Skip to content
Campus Journey
Back to Campus Journey

Draft · Not yet effective

Privacy Policy

Your photos, the words you write for your child, and the way you keep and share them deserve care. This page explains what Campus Journey processes, why, and how you can manage it.

Version
1.0
Last updated
Effective date
Not yet effective

At a glance

  • Made for parents and authorized adults. No child account is required.
  • Subject detection runs on iPhone; saved alignment parameters remain with the archive and can sync through iCloud.
  • Saved keepsakes and drafts stay on the current iPhone and can move through a full ZIP backup.
  • No advertising or third-party behavioral analytics SDKs. You choose what to share or send to support.

1. Scope

This policy applies to the Campus Journey iPhone app and support requests you choose to make about it. The app organizes school-stage photos and creates, saves, and shares keepsakes. It has no public community, stranger browsing, or child login accounts.

For information about a child under 14, also read the separate Children’s Personal Information Rules. Website visits and the Mlaohu feedback form are addressed by the website privacy policy.

2. Archive and keepsake information

The app processes optional nicknames and birthdays, stage names, dates and their selected precision and confirmation state, stage memory notes, ordering and skipped-stage choices, photos you select, and crop, zoom, and position settings. It may read a selected photo’s capture date to suggest a stage assignment, which you review. Photo records also include an optimized image, thumbnail, type, pixel dimensions, and any available capture date; restored backups may retain a filename already present in that backup.

It also stores archive identifiers, creation and modification dates, and the guardian confirmation, consent time, and policy version recorded when an archive is created. A generic label is available instead of a nickname. A child’s full legal name, school name, address, or identity documents are not required.

Drafts include selected stages, templates, colors, dimensions, titles, captions, and display choices. My Keepsakes stores JPEG/PDF files, thumbnails, titles, creation times, photo counts, and editing settings. Saving or sharing a keepsake can also retain a local keepsake record. Replacing a stage photo does not rewrite these independent copies.

3. Subject detection and alignment

Apple Vision detects face bounds and landmarks on the device to help align and crop photos. You can choose a subject in a group photo or adjust the crop by hand. The app does not identify people, build an identity database, predict future appearances, send photos to online AI, or use them to train models.

On-device detection does not mean no detection parameters are stored.Selected face bounds, eye center, angle, confidence, alignment choices, and crop parameters are saved with the photo archive. They also sync when the archive uses iCloud and are included in full ZIP backups. Temporary candidate lists are not saved as identity profiles.

Turning alignment off stops using the alignment result; it does not erase parameters already stored in the archive. You can manage or delete the corresponding photo or archive. Existing keepsakes and external backups need separate handling.

4. Local storage, iCloud, and account separation

Archives are first held in the app’s local data space. When the system iCloud account is available and the current archive selection allows it, the app loads that Apple Account’s private CloudKit archives and syncs them. iCloud use depends on system settings, account availability, and local archive choices. Core recording and creation can also work in a local archive.

CloudKit sync covers archive nicknames, optional birthdays, stages and memory notes, photos, crop and alignment parameters, and consent records stored with the archive. My Keepsakes, editor drafts, and reminder preferences do not automatically sync through the app’s CloudKit service.Apple device backups are a separate mechanism.

For account separation and cache recovery, the app locally stores a hashed account-scope identifier, a cached system iCloud identity token, the current archive selection, and sync state. These technical records distinguish data spaces and are not used for advertising profiles.

The app does not copy growth photos to an operator-run media server. Apple’s iCloud provider, infrastructure, and service arrangements can vary with account region. This policy does not guarantee a single storage region or end-to-end encryption. Apple services are also governed by the Apple Privacy Policy.

5. Permissions and local reminders

Import uses the system photo picker and processes only the photos you select, without requesting access to the entire library. The app creates optimized JPEG copies without carrying over the original EXIF/GPS metadata; capture dates may be stored separately in archive fields. Your original photos are unchanged. Visible photos and text may still reveal a school, place, or person; re-encoding does not make them anonymous.

Saving a keepsake to Photos requests add-only permission when needed. You can decline and use other available system sharing or file destinations.

School-start and yearly-keepsake reminders are off by default. Enabling a reminder requests notification permission and asks iOS to schedule a generic annual local notification for September 1 or December 31. Its date and text do not use or include a child’s nickname, birthday, photos, stages, or account information. Preferences stay on device. Deleting an archive does not turn off these generic reminders; manage them in the app or system notification settings.

6. Purchases, diagnostics, and support

Apple App Store and StoreKit process Lifetime Pro purchases and restores. The app reads product information, transaction verification results, and entitlement state needed to confirm access. It does not receive payment-card numbers or complete payment details. The app may also query Apple for products and current entitlements at startup, before you choose to buy. Apple handles transaction records under its own rules.

