Housecat — Privacy Policy
Last updated: 7 September 2026
What we collect, and why
- The pet photo you choose and the files made from it. We upload only the photo you select. It first reaches Housecat's server hosted in the United States, which stores and serves the temporary task files; the AI processors listed below perform the safety check and create the portrait and motion clip. We request the providers' available privacy/no-training controls. Their processing and retention are also governed by their own policies. Housecat does not browse your library, use your photo to train its own models, sell it, or use it for advertising.
- Image-safety classification before generation. After upload, the sanitized pet photo first goes through an NSFW image classifier as part of the same image-processing relationship described below. If the classifier reports unsafe content or is unavailable, Housecat rejects the request and does not send it into the portrait or motion-generation steps. This check does not add another data recipient.
- Account and device-security identifiers. An account is optional. You can use Housecat, buy shots, and save wallpapers without signing in; we then use only a random app account ID stored on your device, and your shots stay with this device. If you choose to sign in with Apple, we also receive the subject identifier Apple supplies, which lets you use your shots on your other devices. We never receive your Apple password. Apple App Attest supplies an app-and-device-specific key and counter used to stop automated abuse, replay, repeated free trials, and unlimited sandbox credits.
- Your email address, only if you sign in with Apple. Apple gives us the address you choose to share, or a private relay address. We use it only to identify your account and to answer support requests. We do not send sign-in emails and do not currently send marketing email. If that changes, marketing will require your express opt-in and every marketing message will include an unsubscribe control.
- Purchase and subscription records. Apple processes payment. Our purchase-management provider receives an app-specific user ID and purchase history for receipt validation and subscription operations, and holds your shot balance. We receive transaction, product, renewal, refund, reversal, and entitlement data, but never your card details.
- Apple server notifications. A signed Apple notification may be held in a durable inbox while its signature and purchase effect are verified or retried. The signed payload is cleared as soon as processing reaches a terminal result. We then keep only its hash, processing status, attempt count, and a coarse error category for up to 30 days.
- Limited product-interaction, operational, and anti-abuse data. We keep the style/action selected for a task, task state, failure category, rate-limit counters, and keyed hashes derived from network/account identifiers where needed to deliver and secure the service. Operational logs use keyed tags and coarse error categories instead of raw account, email, network, transaction, task, or provider-job identifiers, and are rotated by a bounded file count and size. These data are not used for advertising or cross-app tracking.
We do not sell personal data, serve targeted advertising, or track you across other companies' apps or websites.
Third parties that touch your data
| Who | What they receive | Why |
| Tencent Cloud (US region) | your selected photo, task files | hosts our server; temporary storage and delivery |
| Replicate, LLC | your selected photo | safety check and portrait generation |
| OpenRouter, Inc. → ByteDance's international service | portrait-derived start/end frames | motion-clip generation |
| RevenueCat, Inc. | app-specific user ID, purchase history | receipt validation; holds the shot balance |
We enable each provider's available privacy and no-training settings; copies already sent to a processor also follow that processor's policy.
How long we keep it
- Your original photo on Housecat servers: access ends no later than 48 hours after upload. We attempt physical deletion of the original (and its normalized working copy) by the 48-hour limit and retry automatically if storage is temporarily unavailable. Copies already sent to an AI processor follow that processor's policy.
- Generated media on Housecat servers: the test-shot portrait and the finished wallpaper files (still image and motion clips) are kept while your account exists, so you can view them in History and save a wallpaper again. They are removed when you delete your account. Download links are signed, tied to a current task file, and normally expire within 15 minutes.
- Private on-device app caches: to support a retake or re-save, the app may temporarily cache the selected photo and latest generated media in its private sandbox. Those caches are used for no more than 48 hours from the selected photo's cache time and are purged on the next app launch or return to the foreground after that limit. Signing out, deleting the account, or changing identity also triggers their immediate removal and blocks a new identity from reading them. A Live Photo you expressly save to Photos is outside this app cache and remains under your control.
- Active account data: kept while the account is in use. A deletion receipt contains a keyed hash of the request ID and cleanup states so the app can confirm a deletion even if the original response was lost; it expires within 30 days.
- After account deletion: profile, email, sessions, spendable shots, shot history, task access, and profile-facing purchase labels are removed. We retain the minimum pseudonymous financial records needed to stop transaction replay and handle later renewals, refunds, refund reversals, disputes, accounting, and legal obligations. They can include Apple transaction/original-transaction IDs, a retired appAccountToken, the exact or categorized product ID where required for reconciliation, refund amounts/state/liability, and keyed hashes of formerly verified sign-in subjects. They are removed or de-identified when those obligations and transaction-replay risks no longer apply. Deleted positive shot balances are never restored.
- Device-abuse records after deletion: the App Attest receipt and account link are removed. The public key, counter, and trial/sandbox usage counters may remain unlinked from the deleted account for up to 24 months after last use, then are deleted. Keyed deletion tombstones use the same maximum. An unsubscribe suppression is kept until you expressly opt in again or ask us to remove it.
- Queued cleanup: if a local file, a provider-side customer record, or an Apple authorization cannot be removed immediately, access is revoked and the minimum encrypted cleanup credential/identifier remains only until the retry succeeds. A completed cleanup audit is kept for up to 30 days.
- Backups: encrypted operational rollback backups, when created, are isolated from the live service and kept for no more than 30 days. They are used only for disaster recovery; deleted account access is not restored, and deleted data ages out with the backup.
Your choices
Deleting your account and data. In the app, open Settings and choose Delete my account and data. The account is disabled and its sessions, email, balance, history, and server-media access are logically removed as part of the deletion transaction. Physical file removal, third-party authorization cleanup, and compaction of residual database journal storage may finish asynchronously and retry if storage or a provider is temporarily unavailable. Unused shots are forfeited. Deleting Housecat does not cancel an Apple subscription; cancel it separately in Apple's subscription settings. Live Photos already saved in your library remain on your device.
