This Privacy Policy explains how Eli Riedel, an individual (“Colorlife,” “we,” “us,” or “our”) handles personal information through the Colorlife iOS application, related cloud services, support, and colorlife.app (together, the “Services”).
The short version: Colorlife uses a selected photo or text prompt to make the page you request; the source photo is not saved in Colorlife's own database or Storage bucket; V1 contains no product-analytics or crash-reporting client SDK, purges its legacy PostHog queue, and sends no PostHog product-usage, crash, or diagnostic events; and account deletion is available inside the app. Colorlife asks for Apple's tracking permission only in subscription context. If the managing adult allows it, the Meta SDK and RevenueCat may use device/advertising identifiers and subscription lifecycle events to measure and improve Colorlife's Meta ads. Colorlife does not send Meta any photo, prompt, generated or colored page, account UUID, name, email address, or phone number.
Colorlife does not sell personal information for money. The ATT-authorized advertising measurement described in Section 7 may be considered targeted advertising, “sharing,” or tracking under some laws. You can decline the Apple prompt or later turn tracking off in iOS Settings without losing app functionality or the ability to purchase. We do not use photos, prompts, or pages for advertising.
1. Who may use Colorlife
Colorlife is a general-audience family app. A parent, legal guardian, or other adult who can enter a binding agreement must set up and manage the account, purchases, uploads, prompts, and other online features. Children may use the coloring tools with appropriate adult supervision. School- or educator-managed accounts are not part of the intended V1 service. See Section 14. A managing adult may upload a photo showing a child when they are the child's parent or legal guardian, or have permission from the child's parent or legal guardian. Prompts should not include unnecessary sensitive personal information, especially a child's full name, home address, school, precise location, or health information.
2. Information we collect
Account and session information
When the app starts, it creates or restores a pseudonymous anonymous backend account identified by a random UUID. We process authentication tokens, session state, and account-security metadata. If you use Sign in with Apple, Supabase receives the Apple provider subject and any relay email Apple makes available. If you use Google, Google authenticates you and Supabase receives the Google provider subject, email address, and basic profile information returned for sign-in. If you create an email account, Supabase processes the email address and password-based authentication data. These options let you recover the account and sign in on another device.
Content and page information
We process the selected source photo or text prompt, generation instructions, chosen detail level, generated outline, colored page, page settings, favorites, creation/update times, and sync state. The prompt, outline, colored version, and page settings are stored with the private account until you delete the page or account. Colorlife does not persist the original source photo in its own database or Storage bucket.
Your pages are not public. Access is limited to your account and to authorized Colorlife service processes, providers, and personnel when necessary to operate, secure, support, or comply with law.
Colorlife does not request broad or full-photo-library access. You select individual photos through Apple's picker or camera, and saving a finished page uses add-only Photos access.
Subscription and transaction information
Apple and RevenueCat provide product ID, purchase and renewal status, trial status, entitlement, transaction identifiers, storefront/country, expiration, cancellation, refund, transfer, and related device/app metadata. Colorlife does not receive card or bank-account details; Apple processes the payment.
App, device, network, and security information
Our systems and providers may process app version, operating-system/device information, IP address, request time, request and error identifiers, authentication/security events, function and server logs, generation-attempt status, and data needed to detect abuse, debug failures, meter use, and secure the Services. We do not intentionally place photos or prompts in application logs.
To recover a generation interrupted by a timeout, cancellation, or lost connection, the App keeps a device-local recovery record in protected, backup-excluded app storage. The record contains random page and account UUIDs, source type, detail level, creation time, and either the exact text prompt or a SHA-256 hash of the exact downscaled JPEG sent for a photo request. It contains no photo bytes. When online, the App uses the record to check for and restore a generated outline. The App removes the record after the page is safely saved or recovered, after a definitive pre-result rejection, or during applicable account-switch or account-deletion cleanup. It keeps at most eight records. An unresolved record older than 48 hours is removed only after a successful online check confirms that no generated outline exists; if the device is offline or that check fails, the App keeps the record so it can try reconciliation later.
