Covelet is published by Chenglin Wu under the CoolMio brand. This policy explains how information is handled by the Covelet iPhone app and this website, covelet.coolmio.com. For privacy questions, contact [email protected].
1. Information we handle
Your local space
Covelet stores the photos, videos, Live Photos, files, notes, and custom wallpapers you choose to keep. Local records also include filenames, folders, note titles, thumbnails, favorites, dates, and other metadata needed to organize your space. Imported originals can contain their existing metadata, including location metadata; Covelet does not request your device's location.
Your library content and its indexes are encrypted locally. Your PIN, password, or pattern protects the library key. Credential-protected key material and local authentication settings are stored on your device; an optional Face ID access key is protected by the iOS Keychain. Face ID is handled by iOS, and Covelet does not receive your face images or biometric templates. Non-sensitive preferences, such as appearance settings, are also stored locally.
Covelet does not upload your library content, either encrypted or unencrypted, to CoolMio or to a cloud storage service as an app feature. This is separate from the system backups, imports, and exports described below.
Purchases and RevenueCat
Covelet uses RevenueCat to load Pro plans, validate purchases, restore access, and keep purchase status current. The app creates a random, anonymous app user ID rather than a Covelet account. RevenueCat processes that identifier, Apple transaction or receipt information, product identifiers, purchase and expiration dates, and subscription or entitlement status.
Requests also include technical information needed by the service, such as app and SDK versions, device and operating-system information, locale, and currency. RevenueCat records when this anonymous installation connects to its service. Its servers receive your IP address and may use it to determine a country; RevenueCat states that it then discards that IP address. These requests may occur when the app starts or refreshes access, even if you have not purchased Pro.
We use purchase records for app functionality, purchase support, and RevenueCat's purchase and revenue reporting. Covelet disables the SDK's automatic device-identifier collection and optional diagnostics, does not supply advertising identifiers or contact attributes, and does not send library contents to RevenueCat. See RevenueCat's data practices and customer-data documentation.
Apple purchases
Apple processes App Store payments using your Apple Account. We and RevenueCat do not receive your full payment-card details. Apple handles its account, billing, fraud-prevention, and store data under Apple's Privacy Policy. Apple purchase records are separate from your local Covelet library.
Wish Well submissions
When you choose to submit a wish in the app, we receive the text you enter, your email address if you choose to provide one, the app version, and a random identifier for that submission. We also record the time received, a review status, and delivery information used to retry the developer notification. The submission identifier helps avoid saving the same retry twice; it is not a permanent device or account identifier.
Cloudflare processes the submission through our API and stores it in a D1 database. We send a notification containing the wish and its optional email address to our developer support inbox, hosted by Google. We use this information to read and evaluate suggestions and, if you left an email address, to reply about your wish. See Cloudflare's Privacy Policy and Google's Privacy Policy.
Wish Well sends only the text you enter and the submission details described above. It does not attach your library photos, videos, files, notes, or keys. Submitting does not require an account. Wishes are not shown in a public list, and the form does not accept attachments or send an automatic confirmation email to you. Please leave credentials and private library contents out of your wish.
To limit repeated requests, the API uses a keyed, daily-changing identifier derived from the request IP address with Cloudflare's short-lived rate-limit counters. We do not put the raw IP address or that identifier in wish records, notification emails, or our application logs. Our application logs do not include wish text or email addresses. Cloudflare still processes network and service data under its own operational practices.
This website
Cloudflare hosts and delivers this static website. To deliver pages and protect its services, Cloudflare processes network-request data, which can include an IP address, requested URL, request time, browser information, and security or error information. Operational logs and service metrics may be processed by Cloudflare and made available to us. See Cloudflare's Privacy Policy.
We do not add advertising, tracking pixels, analytics scripts, or analytics cookies to this website. Following an external link or opening your email app brings you to a service with its own privacy practices.
Support messages
If you email us, we receive your email address and the message, attachments, and other information you choose to send. Our email provider, Google, processes that correspondence to deliver and store it. We use it to respond and resolve your request. Please do not send your PIN, password, pattern, payment-card details, or private library contents. Support does not require access to your encrypted library.
Information we do not request
Covelet has no account registration, advertisements, advertising identifiers, or cross-app advertising tracking. It does not request your contacts, location, microphone, health information, or notification permission. We do not ask for your name or require an email address to use the app. Wish Well offers an optional reply email. Voluntary wishes and support correspondence, together with the purchase and network data described above, are exceptions to any general description of Covelet as a local app. We do not install a separate behavior-analytics SDK; RevenueCat's purchase reporting is described above.
2. How we use information
Information is handled to save and organize the content you select, authenticate access, provide previews and exports, deliver Pro purchases, evaluate wishes, respond to support, operate the website, and protect these services against abuse. We do not sell personal information or share it for cross-context behavioral advertising. We do not use your library content to train AI models.
Where applicable data-protection law requires a legal basis, we rely on providing the app or purchase service you request, our legitimate interests in reliable operation and support, compliance with legal obligations, and consent where required. We do not use this information to make automated decisions producing legal or similarly significant effects about you.