You can withdraw photo-processing consent in Settings, request access or correction, or ask a privacy question at any time by emailing hello@gethousecat.app.
Who operates Housecat. Housecat is operated by an independent developer, reachable at hello@gethousecat.app. That address is also where you can ask what we hold about you.
While your wallpaper is being made, processors and your device receive short-lived signed file links. A signature authorizes only a currently referenced task file and stops working when it expires or the task/media is deleted.
住了只猫 — 隐私政策
最后更新:2026 年 9 月 7 日
一句话:你选一张猫咪照片,我们把它做成壁纸。除此之外,我们尽量什么都不拿、什么都不留。
我们会接触哪些信息
- 你选中的那张照片,以及用它生成的写真和动画。只有你亲手选的这一张会被上传。它先到我们在美国的服务器,再交给下方列出的 AI 处理方生成写真和动画。我们不翻你的相册,不拿你的照片训练模型,不卖,也不投广告。
- 生成前的安全检查。照片会先过一道图像安全分类,查出不适宜内容就直接拒绝,不再往下走。这一步不会把照片交给额外的公司。
- 账号标识。登录不是必需的。不登录也能使用、购买张数、保存壁纸,这时我们只用一个存在你手机上的随机应用账号 ID,张数跟着这台手机走。你选择用 Apple 登录时,我们会多拿到 Apple 提供的登录标识,这样张数在你的其他设备上也能用;我们拿不到你的 Apple 密码。Apple 的 App Attest 会签发一把设备专用密钥,帮我们挡住机器人、防止重复薅免费额度。
- 邮箱(只在你用 Apple 登录时)。Apple 会把你选择共享的邮箱或一个隐藏的中转邮箱交给我们,只用来识别账号和回复你的支持请求。我们不发登录邮件,目前也不发营销邮件;以后如果发,一定先征得你的同意,并且每封都可以退订。
- 购买记录。付款全程由 Apple 处理,我们碰不到你的卡号。凭据核验和张数余额由购买管理服务商维护;我们能看到交易、续订、退款这类记录。
- Apple 服务器通知。Apple 发来的签名通知会在验签和处理期间暂存,处理一旦有结果,签名原文立即清除,之后最多保留 30 天的哈希、状态和粗粒度错误类别。
- 少量运行数据。你选的模板、任务状态、失败原因、限频计数。日志里不写原始账号、邮箱和交易号,只保留打了码的标签,并按数量和大小定期轮换。
我们不出售个人数据,不做定向广告,不跨 App 跟踪你。
会接触你数据的第三方
| 谁 | 拿到什么 | 做什么 |
| 腾讯云(美国节点) | 你选的照片、任务文件 | 托管我们的服务器,临时存取 |
| Replicate | 你选的照片 | 安全检查、生成写真 |
| OpenRouter → 字节跳动国际服务 | 写真衍生的首尾帧 | 生成动画 |
| RevenueCat | 应用专用用户 ID、购买历史 | 凭据核验、维护张数余额 |
我们对以上各家都启用其可用的隐私与不训练设置;已发给它们的副本同时受其各自政策约束。
留多久
- 服务器上的原图:上传后最多 48 小时终止访问,并在此之前尝试物理删除原图(含规整后的工作副本),存储暂时不可用会自动重试。已发给 AI 处理方的副本按其政策处理。
- 服务器上的生成物:试镜写真和成片文件(静帧与动态片段)在账号存续期间保留,供你在「历史」里查看和重新保存壁纸;删除账号时一并删除。下载链接带签名、只能读取任务当前引用的文件,通常 15 分钟内失效。
- 手机本地缓存:为了支持重拍和重新保存,App 会在自己的沙盒里缓存所选照片和最新成片,从缓存之时起最多使用 48 小时,超时后在下次启动或回到前台时清除。退出登录、删除账号、切换身份都会立即清空缓存,新身份也读不到旧缓存。你已存入相册的实况照片不属于缓存,一直归你。
- 账号数据:账号在用就一直保留。删除回执只含请求 ID 的哈希和各项清理状态,用于在网络异常时向 App 确认删除结果,30 天内过期。
- 删号之后:资料、邮箱、会话、余额、拍摄历史、任务访问全部移除。只保留防交易重放和处理退款、争议、记账、法律义务所必需的最少伪名记录(如 Apple 交易号、已退役的购买凭据、必要的商品与退款信息、原登录主体的哈希),义务结清即删。已删除的正余额不会恢复。
- 删号后的反滥用记录:设备密钥、计数器和试用次数最长再保留 24 个月(已与你的账号脱钩),用于防止重复薅免费额度,到期删除。退订记录保留到你再次主动订阅或要求删除为止。
- 排队清理:本地文件、第三方账户或 Apple 授权一时删不掉时,先撤销访问,只保留完成重试所需的最少加密凭据;完成后的审计记录最长保留 30 天。
- 备份:加密的运维备份与在线服务隔离,最长保留 30 天,只用于灾难恢复,不会恢复已删账号的访问。
你的权利
删除账号和数据:App 内「设置 → 删除账号和数据」,一键执行。未用张数作废;Apple 订阅需另行在 Apple 的订阅设置中取消;已存入相册的实况照片留在你的设备上。物理文件与第三方授权的清理可能异步完成,遇到故障会自动重试。
撤回照片处理同意:在 App 设置中随时可以撤回。
查阅、更正、提问:发邮件到 hello@gethousecat.app,我们会尽快回复。
关于运营者
Housecat 由独立开发者运营,联系邮箱 hello@gethousecat.app。如需了解我们持有的与你相关的信息,也请写信至此。