1Who we are
This policy applies to Hidden Gallery (com.webjow.hidden_gallery). It is developed and published by Faiz Dae, an independent developer based in Afghanistan, under the developer profile name Webjow that you see on the Google Play and App Store listings. Webjow is a trading name only, not a separate registered company: Faiz Dae is the natural person who is the data controller for the limited data described below, and is personally answerable for it.
You can reach us at any time at [email protected]. There is no cost and no form to fill in β a plain email is enough.
This policy is written to satisfy the Google Play User Data policy, Apple App Store Review Guideline 5.1.1, the EU/UK GDPR, the Swiss FADP, the California CCPA/CPRA and comparable US state laws, Brazil's LGPD, Canada's PIPEDA and the Australian Privacy Act.
2What data is involved
The table below is the complete list. It is written to match, line for line, the Google Play Data safety form and the Apple Privacy Nutrition Label for this app.
| Category (Data safety) | Exactly what | Why | Who receives it | Shared? |
|---|---|---|---|---|
| Device or other identifiers | Advertising ID (Android), IDFA/IDFV (iOS), App Set ID | Serve and cap ads, measure ad performance, prevent ad fraud | Google (AdMob) | Yes |
| App activity & performance | Ad impressions, taps, video views, app launches | Ad delivery, measurement and billing | Google (AdMob) | Yes |
| Approximate location | Country/city level only, derived from your IP address β the app never requests GPS or precise location | Region-appropriate ads, applying the correct privacy law and consent form | Google (AdMob) | Yes |
| App interactions | Screens opened, features used, session length, app/OS version, device model, country | Understand which features are used so we can improve them | Google (Analytics for Firebase) β acting for us | No |
| Crash logs & diagnostics | Stack trace, device model, OS version, app version, free memory, whether the app was in the foreground | Diagnose and fix crashes and bugs | Google (Firebase Crashlytics) β acting for us | No |
| Photos, videos & files | Only the items you personally select or create, plus files the app saves at your request | Perform the task you asked for (open, edit, compress, save, share) | Nobody β stays on your device | No |
| Items you move into the private vault | The photos/videos you hide and the PIN or pattern that unlocks them | Keep the items hidden from the normal gallery and locked | Nobody β never uploaded anywhere | No |
| Messages you send us | Your email address and whatever you write, only if you email support | Answer your question or handle your privacy request | Our email provider (Google) | No |
βSharedβ has the store meaning: the data leaves our control and goes to another company. Data marked as staying on your device is never transmitted to us or to anyone else.
3What we never do
- We never sell your personal information, and we never share it for money.
- We never ask for your name, phone number, address, ID document or payment card.
- We never request GPS or precise location.
- The app does not request the Android or iOS permissions needed to read your SMS, call log, contacts, calendar or microphone β you can check this yourself in the appβs permission list.
- We never scan or upload your gallery in the background β only the items you pick, at the moment you pick them.
- We never build a profile about you from other companies' apps or websites.
- We never use your data to train artificial-intelligence models, and we never pass it to a third-party AI service.
- This app has no user account at all β no registration, no sign-in, no password.
4Why we use it, and our legal basis
If you are in the EEA, the UK or Switzerland, the GDPR requires us to name a legal basis for each purpose:
| Purpose | Legal basis |
|---|---|
| Running the app and doing what you asked it to do | Performance of a contract β Art. 6(1)(b) |
| Keeping the app stable: crash reports, error diagnostics, security and anti-fraud | Legitimate interests β Art. 6(1)(f) |
| Usage analytics and personalised advertising, and any storing of or access to information on your device that is not strictly necessary | Your consent β Art. 6(1)(a), collected through the Google consent form the first time you open the app |
| Answering your privacy request and keeping proof that we answered it | Legal obligation β Art. 6(1)(c) |
| Health, financial or private-vault entries you keep inside the app | No legal basis is needed from us: this content never leaves your device and never reaches us, so we do not process it at all β including the special categories of data under Art. 9 |
Where the basis is consent you may withdraw it at any time, and withdrawing it is as easy as giving it β see Advertising & consent. Withdrawal does not affect processing that already happened.
