Hueforia Privacy Policy

Last updated: July 31, 2026  ·  App version 1.7

Hueforia is built and operated by Louis Wiyono, the artist and creator behind Whimsy Tales. This policy explains — in plain language — exactly what data the app collects, why, and how it is handled. No legalese, no surprises.

Bottom line, up front: Hueforia does not sell your data, show third-party ads, or share your artwork. Product analytics use a random, app-only ID — never your name, email, or Apple ID — and you can switch them off in Settings. On an eligible fresh installation, Apple may ask for permission to track. Only if you choose Allow, Hueforia and RevenueCat provide limited identifiers and app or purchase events to Meta so we can understand how people discover Hueforia and measure our own advertising. Declining does not restrict the app or its free trial. Photos are processed on your device and never uploaded. Text to Palette descriptions are used only for palette generation and are never sent to Meta. Purchases are processed by Apple, not by us.

1. Information We Collect

Product Analytics (PostHog)

Hueforia uses PostHog, a first-party product analytics service, to understand how people use the app so we can fix bugs and improve features. This data is pseudonymous — it is linked to a random, app-generated ID, never to your name, email, or Apple ID. We collect:

  • Which screens you visit and which features you tap
  • Palette generation, save, share, and refresh actions
  • Device model, OS version, app version, and build channel (development / TestFlight / production)
  • General country or region (city-level location is not collected)

A persistent app ID and a usage profile. So we can understand how features are used by the same person over time, this analytics data is tied to a persistent identifier — the same random RevenueCat App User ID described below, which is not linked to your real-world identity. Alongside it we record a small profile of non-identifying attributes: your subscription tier (free / Pro / Founding), whether your plan is monthly or annual, your chosen medium (Ohuhu or other), which Ohuhu series you own, and your current streak length. Your display name is deliberately excluded — it never leaves your device.

You can turn this off. Open Settings → Privacy in the app and switch off “Share usage data.” PostHog then stops all collection on your device.

PostHog does not use your device’s advertising identifier (IDFA). The in-app “Share usage data” switch controls PostHog product analytics separately from Apple’s App Tracking Transparency choice. The ATT prompt described below is used only for consented Meta advertising attribution and measurement.

Crash & Error Reporting (Sentry)

When the app encounters an error or crash, Sentry captures a diagnostic report so we can fix the issue quickly. Sentry receives:

  • A stack trace showing which code path triggered the error
  • Device model, OS version, and app version at the time of the crash
  • Build channel (development / TestFlight / production)

Sentry does not receive your name, email, palette content, or any personally identifiable information. Crash reports are held for 90 days.

Subscription Management (RevenueCat)

If you subscribe to Hueforia Pro or purchase the Founding Colourist lifetime plan, the transaction is handled by Apple’s App Store through RevenueCat, our subscription management layer. RevenueCat receives:

  • An anonymous RevenueCat App User ID (not linked to your Apple ID or identity)
  • Your subscription status and the product you purchased (for example, Monthly Pro)
  • Transaction receipts from Apple for validation

RevenueCat does not receive your name, email, payment details, or Apple ID. All payment processing happens directly between you and Apple.

Advertising Attribution & Measurement (Meta and RevenueCat)

On an eligible fresh installation, Hueforia displays Apple’s App Tracking Transparency prompt when you first try to move forward from the “Create your way” onboarding page. You can choose Allow or Ask App Not to Track; either choice continues onboarding normally and does not change your access to Hueforia or its free trial.

Only after you choose Allow:

  • Hueforia sends Meta a manual app-activation event and Meta’s app-scoped anonymous identifier.
  • RevenueCat may collect the IDFA, IDFV, IP and device information, and your ATT status.
  • RevenueCat may send Meta trial, subscription, renewal, and Founding Colourist purchase events, including the product, currency, and net value, for Hueforia advertising attribution, measurement, and optimisation.