For sensitive generation requests, Colorlife uses Apple's App Attestservice to verify that a request came from a legitimate instance of the App. Colorlife stores an Apple-generated app-instance key identifier, its public key, attestation environment, assertion counter, and verification times with the random account UUID. When Apple supplies them, Colorlife also stores the App distribution category and build version. The private key remains in Apple-protected device storage and is never received by Colorlife. During enrollment, the App may temporarily retain Apple's attestation object in protected, this-device-only Keychain storage so an interrupted enrollment can resume. The App removes that object after server acknowledgment, expiry/recovery, or account cleanup; Colorlife does not store the App Attest receipt on its server.
Colorlife also uses Apple's DeviceCheckservice to help limit the one-time promotional generation to an eligible account and device. Only when Colorlife's server requests this check for an otherwise eligible free promotion does the App send an ephemeral Apple-generated DeviceCheck token to Colorlife. Colorlife sends it to Apple to read or set one per-device eligibility bit, then discards the raw token without logging or persisting it. Requests that the server already recognizes as active Pro, and requests made while this server control is off, do not request a DeviceCheck token. A recently purchased subscription whose server entitlement has not reconciled yet may still look locally eligible for the free promotion; if so, Colorlife discards the requested token without sending it to Apple after the subscription is confirmed. Colorlife does not use App Attest or DeviceCheck for advertising, cross-app tracking, precise location, or as proof of a person's identity. DeviceCheck is an abuse deterrent rather than a guarantee that a device or person is unique.
Apple-provided crash and performance reports
The shipping app contains no client crash-reporting or performance-monitoring SDK. When a user opts to share diagnostics with Apple, Colorlife may access Apple-provided crash logs and performance reports through App Store Connect or Xcode solely to diagnose crashes, hangs, launch failures, resource use, and performance problems. Access is limited to the operator and is not used for advertising or tracking. Reports normally remain in Apple's tools; any report exported for an active investigation is deleted within 90 days after the investigation is resolved unless a longer period is needed for a security incident, dispute, or legal obligation.
PostHog product analytics at launch
V1 Release contains no product-analytics or crash-reporting client SDK and does not offer an analytics switch. It clears any stale choice from an earlier build, deletes the legacy on-device PostHog queue directory, and sends no PostHog product-usage, crash, or diagnostic events. Settings displays Usage analytics — Off at launch. Server-side account deletion may still query PostHog using the random account UUID solely to remove any historical or test person/event record; that deletion request does not enable collection.
Aggregate advertising attribution
After the App starts, Colorlife may ask Apple's SKAdNetwork/AdAttributionKit system to register a base install conversion using fine value 0, coarse value low, and an unlocked window. If the installation followed a qualifying Meta advertisement, Apple may later send Meta a cryptographically signed, delayed attribution postback. This Apple-operated aggregate path is separate from the ATT-authorized subscription attribution described below. Apple designs these postbacks for crowd privacy and states that they do not contain user- or device-specific data. Depending on Apple's privacy tier, a postback may contain the advertised App, campaign/source values supplied by the ad network, a coarse or fine conversion value, redownload status, and limited publisher information.
Colorlife also includes Meta's official Core SDK for subscription-ad attribution. Automatic Meta App Events, automatic SDK initialization, and automatic advertiser-identifier collection are off. When the subscription screen appears, the App may present Apple's App Tracking Transparency (“ATT”) prompt. If the managing adult allows tracking, the App initializes Meta Core, obtains Meta's pseudonymous app-scoped identifier, and asks RevenueCat to collect the identifiers Apple makes available for authorized advertising attribution, including IDFA and IDFV plus limited device, network, and consent-status information.
