Plain-language policy
Privacy at Geertje
Effective 28 July 2026
Geertje is an iPhone sticker creator. The public App Store version does not connect to your WhatsApp account or read WhatsApp chats.
What leaves your iPhone
When you tap Make, Geertje sends the photos you selected, the style and creative direction you reviewed, a random installation identifier, and a request identifier to Geertje's generation service. Photos you do not select are not sent by Geertje.
If you choose Google Photos, Google handles sign-in and photo selection. Google Sign-In may process account and device information described in the App Store privacy label, while Geertje uses the resulting credential only to operate the picker. You can choose Disconnect Google Photos in Geertje Settings to revoke every Google OAuth scope granted to Geertje and clear the local Google session.
How generation works
Requests pass through Geertje services hosted on Cloudflare. The image-generation request is processed by Google Gemini; OpenAI may be used as a fallback when Gemini is unavailable. Generated results are returned to the app and held in Cloudflare R2 so an interrupted request can be recovered. An hourly cleanup deletes results after they become 48 hours old, normally within 49 hours of storage.
Who controls your data
Geertje is operated from the Netherlands. Geertje's operator is the data controller for the generation account, app analytics, support requests, and other processing described here. Apple, Google, Cloudflare, OpenAI, and PostHog may also act as independent controllers for parts of their own services under their terms. Contact the Geertje controller at privacy@geertje.app.
Why Geertje may process data
- Contract: to create, recover, save, and account for stickers and credits you request.
- Legitimate interests: to keep the service secure and reliable, prevent fraud and duplicate credit grants, and understand coarse session-level performance without building advertising profiles.
- Legal obligations: to keep records required for tax, accounting, consumer-protection, or law-enforcement obligations.
- Your choice or permission: iOS notification and photo permissions, and the optional Google Photos authorization, remain under the controls supplied by Apple and Google. You can withdraw them without affecting earlier lawful processing.
Account and purchase records
Geertje creates a pseudonymous generation account after you accept the in-app privacy notice. The service stores a hashed installation alias, account identifier, credit balance, generation accounting events, and Apple-signed purchase evidence. It never receives your payment-card details.
Purchase and minimal anti-fraud records are retained as needed to prevent a transaction being granted twice, preserve ledger integrity, and meet financial or legal obligations. Raw App Store signed data is stored only as a cryptographic hash.
Analytics
Geertje sends limited product-interaction, latency, and failure-category events to PostHog's EU service. Events use a new random identifier each app session. They do not include photos, prompts, sticker images, names, email addresses, chat content, or advertising identifiers. Geertje does not use this data for tracking or advertising.
How long data is kept
- Recoverable generated results are deleted by hourly cleanup after becoming 48 hours old, normally within 49 hours of storage.
- Generation operations, balances, and the pseudonymous account remain while the cloud account is active and are removed or de-identified as described below when you delete it.
- Session-scoped PostHog EU analytics may be retained for up to 84 months under the current PostHog EU project plan. Geertje uses a new random identifier each app session and excludes photos, prompts, sticker images, names, email addresses, chat content, and advertising identifiers.
- Support correspondence is retained only while it is needed to answer the request, protect the service, handle a dispute, or meet a legal obligation. Geertje does not currently promise an automatic 24-month mailbox deletion schedule.
- Minimal purchase and accounting evidence is kept for the period required by Dutch tax and accounting rules, normally seven years. A transaction fingerprint may be kept longer where necessary to prevent the same consumable purchase being granted twice or to establish, exercise, or defend a legal claim.
- Locally saved stickers remain until you delete the local library or remove the app. Google OAuth credentials remain in Google's Sign-In storage until you disconnect, sign out locally, revoke access in Google, or remove the app's stored data.
Notifications
If you allow notifications, the App Store version uses local completion alerts after usable stickers are ready. Notification permission is optional and is not used for advertising.
What stays local
Stickers you save in Geertje's library remain on your iPhone until you delete them in Settings or remove the app. Your original photos remain governed by Apple Photos or Google Photos.
Your choices and deletion
- Use Apple Photos' permission controls to change which photos Geertje can access.
- Disconnect Google Photos in Geertje Settings to revoke Geertje's Google OAuth grant and clear its local Google session. You can also revoke access in your Google Account.
- Delete all locally saved stickers in Geertje Settings.
- Delete your cloud generation account in Geertje Settings. This revokes credentials, deletes generated cloud results and generation operations, removes installation aliases, and removes unused credits.
After cloud account deletion, minimal pseudonymous App Store transaction and accounting evidence remains to prevent duplicate grants and preserve purchase integrity. A later reinstall can create or reactivate an account, but the deleted free allowance and unused consumable credits are not restored.
Your European privacy rights
Depending on the law that applies, you can ask to access, correct, delete, restrict, or receive a portable copy of your personal data. You can object to processing based on legitimate interests and withdraw a permission or consent for future processing. These rights can have legal exceptions, including records Geertje must retain.
Email privacy@geertje.app from a context that lets Geertje safely verify the relevant account. Geertje will respond without undue delay and normally within one month. You may also complain to your local supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens.
Processors
Geertje uses Cloudflare for edge processing and temporary result storage, Google Gemini and potentially OpenAI for image generation, PostHog EU for limited analytics, Apple for App Store purchases and system services, and Google only when you choose Google Photos.
Security and transfers
Network traffic uses encrypted HTTPS connections. Providers may process data in countries outside yours under their applicable safeguards and terms. No internet service can promise absolute security, so Geertje minimizes what it sends and how long generated results remain recoverable.
Children
Geertje is not directed to children under 13. Do not use the service to submit content you do not have permission to use.
Contact
Questions or privacy requests: privacy@geertje.app. Support: support@geertje.app. Do not email private photos, access tokens, credentials, or full App Store receipts.