Skip to content
ZivoFlow
Support Google Play

ZivoFlow policy

Sticker Privacy Policy

This Privacy Policy explains how ZivoFlow handles information when you use the Sticker Android app, zivoflow.com, and related public Sticker services.

Last updated: August 9, 2026

Scope and who we are

ZivoFlow operates Sticker under the ZivoFlow name. This policy covers the Sticker Android app, the public website at zivoflow.com, the supporting Sticker API and content service, and public sticker, pack, catalog, and shared-link services.

Sticker currently has no end-user login or account system and no ZivoFlow cloud-synchronized personal sticker library. It offers local created and downloaded content, public catalog and reporting features, advertising infrastructure, and app privacy controls. This policy does not describe the private administration tools used to operate the service.

Information stored locally on your device

A substantial part of Sticker works locally. The app may keep created sticker packs, downloaded sticker packs and media, library and app state, and Room-backed application data on your device. ZivoFlow does not provide account-based cloud synchronization or restoration for this local library.

You can generally remove local app data through Android app-storage controls or by uninstalling the app. Depending on Android settings and device features, some app data may be included in Android backup or device-transfer processes. Sticker excludes its telemetry privacy preferences and report-installation identity preference from those processes, but does not broadly exclude its database or sticker media.

Online requests and public catalog use

When you browse public content, open a public link, download media, or search, the app communicates with the Sticker service. Search terms must be sent to the service to perform a search; the app does not intentionally retain raw search text as first-party analytics telemetry.

As with other internet services, hosting, CDN, and API providers may process ordinary request information, such as IP address, network information, user-agent or device/app information, and request timing, as needed to deliver, secure, and operate the services. This policy does not promise that provider infrastructure logs omit those data types.

First-party product engagement metrics

Sticker records operational engagement events when you view, download, share, like, or unlike a public sticker or pack. These events support public content counters and core product operation; they are separate from optional Firebase Usage Analytics and are not controlled by the Usage Analytics choice.

An event may include its type, the relevant sticker or pack identifier or slug, a randomly generated event UUID used to prevent duplicate processing, source or platform context where applicable, and event or receipt timing. These are pseudonymous product-level operational events, not end-user account records. Aggregate public counters may remain with the catalog even after an individual delivery receipt is removed.

Public content reports

If you choose to report public content, we process the report target or content identifier, report reason, any optional details you enter, a report ID, and timestamps or status needed to investigate and manage the report. Please do not include sensitive information in optional report details unless it is necessary for the report.

For reporting, the app creates a random installation UUID. It is not an Android ID, advertising ID, Firebase ID, phone number, account ID, or hardware identifier. The app sends the raw UUID with the report request; the Sticker API stores a SHA-256 hash for abuse prevention and rate limiting. The identity preference is excluded from Android backup and device transfer, although a pending local report can keep the UUID already stored in its delivery record until it is delivered or expires.

Firebase operational services

Sticker uses Firebase Remote Config for operational configuration, including feature and advertising enablement. Remote Config can initialize independently of optional Usage Analytics or Diagnostics choices because it is an operational service. Google and Firebase may process information needed to provide Remote Config and Firebase Installations, such as a Firebase installation identifier, app or package identifiers, platform and operating-system information, language, time zone, country-level or network-derived information, and SDK or app metadata.

A Firebase installation identifier is distinct from the app-generated UUID used for public content reports. Remote Config is not a local-only service and is not the same as optional Firebase Analytics.

Optional Usage Analytics

Usage Analytics is optional. Firebase Analytics collection starts disabled in the app configuration, as do Analytics advertising-ID collection, automatic screen reporting, and default Analytics ad-personalization signals. Analytics may be enabled in accordance with applicable UMP and Consent Mode state unless you explicitly disable Usage Analytics; an explicit opt-out keeps it disabled.

When enabled, the app intentionally uses limited, categorical custom analytics events. Its custom payloads do not intentionally include raw search text, free-text report details, filenames, user account IDs, or advertising IDs supplied by app code. Google Analytics may nevertheless process identifiers or device information needed for its service. The current GA4 configuration permits granular location and device data collection, which can include coarse geographic, device, browser, or operating-system characteristics; Sticker does not request location permission or collect GPS location for this purpose.

Optional Diagnostics

Diagnostics is optional. Firebase Crashlytics and Firebase Performance start disabled in the app configuration and are enabled only when you explicitly opt into Diagnostics. You can disable Diagnostics again in the app privacy settings.

Crashlytics may process crash or error information, including stack traces, application state, device or app metadata, and Firebase installation identifiers. Firebase Performance may process app and network performance information, device or app metadata, and network-derived coarse geographic information where Firebase does so. Sticker limits its own Crashlytics enrichment and does not deliberately attach raw search text, report details, or user account information.

Firebase provider practices can change. Current Firebase documentation indicates that Crashlytics crash data and associated identifiers are generally processed for about 90 days before deletion processing, Performance IP-associated events for about 30 days, and installation-associated or de-identified Performance data for about 60 days.

Advertising and privacy choices

The Android app contains Google Mobile Ads (AdMob) and Google User Messaging Platform (UMP) services and can support banner, native, and rewarded ads. A placement is not necessarily active: actual ad requests depend on production or Remote Config settings, placement enablement, UMP consent or privacy state, and Google SDK eligibility.