RevenueCat may then send Meta server-side events for a trial start, trial conversion, initial subscription purchase, and subscription renewal, including product, value, currency, timing, and attribution context. This feed is used to measure and optimize Colorlife's Meta campaigns. Colorlife does not send Meta a Colorlife account UUID, email address, phone number, name, photo, prompt, generated or colored page, brush activity, or gallery activity. If ATT is denied or restricted, Colorlife does not initialize Meta Core for attribution or install Meta identifiers in RevenueCat, and RevenueCat's production integration is configured not to send that user's events to Meta. Plans, purchases, restore, generation, coloring, and every other feature remain available.
Support and website information
If you contact support, we process your email address, any sender or display name and ordinary email headers supplied by your mail service, your message, attachments, and the information needed to resolve the request. Do not attach a photo or page unless it is necessary and you have permission to share it.
The reviewed legal/support site code, when published as currently configured, does not use advertising pixels, behavioral analytics, sign-in, or a database. Its hosting and security providers may process ordinary HTTP request data such as IP address, browser/user-agent, requested URL, time, and security signals. If marketing pages later add analytics, pixels, cookies, or forms, this policy and any required consent flow must be updated before those tools are enabled.
3. How we obtain information
We receive information directly from you; automatically from the app, device, and Services; and from Apple, Supabase, OpenAI, RevenueCat, PostHog, and website or security providers as described here. We do not buy data-broker profiles about Colorlife users.
4. Why we use information and legal bases
We use personal information only for the following purposes:
- Provide the Services and perform our agreement: create and secure the account, generate and safety-check a requested page, store/sync pages, process subscription status, restore purchases, export pages, provide support, and fulfill deletion or other requests.
- Consent or your affirmative choice: process a selected photo/prompt after the in-app AI disclosure. You can withdraw this choice as described below.
- Legitimate interests where applicable:protect accounts and the Services, prevent fraud and abuse, meter generation, diagnose failures, maintain reliability, measure aggregate campaign installs through Apple's privacy-preserving system, enforce the Terms, and prevent a deleted identity from being accidentally recreated. We balance these interests against user rights and minimize the data used.
- Legal obligations and claims: comply with tax, accounting, consumer, privacy, safety, and valid legal-process requirements; preserve evidence; and establish, exercise, or defend legal claims.
Where consent is the legal basis, withdrawal does not affect processing that was lawful before the withdrawal. The in-app AI permission is also a just-in-time product disclosure and instruction; the precise legal basis may be performance of your request where permitted.
5. How OpenAI processes photos and prompts
Before the first upload, Colorlife shows an in-app disclosure and asks permission to send the selected photo or typed prompt and Colorlife's generation instructions to OpenAI's image API. OpenAI processes those materials to create the requested page, then processes the generated output for safety and delivery to Colorlife. If you choose Not now, nothing is uploaded. Before the first photo upload, Colorlife separately requires the managing adult to acknowledge that they will only choose photos they have permission to use and, for any child shown, that they are the child's parent or legal guardian or have permission from the child's parent or legal guardian. The versioned acknowledgment is stored only as an app privacy choice and is requested again after a material policy change, withdrawal, or local privacy-choice erasure. Colorlife does not try to estimate a person's age from the image.
The permission covers later requests until you withdraw it in Settings → Privacy choices → AI processing permission. After withdrawal, Colorlife asks again before another upload. Withdrawal prevents future uploads unless you grant permission again; it does not delete pages already stored in the Colorlife account.
OpenAI states that API content is not used to train its models by default unless the API customer affirmatively opts in. Its default abuse-monitoring logs may include prompts, selected photos, outputs, and derived safety metadata and are normally retained for up to 30 days, with longer retention possible when required for legal or safety reasons. Colorlife will not claim Zero Data Retention unless the exact production project and gpt-image-2 model configuration are verified as eligible and enabled.
OpenAI also states that image inputs are scanned for potential child sexual abuse material (CSAM). An image flagged as potential CSAM may be retained for manual review even when Zero Data Retention is enabled.
