Privacy Policy
Last updated: 31 July 2026
This policy explains what happens to your data when you use WinkPilot, an iOS app that reads a screenshot of a conversation and suggests a reply.
It describes what the app actually does. Where something is uncomfortable — where data leaves our control, or where we cannot delete something on request — this policy says so instead of leaving it out.
1. Who is responsible
Kirill Cheremkhin PR NOVI SAD
Ulica Železnička 20, 21101 Novi Sad, Serbia
Registration number: 68344808
Tax identification number: 115410331
Email: support@winkpilot.app
We are the data controller for the processing described here. We are established in Serbia and process personal data under the Serbian Personal Data Protection Act. Because we offer the app to users in the European Economic Area, the GDPR also applies to that processing.
For any privacy question, including a request to exercise your rights, write to support@winkpilot.app.
2. The short version
- There is no account. No sign-up, no email address, no password, no phone number.
- Your conversations stay on your phone. Chats, messages, screenshots and AI reports are stored in the app on your device, not on our servers.
- To generate a reply, the screenshot and the conversation text are sent to our AI provider, OpenAI. Under OpenAI's default API settings, that content may be retained by OpenAI for up to 30 days for abuse monitoring before deletion. This is the single most important fact on this page.
- Our servers store counters, not content. How many generations, on which day, what they cost. There is no place in our database where a screenshot or a message could be written.
- One thing cannot be undone. When your device receives its free credits, a single bit is set against your device at Apple. Neither you nor we can clear it. Section 8 explains it in full.
- The website you are reading sets no cookies and runs no analytics.
3. What we process, and why
3.1 The content you submit for a reply
When you ask for a reply, the app sends:
- the screenshots you selected (up to five per request, recompressed before sending);
- the text of that conversation as the app holds it: text you pasted or typed, what you told us the other person answered, and the app's own earlier description of a screenshot;
- the tone and the goal you chose, including anything you typed yourself into those two fields;
- the personalisation settings described in 3.2.
Purpose: to produce the suggested reply and the AI report you asked for. Without this the app has nothing to work with.
These are conversations between real people, and screenshots contain whatever was on the screen — including messages written by someone who has not read this policy. Please send only what the request needs, and crop out what it does not.
3.2 Your personalisation settings
Gender, age range, primary use (dating, social, work), goal and language. You choose these during onboarding and can change them in Settings. They are stored on your device and travel with each generation request so that the reply fits you.
The age field is a range, such as 25–34. We never ask for a date of birth and could not verify one if you gave it.
3.3 Purchase data
If you subscribe, Apple gives the app a signed transaction. Our server verifies it with Apple and stores two values: the original transaction identifier and the product identifier of your plan.
Purpose: to know that your subscription is active, and to attribute usage and cost to it.
We never see your payment card, your billing address or your Apple Account. Payment happens entirely inside Apple's systems.
3.4 Device integrity identifiers
Two Apple mechanisms protect the free credits from being farmed:
- App Attest proves the request comes from a genuine, unmodified copy of our app. Our server stores the resulting key identifier — a value tied to that installation, not to you.
- DeviceCheck stores two bits against your device at Apple. We use one of them to record that this device has already received its free credits. See section 8.
Purpose: fraud prevention and abuse prevention. Without them, five free replies per device would be five free replies per reinstall, and the free tier could not exist.
3.5 Usage counters
Per subscription and per day, our database records: the number of image requests and text requests, whether any request was served by the smaller model, the cost in dollars, and token counts.
Purpose: to keep the service affordable and stable, and to enforce fair-play limits. These are numbers. No message text and no screenshot is stored alongside them.
3.6 Server logs
Our server writes short diagnostic lines: which device identifier received free credits, which product identifier was checked against Apple, status codes and error shapes. No screenshot, no message text and none of your settings appear in any log line.
3.7 Connection data
Requests reach us through Cloudflare, which necessarily processes your IP address to route the request and to apply rate limiting. We do not log it, and we do not store it. Our server code reads only the authorisation header from an incoming request.
3.8 If you write to us
If you email support, we receive your email address and whatever you put in the message, and we keep the correspondence for as long as needed to deal with it.
3.9 Notifications
The reminders about your free credits are scheduled by the app on your device. There is no push server, and no notification token is sent anywhere.
