Legal

Privacy Policy

What we collect

Your account details, what you type and the photos you pick for AI features, and — only for the sources you switch on — live data like weather, health, or your next calendar event.

What leaves your device

Only what a request needs, only when you act. Section 3 lists every field, exactly.

Who we share with

Service providers that run the app: Supabase, Google (Gemini + Firebase), Apple, RevenueCat, Open-Meteo, Cloudinary, Brevo, and Google AdMob.

What we never do

We don't sell your personal information, we don't use your health data for advertising, and we don't train our own AI models on your content.

Where designs live

On your device and in your own iCloud — not on our servers, unless you deliberately share one by link.

Children

WidgetAI is not for children under 13, and we don't knowingly collect their data.

1. Who we are

WidgetAI (“WidgetAI,” “we,” “us,” or “our”) is an independent iOS app for designing home screen and Lock Screen widgets. It is developed and operated by a sole developer based in Saudi Arabia. For the purposes of the GDPR, the Saudi Personal Data Protection Law, and similar laws, WidgetAI is the controller of the personal information described in this notice.

This notice explains what we collect, why, who else sees it, and what you can do about it. It covers the WidgetAI iOS app, its home screen and Lock Screen widget extension, and this website.

Questions? Email support.widgetai@gmail.com. If you disagree with anything here, please don't use WidgetAI.

2. What information do we collect?

In Short: Account details, the content you hand to AI features, the live-data sources you switch on, and basic usage data.

Information you give us

  • Account details — your email address and password (stored hashed, never in readable form), or the name and email your Apple ID or Google account shares with us if you sign in that way.
  • Profile — an optional display name and profile photo. Profile photos are stored on our servers.
  • Onboarding and “About You” answers — your first name, lifestyle, goals, and aesthetic preferences, if you choose to give them. Used only to personalize your widgets. You can view and edit them in Settings → About You.
  • Support, feedback, and feature requests — whatever you write to us, plus your app version and device model so we can reproduce a problem.

You can use parts of WidgetAI without an account. In that case we create an anonymous identifier so the app functions; it is not connected to your name or email unless you later create an account.

Content you give to AI features

  • Chat messages and prompts — what you type when describing a widget.
  • Photos you choose — a wallpaper for Color Match, a home screen screenshot for Home Screen Doctor, or an image you attach in chat. Photos are sent for analysis only when you pick them. We never scan your photo library.
  • Voice input — the microphone button uses Apple's speech recognition, which may process the audio on Apple's servers under Apple's Privacy Policy. We only ever receive the resulting text.
  • Your saved designs — used as soft style hints so future results feel like yours.

Live data — only the sources you switch on

Every live-data source is off until you enable it in Settings → Live Data and grant the matching iOS permission. Each is read on your device so your widgets can display real values:

  • Apple Health — activity, heart, sleep, body and hydration measurements.
  • Location — for local weather, at approximate (neighbourhood-level) accuracy. If you set up Smart Widget place conditions, it may also be checked in the background so a widget can change by place; optional, and off by default.
  • Calendar and Reminders — your next event and pending reminders.
  • Contacts — only the name and birthday fields, to show the next upcoming birthday. Never phone numbers, emails, or addresses.
  • Battery level — no iOS permission required.

Turning a source on lets both your widget and the AI use it — section 3 covers what that sends. You can turn any source off at any time.

Data we write back to your device

With your permission, two features write to Apple's own apps so those records live where you own them: tapping a water tracker logs hydration to Apple Health, and habits on a habit-tracker widget become recurring Reminders in a “WidgetAI Habits” list. We never write estimated values, and this data goes nowhere else.

Information collected automatically

  • Usage and device data — screens viewed, features used, app version, device model, iOS version, and general region, via Google Firebase Analytics. Used to understand which features work, not to profile you.
  • A hashed device identifier — used only to prevent abuse of referral bonuses. We store an irreversible hash; the identifier itself never leaves your device, and the hash can't be used to identify you or track you across other apps.
  • Service-health signals — whether our backend responded, so the app can tell you honestly when something is down.

Payment data

Subscriptions are sold and billed by Apple through your Apple ID. We never see or store your card details. We receive from Apple, via RevenueCat, only your subscription status: which plan, whether it is active, and when it renews or expires.

Google API Services

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. AI features — what leaves your device

In Short: Nothing goes to the AI unless you act. When it does, this is what goes with it.

