Layered (hereinafter referred to as the "App") values your privacy and complies with relevant laws and regulations. This Privacy Policy explains how the App collects, uses, and protects your personal information.
1. Information We Collect and Access
The App prioritizes your privacy and processes its core feature data locally on your device.
A. Locally Processed Data (Not Collected)
The following data is accessed and processed directly on your device to provide the App's core features. This data is NOT transmitted to or stored on our servers.
- Calendar Data: The App reads your device's calendar events to display your schedule on wallpapers.
- Reminders Data: The App reads your device's reminders to display your pending tasks on wallpapers.
- Google Tasks Data (Optional Integration): Only if you choose to connect your Google account inside the App, the App reads your task lists through the Google Tasks API to display them on wallpapers, home-screen widgets, and in-app calendar views. Access is read-only and the retrieved data is stored only on your device. See Section 4. Use of Google User Data below for details.
- Photo Library: The App requests Photo Library access so you can choose background images for your wallpaper and save generated wallpapers to your device. Selected photos and generated wallpapers are stored only on your device.
B. Information Collected When Using In-App Support
If you use the in-app "Contact Us" (inquiry) feature, the following information is stored on Google Firebase servers used by the operator in order to respond to your inquiry:
- Inquiry Content and Attached Images: The content and images you write and attach yourself.
- Anonymous User Identifier: A random identifier generated by the purchase-management SDK (RevenueCat). It is not linked to your name, email address, or other real-world identity.
- Device and App Information: Device model, OS type and version, app version, and whether you are a free or premium user.
C. Push Notifications (Optional)
Only if you enable notifications to receive inquiry replies, a push token (FCM token) and your language setting are stored on our servers. This information is deleted immediately when you turn notifications off in the App.
D. Automatically Collected Information (Third-Party Services)
To provide in-app advertisements, measure ad performance, and improve service quality, third-party services may collect the following information:
- Advertising Identifiers and Device Information: Mobile advertising IDs (iOS: IDFA, Android: GAID), device model, OS version, etc.
- App Usage Data: Screen usage statistics, ad interaction history, crash reports, and other log data related to service usage.
- Anonymous Usage Statistics: Aggregated, non-identifiable data such as template and font usage counts.
2. Purpose of Collection and Use
The information is used only for the following purposes:
- Service Provision: Generating custom wallpapers based on your calendar and reminders data (processed locally).
- Customer Support: Receiving inquiries, providing replies, and sending reply notifications.
- Purchase Management: Verifying, restoring, and managing in-app purchases (subscriptions and lifetime access).
- Ad Serving and Measurement: Providing interstitial and rewarded ads and analyzing ad campaign performance.
- Service Improvement: Analyzing app usage statistics, improving performance, and fixing bugs.
3. Third-Party Services (Processing and Provision)
The App does not sell or provide personal information to external parties without your consent. However, the following third-party services process information to operate the service:
- Google Firebase (Analytics, Firestore, Cloud Messaging, Storage): App usage analytics, inquiry data storage, and push notification delivery — Privacy Policy
- Google AdMob: Ad serving and performance analysis — Privacy Policy
- AdMob Mediation Partners: The following ad networks may serve ads for better ad efficiency — Unity Ads, Pangle, Liftoff Monetize
- Meta (Facebook SDK): Ad campaign measurement and attribution. Advertising identifiers are used only if you have consented to tracking — Privacy Policy
- RevenueCat: In-app purchase management (anonymous identifier, purchase receipt information) — Privacy Policy
4. Use of Google User Data (Google API Services User Data Policy)
Only if you choose to connect the Google Tasks integration inside the App does the App access your Google user data through Google APIs. The App's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Scope Requested:
https://www.googleapis.com/auth/tasks.readonly— read-only access to your task lists. The App never creates, edits, completes, or deletes tasks, and requests only the narrowest scope required for this feature. - Data Accessed: Task list names, and the title, due date, and completion status of each task.
- Purpose of Use: Limited to displaying your tasks as reminders on your own wallpapers, home-screen widgets, and in-app calendar views.