A diagnostic summary includes the app version and build, iOS version, device model category, and a limited set of sync states. It excludes archive photos, child nicknames, Apple Account identifiers, file paths, and arbitrary raw error messages. You may copy it to the clipboard. Contacting support may also prefill it into an email, which you review and send in your mail client; the app does not automatically send it to the operator.

If you send support email, support staff receive the sender address, description, attachments, and diagnostics you choose to include, to answer your request and investigate issues. Remove unnecessary child photos or identifying material before sending. Support email is transmitted and stored through email services such as Gmail and is also subject to applicable service policies, including the Google Privacy Policy. Support retention is described in the operator and contact details on this page.

7. Export, sharing, and third parties

Apart from the iCloud and purchase services described above, keepsake images, PDFs, full ZIP archives, or support material are handed to a Photos library, file location, other app, printer, mail client, or recipient only when you choose that action. A completed system share action does not prove delivery, publication, or that a backup can be restored.

New keepsake drafts hide nicknames and years by default. Restoring a draft or sharing an existing keepsake preserves its previous content and choices; it does not anonymize it again. Photos, backgrounds, uniforms, stage names, titles, and captions may still contain personal information.

A full ZIP contains more information than a visible poster.It may include nicknames, birthdays, stage memory notes, unused photos, alignment parameters, consent records, and existing drafts and keepsakes. Store it in a trusted location rather than treating it as a promotional image. The app does not add password encryption to ZIP archives.

If an official public link is configured and you enable the relevant sharing option, shared text or a free keepsake QR code can include that product URL. It does not contain archive identifiers, nicknames, or photos. Pro unbranded keepsakes do not include a QR code.

The current app has no advertising, cross-app tracking, third-party behavioral analytics, or profiling SDKs. It does not sell growth archives or use them for advertising, model training, or public recommendations. New purposes or recipients will require updated disclosure and renewed consent where applicable.

8. Retention and security

Local archives, photos, drafts, and keepsakes generally remain until you delete the content, remove app data, or the system removes it. CloudKit data is handled through your deletion actions and Apple’s service mechanisms. Uninstalling the app or disabling sync does not delete iCloud copies. ZIP files, Photos items, external files, printed copies, and recipients’ copies are managed at their respective destinations.

Export and recovery create temporary image, PDF, ZIP, or intermediate files. The app attempts cleanup at the end of relevant flows, on cancellation, or during later exports, including checking for export files older than 24 hours during a subsequent export. This does not guarantee removal within 24 hours. Interruptions and storage errors can leave temporary files behind.

The app uses on-device processing, system sandboxing, account data-space separation, and deletion confirmation to protect information. No storage or transmission method is perfectly secure. Incidents affecting users or children will be addressed with the steps and notices required by applicable rules.

The retention period for support email and attachments is stated in the operator details. Apple-managed transactions and service records follow Apple’s arrangements.

9. Access, correction, export, and deletion

You can review and edit nicknames, dates, stages, and photos; delete keepsakes; export a full ZIP; manage notifications; or use the app’s withdraw-consent-and-delete action for an archive. Full archive backup and recovery do not require Pro. Premium keepsake exports follow the entitlements shown in the app.

To delete cloud archives, use in-app deletion on a device that can still sync, allow sync to complete, and check other devices. Offline completion, a local deletion, or a submitted sync request does not prove that every cloud copy has been removed. Disabling sync does not delete previously uploaded content.

Deleting a keepsake record does not delete its original stage photos. After archive deletion, the app attempts to clear related local keepsakes and drafts and retains cleanup state for retry if needed. Local database deletion, file cleanup, and cloud deletion propagation are separate steps. Other accounts and data spaces, independently restored archives, exported ZIPs, and shared copies require separate management.

You may also use the official contact channel on this page for access, correction, deletion, explanations, or complaints. Only information necessary to verify and handle a request should be requested. Do not send a full child archive, identity documents, or other unnecessary material without a specific need.

10. Children’s information

The app is for parents and adults authorized by a guardian. Creating an archive requires confirmation of guardianship or authorization and an affirmative privacy choice. Children are not required to register accounts or make purchase decisions.

Child photos and associated information deserve particular protection. For a child under 14, read the separate Children’s Personal Information Rules for consent records, information types, sync, sharing, and guardian controls.

11. Updates and contact

The top of this page identifies the version, revision date, effective status, and operator contact details. Material changes to information types, purposes, recipients, or sync behavior will be explained through updated policies and appropriate product notices, with renewed consent where required.

Use the official contact channel listed here for privacy, children’s information, or deletion requests. A page marked “Draft” has not yet been approved to take effect and is not an effective service policy.

Operator and contact details

Operator
Jingren Chen
Privacy and children’s information lead
Jingren Chen
Privacy contact email
mlaohu.app@gmail.com
Support information processor
Gmail (Google)
Support information retention period
Email and attachments are used to reply to and handle your request, and are transmitted and stored by email services such as Gmail. You may use the address above to request deletion of records we control. Email providers determine their own retention under their settings and policies; we do not promise an unverified fixed retention period.