AI features are powered by Google Gemini. When you ask for a design, your request goes to Google to be turned into one. WidgetAI currently uses Gemini's free service tier, and under Google's terms for that tier Google may use these requests to improve their models, and a human reviewer may read them. So please don't put anything private or sensitive in a prompt. We don't train any model of our own on your content, and we never send anything to the AI unless you ask for it. If we move to Gemini's paid tier — where Google does not use your content this way — we'll update this section and say so.

A request only happens on a deliberate action — sending a message, picking a photo, asking for a design or an image. Nothing is sent in the background.

One exception, and you switch it on yourself. A widget with Live Adaptive enabled re-checks its own design when you open the app, so that widget's current conditions are sent the same way — without you asking each time. It applies only to widgets you turned it on for, and turning it off stops it.

What a request contains

  • Your prompt and the recent conversation
  • Any photo you picked for that request
  • A picture of the design as it was built, so the AI can check it came out right — if your own photo is in the design, it is part of that picture
  • Style hints from designs you've saved, and your “About You” answers
  • For chat replies, a short account summary — your first name if you set one, your plan and renewal date, your credit and save counts, and whether a WidgetAI widget is placed — never your email, password, payment details or any identifier
  • A snapshot of the live-data sources you switched on, so the design can be built around real values: the time and date; your city and country (never coordinates); current weather; the health values you enabled, such as activity, heart, sleep and body measurements; the title and time of your next calendar event and next reminder; the name and date of the next birthday; battery level.

If a source is off, none of its values are ever included — turn any of them off in Settings → Live Data or in iOS Settings, and it takes effect immediately. Health data is never used for advertising, marketing, or profiling, and goes nowhere beyond Google as described here. Photos are used to fulfil the request and aren't kept on our servers.

AI-generated content

Designs, text, and images from WidgetAI are AI-generated and can be imperfect — review a design before relying on it, and never treat a widget as medical, financial, or professional advice. Images generated through Gemini carry Google's SynthID watermark and C2PA metadata marking them as AI-generated.

If Gemini is unavailable while you're creating an essential image such as a wallpaper, the text prompt alone may go to Pollinations, a free image service, to produce that one image. No photos, live data, or account information are sent there.

4. How do we use your information?

In Short: To run the app, build what you ask for, bill you correctly, keep the service safe, and make it better.
  • Providing the app — your account, your saved designs, and rendering your widgets.
  • AI generation and personalization — producing what you ask for, and using your saved designs and stated preferences as hints so results feel like yours.
  • Subscriptions and credits — confirming your plan with Apple and metering credit use.
  • Support — answering you and diagnosing bugs you report.
  • Safety and anti-abuse — rate limits, referral-fraud checks, and preventing misuse of AI features.
  • Analytics and advertising — understanding which features get used (section 7 covers ads).
  • Legal compliance — meeting our obligations and responding to lawful requests.

5. What legal bases do we rely on?

In Short: We only process your information when we have a valid legal reason.

If you are in the EU, EEA, UK, or Switzerland, we rely on the following bases under the GDPR:

  • Performance of a contract — running your account, generating what you request, and delivering your subscription.
  • Consent — for sensitive data (health, location, calendar, reminders, contacts) and for any personalized advertising. You may withdraw consent at any time by turning the source off; that does not affect processing that already happened.
  • Legitimate interests — security, anti-fraud, service health, and product analytics, balanced against your rights.
  • Legal obligation — where the law requires us to keep or disclose information.

If you are in Saudi Arabia, we process personal data under the Personal Data Protection Law on the basis of your consent, the performance of our agreement with you, and our legitimate interests where the law permits. In Canada we rely on express or implied consent under PIPEDA and Quebec's Law 25.

6. When and with whom do we share your information?

In Short: Only with the service providers that make the app work — and we don't sell your data.

Each provider below is bound to use your information only to provide their service to us, and to protect it to a standard equal to this notice.

  • Supabase — hosting, accounts, and storage · Privacy Policy
  • Google (Gemini API) — AI generation: your prompts, photos you pick, and the live-data snapshot described in section 3 · Privacy Policy
  • Google (Firebase Analytics) — app usage analytics · Privacy Policy
  • Google (AdMob) — advertising in the free tier, see section 7 · How Google uses data
  • Apple — app distribution, payments, sign-in, speech recognition, and iCloud where you use it · Privacy Policy
  • RevenueCat — subscription status and receipt validation · Privacy Policy
  • Open-Meteo — weather. Receives approximate coordinates and nothing else, including from the widget itself so it stays current while the app is closed · Terms & Privacy
  • Cloudinary — hosts template imagery; your device's IP is visible to it, as with any image on the web · Privacy Policy
  • Brevo — account emails such as verification codes and password resets · Privacy Policy
  • Pollinations — image-generation fallback, text prompt only (section 3) · pollinations.ai

We may also disclose information where the law requires it, to protect our rights or someone's safety, or in connection with a merger, acquisition, or sale of assets — in which case we will tell you before your information becomes subject to a different privacy notice.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

7. Advertising

In Short: The free tier may show ads, served by Google AdMob. We request non-personalized ads. Pro removes them.