- Where It Is Stored: Retrieved data is cached only in local device storage (Android: SharedPreferences, iOS: App Group UserDefaults) so that wallpapers and widgets can render while offline. It is never transmitted to or stored on our servers or shared with any third party.
- Restrictions: Google user data is not used for advertising purposes, is never sold or transferred to any third party, and is not used to train artificial intelligence or machine learning models. No humans, including the operator, read this data, except with your explicit consent, for security purposes, or when required by applicable law.
- Disconnecting and Deletion: You can disconnect the integration at any time in the App's settings; doing so immediately deletes the cached task data and authentication tokens. You may also revoke the App's access from your Google Account permissions page.
5. Data Protection and Security Measures
We apply the following technical and organizational safeguards to protect your data, in particular sensitive data including Google user data.
- Encryption in Transit: All communication with Google APIs and with our servers is encrypted using HTTPS (TLS). We do not use unencrypted communication channels.
- Protection at Rest: Google Tasks data, calendar and reminders data, and generated wallpapers are stored only inside the operating system's app sandbox (Android: app-private storage, iOS: App Group container), where other apps cannot access them. That storage area is protected by the device's full-disk encryption.
- Authentication Token Handling: The App does not store OAuth access tokens itself. Tokens are managed by Google's official Sign-In SDK through each platform's secure storage (Android: Google Play services, iOS: Keychain), and are never transmitted anywhere else.
- Data Minimization and Least Privilege: We request only the minimum data and the narrowest scopes required to provide the feature. Google user data is never transmitted to our servers, so there is no server-side exposure risk for that data.
- Access Control: Information stored on our servers (Google Firebase), such as inquiry data, is restricted by Firebase Security Rules, and administrator accounts are protected with two-factor authentication. Access is limited to the minimum number of people required to respond to inquiries.
- Retention Minimization: On-device caches are kept only as long as needed to provide the feature and are deleted immediately when you disconnect the integration, delete the App, or revoke permissions.
- Vulnerability Management: We keep platform SDKs and third-party libraries up to date and release fixes without delay when a security issue is identified.
6. Ad Personalization and Tracking Consent
- iOS: On first launch, the App asks for your permission to track in accordance with Apple's App Tracking Transparency (ATT) framework. You can use all features of the App without consenting; in that case, non-personalized ads are shown instead.
- GDPR Regions (e.g., EEA): Advertising-related consent is collected through Google's consent management platform (UMP), and ad personalization and tracking are determined by your consent choices.
7. Retention and Destruction of Personal Information
- Local Data: Calendar and reminders data and generated wallpapers are stored only on your device and are removed if you delete the App or the specific data.
- Google Tasks Data: Cached task data and authentication tokens on your device are deleted immediately when you disconnect the integration or delete the App.
- Inquiry Data: Retained for responding to inquiries and improving service quality, and destroyed without delay upon your deletion request.
- Push Tokens: Deleted when you turn notifications off or when the token becomes invalid.
- Third-Party Data: Information collected by third-party services follows the retention policy of the respective service.
8. User Rights
Users can exercise the following rights:
- Revoke Permissions: You can revoke access to Calendar, Reminders, or Photos at any time in your device settings (iOS: [Settings] > [Apps] > [Layered], Android: [Settings] > [Apps] > [Layered] > [Permissions]). Note that some features may not function if permissions are revoked.
- Disconnect Your Google Account: You can disconnect the Google Tasks integration in the App's settings, or revoke the App's access from your Google Account permissions page.
- Limit Ad Tracking: On iOS, go to [Settings] > [Privacy & Security] > [Tracking]. On Android, go to [Settings] > [Google] > [Ads] to reset or delete your advertising ID and limit personalized ads.
- Request Deletion of Inquiry Data: You can contact us at the address below to request deletion of your inquiry history stored on our servers.
9. Contact
If you have any inquiries regarding privacy protection, please contact us at the email address below.
- Email: contact@nemostudio.net
10. Changes to this Policy
This Privacy Policy may be modified according to changes in laws or services. Significant changes will be notified through in-app announcements or update notes.