V1 allows parent- or guardian-authorized family photos, including photos showing children. It warns against putting unnecessary sensitive personal information in prompts. The App displays a versioned photo-permission acknowledgment before the first photo upload and again after a material policy change, permission withdrawal, or local privacy-choice erasure. The current policy version remains bound to every photo-generation request, and the server rejects a request missing that version before authentication, metering, or OpenAI processing. These controls enforce the declared product rule; they do not inspect a photo to verify age or legal authority.
Colorlife does not persist the original source photo in its own database or Storage bucket. The text prompt and generated page are stored in Colorlife until page/account deletion as described below.
6. PostHog product analytics at launch
PostHog product analytics is unavailable in V1 Release through a compile-time gate that a saved preference or remote setting cannot reopen. More fundamentally, the Release binary contains no product-analytics or crash-reporting client SDK. On launch and at identity boundaries, the app withdraws any stale PostHog choice and deletes the legacy on-device PostHog queue directory. It does not contain or configure the PostHog SDK, or identify or capture through it. Fatal-crash capture, session replay, surveys, automatic screen or lifecycle capture, element autocapture, console logs, network capture, and performance capture are unavailable through a client analytics/crash SDK.
Colorlife does not treat a provider-plan default as a retention policy for V1 product data. V1 sends no PostHog product-usage, crash, or diagnostic events, so it creates no new V1 analytics-retention period. Server-side account deletion may use a project-restricted credential to query the random account UUID solely to remove a historical or test record. That deletion request does not enable product analytics. Before a later version can offer product analytics or crash reporting, Colorlife must re-review the exact binary and embedded SDK privacy manifests, provider and exact event set, production payloads and network behavior, enforceable retention, this policy, the App Store privacy declaration, and the in-app notice and obtain a fresh voluntary choice in that later version.
7. Advertising attribution and tracking choices
Colorlife uses two Meta campaign-measurement paths. First, the app may register a baseline conversion through Apple's privacy-preserving SKAdNetwork/AdAttributionKit system. Apple decides whether a qualifying, crowd-protected postback exists and sends it to the registered ad network after a delay. Colorlife does not control or receive a user-level identity from that aggregate postback.
Second, in subscription context, the app may ask the managing adult for Apple's ATT permission. If allowed, Meta Core supplies a pseudonymous app-scoped identifier and RevenueCat collects authorized device/advertising identifiers. RevenueCat—not Colorlife's client—then sends configured trial and subscription lifecycle events to Meta's Conversions API for advertising measurement and campaign optimization. Meta may combine those identifiers and events with information it already has under its terms and privacy policy. This is tracking under Apple's definition and may be considered targeted advertising or “sharing” under some U.S. state laws.
The Meta SDK never receives photos, prompts, pages, coloring activity, a Colorlife account UUID, email address, phone number, or name. Automatic Meta App Events are disabled, and the app does not log client-side purchases, so the same purchase is not reported twice. RevenueCat's production integration must remain set not to send events when ATT is unauthorized.
You can choose Ask App Not to Trackwithout losing access to plans, purchase, restore, or any Colorlife feature. You can later change the choice in iOS Settings → Privacy & Security → Tracking → Colorlife. Turning tracking off stops future collection and event forwarding for this path after the app and providers process the updated status; it cannot recall aggregate Apple postbacks or data already processed by Apple, RevenueCat, or Meta. Contact support@colorlife.app for privacy requests concerning information Colorlife controls.
8. When we disclose information
We disclose only the categories needed for the purpose:
- Supabase: authentication, database, private file storage, Edge Functions, and related security and operational processing in the United States.
- OpenAI: selected photo or prompt, generation instructions, generated output, and safety data for AI generation and moderation.
- Apple: authentication, purchase, subscription, distribution, device permissions, App Attest and DeviceCheck security/offer-eligibility verification, and other platform services under your Apple relationship.
- Google: authentication and the email/basic profile information returned when you choose Sign in with Google. Colorlife does not request access to your Google Drive, contacts, photos, or other Google account content.
