← Back to wuyuXAI

CoverForge Privacy Policy

Effective: July 16, 2026

CoverForge is an iOS book-cover creation service operated by its independent developer ("CoverForge," "we," "us," or "our"). This Privacy Policy explains what information CoverForge processes, why it is processed, who receives it, how long it is retained, and your choices.

1. Information processed on your device

CoverForge stores your language preference, local project library, generated covers downloaded to the app, and related project metadata on your device. Local projects remain there until you delete them, use Delete CoverForge Data, or remove the app and its data. CoverForge does not provide a permanent cloud library for those projects.

2. Information sent to or retained by the service

  • Cover inputs and output: book title, author name, genre, selected style, aspect ratio, creative or mood brief, and generated cover image.
  • Pseudonymous StoreKit identity: no registration is required. Apple provides an app-specific StoreKit transaction identifier signed for CoverForge. The service derives a one-way pseudonymous account hash and Support ID for purchase delivery, balance recovery, security, and fraud prevention. The submitted app does not request your Apple name or email.
  • Authentication information: a signed AppTransaction, device-verification identifier, and CoverForge session token are processed to verify the app-specific StoreKit identity and prevent replay. Raw AppTransaction identifiers, signed JWS values, and device UUIDs are not retained in the account profile or returned in its public data.
  • Purchase information: App Store product and transaction identifiers, signed transaction information, subscription state, credit balances, entitlement history, and refund or revocation status. CoverForge does not receive your payment-card number.
  • Service, security, and diagnostics: request time and status, generation model and size metadata, prompt hash and length, rate-limit information, errors, and IP address or comparable infrastructure logs used for security and troubleshooting.
  • Communications: support messages, privacy requests, and content or rights reports you choose to email.

3. How we use information

  • Generate and deliver the cover you request.
  • Verify a pseudonymous StoreKit identity and synchronize credits and subscriptions without registration.
  • Verify App Store purchases, refunds, and entitlement changes.
  • Prevent credential replay, duplicate transaction redemption, fraud, abuse, and service attacks.
  • Operate backups, troubleshoot failures, answer support requests, and maintain reliability.
  • Comply with law and enforce the CoverForge Terms of Use.

4. AI generation and service providers

When you choose Generate and have granted the in-app AI data permission, CoverForge sends the inputs needed for your request to the CoverForge backend. The backend forwards them through its configured API gateway to OpenAI's image model. The returned image is delivered to the app and temporarily stored for delivery, retry, security, and support.

Information may also be processed by:

  • Apple for StoreKit identity verification, subscriptions, purchases, refunds, and App Store account services.
  • OpenAI's image model for the requested image generation.
  • API gateway, hosting, storage, backup, network-security, and email providers needed to operate CoverForge.

We limit transfers to information reasonably needed for the service and select providers and safeguards intended to protect it consistently with this policy. We do not authorize providers to sell your information or use it for third-party advertising on our behalf. Providers may process data in countries other than your own, so international data-protection rules may apply.

5. Retention and deletion

  • Generated cover-image files on the CoverForge server expire within 24 hours.
  • Active pseudonymous identity, entitlement, purchase, and generation metadata is retained while needed to provide and secure the service or meet legal obligations.
  • Daily backups contain account and generation ledgers but not generated-image files. Local backup archives are scheduled for deletion after 30 days and may remain until the next daily cleanup.
  • Delete CoverForge Data removes local projects, active sessions, prompts, titles, creative and generation records, export and replay records, and temporary cover files. Deleted live creative data may remain in restricted backups until the applicable backup expires and is not restored except for disaster recovery or legal necessity.
  • After deletion, CoverForge retains a minimum economic ledger: the pseudonymous StoreKit account hash and environment, purchase ownership claims, paid permanent and subscription balances, credit-grant spend and refund history, processed or revoked transaction records, subscription refresh or terminal state, and free-preview eligibility. These records support purchase delivery, balance recovery, refunds, legal obligations, security, and fraud prevention.
  • The retained economic ledger does not include your Apple name or email, raw AppTransaction identifier, signed AppTransaction JWS, device UUID, session, prompt, title, or cover image. It does not retain the deleted prompt or cover image for anti-abuse purposes.
  • A one-way pseudonymous account hash and minimal timestamps show that free-preview eligibility was already claimed. This prevents repeated introductory-credit abuse after deletion.
  • Support and legal communications are retained only as reasonably necessary to resolve the matter, maintain appropriate records, or meet legal obligations.

6. Sale, advertising, and tracking

We do not sell your personal information. CoverForge does not use it for cross-context behavioral advertising and does not track you across unrelated apps or websites. The app has no third-party advertising system.

7. Security

CoverForge uses encrypted transport, device Keychain storage, restricted server files, authenticated endpoints, and access-controlled backups. No transmission or storage method is completely secure, and absolute security cannot be guaranteed.

8. Your choices and privacy rights

  • You can decline or withdraw third-party AI permission in CoverForge Settings.
  • You can delete individual local projects inside the app.
  • You can use Delete CoverForge Data in Settings to remove local projects and server-side creative data. The minimum economic ledger described above remains.
  • You can manage or cancel an App Store subscription separately in your Apple account. Delete CoverForge Data does not cancel an App Store subscription.
  • You may email us to request access, correction, deletion, or a copy of applicable personal information.

Privacy rights vary by jurisdiction. We honor rights that apply to your request and may verify the request to protect the account from unauthorized access.

9. Children

CoverForge is intended for authors and creators and is not directed to children under 13. Contact us if you believe a child provided personal information improperly.

10. Changes to this policy

We may update this policy when the product, providers, or law changes. We will post the new effective date and give additional notice when required.

11. Contact

For privacy questions or data-rights requests, email wuyuxai@gmail.com with the subject "CoverForge Privacy Request."

Read the Terms of Use or visit CoverForge Support.