLS SDK personal information protection rules.
Contact
For support or privacy requests, contact the developer, Ralap, at 524640912@qq.com.
Submit your work
When you choose to submit your work, we upload 1–9 compressed images you select, required contact details, an optional description, app version, build number and iOS version for review and follow-up. Submissions are not published automatically. Images are accessible only to authorized staff and image metadata is removed on the server. Submission images, descriptions and contact details are retained as needed for review and communication; contact 524640912@qq.com to request deletion. Only submit images you have permission to share, without sensitive personal information.