WidgetAI's free tier may show a small number of ads, and may offer you the option to watch a short ad in exchange for AI credits. Ads are served by Google AdMob.

  • We request non-personalized ads — chosen from general context rather than a profile built from your activity across other apps and sites. Google processes limited data to serve, measure, and protect against fraud in those ads (details).
  • Health, location-history, calendar, reminder, and contact data are never used for advertising.
  • If we ever offer personalized ads, iOS will ask your permission first, and declining changes nothing else about the app.
  • WidgetAI Pro removes ads entirely.

8. Shared designs and referrals

In Short: Sharing a design uploads it so the link works. Anyone with the link can see it until you remove the link.

Share links

Sharing is the only thing that puts a design on our servers. It uploads what the link needs: the design itself, a preview image, and any photo you used in it. Personal tracker state, Smart Widget rules, and live data never travel — the recipient's widget reads their own weather, health, and calendar, never yours.

A share link keeps working until you remove it (in the app: Settings → Shared links → Stop sharing), and anyone holding it can view the design until then, so treat it as public and don't put anything private in a design you intend to share. A removed link stops working at once, and the shared design and its uploaded images are deleted automatically within a day. Deleting your account removes all of your shares too, and you can email support.widgetai@gmail.com if you need help removing one.

Referrals

If you invite a friend, we record the link between the two accounts to award the bonus credits, plus the hashed device identifier from section 2 as an anti-abuse check. Your friend sees only your invite code, never your email address.

9. Where your data actually lives

In Short: Some of it is only on your iPhone, some is on our servers, and some is in your own iCloud.
  • On your device only — the rendered widget images on your Home Screen and Lock Screen, cached live-data values, and your local preferences. These are never uploaded.
  • In your own iCloud — your designs back up to your private iCloud container, which we cannot read, so a new phone or a reinstall restores them. On by default when iCloud is available; you can turn it off in Settings. We never put health data in iCloud.
  • On our servers — your account, your profile photo, your credit balance and subscription status, your referral records, and any design you have deliberately shared by link.

10. Is your information transferred internationally?

In Short: Yes — our servers and providers are primarily in the United States and Europe.

WidgetAI is operated from Saudi Arabia and our providers operate globally, so your information is processed outside your country. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which our providers maintain as part of their data processing agreements. Transfers of Saudi personal data outside the Kingdom are made in line with the Personal Data Protection Law and its implementing regulations.

11. How long do we keep your information?

In Short: As long as you have an account — and no longer than we need.
  • Your account — kept while the account exists. Deleting it removes your records from our active systems, and from our providers' ordinary backup cycle.
  • Your designs — we don't hold them, so there is nothing for us to keep. Deleting your account erases them from this device and from your iCloud; the app offers to export a copy first.
  • Photos sent to AI features — used to fulfil that request and not retained on our servers afterwards.
  • Location — used to look up weather and discarded immediately; we never build a location history.
  • Health, calendar, reminders, and contacts — read on your device when a widget or request needs them. We do not store them on our servers.
  • Shared designs — kept until you remove the link (Settings → Shared links), then deleted automatically within a day. Deleting your account removes them too.
  • Support emails — kept while we need them to help you and to keep a record of the issue.
  • Records we must keep — such as those needed for tax, accounting, or fraud prevention, for as long as the law requires.

12. How do we keep your information safe?

In Short: Encrypted in transit and at rest, with access scoped to your own account.

We use appropriate technical and organizational measures to protect your information: traffic between the app and our servers is encrypted in transit, our provider encrypts data at rest, and database access is scoped so your records are readable only by your account.

No system is perfectly secure. Please use a strong, unique password and tell us at support.widgetai@gmail.com if you suspect someone has accessed your account.

13. Do we collect information from children?

In Short: WidgetAI is not intended for children under 13.

WidgetAI is a general-audience app and is not directed to children. You must be at least 13 to use it, and if you are under the age of majority where you live, a parent or guardian must agree to our Terms of Service on your behalf. In parts of the EEA and the UK the age of consent for online services is higher than 13, and below it a parent or guardian must consent.

