TJ Photo Studio for iPhone and iPad

Last updated: 8 October 2026

TJ Photo Studio for iPhone and iPad — Privacy Notice

This notice covers the native TJ Photo Studio iOS app operated by TJ NOVA LTD, the controller of the account and service data described below. Privacy enquiries: support@tjnovaltd.com.

Photos and local projects

The native photo editor processes the images you choose on your iPhone or iPad. Its photo-processing and project-storage code does not upload those images to our account service or a cloud image model. Saved projects contain image pixels, thumbnails, edit settings, a project name and a creation date in the app's private storage. This project folder is excluded from iOS device backup by the app. Edited images are newly encoded without copying the source image's EXIF/GPS metadata. Your original library photos are not changed.

An account is optional for local editing. Local projects are tied to this app installation, rather than a TJ account: they can remain available after sign-out, account deletion or an account change. Exporting or sharing creates additional copies. The destination you select, and any recipient, handles the copy under its own rules.

Account and subscription data

Signing in with Apple supplies an Apple account identifier and a verified email address, which can be Apple's private relay address. Apple may also supply your name on the first authorisation. We use this information to create and authenticate your TJ account. The app stores its session credential, account ID, email and Apple account identifier in this device's Keychain. It sends the session credential when requesting account or subscription services.

Pro purchases and subscription reconciliation in the native app require a signed-in TJ account. The app sends Apple transaction identifiers to our account service, which verifies purchase information with Apple and records product identifiers, transaction and order identifiers, subscription status and expiry, and the account to which the purchase belongs. An account-specific purchase UUID helps bind the purchase to that account; it is not a physical-device identifier. Our records can also contain the product's configured amount and currency, which need not equal the amount Apple actually charged. Apple handles checkout and payment details; this native purchase flow does not give us your card number or bank details.

If you choose email sign-in, registration or password reset, the service receives the email address, the password you submit for that operation and, where required, a verification code. Stored account passwords are hashed on the server. The native app does not save your password in its session Keychain item. Verification and recovery messages use the configured email-delivery provider. The app can send your preferred language; the provider's available message templates may use a supported language or an English fallback.

Service events, statistics and security

Our account service records account registration, sign-in, purchase and deletion events, including event times and, while attributed to an account, its account identifier and relevant order/provider information. We use these records to operate the service and to calculate service statistics such as active accounts, sign-ups, paying accounts and purchase totals. These records are not limited to an analytics SDK: the account service itself creates and reports them.

Account sessions and security/audit records can contain your IP address and User-Agent. Requests also carry the app's bundle identifier and preferred language. We use connection and session information for authentication, security and abuse prevention. This native app has no advertising-identifier or GPS-location collection feature, and its service flow does not perform cross-app advertising tracking.

Service providers and disclosure

Apple processes sign-in, App Store purchases and transaction verification under Apple's own privacy rules. Our hosted account service uses Cloudflare infrastructure. Service providers may process the account, transaction and connection data needed to provide those functions. If an operational order webhook is enabled, it can receive your account ID, email, order/product identifiers, provider and the recorded amount/currency to reconcile the order. Email delivery, where used by an account or support service, involves the recipient address and the message provider. These account-service integrations do not receive photo pixels from the native editor's account/commerce requests.

We may also disclose information when necessary to comply with applicable law, address fraud or protect rights. We use account and purchase data to provide the service you request, rely on legitimate interests for security and service statistics subject to applicable law, and retain records when required by legal obligations. Where a particular processing activity requires consent, that consent applies to that activity.

Account deletion and retention

In the app's Account screen, choose Delete account and confirm. For an Apple-linked account, complete Apple's reauthorisation when requested. Email accounts use their current authenticated session for deletion. A confirmed server response deactivates the account and removes its direct profile and sign-in/session information. Some financial, transaction-ownership, fraud-prevention, security or deletion-receipt records may remain personal or pseudonymous. A stable account or purchase identifier does not make a record anonymous. We do not promise that deleting an account erases every historical record, third-party copy or backup.

