ZiHu is built to be private by design. Your photos and the words you write are turned into monument images entirely on your device. We do not run servers that store your content, we have no user accounts, and your creations never leave your iPhone unless you explicitly share them yourself.
We do not collect, transmit, or store on any server: your selected photos, the rendered monument images, the text you write, your name, email, contacts, or location. There is no account system and no analytics SDK embedded in the App.
The following stays local to your device and is never uploaded:
You can permanently erase all of it at any time via Settings → Purge Local Archive, or by deleting the App.
Photo Library: requested only so you can pick a base photo. Selected photos are read into the App and stay on the device.
App Tracking Transparency (ATT): iOS may show a prompt asking whether the App can use the device advertising identifier for performance measurement. If you decline, the App still works fully. You can change this anytime in iOS Settings → Privacy & Security → Tracking.
Lightweight network check: on launch the App performs a single lightweight connectivity request to a public address. This is used only to trigger the standard system network-permission prompt; no personal data or content is sent.
On-device data is used solely to create, display, zoom, and export your monuments and rubbings. We do not profile you, build advertising audiences, or sell data — we never receive your data in the first place.
Content is shared only when you tap export and choose a destination in the iOS share sheet (for example, saving an image to Photos or sending it to another app). That action, and any third-party app you pick, is governed by Apple and that app’s own terms.
Because storage is entirely local, retention is controlled by you. Data persists until you purge the archive or uninstall the App. We hold no copies.
Your monuments live inside the App’s sandboxed storage protected by iOS. Since nothing is transmitted to us, there is no server-side data that could be breached. Maintaining device security (passcode, OS updates) helps protect locally stored content.
The App is not directed at children and collects no personal information from anyone. No data is gathered that could identify a child or any user.
If this Policy changes, the updated version will be published at this address with a new effective date. Material changes will be reflected here before they take effect.