We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, email support.widgetai@gmail.com and we will delete it promptly.

14. What are your privacy rights?

In Short: Access, correct, delete, export, object, and withdraw consent — free of charge.

Depending on where you live, you have the right to:

  • Know and access what personal information we hold about you, and get a copy.
  • Correct information that is wrong or incomplete.
  • Delete your personal information.
  • Port your data to another service in a machine-readable format.
  • Object to or restrict certain processing, including profiling.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Not be discriminated against for exercising any of these rights. WidgetAI works the same either way.

The fastest routes are in the app: Settings → Live Data to withdraw consent for any source, Settings → About You to see and edit what you told us, and Settings → Manage Account → Delete Account to delete everything. You can also email support.widgetai@gmail.com. We may need to verify your identity — usually by confirming the email on the account — and we will answer within the time your law allows (30 days in most places, 45 in California).

If you are in the EEA, the UK, or Switzerland you may also lodge a complaint with your local data protection authority. If you are in Saudi Arabia you may complain to the Saudi Data & AI Authority (SDAIA).

15. Do United States residents have specific rights?

In Short: Yes — and the answer is the same in every state: we don't sell your data.

If you live in a US state with a comprehensive privacy law — California, Colorado, Connecticut, Texas, Virginia and a growing number of others — you have the rights listed in section 14.

Categories of personal information collected in the past 12 months

  • Identifiers — name, email address, account ID, hashed device identifier
  • Customer records — account credentials (stored hashed)
  • Commercial information — subscription plan and status, AI credit balance
  • Internet or network activity — feature usage and screens viewed
  • Geolocation data — approximate location for weather; not retained
  • User content — prompts, photos you pick, and designs you create
  • Inferences — style preferences drawn from designs you save
  • Sensitive personal information — account credentials, health data, and location where you enable it

We collect these for the purposes in section 4 and share them only with the providers in section 6. We have not sold or shared personal information for cross-context behavioural advertising, and we do not use or disclose sensitive personal information beyond the purposes permitted without an opt-out right. We do not knowingly sell or share the personal information of anyone under 16.

How to exercise your rights

Use the in-app controls in section 14, or email support.widgetai@gmail.com. You may use an authorized agent with proof of authorization. If we decline a request you may appeal by replying to our response, and we will explain our decision in writing. As a native app we don't receive browser opt-out signals such as Global Privacy Control — but since we don't sell or share personal information, there is nothing to opt out of.

California “Shine the Light”

We do not share personal information with third parties for their own direct marketing purposes.

16. Do other regions have specific rights?

EU / EEA / UK / Switzerland (GDPR)

You have rights of access, rectification, erasure, restriction, portability, and objection, plus the right to withdraw consent and to complain to your supervisory authority. Our legal bases are in section 5 and our transfer safeguards in section 10.

Saudi Arabia (PDPL)

You have the right to be informed, to access and obtain a copy of your personal data, and to request its correction or destruction, subject to the exceptions in the law. Contact support.widgetai@gmail.com, or SDAIA if our response doesn't satisfy you.

Canada, Australia, New Zealand, South Africa

You have rights of access, correction, and — where applicable — deletion and consent withdrawal under PIPEDA and Quebec's Law 25, the Privacy Act 1988 (Cth), the Privacy Act 2020, and POPIA. Contact us first; if you're unsatisfied you may approach your national privacy regulator.

17. Controls for Do-Not-Track features

WidgetAI is a native iOS app and does not track you across other companies' apps or websites. There is no finalized standard for how mobile apps should respond to Do-Not-Track signals, so we do not respond to them. On iOS, Apple's App Tracking Transparency setting is the control that matters, and we honour it.

18. Do we update this notice?

In Short: Yes — and we'll tell you before anything material changes.

We update this notice as the app changes and as the law changes. The “Last updated” date at the top always reflects the current version. If we make a material change — for example, sending a new category of data to a new provider — we will tell you by email or in the app before it takes effect, and where the law requires it we will ask for your consent again.

19. How can you contact us?

For anything in this notice, including data protection requests:

20. How can you review, update, or delete your data?

In the app: Settings → Manage Account → Delete Account permanently deletes your account, your saved designs, your credit balance, and your referral records. This cannot be undone. Widgets already placed on your Home Screen stop updating.

By email: write to support.widgetai@gmail.com and we will respond within 30 days, or sooner where your law requires it.

Deleting the app alone does not delete your account — use the in-app option or email us.