Weya

Privacy & permissions

Your photos, your choices. This notice explains how Weya handles data when you use the Android app.

Policy date: 2026-10-03 · Operator: To be configured before launch

Pre-launch notice: operator, support contact, generation provider, storage region and retention details are awaiting confirmation. This draft must be completed before public release.

Data we process

Android permissions and access

Access Purpose Your control
Internet Login, templates, photo upload, generation, results and payment verification. Required to use online functions.
Advertising ID Installation attribution through Adjust and Google Play services. Manage advertising privacy in Android settings.
Photo selection Read the specific photo chosen using the system document picker. Choose a photo or cancel. No broad photo-library permission is requested.
Downloads Save a result through Android DownloadManager. Download only when you tap the result’s download action.

This implementation does not request microphone, camera, contacts or location permissions. Picking a photo does not itself upload it. Generation is the upload action.

Service providers and sharing

Data is sent to the configured Weya backend and the storage and generation services needed to fulfill your request. The backend selects AWS/R2 or OSS upload paths. Generation provider: pending operator confirmation. Storage location: pending operator confirmation.

Whether uploaded content is retained, reused for model training, or processed in other countries must be confirmed with the actual backend and generation provider before publishing this notice. No unsupported claim about model training is made here.

Retention and security

Retention periods for uploaded originals, generated results, account records and payment records are pending operator confirmation. The app allows deletion of creations and accounts; backend deletion scope, processing time and legally required retention must be specified before launch.

API and checkout requests use HTTPS. Authentication tokens are stored in the app’s private preferences. Object-storage uploads use signed links or temporary credentials; the app’s bearer token is not forwarded to storage providers.

Your data controls

You can delete a creation from Results. For account deletion, open your account using the settings icon and choose Delete account. Confirmation submits a request to the backend. Deleting your account does not automatically cancel Google Play subscriptions; manage them separately in Google Play.

Request account and associated-data deletion. You may also contact the operator about access, correction or deletion.

Children and policy changes

The app’s intended age group and applicable parental-consent measures must be set by the operator before release. If this policy changes, the operator will update this page and its policy date. Material changes requiring consent should be communicated before the affected processing begins.