Effective September 19, 2026
Privacy Policy
This policy explains how AltShft (“we” or “us”), based in Ontario, Canada, handles information through the ZzaL iOS app, keyboard extension, website and related account services. AltShft operates ZzaL.
1. Information handled by ZzaL
- Optional account information: email address, authentication provider, user ID, account dates, and session credentials used to create, secure and restore a Supabase-backed account. Passwords are submitted directly to the authentication service and are not readable by ZzaL.
- Launch promotion: the app sends Apple's signed AppTransaction proof to the ZzaL API to determine the initial free promotion. The API verifies the proof and does not store the raw proof or Apple transaction identifier. It stores a keyed, pseudonymous acquisition marker, the original acquisition time, promotion expiry, whether the one-time signup bonus was claimed, and any linked ZzaL user ID while the account remains active.
- Sign in with Apple credential: ZzaL exchanges Apple's one-time authorization code on the server and stores the resulting revocation credential encrypted. If you request account deletion, ZzaL uses that credential to ask Apple to revoke access and removes it after successful revocation. An older account for which no revocation credential exists can still be deleted.
- KLIPY requests and provider processing: ZzaL sends KLIPY search terms and share events, along with language or locale, requested content IDs, and an app-generated pseudonymous installation identifier, to return and refresh results, maintain provider attribution, and record a selection copied for sharing. The identifier is a random UUID shared by the ZzaL app and keyboard. ZzaL does not combine it with your account email or name. GIF and sticker media loads directly from provider URLs, so KLIPY and its delivery partners receive IP address, request metadata, and approximate location inferred from IP address. KLIPY's published policy says it may also process device or app identifiers, content-view and search history, service-use and interaction information, service errors or diagnostics, and information about interactions with advertising or sponsored content. KLIPY says it uses this information to deliver and secure its service, localize and optimize results, measure use, improve and personalize its services, and support advertising or sponsored content. KLIPY controls that provider-side processing under its own policy; ZzaL does not receive KLIPY's resulting advertising profile. ZzaL remains responsible for this integration, its own disclosures, and any choices required by applicable law.
- Information kept on your device: Favorites, Recents, content references, ticket usage, display language, appearance, onboarding progress, keyboard preferences and the pseudonymous installation identifier are stored locally or in the ZzaL app group. They remain until you remove them, clear app data, or uninstall ZzaL, subject to iOS backup behavior, and are not account profile fields.
- Advertising and diagnostics: the iOS app asks once, after onboarding, for your year of birth, and derives from it whether you are treated as 13–17 or 18+. Only that year is kept, only on your device, and it is never sent to ZzaL or to an advertising provider. It cannot be changed in Settings; reinstalling the app clears it and the app asks again. Google User Messaging Platform records any consent choice, and Google AdMob may process approximate location, device or advertising identifiers when available, ad and product interactions, performance information, crash data and other SDK diagnostics to provide, measure and protect ads. Users aged 13–17 receive age-restricted, non-personalized treatment and are not asked for App Tracking Transparency permission. Adults may be asked for that permission only after consent information is ready. Answering the year-of-birth question is required to continue past onboarding. Refusing or dismissing a tracking or consent permission does not block the app; it prevents personalized ads or suppresses ads when a safe request is unavailable. ZzaL does not send your account email to Google for ads.
- Website and API operation: Cloudflare processes standard request information such as IP address, time, URL, device/browser headers and security signals to deliver and protect the website and API. ZzaL does not use a separate product-analytics service in this release.
- Support: if you contact us, we process the information you choose to provide and your contact details as needed to review and respond.
2. Keyboard and Full Access
ZzaL uses Full Access to load KLIPY GIFs and stickers over the internet, copy selected media to the clipboard, and share preferences and local library references with the ZzaL app.
When you search for GIFs or stickers, the search terms you enter and a pseudonymous installation identifier are sent to KLIPY. Content requests and copy-for-sharing events may also include content identifiers. Loading provider media exposes your IP address and standard request information to KLIPY and its delivery partners, as described above.