- RevenueCat:random account UUID and subscription/transaction and device/app metadata for entitlement, restore, billing support, fraud prevention, and first-party subscription analysis. With ATT authorization, RevenueCat also receives Meta's app-scoped identifier and authorized device/advertising identifiers and forwards configured trial/subscription events to Meta.
- PostHog (U.S. cloud): V1 Release contains no PostHog client SDK and sends no product-usage, crash, or diagnostic events. Server-side account deletion may submit the random account UUID solely to find and remove any historical or test record; that request does not enable collection.
- Meta:may receive Apple's delayed aggregate install-attribution postback. With ATT authorization, Meta also receives its app-scoped identifier, authorized advertising/device identifiers, limited attribution context, and RevenueCat trial/subscription lifecycle events for Colorlife ad measurement and optimization. Meta does not receive Colorlife content or contact information through this integration.
- Website, email, security, and professional providers: request/security logs and support or business records needed to host the site, answer requests, secure the Services, obtain professional advice, or operate the business.
- Legal and corporate events: information reasonably necessary to comply with valid law or legal process, protect rights and safety, investigate abuse, or complete a merger, financing, reorganization, or sale subject to applicable notice and protection requirements.
We do not make your pages public and do not disclose photos, prompts, or pages to Meta or PostHog.
9. International processing and transfers
Colorlife's Supabase project is in a U.S. region, PostHog uses U.S. cloud, and other providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws.
For EEA, UK, and Swiss transfers, Colorlife will rely on an applicable adequacy decision, provider certification, standard contractual clauses, the UK addendum, or another lawful transfer mechanism, as appropriate. The exact provider mechanisms and any required EU/UK representative must be verified before those storefronts launch.
10. Retention
We keep personal information only as long as reasonably necessary for the purpose, legal requirements, security, disputes, and enforcement. The launch schedule is:
| Information | Intended retention |
|---|---|
| Account, prompts, page settings, outlines, and colored pages | While the account/page exists, then deleted as described below |
| Inactive, unlinked anonymous accounts and their content | Automatic inactivity deletion is disabled for V1; retained while the account exists unless the user requests deletion or a later disclosed cleanup policy applies |
| Original selected source photo in Colorlife | Not persisted in Colorlife's database or Storage bucket |
| Device-local interrupted-generation recovery record | Until the page is safely saved or recovered, a definitive pre-result rejection, applicable account cleanup, or the limited reconciliation conditions described in Section 2; a failed or offline check retains the record for a later attempt |
| Colorlife-stored App Attest key identifier, public verification record, counters, and account-level promotion claim | While the account exists, then removed with account deletion, subject to the restricted records below |
| Raw DeviceCheck token | Used only to service the verification request; not logged or persisted by Colorlife |
| Apple's per-device promotional eligibility bit | Maintained by Apple and may remain after app reinstall, local-data clearing, credential changes, or Colorlife account deletion to prevent repeat offers |
| Deleted-page sync tombstone | Eligible for purge after 90 days and normally removed by the next daily cleanup; an outage may delay cleanup; no image, prompt, page settings, or former Storage path |
| PostHog product-usage, crash, and diagnostic events | Not collected by V1 Release; server-side deletion may remove a historical/test record, and any future collection requires the full re-review described in Section 6 before it is enabled |
| Apple-provided crash and performance reports | Normally retained in Apple's tools under Apple's controls; an exported report is deleted within 90 days after the related investigation is resolved, unless needed longer for a security incident, dispute, or legal duty |
| OpenAI API abuse-monitoring content | Normally up to 30 days under OpenAI's default controls, with legal/safety exceptions |
| Generation reservation and metering records | Finalized pseudonymous bookkeeping records are retained for up to 90 days, then deleted; longer only for an active dispute, security incident, or legal duty |
| RevenueCat webhook and subscription records | While needed to administer the subscription and account, then as required for billing, fraud prevention, idempotency, tax/accounting, disputes, and legal duties |
| ATT-authorized RevenueCat/Meta attribution identifiers and events | Under RevenueCat's and Meta's applicable advertising, security, and retention controls; Colorlife does not maintain a separate copy of Meta's app-scoped identifier or IDFA |
