Appcelerator Studio

Apps/Extend Wallpaper: AI Fill

Extend Wallpaper: AI Fill Privacy Policy

Last updated September 15, 2026 · Terms of Use

Overview

Extend Wallpaper: AI Fill (the “App”) takes a photo you choose and uses an AI model to generate the missing edges, so the photo fills your iPhone’s screen as a wallpaper instead of being cropped. You position the photo on a frame shaped like your screen, tap Extend, and a few seconds later you get back a full-resolution wallpaper you can save to Photos.

Unlike our other apps, this one cannot do its job entirely on your device: generating the new edges takes a model far too large to run on a phone. So the part of your photo that needs extending is sent, over an encrypted connection, to our generation service and from there to Replicate, which runs the model. This policy is mostly about exactly what is sent, what is kept and for how long — because that is the part that matters here.

The short version: there are no accounts, no analytics SDK, no advertising and no tracking of any kind. We never learn your name, your email or who you are. We do not keep your images: our service passes them straight through and stores nothing but a small job record, keyed to a random identifier, that expires within seven days. Everything you make stays on your phone.

Information we do not collect

The App does not collect, transmit or store on any server:

  • Your name, email address, phone number or any account information (there are no accounts, and there is nothing to sign in to).
  • Your location. The App never asks for location permission, and the metadata your camera wrote into a photo — including GPS coordinates — is not carried into what is uploaded (see “What leaves your device when you tap Extend” below).
  • Your photo library. The App never reads, scans or indexes it, and receives only the single photo you pick.
  • Your finished wallpapers, your history, or the framing you chose. Those live on your phone.
  • Your advertising identifier, device identifier, or any behavioural, usage or crash analytics. There is no analytics or advertising SDK in the App, and RevenueCat’s optional diagnostics collection is switched off.
  • Your contacts, calendar, health data, camera, microphone or any other data from other apps. The App requests none of those permissions.

Choosing a photo

The App does not ask for permission to read your photo library, and does not have it. Picking a photo uses Apple’s system picker, which runs outside the App in its own process: the App is handed only the one photo you tap, and never sees the rest of your library. That is also why no “Allow access to Photos” prompt appears when you start.

The photo you pick is copied into the App’s private storage so that it can be re-used if a generation fails or you ask for another variation. That copy stays on your phone, and is deleted when you delete the result from History or delete the App.

What leaves your device when you tap Extend

When you tap Extend, the App builds two images on your phone. The first is the canvas: your photo drawn at the position and scale you chose, on a frame the shape of your screen, with the area still to be filled covered by a blurred, mirrored bleed of your own photo. The second is the mask: a black-and-white image marking which pixels must survive untouched and which the model should paint. The canvas is scaled down to at most four megapixels and encoded as a JPEG; the mask is a PNG. Those two images are what leaves your phone, over an encrypted HTTPS connection, and nothing else about the photo does.

The canvas is redrawn from your photo’s decoded pixels rather than copied from the file, so the metadata your camera wrote into the original — GPS coordinates, the date and time, the camera and lens, any editing history — is not present in what is uploaded. The original file itself is never uploaded, at any size.

Alongside the images, each request carries three small pieces of information: an install identifier, the same value repeated as your RevenueCat customer id, and the App’s version number. The install identifier is 32 random bytes generated on your phone the first time the App needs one, and kept in the App’s private folder. It is not derived from your device, your Apple Account or anything about you, it is not your advertising identifier, and it tells us nothing except that two requests came from the same installation. It exists so that generations can be rate-limited, so that a paid subscription can be checked, and so that only the device that started a job can read its result. Deleting and reinstalling the App produces a new one.

The finished image comes back the same way, and is composited on your phone at your screen’s native resolution with the original pixels of your photo placed back on top untouched.

Our generation service

Between the App and the AI model sits a small server of ours, running on Cloudflare. It exists so that the API token for the model service never has to ship inside the App, where it could be extracted. It is the only server we operate for this App.

It does not store your images. The two uploads are passed straight to Replicate, and the finished image is streamed through to your phone as it downloads; no copy is written on our side. What the service does keep is a small job record: a random job id, your install identifier, the geometry of the frame (the sizes involved and the rectangle your photo occupies), the random seed, which model ran, the time it started, and the links to the two uploads held by Replicate. That record is what lets you close the App in the middle of a generation and still find the result in History afterwards. It contains no image, and nothing that identifies you by name.

Job records expire seven days after they are created. The links to your uploads expire after twenty-four hours. The counter used to rate-limit requests expires after one hour. All three are deleted automatically at those points; we do not have to do anything, and neither do you.

As with any web request, the server sees the IP address your request came from while it handles it. We do not log it, profile it or keep it. Cloudflare, which operates the network the service runs on, processes it on our behalf to route and protect the request, under its own privacy terms.

Replicate and the AI model

Generation runs on Replicate, a platform for hosted AI models, using the FLUX Fill model made by Black Forest Labs. Replicate receives the canvas, the mask, a fixed text prompt and a random seed. The prompt is written by us, is the same wording for every user and every photo, and describes only how to continue a photograph naturally; nothing about you or about your image is added to it.

Replicate does not receive your install identifier, your purchase status, your IP address, your device details or the App’s version, because the request reaches it from our server rather than from your phone. It holds the uploaded images and the result for as long as it needs to run the generation and deliver it, and handles them under its own privacy policy, available at https://replicate.com/privacy.

Your photos are not used to train models — not by us, and not by the model provider under the terms we use the service on. We could not do so in any case: we keep no copy of them.

