Skip to content
WristAlbum
HomeWorkflowPrivacy

Local-first privacy

Privacy Policy

WristAlbum keeps the data boundary narrow: your original photos stay on your phone, and only the cropped images you choose to publish are uploaded for Garmin watch download.

Effective Date, Scope, and Operator

This policy is effective as of July 12, 2026 and was last updated on July 19, 2026. WristAlbum is operated by 武汉牛拉松科技有限公司 (Newrathon, referred to as “we” or “us”). It applies both to the global store builds distributed through the App Store or Google Play and to the directly distributed mainland China Android china build. Their purchase and update services are described separately below.

For privacy questions, use the support page or email support@wristtale.com.

Data We Process and Why

  • Local album data: original photos, the editable album list, local file paths, crop rectangles, and watch selection state remain on your phone and are used to select, edit, and preview a watch album.

  • Sync data you choose to publish: only exported watch-sized crops, the album manifest, a random album token, and image integrity metadata are used so your Garmin watch can download and display the current album offline.

  • Install, device, and network data: this may include a local install identifier, access tokens, app version, phone and watch model, sync state, request time, IP address, response status, and necessary error details for authentication, abuse prevention, quotas, security, and troubleshooting.

  • Internal user association: we derive an opaque WristAlbum user identifier from protected installation credentials. In global store builds, the same identifier may be used as the RevenueCat App User ID so purchase status and published album data can be traced to the same internal user without putting an email address, phone number, or store account identifier in an album URL.

  • Purchase and entitlement data: global store builds process store purchase identifiers and RevenueCat entitlement status. The mainland China build processes temporary Alipay authorization codes, an Alipay account identifier, order and payment status, the selected plan, entitlement period, restoration history, and activation-code bindings for sign-in, payment, fulfillment, and restoration. We do not ask you to give your Alipay password to the app.

  • Support data: when you contact support, we process the contact details, app/device version, issue description, and attachments you choose to provide only to respond and troubleshoot.

Photos, Albums, and Secure Servers

Editing a local album does not require a WristAlbum account. Original photos and the local album database are not uploaded to our secure servers. Only when you explicitly publish an album are the exported watch-sized crops and small sync manifest uploaded to our secure servers for album sync. They are accessed using a random album token and remain separate from the originals on your phone.

A limited number of authorized operations personnel can use a password-protected, read-only administration page to inspect the current watch-sized crops and related storage metadata for support, abuse investigation, and storage operations. The page does not provide an image deletion action and does not expose your original phone photos. When an album is published or downloaded, or when the mainland build checks for or downloads an update, our secure servers may process IP addresses, request times and paths, response statuses, and security logs.

Mainland China Android update files are stored separately from album data on our secure servers and include only signed APKs and update manifests. A manifest contains the version, build number, release notes, forced-update settings, and APK download address; it does not contain photos, album content, Alipay account information, or entitlements. The app only requests the version API and uses the HTTPS download URL returned by our secure servers.

Accounts, Purchases, and Channel Differences

Payments in global store builds are processed by the App Store or Google Play, with RevenueCat used to manage products, purchase status, and entitlement restoration. RevenueCat may receive store purchase identifiers, entitlement status, app/device metadata, and diagnostics needed to provide and restore paid features.

The mainland China direct build does not use RevenueCat. It invokes the Alipay SDK only after you actively choose Alipay sign-in or payment. Our secure servers use the authorization result to establish the mainland WristAlbum session and grant an entitlement only after receiving a verified asynchronous payment notification. Current mainland plans are monthly (CNY 28/one month), yearly (CNY 48/12 months), and lifetime (CNY 68/permanent). Actual price, duration, payment, restoration, and refund status are determined by the purchase screen, Alipay, and our records.

Third-Party SDKs and Services

SDK/serviceChannel and triggerPurpose and data that may be processedProvider privacy notice
Garmin Connect IQ / Garmin Connect MobileAll channels; when you connect a watch or start syncDevice discovery, watch communication, and sync status; device identifiers, model, and app messages may be processed.Garmin Privacy Center
RevenueCatGlobal store builds only; when loading paid access, purchasing, or restoringProduct and entitlement management; store purchase identifiers, entitlement status, app/device metadata, and related diagnostics may be processed.RevenueCat Privacy Policy
Alipay SDK and Alipay Open PlatformMainland China direct build only; after you initiate Alipay sign-in or paymentAccount authorization and App payment; authorization/order parameters, an Alipay account identifier, and device/network information used by Alipay for security and risk control may be processed.Alipay agreements and privacy policies

Third parties process data they control under their own policies. Payment and transaction records controlled by the App Store, Google Play, or Alipay are also subject to the relevant channel rules.

Retention and Security

Local data remains until you delete it in the app, clear app data, or uninstall the app. After our secure servers accept a new album manifest, crops that are no longer referenced are normally scheduled for deletion after a safety window of at least 24 hours. Temporary service failures may delay physical deletion; cached copies and copies already downloaded to a phone or watch are not remotely revocable. There is currently no user-facing self-service deletion API. Contact support to request deletion of the remaining album data stored on our secure servers and provide the information necessary to verify the request.

Mainland account, order, entitlement, restoration, and activation-code binding records are retained as needed for fulfillment, purchase restoration, dispute handling, security audits, and applicable legal obligations, and are then deleted or anonymized unless the law requires otherwise. Update APKs and manifests are non-personal release artifacts and may remain for update delivery and release traceability. Support records and security logs are retained only as needed to handle requests, protect the service, and meet legal obligations. Where no fixed period is stated, we do not invent one and instead apply necessity and data-minimization principles.

We use measures such as random album tokens, access tokens, ownership checks, delayed deletion, restricted read-only administration, service separation, and collection minimization, but no network transmission or storage system can be guaranteed completely secure.

Your Rights, Withdrawal, and Account Deletion

You may ask to access, correct, or delete relevant personal information, and may withdraw consent or request deletion of a mainland account. The mainland China build provides an explicit first-use consent flow and an in-app privacy consent withdrawal entry. After withdrawal, features that depend on the relevant network processing or third-party SDK may stop working. Withdrawal does not affect processing already lawfully completed.

There is currently no self-service data deletion or account-deletion API. Send a request from an email that can describe the associated account/install information to support@wristtale.com, or use the support page. We will act after necessary verification. Uninstalling removes app data from the device but does not automatically delete published crops stored on our secure servers, orders, or channel transaction records. Rights over data independently controlled by Apple, Google, RevenueCat, Alipay, or Garmin should also be exercised with that provider; transaction records required by law may not be immediately erasable.

Diagnostics, Policy Changes, and Contact

If you contact support, include only details you want reviewed, such as device model, app version, watch model, and a description of the sync issue. Do not send original private photos unless support explicitly asks and you choose to share them.

If this policy changes materially, we will provide the updated text and date through the app or website. For privacy and data-rights requests, email support@wristtale.com or visit wristalbum.wristtale.com/en/support.

More from us

Other small tools for Garmin watch users.

WristStackFalling-block game and leaderboard.JiaKeGarmin screenshot framer.WristListenAudiobook listening for Garmin.WristTaleEbook reader for Garmin watches.GameraSnapRemote camera shutter for Garmin.SnakeSnake game and leaderboard.WristBenchGarmin performance rankings.
WristAlbum
PrivacyTermsSupport
wristalbum.wristtale.com/en/privacy