5Device permissions
We follow the principle of data minimisation: the app asks only for what its core function needs, asks at the moment the function is used, and keeps working β with that one feature unavailable β if you say no.
| Android permission | Apple equivalent | Why | Optional? |
|---|---|---|---|
INTERNET Β· ACCESS_NETWORK_STATE | β (no prompt on iOS) | Load ads and, where the app has online content, fetch it | Required |
com.google.android.gms.permission.AD_ID | App Tracking Transparency (ATT) | Read the resettable advertising ID for ad frequency capping and fraud prevention. On iOS the IDFA is only used if you allow tracking. | Yes |
READ_MEDIA_IMAGES Β· READ_MEDIA_VIDEO (Android 13+) / READ_EXTERNAL_STORAGE (older) | Photo Library (NSPhotoLibraryUsageDescription) | Let you pick the photos or videos you want to work with. Android 13+ and iOS let you grant access to selected items only. | Yes |
WRITE_EXTERNAL_STORAGE (Android β€ 10) / scoped storage after that | Files & Save to Photos | Save the file you asked the app to produce or download into your device storage | Yes |
You can change any of these later in Settings β Apps β Hidden Gallery β Permissions on Android, or Settings β Hidden Gallery on iOS.
6Advertising & consent
The app is free and is paid for by advertising served through Google AdMob. For advertising, Google acts as an independent controller of the data it receives, under its own terms and privacy policy.
If you are in the EEA, the UK or Switzerland
The first time you open the app you are shown a consent form built with Google's certified User Messaging Platform, which is registered with the IAB Transparency & Consent Framework. It lists every advertising partner and lets you accept or refuse each purpose separately.
- If you consent, ads may be personalised using the advertising identifier described above.
- If you refuse, you still get ads, but only non-personalised or limited ads β chosen from context, not from any profile of you. The app itself stays fully usable either way; we never lock a feature behind an advertising choice.
- To change your mind later, open the app's Settings β Privacy options (or Consent) entry, which re-opens the same form.
If you are in the United States
Some US state laws treat sharing an advertising identifier for cross-context behavioural advertising as a βsaleβ or βshareβ, even though no money changes hands. To opt out, turn off personalised advertising as described below, or email us β see US state privacy rights.
Controls that work everywhere, in every app
- Android: Settings β Privacy β Ads β Delete advertising ID (or reset it). Once deleted, apps receive a string of zeros.
- iOS: Settings β Privacy & Security β Tracking β turn off Allow Apps to Request to Track. Without your permission the IDFA is never available to us.
- Google account level: My Ad Center and My Activity.
7Analytics & crash reporting
We use Google's Firebase tools to answer two questions: which features do people actually use? and where does the app crash? Google processes this data on our behalf as a processor, under Google's data-processing terms, and is not allowed to use it for its own purposes.
These reports are statistical. They are keyed to a random, app-scoped instance identifier β not to your name, your email or your phone number. We cannot look up an individual person in them.
You can switch analytics collection off at any time from the app's Settings β Privacy screen where that option is offered, and deleting the app removes the identifier from your device.
8Third parties
These are the only companies that can receive data from the app. Each is bound by a contract or by platform terms to protect your data to at least the standard set out in this policy, and none of them is allowed to use it for anything beyond the purpose listed here.
| Company / service | Role | Privacy policy |
|---|---|---|
| Google AdMob | Advertising β independent controller for ad personalisation | Read β |
| Google User Messaging Platform (UMP) | Collects and stores your consent choice | Read β |
| Google Analytics for Firebase | Usage analytics β processor acting on our instructions | Read β |
| Firebase Crashlytics | Crash reporting β processor acting on our instructions | Read β |
| Google Play services / Google LLC | App distribution, updates, integrity and (where offered) purchases | Read β |
| Apple Inc. (App Store) | App distribution, updates and (where offered) purchases on iOS | Read β |
We do not work with data brokers. We do not run any ad network, tracking pixel or social-media SDK beyond the ones listed above.
9International transfers
Google and Apple operate globally, so the small amount of data described above may be processed on servers in the United States, Ireland or elsewhere. Those transfers rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and, where the recipient participates, the EUβUS and UKβUS Data Privacy Framework.
You may request a copy of the safeguards that apply by emailing [email protected].
10How long data is kept
| Data | Kept for |
|---|---|
| Everything you create inside the app | Until you delete it, or until you uninstall the app β it lives only on your device, so we have no copy and no way to restore it |
| Crash reports | Up to 90 days in Firebase Crashlytics (Google's current default), then deleted automatically |
| Usage analytics | User-level records are deleted on Google's configured retention schedule (2β14 months); only anonymous aggregate counts remain afterwards |
| Advertising data | Retained by Google under Google's own retention policy; you can delete it yourself from My Activity |
| Support emails | Up to 24 months, then deleted |
Because the app keeps your content on your device rather than on a server, uninstalling the app permanently erases that content. Export or back up anything you want to keep first.