| Supabase auth, security, request, and Edge Function logs | For the period made available under the production provider plan and only as operationally needed; longer only for an investigated incident or legal requirement |
| Managed backups | Until they roll off under the provider's managed backup schedule; deleted data may remain temporarily in a backup and is not restored except for disaster recovery |
| Website/CDN security logs | Only as long as needed by the hosting/CDN provider for delivery, security, abuse prevention, and legal obligations |
| Support correspondence and attachments | While the request is active and ordinarily for up to 12 months after resolution; longer only while needed for an active dispute or legal duty |
| Deletion-worker operational records | While cleanup/retries are pending, then minimized to the suppression record below |
| Apple/Meta aggregate install-attribution postbacks | Delayed and retained under Apple/Meta aggregate-attribution controls |
Colorlife has implemented a conservative inactive-anonymous-account cleanup control, but automatic destructive cleanup is disabled for V1. An anonymous account may therefore remain server-side until the user deletes it. Colorlife will not enable an inactivity-based deletion schedule without first choosing and disclosing an inactivity period and grace period and verifying that paid, linked, or recently active accounts are excluded.
Restricted deletion-suppression record
After account deletion, Colorlife retains a restricted anti-resurrection record because delayed subscription receipts, webhooks, or long-offline devices could otherwise recreate the deleted identity. It contains only pseudonymous random UUIDs and non-content deletion and verification controls, such as timestamps, status, and sweep counters. It contains no pages, images, prompts, email, Apple subject, payment details, or contact information.
Restricted deletion-suppression and status records may also contain one-way, domain-separated hashes of temporary deletion-continuation capabilities. Colorlife uses those hashes only to verify crash-safe deletion continuation or status requests after the source account can no longer authenticate. The hashes cannot be used to reconstruct the raw capability, which is not retained in those records.
Only restricted server-side processes can access it. It is used solely to block recreation and repeat/verify provider deletion if the same pseudonymous identifier reappears. The current design retains it because the resurrection risk does not expire. The operator reviews this need at least annually and will delete or further tokenize the record if a less identifying control can provide the same protection.
Aggregated or de-identified information that cannot reasonably be linked back to a person may be retained for longer.
11. Deleting an account or page
Deleting an individual page removes its cloud image files and local cached images when deletion syncs. The minimized tombstone becomes eligible for purge after 90 days and is normally removed by the next daily cleanup so an offline device also removes the page; an outage may delay cleanup.
Settings → Delete accountstarts permanent deletion. During the request, Colorlife removes the first-party profile, page rows, stored images, and authentication account and signs out that deleted identity. The installed app then automatically starts a separate, empty guest account with a new random UUID so the app can continue working. The deleted pages and linked Apple, Google, or email identity are not restored to that guest, but Apple billing and limited RevenueCat subscription records may continue or associate an active entitlement. The replacement guest can also be deleted. Colorlife requests Apple credential revocation when applicable and queues removal of the deleted account's RevenueCat customer and any historical or test PostHog person/events where supported. Those processor operations and verification may continue after the first-party account is gone and are designed to retry after a temporary failure. Colorlife's operational target is to complete ordinary processor cleanup within 30 days; contact support for status if you have concerns.
The restricted suppression record remains as described above. Colorlife's server-side App Attest verification row, local key-identifier reference, and account-level promotion-claim rows are removed with the account, but deleting the account does not reset Apple's per-device DeviceCheck eligibility bit. That bit may continue to prevent a repeated promotional offer after reinstall or account recreation; Colorlife does not retain the raw token that identified the device to Apple. Colorlife cannot delete Apple's underlying App Attest private key or Apple service-side security records, which remain under Apple's controls. Providers may retain transaction or security records required for billing, fraud prevention, tax, accounting, legal obligations, or claims. Account deletion cannot recall a page you exported, printed, or shared outside Colorlife.
