JotPop

Privacy Policy

Last updated: August 28, 2026

1. Introduction

This Privacy Policy explains how JotPop LLC ("we," "us," or "our") collects, uses, and protects information when you use JotPop (the "App"). We are committed to protecting your privacy and being transparent about our data practices.

Please read this policy carefully. By using the App, you agree to the practices described here.

2. Information We Collect

2.1 Information You Provide

Text Prompts
When you generate a sticker, your text prompt (e.g., "happy beagle basset") is sent to our backend server, which forwards it to OpenAI's image API to generate the image. Our backend does not permanently store prompts in its database — each generation request is processed and discarded.

That said, prompt text does reach us and our service providers in a few limited ways:

Generated Images
Generated stickers are stored locally on your device only — in your device's private app storage. We do not upload, store, or retain copies of your generated stickers on our servers, except for a sticker you specifically report (see Section 5A).

2.2 Information Collected Automatically

Two Device Identifiers
We use two separate anonymous identifiers, which behave differently:

Neither identifier is linked to your name, email, Apple ID, or Google account.

Usage Analytics
We use PostHog (posthog.com), a product analytics service, to collect usage data including app launches, sticker generation attempts (including the prompt text and whether it succeeded), sticker saves, and onboarding completion. This data is associated with your session identifier, not with any personal information you have not separately provided to us. PostHog processes this data on servers located in the United States. PostHog's privacy policy is available at posthog.com/privacy.

Crash and Error Data
We use Firebase Crashlytics (a Google service) to collect crash reports and error logs, which may include your device model, operating system version, app version, and the technical details of what the App was doing when it crashed. This data helps us find and fix bugs. Firebase's privacy policy is available at firebase.google.com/support/privacy.

Purchase and Subscription Data
If you make a purchase or start a subscription, our payment infrastructure provider, RevenueCat, receives your purchase history, subscription status, and the device identifier described above. See 4.4 for details.

2.3 Information We Do NOT Collect

We do not collect:

3. How We Use Your Information

We use the information we collect to:

We do not use your information for:

4. How We Share Your Information

We share data with the following third parties, solely as needed to operate the App:

4.1 OpenAI

Your text prompts are transmitted to OpenAI's API to generate sticker images, and are also screened by OpenAI's moderation service as part of our safety filtering. OpenAI may process and retain prompts in accordance with its own privacy policy and API usage policies (openai.com/privacy).

4.2 PostHog

Usage events, including prompt text from generation attempts, are transmitted to PostHog for analytics. PostHog receives your session identifier and event data, not your name, email, or any information that directly identifies you.

4.3 Firebase / Google

Crash and error data is sent to Firebase Crashlytics, operated by Google, to help us diagnose and fix problems.

4.4 RevenueCat

If you make a purchase or subscribe, RevenueCat processes and manages that subscription on our behalf. RevenueCat receives your purchase and subscription history and the persistent device identifier described in 2.2, which functions as your account reference with them. RevenueCat's privacy policy is available at revenuecat.com/privacy.

4.5 Railway (Backend Hosting)

Our backend server is hosted on Railway (railway.app). Prompt data and operational logs pass through Railway's infrastructure as part of normal request processing and server logging. Railway's privacy policy is at railway.app/legal/privacy.

4.6 Apple / Google

If you purchase a subscription or one-time item, payment is processed by Apple (via the App Store) or Google (via Google Play). We do not receive your payment card information. Their respective privacy policies govern payment data handling.

4.7 Legal Requirements

We may disclose information if required to do so by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the rights, property, or safety of JotPop LLC, our users, or the public.

We do not sell your personal information to any third party.

5. The Custom Keyboard and "Full Access"

Our custom keyboard extension lets you insert your saved stickers directly while typing in other apps. What "Full Access" actually does is different on each platform, so here's the precise picture rather than a generic one:

On iOS, "Allow Full Access" enables exactly one thing: a shortcut button in the keyboard that jumps back to the main JotPop app to create a new sticker. Reading your saved sticker gallery and inserting a sticker into what you're typing both work without Full Access — they use a private, on-device storage area that Apple sets aside specifically for sharing data between an app and its extension (called an "App Group"), not network or system-wide access. If you decline Full Access, everything works except that one shortcut button; you can still switch back to JotPop manually.

On Android, standard keyboard permissions are sufficient — no additional access beyond enabling JotPop as a keyboard is requested.

On both platforms, here is what the keyboard does and does not do:

5A. Reporting Content

If you report a sticker as inappropriate, we store that sticker's prompt and image, along with the reason you selected, so we can review it. This is the one deliberate exception to "we don't store your generated images" described elsewhere in this policy — it exists because a report has to be reviewable to be acted on. Reported content is used only to evaluate and improve our safety filters and is not shared beyond what is described in Section 4.

6. Data Storage and Security

On-Device Storage
Your generated stickers are stored locally on your device in the app's private storage directory. They are not backed up to our servers. If you delete the App, your locally stored stickers are deleted with it.

Server-Side
Our backend server's database does not permanently store prompts or generated images, other than reported content as described in Section 5A. Account and subscription state (your plan, remaining allowance, and the identifiers described in 2.2) is stored so we can enforce usage limits and process purchases correctly.

Security Measures
We use HTTPS for all data in transit between the App and our servers. We use a shared secret key and per-device rate limiting to reduce unauthorized or abusive access to our API. However, no method of electronic transmission is 100% secure, and we cannot guarantee absolute security.

7. Data Retention

8. Age Requirement and Children's Privacy

The App is intended for users 18 years of age or older and is not directed to children. We do not knowingly collect personal information from anyone under 18, consistent with our obligations under the Children's Online Privacy Protection Act (COPPA) and our own eligibility requirements. If you believe someone under 18 has used the App, please contact us at [email protected] and we will take appropriate action.

9. Your Rights and Choices

Depending on your location, you may have certain rights regarding your information:

Access and Deletion
Because we store very little data server-side, most data associated with you exists on your own device. You can delete your sticker gallery at any time within the App. Uninstalling the App removes all locally stored data. To request deletion of server-side account or analytics data, contact us at [email protected].

Analytics Opt-Out
If you prefer not to have usage events sent to PostHog, contact us and we will provide instructions for opting out.

California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at [email protected].

European Users (GDPR)
If you are located in the European Economic Area, you have rights under the General Data Protection Regulation including access, rectification, erasure, and data portability. Our legal basis for processing is legitimate interests (operating and improving the App) and, where applicable, performance of a contract. To exercise your rights, contact us at [email protected].

10. Third-Party Links and Services

The App may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties. We encourage you to review their privacy policies before providing any personal information.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this policy and, where appropriate, through an in-app notice. Your continued use of the App after changes are posted constitutes your acceptance of the updated policy.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

JotPop LLC
2800 E. Enterprise Ave, Ste 333
Appleton, WI 54913
Email: [email protected]
Website: getjotpop.com

We will respond to all legitimate privacy inquiries within 30 days.