Privacy Policy
Updated September 5, 2026
Scope and contact
This notice covers the IconBundlr website and the IconBundler iOS app. The developer is identified on our App Store listing. Contact support@iconbundlr.com for privacy, access, correction, or deletion requests. Please do not send passwords, payment-card details, or sensitive information in icon descriptions.
The controls available depend on the version you use. App version 2.30.1 introduces a fresh optional analytics choice and disables session replay. Earlier installed versions may have different defaults and previously collected data; changing a setting does not recall data already received by a provider.
Data needed to provide the service
- Generation: Your icon description and selected design options are sent through Supabase to OpenAI to create an image. Generated image bytes pass through our servers. Saved app icons and their design details are kept on your device. Recovery-enabled requests also use private server-side image storage, an operation identifier, and a request fingerprint so an interrupted request can recover the same result.
- Accounts: The app can use an anonymous service account. If you register or sign in, Supabase handles your account identifier, authentication information, and the email supplied by your sign-in method. An anonymous account identifier is still an identifier, not a promise that all activity is anonymous.
- Purchases: Apple processes payments. Apple-signed transaction identifiers and receipts, product and subscription status, account-binding information, and credit-use records help us deliver purchases, restore access, and handle refunds. RevenueCat helps manage purchase information. We do not receive your full payment-card number.
- Operation and security: Our hosting and service providers receive network information needed to handle requests, including IP addresses. Server-side preview limits use a derived IP identifier. Authentication, generation allowances, recovery, purchase verification, abuse prevention, and deletion requests do not depend on optional analytics consent.
- Support: If you contact us, we receive the details you choose to send and the information needed to respond. Marketing email signup is not offered on this website.
Optional analytics and diagnostics
Website: PostHog interaction analytics stays off until you choose “Allow analytics.” If allowed, the website sends a browser identifier, limited interaction events, coarse page type, language, and selected design options. It does not send your icon descriptions, images, email, full page URL, or URL query parameters through this analytics code. We disable profile processing and location enrichment in these events. PostHog still receives the network request; this is identified analytics, not anonymous data.
Use the Privacy settings control in the footer to reject or withdraw website analytics. Rejecting does not prevent ordinary site use or generation. Withdrawal stops future optional events from this page and retires its analytics identifier. It cannot recall requests already received. This website does not load Google Analytics, Vercel Insights, or session replay.
App version 2.30.1: Analytics is optional and requires a fresh choice. When enabled, PostHog receives usage events associated with an app identifier, while Sentry receives crash and error diagnostics. App version, operating environment, language, purchase/access status, and relevant interaction details can be included. Session replay remains off. Use the app’s Settings → Analytics control to withdraw. Core generation, purchases, and your library do not require optional analytics.
App feature configuration can be fetched separately from optional event collection so privacy choices do not change purchase availability or safety controls. A request to the configuration service still requires network communication.
Apple advertising attribution: With app analytics enabled, the app can request an Apple AdServices attribution token and send it to Apple to learn whether an installation followed an Apple advertising campaign. The returned attribution status and available campaign, ad-group, keyword, country or region, and conversion details can be shared with PostHog and RevenueCat to measure acquisition. This is separate from your icon description and is not enabled by purchasing export access. Withdrawing analytics consent stops future optional attribution collection.
Browser storage and retention
- The website stores your analytics choice and, only after consent, a separate optional analytics identifier. These remain until you change the choice or clear the site’s data.
- Essential browser storage holds preview-allowance information and, for recovery-enabled requests, a separate operation receipt containing a random recovery capability, time, style, and color. It does not persist your description or generated image. Treat browser site data as private: someone with access to a recovery capability may retrieve that preview.
- Recovery access is limited to 24 hours from a request. The website removes its expired recovery receipts when it next checks them. Server cleanup can finish later than the access-expiry time. This is not a promise that all provider logs or backups disappear after 24 hours.
- App icons and their saved design details are stored in the app’s local library until removed there. The app does not provide automatic cross-device synchronization of that image library. Depending on your Apple device and backup settings, ordinary app data may be included in device or iCloud backups. Removing an app item does not remove an independently saved copy or a previously created backup.
- A stable purchase-service identifier is stored in Apple Keychain and cached locally. It can synchronize through iCloud Keychain when available, with a local-only fallback. This identity continuity is separate from image-library synchronization. Generation recovery-capability directories are excluded from app backups; this does not exclude all library data. A pending account-deletion capability uses device-only Keychain protection.
- Account, transaction, allowance, security, and deletion-verification records can be retained separately as needed to operate the service, reconcile purchases, prevent abuse, and meet applicable obligations. Provider logs and backups have their own retention and deletion processes.
Clearing browser storage removes your local consent and recovery information; it does not itself delete server records or cancel an Apple subscription. Generated previews are not automatically saved to your device. Keep any image you need independently of the recovery receipt, using your browser’s image-save controls where available.
Service providers
We use these providers for the functions described above, rather than promising that data never leaves your device:
- OpenAI — image generation from your descriptions. Its API data policy says API data is not used for training by default. Provider abuse-monitoring logs can retain content, generally for up to 30 days and longer in specified legal or safety circumstances. We do not claim zero retention.
- Supabase — authentication, backend processing, database and private recovery storage.
- Apple — App Store distribution, sign-in where chosen, payments, and signed purchase information.
- RevenueCat — purchase and subscription management.
- PostHog — optional analytics and app configuration delivery.
- Sentry — optional app diagnostics.
- Vercel — website hosting and necessary request delivery.
- Resend — transactional email in the older data-export workflow, including the recipient address and requested export attachment. Email previously sent through this workflow can remain subject to the provider’s retention and deletion processes. The download-first replacement does not erase that history.
Providers may process information outside your country. Their notices describe their processing and safeguards; contacting a provider does not replace contacting us about data we control. We do not sell your personal information or use it for cross-company targeted advertising.
Deletion and your choices
Use the app’s account-deletion control or our deletion instructions. Account deletion requests cover associated service data and that account’s local app icons. Other accounts’ icons are kept. Some provider-side work may remain pending after authentication is deleted; the app reports this separately rather than claiming instant deletion everywhere. Purchase and minimal verification records may need separate retention.
To protect a deleted account, app analytics or diagnostic queues that cannot safely be separated by account may be discarded, including some diagnostics from another account on the device. This does not delete another account’s icons or purchases.
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your information, restrict or object to processing, withdraw consent, or raise a concern with your privacy regulator. Contact us to exercise them. We may need proportionate verification to avoid giving your information to someone else. Withdrawing consent does not undo processing already performed.
Deleting the app or your account does not automatically cancel an Apple subscription. Manage subscriptions through your Apple account.
Children and changes to this notice
IconBundlr is not intended for children under 13, and we do not knowingly collect their personal information. Contact us if you believe a child has provided it. We update this notice when our practices change and show the revision date above.