Deleting the Colorlife account does not cancel an Apple subscription. The app warns active subscribers and offers Apple's Manage Subscription screen. Cancel through Apple to stop future billing. No email or support ticket is required to start deletion in the app.
12. Your choices and privacy rights
You can:
- choose individual photos and decline AI processing;
- withdraw AI permission in Settings, which causes Colorlife to ask again before another upload;
- use V1 with no product-analytics or crash-reporting client SDK and no PostHog analytics enable control;
- decline ATT or turn tracking off later in iOS Settings without losing app or purchase functionality;
- view and delete pages in the app;
- manage the Apple subscription; and
- delete the Colorlife account in Settings.
Depending on where you live, you may also request access, correction, deletion, portability, or a copy of personal information; restriction or objection; withdrawal of consent; an appeal of a denied request; or an authorized-agent request. We may need information to verify the requester without collecting more than necessary. We do not discriminate for exercising a privacy right.
Send requests to support@colorlife.app. If we cannot honor a request, we will explain why and provide any appeal or complaint information required by law.
13. Regional disclosures
United States state privacy laws
Where applicable, the categories collected, sources, business purposes, recipients, and retention criteria are described above. We do not sell information for money. The ATT-authorized RevenueCat-to-Meta advertising measurement in Section 7 may be considered targeted advertising or “sharing.” Declining or revoking ATT opts out of that path without affecting service. Colorlife will honor applicable access, correction, deletion, portability, opt-out, appeal, and authorized-agent rights for information it controls.
We respond to applicable privacy requests through the contact method in Section 17.
EEA, UK, and Switzerland
The controller is Eli Riedel, an individual. The purposes and legal bases are in Section 4, recipients in Section 8, transfers in Section 9, and retention in Section 10. Where these laws apply, you may have rights to access, correct, erase, restrict, port, and object; withdraw consent; and complain to your local data-protection authority. You may object at any time to direct marketing and to processing based on legitimate interests, subject to legally permitted grounds.
Automated safety systems may refuse a generation request, but do not make a decision that produces a legal or similarly significant effect. Contact support if you believe a safety refusal was mistaken. Before those storefronts launch, verify and state the purpose-specific legal basis for each data category, whether providing it is required and the consequence of withholding it, the exact transfer mechanisms and how a person can obtain the safeguards, and any required EU/UK representative or data-protection contact.
14. Children
Colorlife is intended for families, but V1 does not offer child accounts or ask a child to provide personal information directly. A parent, legal guardian, or other authorized adult must manage the account, purchases, uploads, prompts, and consent controls. Children may use the coloring tools with appropriate adult supervision. An adult may upload a photo showing a child when they are the child's parent or legal guardian or have permission from the child's parent or legal guardian. The adult should avoid including unnecessary sensitive details about a child in a prompt. Colorlife is not enrolled in Apple's Kids Category and is not intended for a child to independently manage an account, purchase, upload, or advertising-tracking choice. The managing adult should answer the ATT prompt.
If you believe a child provided personal information without appropriate adult involvement, contact support@colorlife.appso we can investigate and delete it. If Colorlife's audience, accounts, or data practices change, we will update this policy and add any notices, consent, retention, or account controls required by law.
15. Security
We use administrative, technical, and organizational safeguards designed for the nature of the information, including TLS in transit, private owner-scoped Storage, row-level authorization, server-side secrets, restricted service roles, data-protection controls on device, bounded requests, and deletion verification. No system is perfectly secure, and we cannot guarantee absolute security.
16. Changes to this policy
We will update this policy when practices or law change. We will state the effective date and provide any additional notice or consent required for a material change. Prior versions will be archived with their effective dates.
17. Contact
Data controller: Eli Riedel, an individual
Public business address: 1175 Glenewinkle Road, Seguin, Texas 78155, United States
Privacy and support requests: support@colorlife.app
EU/UK representative: Not applicable to Colorlife's current U.S.-only availability.