The model provider applies an automated safety filter to what is generated. If it flags an image, the generation comes back to the App as a failure with no picture, and a message saying the photo could not be extended. We are told nothing further, and no human at our end looks at your photo: there is no queue, dashboard or inbox anywhere on our side where your images could be viewed.

Saving to Photos

When you save a finished wallpaper, the App asks iOS for add-only access to your photo library — the prompt that says “Add to Photos?”. That permission lets the App write the images you explicitly choose to save and nothing more; it does not allow reading your library, and the App does not request read access.

Once saved, a wallpaper is an ordinary photo in the Photos app, managed by iOS and by you. Deleting the App does not remove it.

Network use

Apart from generation, the App makes very little use of the network. Nothing is uploaded in the background, no configuration is fetched at launch, and nothing is reported back to us about how you use the App.

The only other network traffic the App produces comes from Apple’s in-app purchase system and RevenueCat, described below: when the App starts, to check whether your purchase is active, and when you open the paywall, buy or restore a purchase.

If you open the Terms of Use, this Privacy Policy or Contact Support from inside the App, the page loads in an in-app browser, and the server delivering the page — ours, or Apple’s — sees your IP address, as with any web page.

Data stored on your device

The following is stored locally, in the App’s sandbox on your device, and nowhere else:

  • Your extensions: a copy of the photo you picked, the finished wallpaper at full resolution, a thumbnail for the History grid, the framing you chose, the seed, and the job’s status and timestamps. These sit in the App’s private database and files folder.
  • Your install identifier, in a single file in the App’s private folder.
  • Your settings: whether you have completed the introduction, whether the Lock Screen clock is drawn over the preview, and whether haptics are on.
  • Your purchase status, cached by RevenueCat so the App knows you are Pro even when offline.

Deleting your data

Deleting a wallpaper in History permanently removes its files from your device — the copy of your photo, the result and the thumbnail. Anything you had already saved to Photos is a separate copy and stays where it is until you delete it in the Photos app.

Deleting the App removes everything it stores, including your install identifier, your history and your settings. On our side there is nothing to delete but the job records described above, which hold no image and expire on their own within seven days; if you want one removed sooner, email us and we will remove it. Your purchase record stays with Apple and can be restored after reinstalling the App.

In-app purchases (RevenueCat and Apple)

Picking a photo, positioning it in the editor and the wallpaper tutorial are free. Generating an extension, generating another variation and saving a result require Pro, unlocked with either an auto-renewing weekly subscription or a one-time lifetime purchase. Purchases are processed by Apple through the App Store; we never see your payment details.

To validate purchases and keep the App unlocked across reinstalls, the App uses RevenueCat, a purchase management service. RevenueCat receives your install identifier as an anonymous customer id, your App Store purchase receipt, and basic device information (device model, OS version, app version, locale). This is the minimum information needed to confirm that a purchase is active. RevenueCat does not receive your name, your email or any of your photos, and its optional diagnostics collection is disabled in the App.

Before spending money on a generation, our service asks RevenueCat whether the customer id on the request currently holds Pro. That check sends RevenueCat the identifier and nothing else, and it sends back only whether the entitlement is active and when it expires.

RevenueCat’s privacy policy is available at https://www.revenuecat.com/privacy. Apple’s privacy policy is available at https://www.apple.com/legal/privacy/.

Children

The App is a general-audience photo utility, rated 4+. Whatever the age of the person using it, the App behaves the same way and learns the same amount about them: nothing beyond a random identifier for the installation.

There are no accounts, no sign-in, no messaging, no social features, no advertising, no analytics and no third-party tracking, and the App gives no one — child or adult — any way to send personal information to us. We do not knowingly collect personal information from children. Parents should know that extending a photo means that photo is sent to an AI service to be processed, as described above; it is not kept there afterwards, is not shown to anyone, and is not used to train anything.

Purchases are made through the Apple Account signed in on the device. Parents can require approval for every purchase using Ask to Buy, or block in-app purchases entirely in iOS Settings › Screen Time. If a child has made a purchase without permission, contact Apple Support to request a refund.

Your rights

We hold no account, name, email or profile for you, so requests to access, correct, export or delete your data are fulfilled almost entirely by you, on your device, as described above. The only data about you on a server we run is the short-lived job record, keyed to a random install identifier and holding no image; email us and we will remove it, or wait and it removes itself.

If you have a question about your rights under GDPR, the UK GDPR, CCPA/CPRA or similar laws, or want to know what RevenueCat holds for your anonymous identifier, contact us and we will help.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California law. We never have, and there is nothing for us to sell or share.

Security

Your photos, results and settings are stored in the App’s private container, protected by iOS sandboxing and your device passcode and encryption. Every network connection the App makes — to our generation service, to RevenueCat and to Apple — uses TLS, and a release build refuses to talk to a generation service over plain http at all. The API token for the model service is held only on our server and never ships inside the App.

No app, device or transmission can be made perfectly secure. We keep the risk low by holding as little as possible, for as short a time as possible, and keeping the rest on your device, but we cannot guarantee absolute security, and you are responsible for keeping your device updated and locked with a passcode.

Changes to this policy

If we change how the App handles data — including changing which service runs the model — we will update this page and the “Last updated” date. Material changes will also be described in the App Store release notes for the update that introduces them.

Contact

Appcelerator Studio is the data controller for Extend Wallpaper: AI Fill. For any privacy question or request, email team@appcelerator.studio.