Google and advertising technology providers may process information needed for advertising, measurement, fraud prevention, frequency limiting, and related functions. This can include IP or network information, app or product interactions, diagnostics, device or app identifiers, and an Advertising ID or related advertising or device identifier where available and permitted. Advertising does not always use an Advertising ID, and an ad presented without personalization can still involve identifiers or other information for permitted functions. The Android release currently has no separate third-party mediation-network SDK beyond the Google advertising stack.

Where required, UMP can show a Google privacy or consent message, including for users in the EEA, the UK, and Switzerland, and can offer consent, management, or do-not-consent choices. The current control plane enables Consent Mode for advertising and analytics and shows an in-app Privacy Options entry point where required. Your available choices can affect ad storage, advertising personalization, ad user data, and analytics storage.

UMP and AdMob privacy messaging may also provide applicable US-state choices, including choices relating to sale, sharing, or targeted advertising. ZivoFlow does not sell personal information for money. However, advertising-related disclosures or transfers may qualify as a sale, sharing, or targeted advertising under some US privacy laws, and applicable choices are offered through the Google privacy interface where required.

Website and backend operations

The public website at zivoflow.com currently does not run Vercel Web Analytics, has no production GA4 configuration enabled, and does not run Vercel Speed Insights. Website hosting and delivery providers may still process ordinary operational request information needed to serve, secure, and maintain the site. We will update this policy if website analytics are enabled in the future.

The production Sticker API uses Sentry for privacy-minimized reliability and error monitoring. The API disables PII sending, excludes request bodies, disables tracing, profiling, and session tracking, and sanitizes broad request, user, context, and message fields. Limited operational information, such as a validated request ID or service or component context, may remain. Sentry is not used to record full user requests, but provider-level metadata may still be processed to operate the service.

Service providers and disclosures

We use service providers only as appropriate to the function they provide. Google provides Google Play distribution, AdMob, UMP, Firebase Remote Config and Installations, and the optional Firebase Analytics, Crashlytics, and Performance services. Railway provides API and PostgreSQL infrastructure, Sentry provides sanitized backend error monitoring, Backblaze B2 provides object and media storage, Cloudflare provides CDN and public-media delivery, and Vercel hosts the public website.

These providers do not receive every category of information described in this policy. Information may be disclosed to them when needed to provide their service, comply with law, protect the service and users, prevent abuse or fraud, or support a business transfer. Provider processing is also subject to their applicable privacy practices and contractual arrangements.

WhatsApp and other third-party services

When you choose Add to WhatsApp or a related transfer feature, the action is initiated by you. The Android and WhatsApp integration exposes or transfers the local sticker-pack data and files needed to complete that handoff. This is not the same as uploading locally created stickers to the ZivoFlow public catalog.

WhatsApp and Meta operate independently under their own terms and privacy practices. ZivoFlow is not affiliated with WhatsApp or Meta. Google Play likewise handles app distribution under Google's own policies.

Data retention

Local app data generally remains on your device until you remove it or the app lifecycle removes it, subject to Android backup and device-transfer behavior described above. Local metric and report delivery records are retained only for bounded delivery attempts: valid metrics are retried for up to 14 days and expired or terminal records are removed; failed report delivery is similarly bounded and old or terminal records are not retained indefinitely.

Metric idempotency receipts are designed to be retained for approximately 30 days. They may be retained longer during rollout, migration, backup, or other operational exceptions. Aggregate public counters may remain as part of catalog records after individual receipts are removed.

Server-side content reports are currently configured for approximately 12 months, with cleanup running according to that retention configuration. Firebase diagnostic and performance information follows the provider practices described above. API, hosting, CDN, and error-monitoring logs are retained according to operational need, service configuration, and provider retention practices; they do not all share one universal period and may persist in backups for a period after deletion.

Security

We use reasonable safeguards appropriate to the service, including HTTPS or TLS in transit where supported, restricted administrative access, minimized diagnostic payloads, and random or pseudonymous identifiers instead of end-user accounts for applicable features. Public-report installation IDs are hashed on the server for abuse and rate-limit controls.

No method of transmission, storage, or processing can be guaranteed to be completely secure. Please use care when deciding what to include in a content report or share through a third-party service.

Your controls and privacy rights

In the Android app, you can manage the Usage Analytics and Diagnostics choices, and use UMP Privacy Options when that option is required or available. You can also delete local app storage or uninstall the app using Android controls. Applicable advertising and privacy choices are available through the Google or UMP privacy interface where required.

Depending on where you live and subject to applicable law, you may have rights to request access, correction, deletion, restriction or objection, withdrawal of consent, an opt-out of applicable sale, sharing, or targeted advertising, or to complain to an applicable data-protection authority. Some choices are available directly in the app; for other requests, contact ZivoFlow. The absence of an end-user account does not remove rights that may apply to you, but Sticker does not currently offer an account-deletion feature because it has no end-user accounts.

International processing

Sticker uses global infrastructure and service providers. Information may be processed in countries other than the one where you live, subject to applicable safeguards and provider arrangements.

Changes to this policy

We may update this policy when product behavior, service providers, privacy practices, or legal requirements change. The current version will display its Last updated date.

Contact

ZivoFlow is responsible for this policy as the operator of Sticker under the ZivoFlow name.

For privacy or terms questions, contact us at kevinchen198802@gmail.com.

© ZivoFlow

Privacy Sticker Privacy Terms Support