RevenueCat is the only sender of purchase and subscription events to Meta; Meta’s automatic purchase logging is disabled. If you decline, tracking requests are globally disabled, or Apple cannot show the prompt, Hueforia does not enable directly matched Meta activation or purchase-lifecycle events. You can change your choice later in iOS Settings → Privacy & Security → Tracking.

Hueforia does not send Meta your photos, palettes, Mood Boards, Text to Palette descriptions, display name, email, or Apple ID. Hueforia does not show ads inside the app.

Whimsy Tales Discount Codes (Cloudflare Worker & Shopify)

Hueforia Pro members can claim 40% off Whimsy Tales products (2 codes per month). When you request a discount code:

  • Your anonymous RevenueCat App User ID is sent to a Cloudflare Worker — a small, server-side function that verifies your Pro status and generates a unique discount code.
  • The Worker temporarily stores a monthly usage counter in Cloudflare KV, keyed by your anonymous App User ID, to enforce the 2-per-month cap. This counter auto-expires after 45 days.
  • The generated discount code is created via Shopify’s Admin API and redeemed when you check out at whimsytales.com.

No personal information is sent to Cloudflare or Shopify during this process — only the anonymous RevenueCat App User ID. Shopify’s standard privacy practices apply when you complete a purchase on its platform.

Text to Palette (Cloudflare Worker & OpenAI)

Hueforia Pro and Founding users can describe a mood, place, or memory and ask Hueforia to turn it into palette ideas. When you use Text to Palette:

  • The description you type is sent to a Cloudflare Worker, along with your anonymous RevenueCat App User ID so we can verify your Pro or Founding access and enforce usage limits.
  • The Worker sends your description and a compact Hueforia palette-intent summary to OpenAI so it can return structured palette recipes. Hueforia then generates the final colours inside the app using its own colour engine.
  • The Worker stores compact daily and monthly usage counters in a private Cloudflare Durable Object to enforce Text to Palette limits. A generation reserves a slot before processing, commits it after a valid result, and releases it on failure. The counters reset when the next request reaches a new day or month; short-lived abandoned reservations expire automatically.
  • Hueforia’s Worker does not write the words you enter or the generated palette recipes into its own persistent quota storage.
  • Raw descriptions are not sent to PostHog analytics or Sentry crash reports. Analytics only record non-identifying usage details such as prompt length, model name, token counts, result code, and remaining quota.
  • Hueforia sends OpenAI requests with response storage disabled. OpenAI may still retain API inputs and outputs in abuse-monitoring logs for up to 30 days, or longer where legally required.

OpenAI states that API inputs and outputs are not used to train or improve its models unless an API customer explicitly opts in. Hueforia does not opt in to that sharing. Do not enter sensitive personal information into Text to Palette.

Email Updates (Klaviyo)

If you sign up for Hueforia updates or contact us by email, we may collect your email address through Klaviyo, our email platform. You can unsubscribe at any time using the link in any email we send.

Beta Testing (Apple TestFlight)

If you participate in the Hueforia TestFlight beta, Apple collects certain information as part of the TestFlight service — including your email address and anonymous usage data such as crashes, installs, and session length. Apple’s privacy policy governs its collection and processing of this data.

Photos You Choose (Processed On Your Device)

Hueforia can build a palette from one of your photos, let you tap a photo to sample an exact colour, create a Mood Board from 3–7 photos, or place a photo on a share card. When you do this:

  • The app only ever accesses the images you explicitly pick — it does not browse or read the rest of your library.
  • Images are analysed entirely on your device to extract colours and render Mood Boards. They are never uploaded to us or to any third party, and we never see them.
  • Photos used in a Mood Board or share card stay on your device until you choose to share or save the finished image through iOS.
  • Saving a Mood Board or share card writes the image to your camera roll only when you tap Save.

Tonal Value Camera (Processed On Your Device)

On supported Apple devices, Hueforia Pro and Founding Colourist members can choose to open the Tonal Value Camera. iOS asks for camera permission before the live view begins. Hueforia processes the rear-camera feed in memory to display continuous tonal value, simplified value bands and the optional calibrated Spot Check.