4. Legal bases
For users in the EEA and the UK, we rely on:
- Performance of a contract (Art. 6(1)(b) GDPR) — everything in 3.1, 3.2 and 3.3. Generating replies and honouring a subscription is the service you asked for.
- Legitimate interests (Art. 6(1)(f)) — 3.4, 3.5, 3.6 and 3.7: preventing abuse of the free tier, keeping costs under control, diagnosing failures, and securing the service. Our interest is running a service that is not destroyed by automated abuse; the data used for it is device-level and carries no content.
- Legal obligations (Art. 6(1)(c)) — retaining what accounting and tax law requires of records of sales made through Apple.
- Your explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) — for the conversation text and the screenshots themselves, including any special category data they happen to contain. The app asks for this before it sends your first screenshot, and you can withdraw it at any time in the app's Settings, under Allow AI Analysis; withdrawal stops anything further being sent, but does not undo processing that already happened. Your answer is recorded on your own device — the date, and the version of this policy you agreed to — and nothing about it is sent to us. If we later change what we do with your conversations, that version changes and the app asks you again.
5. Special categories of data
We do not ask for your health, religion, political views, sexual orientation or any other special category of data, and we have no field designed to collect them. This is also what we declared in Apple's App Privacy questionnaire.
However, a screenshot of a private conversation may contain anything at all, and so may a free text field — including data about sexual orientation, health, beliefs or political views, whether it is yours or the other person's. We do not seek that data, we do not analyse it for any purpose beyond producing the reply you asked for, and we do not store it on our servers. It is nonetheless sent to our AI provider along with the rest of the request, and it falls under the retention described in section 7.
Because that data cannot be separated from the conversation you upload, we process it on the basis of your explicit consent under Art. 9(2)(a), which the app asks for before your first upload and which you can withdraw at any time in the app's Settings. If a conversation contains something you would not want a third party to hold for up to 30 days, do not send it.
6. Who receives your data
We sell nothing to anyone and share nothing for advertising. There is no advertising network, no attribution SDK, no analytics service and no data broker anywhere in this app or on this website.
Three companies process data on our behalf:
OpenAI (United States) — the AI provider
Receives everything listed in 3.1 and 3.2 in order to generate the reply.
Everything the app suggests is produced by a generative AI system. We say so here, on every screen that shows a suggestion, and in the Terms, in line with the transparency obligations of Article 50 of the EU AI Act. Nothing WinkPilot returns is written by a person.
Under OpenAI's API terms, content submitted through the API is not used to train their models. Under the default API retention setting, which applies to our account, that content may be retained by OpenAI for up to 30 days for abuse monitoring and is then deleted. We have not been granted zero-retention processing. If that changes, this section will change with it and the date at the top of this page will move.
Apple
Receives the App Attest attestation and the DeviceCheck token, and handles all payments and subscription management. Apple's own privacy policy governs what Apple does with it.
Cloudflare
Hosts our server code, our database and this website, and processes connection data as described in 3.7.
We may also disclose data if the law requires it of us.
International transfers. We are in Serbia; OpenAI, Apple and Cloudflare process data in the United States and elsewhere. Where data of EEA users is transferred outside the EEA, it is transferred on the basis of the European Commission's Standard Contractual Clauses agreed with those providers.
7. How long data is kept
| What | Where | For how long |
|---|---|---|
| Chats, messages, screenshots, AI reports | your device | until you delete the chat or the app |
| Your settings | your device | until you delete the app |
| Free-credit token and App Attest key identifier | your device's Keychain | survives deleting the app; removed when the device is erased |
| The content of a generation request | OpenAI | up to 30 days (section 6) |
| Transaction identifier, product identifier, usage counters, cost | our database | for as long as the service operates. We have not set an automatic deletion period, and we do not claim one. These rows carry no content. |
| Free-tier device identifier and its counters | our database | same as above |
| Diagnostic logs | Cloudflare | under Cloudflare's log retention for our plan |
| The DeviceCheck bit | Apple | indefinitely, and it cannot be cleared — section 8 |
| Support email | our mailbox | as long as needed to handle the matter |
8. The one thing we cannot delete
When your device receives its free credits, our server sets one bit against that device at Apple, through DeviceCheck. It records a single fact: this device has already used its free trial.