Ordinary text you type into other apps is processed on your device for keyboard functions such as Korean composition, capitalization, and editing. ZzaL does not send that text or surrounding conversation content to its servers or KLIPY. Text entered into ZzaL’s GIF or sticker search is a search request and is treated as described above.
ZzaL’s GIF and sticker features require Full Access. Without it the keyboard still types and inserts Kaomoji, but the GIF, Sticker, Favorites and Recents panels show a Full Access notice instead of content, and no media is loaded or copied. iOS asks before Full Access is granted, and you can withdraw it at any time in Settings under General > Keyboard > Keyboards > ZzaL.
3. Why we use information
We use information to provide search and sharing, authenticate accounts, determine and protect one-time promotion eligibility, preserve user and advertising choices, operate account deletion and Apple access revocation, prevent abuse, secure and troubleshoot the service, respond to support or legal requests, comply with law, and maintain provider-required delivery and attribution. We do not sell personal information.
4. Service providers and disclosures
We disclose only the information reasonably needed for a provider to perform its role:
- Supabase provides authentication and database services.
- Cloudflare provides the public website, API, security and object infrastructure.
- Apple provides AppTransaction verification and Sign in with Apple.
- Google Cloud runs the account-deletion processor.
- KLIPY provides GIF and sticker search, media delivery and provider event processing. Its policy describes its own collection, use, retention, disclosures and privacy choices for that provider-side processing.
- Google AdMob and User Messaging Platform provide advertising, consent and related SDK services.
We may also disclose information when required by law, to protect users or the service, or in connection with a business transfer where permitted and subject to appropriate notice and protection. We require third parties that receive personal information through ZzaL to provide the same or equal protection described in this policy and required by applicable law.
5. International processing
These providers may process information in Canada, the United States, the European Union, or other locations where they operate. Privacy laws may differ from those in your home jurisdiction. We remain responsible for selecting providers and using contractual or other safeguards required for our processing.
6. Retention and deletion
- Local preferences and library references remain on your device until you remove them, clear the app's data, or uninstall the app, subject to iOS backup behavior.
- Account and authentication records are retained while your account is active and as needed for security and legal obligations.
- Any ZzaL user ID linked to a promotion claim is removed during account deletion. The pseudonymous acquisition marker, original acquisition time, promotion expiry and claim timing remain after account deletion while needed to prevent a reinstall or new account from receiving the same one-time benefit again. They are not used for advertising or user profiling and are deleted when that abuse-prevention purpose no longer applies.
- An encrypted Sign in with Apple revocation credential is kept until Apple access is successfully revoked during account deletion, then removed.
- After an account deletion request is accepted, active sessions end and private account data and personal account links are removed through the deletion process within 7 days, except information we must retain for security, fraud prevention, legal claims, or other legal obligations.
- Support correspondence is retained only as long as reasonably needed to respond, keep an appropriate service record, and meet legal obligations.
- Provider request, security and diagnostic records follow the provider's applicable retention practices and our configured service controls.
7. Your choices and rights
You can use core browsing features without creating an account, manage local Favorites and Recents, open the advertising privacy options in the ZzaL app's Settings when they are required, change device permissions in iOS Settings, stop using the keyboard extension, and request account deletion in the ZzaL app's Settings or on the account deletion page. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent where processing depends on consent.
To exercise a privacy right, email support@zzal.app. We may need to verify your identity before acting on a request. You may also complain to the privacy regulator where you live.
8. Security and children
We use reasonable technical and organizational safeguards, including encrypted HTTPS transport and access controls, but no system is completely secure. ZzaL is not directed to children under 13. If you believe a child provided personal information contrary to applicable law, contact us so we can investigate.
9. Changes and contact
We will post policy changes here with a new effective date and provide additional notice when required. Materially different features such as user uploads, subscriptions, new analytics, or new data uses require this policy and the app's disclosures to be reviewed before launch.
Privacy contact and operator:
Privacy Officer, AltShft
Operator of ZzaL
Ontario, Canada
support@zzal.app
Concerns about GIFs or stickers supplied by KLIPY should be sent through KLIPY Support. Copyright complaints can use KLIPY's copyright process.