Privacy Policy

Last updated: 31 July 2026

This policy explains what happens to your data when you use WinkPilot, an iOS app that reads a screenshot of a conversation and suggests a reply.

It describes what the app actually does. Where something is uncomfortable — where data leaves our control, or where we cannot delete something on request — this policy says so instead of leaving it out.


1. Who is responsible

Kirill Cheremkhin PR NOVI SAD
Ulica Železnička 20, 21101 Novi Sad, Serbia
Registration number: 68344808
Tax identification number: 115410331
Email: support@winkpilot.app

We are the data controller for the processing described here. We are established in Serbia and process personal data under the Serbian Personal Data Protection Act. Because we offer the app to users in the European Economic Area, the GDPR also applies to that processing.

For any privacy question, including a request to exercise your rights, write to support@winkpilot.app.


2. The short version


3. What we process, and why

3.1 The content you submit for a reply

When you ask for a reply, the app sends:

Purpose: to produce the suggested reply and the AI report you asked for. Without this the app has nothing to work with.

These are conversations between real people, and screenshots contain whatever was on the screen — including messages written by someone who has not read this policy. Please send only what the request needs, and crop out what it does not.

3.2 Your personalisation settings

Gender, age range, primary use (dating, social, work), goal and language. You choose these during onboarding and can change them in Settings. They are stored on your device and travel with each generation request so that the reply fits you.

The age field is a range, such as 25–34. We never ask for a date of birth and could not verify one if you gave it.

3.3 Purchase data

If you subscribe, Apple gives the app a signed transaction. Our server verifies it with Apple and stores two values: the original transaction identifier and the product identifier of your plan.

Purpose: to know that your subscription is active, and to attribute usage and cost to it.

We never see your payment card, your billing address or your Apple Account. Payment happens entirely inside Apple's systems.

3.4 Device integrity identifiers

Two Apple mechanisms protect the free credits from being farmed:

Purpose: fraud prevention and abuse prevention. Without them, five free replies per device would be five free replies per reinstall, and the free tier could not exist.

3.5 Usage counters

Per subscription and per day, our database records: the number of image requests and text requests, whether any request was served by the smaller model, the cost in dollars, and token counts.

Purpose: to keep the service affordable and stable, and to enforce fair-play limits. These are numbers. No message text and no screenshot is stored alongside them.

3.6 Server logs

Our server writes short diagnostic lines: which device identifier received free credits, which product identifier was checked against Apple, status codes and error shapes. No screenshot, no message text and none of your settings appear in any log line.

3.7 Connection data

Requests reach us through Cloudflare, which necessarily processes your IP address to route the request and to apply rate limiting. We do not log it, and we do not store it. Our server code reads only the authorisation header from an incoming request.

3.8 If you write to us

If you email support, we receive your email address and whatever you put in the message, and we keep the correspondence for as long as needed to deal with it.

3.9 Notifications

The reminders about your free credits are scheduled by the app on your device. There is no push server, and no notification token is sent anywhere.


4. Legal bases

For users in the EEA and the UK, we rely on:


5. Special categories of data

We do not ask for your health, religion, political views, sexual orientation or any other special category of data, and we have no field designed to collect them. This is also what we declared in Apple's App Privacy questionnaire.

However, a screenshot of a private conversation may contain anything at all, and so may a free text field — including data about sexual orientation, health, beliefs or political views, whether it is yours or the other person's. We do not seek that data, we do not analyse it for any purpose beyond producing the reply you asked for, and we do not store it on our servers. It is nonetheless sent to our AI provider along with the rest of the request, and it falls under the retention described in section 7.

Because that data cannot be separated from the conversation you upload, we process it on the basis of your explicit consent under Art. 9(2)(a), which the app asks for before your first upload and which you can withdraw at any time in the app's Settings. If a conversation contains something you would not want a third party to hold for up to 30 days, do not send it.


6. Who receives your data

We sell nothing to anyone and share nothing for advertising. There is no advertising network, no attribution SDK, no analytics service and no data broker anywhere in this app or on this website.

Three companies process data on our behalf:

OpenAI (United States) — the AI provider

Receives everything listed in 3.1 and 3.2 in order to generate the reply.

Everything the app suggests is produced by a generative AI system. We say so here, on every screen that shows a suggestion, and in the Terms, in line with the transparency obligations of Article 50 of the EU AI Act. Nothing WinkPilot returns is written by a person.

Under OpenAI's API terms, content submitted through the API is not used to train their models. Under the default API retention setting, which applies to our account, that content may be retained by OpenAI for up to 30 days for abuse monitoring and is then deleted. We have not been granted zero-retention processing. If that changes, this section will change with it and the date at the top of this page will move.

Apple

Receives the App Attest attestation and the DeviceCheck token, and handles all payments and subscription management. Apple's own privacy policy governs what Apple does with it.

Cloudflare

Hosts our server code, our database and this website, and processes connection data as described in 3.7.

We may also disclose data if the law requires it of us.