11How data is protected
- All network traffic uses HTTPS/TLS. The app does not accept plain-text connections.
- Content you create is stored in the app's private sandbox, which the operating system keeps unreadable by other apps.
- We hold no user database and no server-side accounts, which removes the single largest source of breach risk.
- Access to the Play Console, App Store Connect and Firebase is protected by two-factor authentication.
No system is perfectly secure. If a breach ever affected your data we would notify the competent supervisory authority within 72 hours where the law requires it, and notify affected users without undue delay.
12Your rights
Wherever you live, you can ask us to:
- Access β get a copy of any data we hold about you.
- Correct β fix anything inaccurate.
- Delete β erase it (βright to be forgottenβ).
- Restrict or object β including objecting to processing based on legitimate interests, and objecting to direct marketing at any time.
- Port β receive your data in a machine-readable format.
- Withdraw consent β at any time, without penalty.
- Not be subject to automated decision-making β we do not carry out any profiling that produces legal or similarly significant effects on you.
Email [email protected] and tell us which right you want to use and which app you are using. We answer free of charge, normally within 30 days and in every case within the period the applicable law allows β one month under the GDPR, extendable by two further months for a complex request, and 45 days under the CCPA, extendable to 90. If we ever need an extension we will tell you why before the first deadline passes. We may ask one question to confirm the request comes from you or from someone authorised to act for you β no ID document is needed.
In most cases the honest answer will be that we hold nothing about you at all, because the app stores your content on your device. In that case we will say so plainly, and explain how to delete the on-device copy yourself β see the deletion page.
If you are unhappy with our response you may complain to your local data protection authority: in the EEA, the authority of your country of residence (list at edpb.europa.eu); in the UK, the ICO; in Switzerland, the FDPIC.
13US state privacy rights
If you live in California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Florida or another US state with a comprehensive privacy law, you additionally have the right to know, delete, correct, obtain a portable copy, opt out of βsaleβ/βsharingβ and targeted advertising, limit the use of sensitive personal information, and appeal a refusal. We will never discriminate against you for exercising any of them.
We do not sell personal information for money, and we have not done so in the preceding 12 months. We also do not knowingly sell or share the personal information of anyone under 16.
The only category that could count as a βsaleβ or βshareβ under California law is the advertising identifier passed to Google for personalised ads. Turning off personalised advertising, deleting your advertising ID, or emailing us with the subject βDo Not Sell or Share My Personal Informationβ all stop it. The Global Privacy Control is a web-browser signal that a mobile app does not receive, so we cannot act on it inside the app; the device and in-app controls above are the working equivalent, and an email from you is always accepted as a valid opt-out.
Categories collected in the last 12 months, in CCPA terms: identifiers (advertising ID, IP address), internet or other electronic network activity (app interactions), geolocation data (coarse, city level), and β only if you write to us β the content of your message. We do not collect the categories of sensitive personal information that trigger the βlimit the useβ right. Anything you keep inside the app on your own device β including health or financial entries β is never transmitted to us, so we do not collect it and it never falls into any of these categories.
14Children
This app is not enrolled in the Google Play βDesigned for Familiesβ programme and children are not its primary audience.
We do not knowingly collect personal information from children under 13 (or under the age of digital consent in your country, which is 16 in some EEA states). We do not build profiles of children and we do not show personalised advertising to anyone we know to be a child.
If you are a parent or guardian and believe a child has given us personal information, email [email protected]. We will delete it promptly and confirm to you in writing.
15Deleting your data
This app has no user account, so there is nothing on our side to delete: all of your data lives on your device and disappears when you uninstall the app.
Full instructions, including what happens to each type of data, are on the dedicated page: Data & account deletion β
16This page itself
This page sets no cookies, loads no external fonts, scripts or images, and runs no analytics. Your language and light/dark choice are stored only in your own browser. Our web host keeps standard server logs (IP address, time, page requested) for security for a short period.
17Changes to this policy
When we change this policy we update the version number and the βlast updatedβ date at the top. If a change materially affects your rights β a new data type, a new recipient, a new purpose β we will announce it inside the app before it takes effect and, where the law requires it, ask for your consent again.
Current version: 2.0, effective 2026-08-07. It replaces the version published on 2024-01-05, which no longer applies.
18Contact
Faiz Dae (Webjow) β privacy point of contact
Email: [email protected]
Website: https://topjow.org
Country: Afghanistan
Write in English, Persian/Dari or Pashto β all three are fine. Please mention the app name so we can answer precisely.