It carries nothing else — no content, no settings, no identity. But it lives at Apple, against the device, and:
- it survives deleting the app;
- it survives reinstalling the app;
- neither you nor we can clear it. There is no API for us to unset it in a way that would restore your free credits, and no request you can send us that would change that.
We disclose this because it is the only place where a promise to erase your data on request would be untrue.
9. Your rights
If the GDPR or the Serbian Personal Data Protection Act applies to you, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, to data portability, and to lodge a complaint with your supervisory authority — in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection.
Write to support@winkpilot.app to exercise any of them.
Two honest limits on what we can do:
- Most of your data is not ours to give you. Your conversations are on your device, and you can already see, export and delete them there. We hold no copy.
- We have no account to look you up by. Our records are keyed to an Apple transaction identifier or to a device key identifier. To act on a request about them, we need you to supply the relevant identifier; otherwise we cannot tell your rows from anyone else's, and we will not guess. The DeviceCheck bit in section 8 is outside this entirely.
Requests about data held by OpenAI or by Apple are best addressed to them directly, and we will help where we can.
Withdrawing your consent is the exception to both limits: it is done in the app's Settings, it takes effect immediately, and it needs neither a message to us nor an identifier, because the answer is held on your device and nowhere else.
10. If you are in the United States
This section applies in addition to everything above if you live in a U.S. state with a consumer privacy law. Those laws use different words for the same things, so here it is in theirs.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have. There is no advertising network, no ad identifier, no attribution partner and no data broker anywhere in this app. There is nothing here for you to opt out of, and we run no financial incentive or loyalty programme tied to your data.
We do not profile you. No automated decision is made about you that produces a legal or similarly significant effect. The AI report describes the tone of a conversation you supplied; it is not an assessment of you, and it is generated on request and kept on your device.
We do not collect health data. We do not ask about your physical or mental health, and nothing in the app is designed to infer it.
Sensitive personal information. We do not collect it for the purpose of inferring characteristics about you. Section 5 explains the one honest caveat: a screenshot or a free text field can contain anything, and what you send is sent.
Categories, purposes, sources and retention. Section 3 lists every category we process and why; section 6 lists who receives it; section 7 says how long it is kept. The source of all of it is you and the device you use.
Your rights. Depending on your state, you may have the right to know what we process and to obtain a copy of it, to have it corrected, to have it deleted, to limit the use of sensitive personal information, and to opt out of sale, sharing, targeted advertising and profiling. You also have the right not to be treated worse for exercising any of them, and we will not do that.
Write to support@winkpilot.app to exercise any right. You may use an authorised agent; we may ask them to prove they act for you. If we refuse a request, we will say why, and you may appeal by replying to the same address.
The two limits in section 9 apply here too, and they are not evasions: your conversations are on your device and we hold no copy, and our server records are keyed to an Apple transaction identifier or a device key identifier rather than to a person.
Children under 13. WinkPilot is not directed to children, and we do not knowingly collect personal information from a child under 13. If we learn that we have, we will delete it. If you believe a child under 13 has used the app, write to support@winkpilot.app.
11. Children
WinkPilot is rated 16+ and is not intended for anyone under 16. We do not knowingly process the data of children under 16. If you believe a child has used the app, write to support@winkpilot.app and we will act on it.
The app must not be used to compose messages to a minor, and the Terms of Use say so as a condition of using it.
12. Security
Everything the app sends travels over TLS. The free-tier token and its key identifier are held in the iOS Keychain. Requests are authenticated with signed tokens and, for the free tier, with Apple's App Attest. The administrative interface of our server sits behind Cloudflare Access.
No system is perfectly secure, and we do not claim ours is.
13. This website
These pages are static files. They set no cookies, load no fonts or scripts from third parties, and run no analytics. Nothing you do here is measured, which is why you are not being asked to consent to anything.
14. Changes
If this policy changes, the date at the top changes with it. Where a change is material — a new recipient of data, or a new category of data — we will say so on this page rather than let the date carry the whole message.
15. Contact
Kirill Cheremkhin PR NOVI SAD, Ulica Železnička 20, 21101 Novi Sad, Serbia
support@winkpilot.app