International transfers. We are in Serbia; OpenAI, Apple and Cloudflare process data in the United States and elsewhere. Where data of EEA users is transferred outside the EEA, it is transferred on the basis of the European Commission's Standard Contractual Clauses agreed with those providers.


7. How long data is kept

What Where For how long
Chats, messages, screenshots, AI reports your device until you delete the chat or the app
Your settings your device until you delete the app
Free-credit token and App Attest key identifier your device's Keychain survives deleting the app; removed when the device is erased
The content of a generation request OpenAI up to 30 days (section 6)
Transaction identifier, product identifier, usage counters, cost our database for as long as the service operates. We have not set an automatic deletion period, and we do not claim one. These rows carry no content.
Free-tier device identifier and its counters our database same as above
Diagnostic logs Cloudflare under Cloudflare's log retention for our plan
The DeviceCheck bit Apple indefinitely, and it cannot be cleared — section 8
Support email our mailbox as long as needed to handle the matter

8. The one thing we cannot delete

When your device receives its free credits, our server sets one bit against that device at Apple, through DeviceCheck. It records a single fact: this device has already used its free trial.

It carries nothing else — no content, no settings, no identity. But it lives at Apple, against the device, and:

We disclose this because it is the only place where a promise to erase your data on request would be untrue.


9. Your rights

If the GDPR or the Serbian Personal Data Protection Act applies to you, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, to data portability, and to lodge a complaint with your supervisory authority — in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection.

Write to support@winkpilot.app to exercise any of them.

Two honest limits on what we can do:

  1. Most of your data is not ours to give you. Your conversations are on your device, and you can already see, export and delete them there. We hold no copy.
  2. We have no account to look you up by. Our records are keyed to an Apple transaction identifier or to a device key identifier. To act on a request about them, we need you to supply the relevant identifier; otherwise we cannot tell your rows from anyone else's, and we will not guess. The DeviceCheck bit in section 8 is outside this entirely.

Requests about data held by OpenAI or by Apple are best addressed to them directly, and we will help where we can.

Withdrawing your consent is the exception to both limits: it is done in the app's Settings, it takes effect immediately, and it needs neither a message to us nor an identifier, because the answer is held on your device and nowhere else.


10. If you are in the United States

This section applies in addition to everything above if you live in a U.S. state with a consumer privacy law. Those laws use different words for the same things, so here it is in theirs.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have. There is no advertising network, no ad identifier, no attribution partner and no data broker anywhere in this app. There is nothing here for you to opt out of, and we run no financial incentive or loyalty programme tied to your data.

We do not profile you. No automated decision is made about you that produces a legal or similarly significant effect. The AI report describes the tone of a conversation you supplied; it is not an assessment of you, and it is generated on request and kept on your device.

We do not collect health data. We do not ask about your physical or mental health, and nothing in the app is designed to infer it.

Sensitive personal information. We do not collect it for the purpose of inferring characteristics about you. Section 5 explains the one honest caveat: a screenshot or a free text field can contain anything, and what you send is sent.

Categories, purposes, sources and retention. Section 3 lists every category we process and why; section 6 lists who receives it; section 7 says how long it is kept. The source of all of it is you and the device you use.

Your rights. Depending on your state, you may have the right to know what we process and to obtain a copy of it, to have it corrected, to have it deleted, to limit the use of sensitive personal information, and to opt out of sale, sharing, targeted advertising and profiling. You also have the right not to be treated worse for exercising any of them, and we will not do that.

Write to support@winkpilot.app to exercise any right. You may use an authorised agent; we may ask them to prove they act for you. If we refuse a request, we will say why, and you may appeal by replying to the same address.

The two limits in section 9 apply here too, and they are not evasions: your conversations are on your device and we hold no copy, and our server records are keyed to an Apple transaction identifier or a device key identifier rather than to a person.

Children under 13. WinkPilot is not directed to children, and we do not knowingly collect personal information from a child under 13. If we learn that we have, we will delete it. If you believe a child under 13 has used the app, write to support@winkpilot.app.


11. Children

WinkPilot is rated 16+ and is not intended for anyone under 16. We do not knowingly process the data of children under 16. If you believe a child has used the app, write to support@winkpilot.app and we will act on it.

The app must not be used to compose messages to a minor, and the Terms of Use say so as a condition of using it.


12. Security

Everything the app sends travels over TLS. The free-tier token and its key identifier are held in the iOS Keychain. Requests are authenticated with signed tokens and, for the free tier, with Apple's App Attest. The administrative interface of our server sits behind Cloudflare Access.

No system is perfectly secure, and we do not claim ours is.


13. This website

These pages are static files. They set no cookies, load no fonts or scripts from third parties, and run no analytics. Nothing you do here is measured, which is why you are not being asked to consent to anything.


14. Changes

If this policy changes, the date at the top changes with it. Where a change is material — a new recipient of data, or a new category of data — we will say so on this page rather than let the date carry the whole message.


15. Contact

Kirill Cheremkhin PR NOVI SAD, Ulica Železnička 20, 21101 Novi Sad, Serbia
support@winkpilot.app