The app clears the signed-in account and locally displayed subscription-access state. If secure storage removal fails, it keeps the old identity hidden and retries exact session removal on a later launch or foreground refresh. A local retry is not a second server deletion request or proof that an interrupted server request succeeded. If the server result is uncertain, the app reports an error; support can help establish the account's status.

Account deletion does not delete local photo projects, editor history, temporary export copies, original library images or files previously saved or shared. Use Delete in Projects to remove a saved project; that action also does not remove export-cache copies or copies elsewhere. Remove images saved to Photos or Files, and copies held by recipients, separately when needed.

Deleting a TJ account does not cancel an App Store subscription, request an Apple refund or erase Apple's purchase records. Manage or cancel the subscription separately in Apple's subscription settings.

We retain information for the purposes described above while it is needed to operate the account/service, verify transactions, prevent duplicate purchase claims, resolve disputes or meet applicable legal obligations. Retention varies by purpose and record; this notice does not promise a fixed deletion deadline for all retained records. Contact support for the retention criteria applicable to a particular record and for requests concerning retained information.

Privacy choices and contact

Depending on applicable law, you may request access, correction, deletion, portability or restriction, object to relevant processing, and withdraw consent where consent is the legal basis. Some requests may require identity verification or have legal exceptions. Contact support@tjnovaltd.com. You may complain to the UK Information Commissioner's Office or your competent local privacy authority.

Privacy notice: https://tjphoto-privacy.pages.dev/

App licence: https://www.apple.com/legal/internet-services/itunes/dev/stdeula/

Support: mailto:support@tjnovaltd.com


TJ Photo Studio iPhone 版隐私说明

本说明适用于 TJ NOVA LTD 运营的原生 TJ Photo Studio iOS App。TJ NOVA LTD 是下述账号和服务数据的控制者。隐私问题联系:support@tjnovaltd.com。

照片与本地项目

原生照片编辑器在 iPhone 或 iPad 上处理你选择的图片。其照片处理和项目存储代码不会将这些图片上传至我们的账号服务或云端图像模型。保存的项目在 App 私有存储中包含图片像素、缩略图、编辑设置、项目名称和创建时间。App 将该项目目录设置为不参与 iOS 设备备份。编辑后的图片会重新编码,不复制原图的 EXIF/GPS 元数据;图库中的原始照片保持不变。

本地编辑可不登录账号。项目属于这次 App 安装,而非某个 TJ 账号,因此退出登录、删除账号或切换账号后仍可能访问这些本地项目。导出或分享会产生额外副本,你选择的目的地和接收方按各自规则处理副本。

账号与订阅数据

通过 Apple 登录会提供 Apple 账号标识和已验证的邮箱地址,邮箱可以是 Apple 的隐藏邮箱转发地址。Apple 还可能在首次授权时提供你的姓名。我们使用这些信息创建并验证 TJ 账号。App 将会话凭据、账号编号、邮箱和 Apple 账号标识保存在本设备的钥匙串中,并在请求账号或订阅服务时发送会话凭据。

原生 App 的 Pro 购买和订阅核验需要先登录 TJ 账号。App 将 Apple 交易编号发送到我们的账号服务;服务向 Apple 验证购买信息,记录商品编号、交易和订单编号、订阅状态与到期时间,以及购买所属的账号。账号专属的购买 UUID 用于将购买与账号绑定,并非物理设备标识。我们的记录还可能包含商品配置中的金额与币种,该金额不一定等于 Apple 实际扣款金额。Apple 处理结账和支付资料;这一原生购买流程不会向我们提供银行卡号或银行账号。