3. Sharing and service providers
The providers involved are Apple for App Store and system services, RevenueCat for purchase management, Cloudflare for website hosting, wish processing and storage, email delivery, and security, and Google for our wish-notification and support inbox. They receive the information described above for those functions. We may disclose information we actually hold if required by law or necessary to protect legal rights. We cannot disclose library content that we do not possess.
When you explicitly export or share an item, its destination receives that content. The recipient or destination service then controls its own copy and privacy practices.
4. Permissions, imports, and exports
- Photos selection: Apple's system picker lets you select photos, videos, Live Photos, or a custom wallpaper. Covelet receives the items you confirm; importing does not require permission to browse your entire photo library.
- Adding to Photos: Covelet requests permission to add items only when you choose to save media back to Apple Photos.
- Removing originals: If you choose to remove successfully imported originals, Covelet requests the photo-library access needed to find and delete those originals. Covelet first saves and verifies its imported copies, then asks for your confirmation. Apple's own deletion and sync rules apply to the originals.
- Camera: Camera access is used when you open Covelet's camera to take a still photo. Captures are saved into Covelet, not automatically into Apple Photos. Covelet does not record microphone audio.
- Files: The system file picker provides access to files you choose. A selected file or photo may first be downloaded by Apple or a file provider if its original is stored in that provider's cloud service.
- Face ID: Optional Face ID lets iOS authorize unlocking or resetting your Covelet credential. It does not share biometric data with us.
You can change system permissions in iPhone Settings. Declining an optional permission leaves unrelated features available. Previewing or exporting may create temporary, decrypted copies on your device; Covelet protects these temporary files and cleans them up when the operation permits. An export already handed to another app may need to remain until that handoff completes.
5. System backups and recovery
Covelet does not provide app-level cloud backup or sync. Your iPhone's system backup may include encrypted Covelet content and credential-protected key material, depending on your device and backup settings. We do not check whether you have a complete, usable backup.
Restoration depends on a complete system backup and the unlock method used when that backup was made. Optional Face ID access is device-bound and is not a replacement for that credential on a different device. Exporting or sharing also creates copies outside Covelet. Uninstalling the app, erasing its space, or losing the device can therefore lose content. We cannot recover your credential or decrypt your space for you.
6. Your choices and rights
You can view, export, and delete your local content in the app. You can change your unlock method after authenticating, disable Face ID, and erase the space. There is no Covelet account to close. Erasing local content does not cancel a subscription or automatically delete submitted wishes, email correspondence, or purchase records held by Apple or RevenueCat. You can leave the Wish Well email field empty or choose not to submit a wish.
Depending on your location, you may have rights to request access, correction, deletion, or portability of personal information we hold, to object to or restrict certain processing, to withdraw consent, or to complain to a data-protection authority. Email [email protected] to make a request. We may need enough information to identify the relevant wish, support, or purchase record. If you submitted a wish without an email address, include enough detail for us to locate it, such as its approximate date and text. We do not have a name-based directory of local libraries and cannot retrieve their contents. Applicable recordkeeping obligations and other legal exceptions may limit deletion of wish, purchase, or support records.
7. Retention and deletion
Local content stays in your space until you delete it or remove the app's data. Deleted Photos items remain in Recently Deleted for up to 30 days and can be permanently deleted sooner. Expired items are removed when Covelet has an opportunity to run and process them; this is not a guarantee of physical erasure at an exact time. Files and notes do not have this recovery period.
Erasing a space removes its local content and associated library keys. It does not remove originals in other apps, exported copies, or older system backups, and is not a forensic-erasure guarantee. You control those other copies separately.
Wish records and their notification emails are kept while needed to evaluate suggestions and handle related follow-up. The current service has no fixed automatic expiry for these records; we remove them through operational cleanup or in response to applicable deletion requests. A database record and its email copy are separate, so removing one does not automatically remove the other.
Purchase records are retained as needed to validate and restore purchases, provide support, and meet legal obligations. Support correspondence is retained as needed to handle the request and related follow-up or legal obligations. Hosting logs are subject to Cloudflare's operational retention practices. We do not promise that deleting the app removes these separate service records.
8. Security
Covelet uses local encryption and iOS protection mechanisms to reduce unauthorized access. Network communications with purchase services, the Wish Well API, and this website use HTTPS. No app, device, or storage method is completely secure. Protection also depends on your device, operating system, and unlock method. Keep that method safe, and keep independent copies of content you cannot afford to lose.
9. Children
Covelet is not directed to children under 13, and we do not knowingly solicit personal information from children under 13. If you believe a child has sent us personal information, contact us so we can address it. Parents or guardians should manage App Store purchases and permissions for children in their care.
10. International processing
Our service providers may process purchase, wish, website, and support information in the United States and other countries. Privacy protections may differ by location. Where required, relevant data-protection and transfer safeguards apply. Your local library is not uploaded as part of this processing.
11. Changes and contact
We will update the date on this page when this policy changes and provide additional notice of material changes where required. The current policy is available at covelet.coolmio.com/privacy.
Publisher: Chenglin Wu, operating under the CoolMio brand. Contact: [email protected]. You can also visit Support or read the Terms of Service.