TJ Photo Studio for iPhone and iPad — Privacy Notice
This notice covers the native TJ Photo Studio iOS app operated by TJ NOVA LTD, the controller of the account and service data described below. Privacy enquiries: support@tjnovaltd.com.
Photos and local projects
The native photo editor processes the images you choose on your iPhone or iPad. Its photo-processing and project-storage code does not upload those images to our account service or a cloud image model. Saved projects contain image pixels, thumbnails, edit settings, a project name and a creation date in the app's private storage. This project folder is excluded from iOS device backup by the app. Edited images are newly encoded without copying the source image's EXIF/GPS metadata. Your original library photos are not changed.
An account is optional for local editing. Local projects are tied to this app installation, rather than a TJ account: they can remain available after sign-out, account deletion or an account change. Exporting or sharing creates additional copies. The destination you select, and any recipient, handles the copy under its own rules.
Account and subscription data
Signing in with Apple supplies an Apple account identifier and a verified email address, which can be Apple's private relay address. Apple may also supply your name on the first authorisation. We use this information to create and authenticate your TJ account. The app stores its session credential, account ID, email and Apple account identifier in this device's Keychain. It sends the session credential when requesting account or subscription services.
Pro purchases and subscription reconciliation in the native app require a signed-in TJ account. The app sends Apple transaction identifiers to our account service, which verifies purchase information with Apple and records product identifiers, transaction and order identifiers, subscription status and expiry, and the account to which the purchase belongs. An account-specific purchase UUID helps bind the purchase to that account; it is not a physical-device identifier. Our records can also contain the product's configured amount and currency, which need not equal the amount Apple actually charged. Apple handles checkout and payment details; this native purchase flow does not give us your card number or bank details.
If you choose email sign-in, registration or password reset, the service receives the email address, the password you submit for that operation and, where required, a verification code. Stored account passwords are hashed on the server. The native app does not save your password in its session Keychain item. Verification and recovery messages use the configured email-delivery provider. The app can send your preferred language; the provider's available message templates may use a supported language or an English fallback.
Service events, statistics and security
Our account service records account registration, sign-in, purchase and deletion events, including event times and, while attributed to an account, its account identifier and relevant order/provider information. We use these records to operate the service and to calculate service statistics such as active accounts, sign-ups, paying accounts and purchase totals. These records are not limited to an analytics SDK: the account service itself creates and reports them.
Account sessions and security/audit records can contain your IP address and User-Agent. Requests also carry the app's bundle identifier and preferred language. We use connection and session information for authentication, security and abuse prevention. This native app has no advertising-identifier or GPS-location collection feature, and its service flow does not perform cross-app advertising tracking.
Service providers and disclosure
Apple processes sign-in, App Store purchases and transaction verification under Apple's own privacy rules. Our hosted account service uses Cloudflare infrastructure. Service providers may process the account, transaction and connection data needed to provide those functions. If an operational order webhook is enabled, it can receive your account ID, email, order/product identifiers, provider and the recorded amount/currency to reconcile the order. Email delivery, where used by an account or support service, involves the recipient address and the message provider. These account-service integrations do not receive photo pixels from the native editor's account/commerce requests.
We may also disclose information when necessary to comply with applicable law, address fraud or protect rights. We use account and purchase data to provide the service you request, rely on legitimate interests for security and service statistics subject to applicable law, and retain records when required by legal obligations. Where a particular processing activity requires consent, that consent applies to that activity.
Account deletion and retention
In the app's Account screen, choose Delete account and confirm. For an Apple-linked account, complete Apple's reauthorisation when requested. Email accounts use their current authenticated session for deletion. A confirmed server response deactivates the account and removes its direct profile and sign-in/session information. Some financial, transaction-ownership, fraud-prevention, security or deletion-receipt records may remain personal or pseudonymous. A stable account or purchase identifier does not make a record anonymous. We do not promise that deleting an account erases every historical record, third-party copy or backup.
The app clears the signed-in account and locally displayed subscription-access state. If secure storage removal fails, it keeps the old identity hidden and retries exact session removal on a later launch or foreground refresh. A local retry is not a second server deletion request or proof that an interrupted server request succeeded. If the server result is uncertain, the app reports an error; support can help establish the account's status.
Account deletion does not delete local photo projects, editor history, temporary export copies, original library images or files previously saved or shared. Use Delete in Projects to remove a saved project; that action also does not remove export-cache copies or copies elsewhere. Remove images saved to Photos or Files, and copies held by recipients, separately when needed.
Deleting a TJ account does not cancel an App Store subscription, request an Apple refund or erase Apple's purchase records. Manage or cancel the subscription separately in Apple's subscription settings.
We retain information for the purposes described above while it is needed to operate the account/service, verify transactions, prevent duplicate purchase claims, resolve disputes or meet applicable legal obligations. Retention varies by purpose and record; this notice does not promise a fixed deletion deadline for all retained records. Contact support for the retention criteria applicable to a particular record and for requests concerning retained information.
Privacy choices and contact
Depending on applicable law, you may request access, correction, deletion, portability or restriction, object to relevant processing, and withdraw consent where consent is the legal basis. Some requests may require identity verification or have legal exceptions. Contact support@tjnovaltd.com. You may complain to the UK Information Commissioner's Office or your competent local privacy authority.
Privacy notice: https://tjphoto-privacy.pages.dev/
App licence: https://www.apple.com/legal/internet-services/itunes/dev/stdeula/
Support: mailto:support@tjnovaltd.com