选择邮箱登录、注册或重置密码时,服务会接收邮箱地址、本次操作提交的密码以及需要时的验证码。账号密码在服务器以哈希形式保存,原生 App 的会话钥匙串条目不保存密码。验证码和恢复邮件经配置的邮件服务发送。App 可传递设备偏好语言;邮件正文使用服务已提供的语言模板,或回退英文。

服务事件、统计与安全

账号服务记录账号注册、登录、购买和删除事件,包括事件时间,以及仍关联账号时的账号编号和相关订单、支付渠道信息。我们使用这些记录运营服务,并计算活跃账号、注册数量、付费账号和购买总量等服务统计。即使 App 没有分析 SDK,账号服务本身也会生成并汇总这些记录。

账号会话和安全审计记录可能包含 IP 地址和 User-Agent。请求还包含 App 包标识和首选语言。连接与会话信息用于身份验证、安全和防滥用。该原生 App 没有采集广告标识或 GPS 定位的功能,其服务流程也不执行跨 App 广告追踪。

服务提供方与披露

Apple 按其自身隐私规则处理登录、App Store 购买和交易验证。我们的托管账号服务使用 Cloudflare 基础设施。服务提供方可能处理实现这些功能所需的账号、交易和连接数据。若启用了业务订单 webhook,它可接收账号编号、邮箱、订单和商品编号、支付渠道,以及记录中的金额与币种,用于订单核对。账号或支持服务使用邮件发送功能时,接收地址和邮件会由邮件服务提供方处理。原生编辑器的账号和购买请求不会向这些账号服务集成发送照片像素。

我们还可能在遵守适用法律、处理欺诈或保护权利所必需时披露信息。账号和购买数据用于提供你请求的服务;安全及服务统计在适用法律允许的范围内基于合法利益处理;法律义务可能要求保留部分记录。某项处理如需同意,同意仅适用于该项处理。

删除账号与数据保留

在 App 的账号页面选择删除账号并确认。关联 Apple 的账号按要求完成 Apple 再授权;邮箱账号通过当前已验证的会话执行删除。收到服务端确认后,账号被停用,其直接个人资料及登录、会话信息被移除。部分财务记录、交易归属、防止重复购买认领、安全或删除回执记录仍可能保留个人数据或假名化数据。稳定的账号或购买编号不代表记录已匿名。我们不承诺删号会清除所有历史记录、第三方副本或备份。

App 会清除已登录账号和本地显示的订阅访问状态。若安全存储删除失败,App 会隐藏旧身份,在后续启动或返回前台时重试删除该会话。本地重试不会再次请求服务端删号,也不能证明中断的服务端请求已经成功。如果服务端结果不确定,App 会显示错误;支持服务可协助核实账号状态。

删号不会删除本地照片项目、编辑历史、临时导出副本、图库原图,或已保存及分享的文件。删除已保存项目需在项目列表中使用删除功能;此操作同样不会删除导出缓存或其他位置的副本。需要移除已存入照片、文件或由接收方保管的副本时,应分别处理。

删除 TJ 账号不会取消 App Store 订阅、申请 Apple 退款或删除 Apple 的购买记录。订阅需在 Apple 订阅设置 中另行管理或取消。

我们按上述用途保留信息,包括运营账号和服务、验证交易、防止重复认领购买、解决争议及履行适用法律义务所需的记录。保留时间取决于用途和记录类型;本说明不承诺所有保留记录均在同一固定期限内删除。有关具体记录的保留标准及仍保留信息的请求,可联系支持服务。

隐私选择与联系

根据适用法律,你可以请求访问、更正、删除、携带或限制处理数据,对相关处理提出异议,并在以同意为依据时撤回同意。部分请求可能需要核实身份,或存在法定例外。联系 support@tjnovaltd.com。你也可以向英国信息专员办公室或有管辖权的当地隐私监管机构投诉。

隐私说明:https://tjphoto-privacy.pages.dev/

App 许可条款:https://www.apple.com/legal/internet-services/itunes/dev/stdeula/

支持:mailto:support@tjnovaltd.com