  • Hueforia does not take, save or upload photos or video from the Tonal Value Camera.
  • Camera frames, colours, lightness or other measurements, Spot Check coordinates, calibration values and physical lens identifiers never leave your device.
  • Calibration and camera-session state are held only in memory and are cleared when the camera closes.
  • Privacy-safe analytics may record categorical actions such as opening the tool, selecting a display mode or completing calibration, but never camera content or measured values.
  • You can deny or revoke camera permission at any time in iOS Settings. The rest of Hueforia remains usable, and Hueforia does not request microphone access.

Local Data (Your Device Only)

Hueforia stores the following data exclusively on your device using iOS SecureStore and AsyncStorage. This data never leaves your device and is never transmitted to any server:

  • Your onboarding completion state and display name, if you set one
  • Your colouring goal commitment and media preferences
  • Saved palettes in Palette Box
  • Per-swatch bloom settings, including lighting preset and mood overrides
  • Daily generation count for free-tier enforcement

2. What We Do NOT Collect

  • Your name, email address, or contact information through the app itself
  • Your precise location, GPS location, or city-level location
  • Your microphone or audio
  • Your contacts or calendar
  • Health, biometric, or fitness data
  • Your device’s Advertising Identifier (IDFA) when you choose Ask App Not to Track or when system tracking requests are disabled
  • Your Apple ID, payment details, or billing address. Apple handles all payments.

3. Third-Party Services

We rely on a small number of trusted services to operate the app. Each is listed below with its purpose and a link to its own privacy policy.

PostHog
Pseudonymous product analytics — screens visited, features used, and device information.
Receives: usage events, device metadata, build channel, a persistent random app ID, and a non-identifying usage profile such as subscription tier, medium, owned series, and streak. No name, email, or Apple ID.
posthog.com/privacy

Sentry
Crash and error reporting — stack traces and device information at the time of a crash.
Receives: error stack traces, device model, OS version, and app version. 90-day retention.
sentry.io/privacy

RevenueCat
Subscription management and consented advertising measurement — verifies Pro status, handles purchase receipts, and, after ATT Allow, may provide configured lifecycle events to Meta.
Receives: anonymous App User ID, transaction receipts, subscription status, and, on the consented path, IDFA, IDFV, IP/device information, and ATT status.
revenuecat.com/privacy

Meta
Consent-based attribution and measurement for Hueforia’s Facebook and Instagram advertising.
Receives after ATT Allow: a manual app-activation event, Meta’s app-scoped anonymous identifier, and RevenueCat-sent trial, subscription, renewal, and Founding-purchase lifecycle events with product, currency, and net value. Does not receive photos, palettes, Mood Boards, or Text to Palette descriptions.
facebook.com/privacy/policy

Cloudflare (Worker + KV + Durable Objects + R2)
Generates Whimsy Tales discount codes for Pro members, delivers Founding Colourist PDF downloads, and routes Text to Palette requests through a server-side Worker.
Receives: anonymous RevenueCat App User ID, limited usage-counter data, and Text to Palette descriptions when you use that feature. Hueforia’s Worker does not write raw Text to Palette descriptions into its own persistent quota storage.
cloudflare.com/privacypolicy

OpenAI
Text to Palette recipe generation for Hueforia Pro and Founding users.
Receives: the short text description you enter, a compact palette-intent summary, and non-identifying request metadata needed to return structured palette recipes. Hueforia disables Responses API storage for these requests. OpenAI may retain API inputs and outputs in abuse-monitoring logs for up to 30 days, subject to its API data policies.
openai.com/policies/privacy-policy

Shopify
Creates and redeems discount codes and powers the Whimsy Tales storefront.
Receives: discount-code creation requests. Standard Shopify privacy practices apply at checkout.
shopify.com/legal/privacy

Klaviyo
Email updates and marketing communications, when you opt in.
Receives: email address and email engagement metrics when you opt in.
klaviyo.com/legal/privacy

Apple (App Store + TestFlight)
App distribution, payment processing, and beta testing.
Receives: payment information, handled by Apple only, plus TestFlight email and usage data.
apple.com/legal/privacy

We do not sell or rent your data, share it with data brokers, or show third-party ads inside Hueforia. Limited identifier, activation, and purchase-lifecycle data is shared with Meta and RevenueCat only after ATT Allow for Hueforia’s own advertising attribution and measurement, as described above.

4. How We Use Your Data

  • To operate and improve the app: Understanding how colourists use Hueforia helps us fix bugs, refine features, and decide what to build next.
  • To fix crashes quickly: Sentry error reports let us identify and resolve bugs without waiting for user reports.
  • To manage subscriptions: RevenueCat verifies your Pro status so premium features unlock correctly.
  • To measure how people discover Hueforia: After ATT Allow, limited activation and purchase-lifecycle data helps us attribute and evaluate our own Facebook and Instagram advertising.
  • To provide discount perks: The Cloudflare Worker generates one-time Whimsy Tales discount codes for Pro members and enforces the monthly usage cap.
  • To deliver Founding Colourist downloads: Bonus PDF content for Founding Colourist members is served from a Cloudflare R2 bucket via a Worker that verifies your entitlement.
  • To generate Text to Palette ideas: The Text to Palette Worker verifies your Pro or Founding access, enforces usage limits, and asks OpenAI to translate your short description into Hueforia palette recipes.
  • To communicate with you: If you’ve opted into email updates, we send launch announcements and product news via Klaviyo.
  • To prevent abuse: Detecting and preventing fraudulent or unauthorised use of the app and its services.

5. Data Retention

  • PostHog analytics: Retained according to PostHog’s data retention policy, which is two years by default for most plans.
  • Sentry crash reports: Automatically deleted after 90 days.
  • RevenueCat subscription and attribution data: Retained according to RevenueCat’s data-retention and deletion practices while needed to manage entitlements and consented measurement.
  • Meta measurement data: Retained and handled according to Meta’s privacy and data-retention practices. You can withdraw future tracking permission through iOS Settings; contact us to request deletion of data we control.
  • Cloudflare usage counters: Discount-code counters in Cloudflare KV auto-expire after 45 days. Text to Palette uses compact Durable Object counters that reset when the next request reaches a new day or month. Abandoned reservations expire after two minutes.
  • OpenAI API processing: Hueforia disables Responses API storage for Text to Palette requests. OpenAI may retain API inputs and outputs in abuse-monitoring logs for up to 30 days, or longer where legally required. Hueforia does not opt API content into model training.
  • Klaviyo email data: Retained until you unsubscribe or request deletion.
  • Local device data: Persists until you delete the app or clear app data from your device.

6. Your Rights

Depending on where you live, you may have rights regarding your personal information, including the right to:

  • Access, correct, or delete your data
  • Export your data in a portable format
  • Opt out of marketing communications using the unsubscribe link in every email
  • Turn off product analytics at any time in the app through Settings → Privacy → “Share usage data”
  • Decline Apple’s ATT request without losing access to Hueforia or its free trial
  • Withdraw future tracking permission through iOS Settings → Privacy & Security → Tracking → Hueforia
  • Withdraw consent where processing is consent-based

To exercise any of these rights, contact us using the details in Section 9 below. We will respond within 30 days.

7. Children’s Privacy

Hueforia is not directed at children under the age of 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

8. Changes to This Policy

We may update this Privacy Policy as Hueforia evolves. When we do, we’ll update the “Last updated” date at the top of this page. For material changes, we’ll notify you through the app or via email, if you’re on our mailing list.

9. Contact

Email: louis@whimsytales.com
Mail: PO Box 20002, RPO Qualicum Centre, Qualicum Beach, BC, V9K 0B1, Canada
Website: hueforia.app · whimsytales.com

This policy applies to the Hueforia iOS application and related services operated by Whimsy Tales Art.