Privacy Policy
Field Book turns your travel photos into illustrated pages. This policy explains exactly what leaves your device and why. The short version: your library lives on your device; we keep as little as possible, as briefly as possible.
What we process, and how
- Photos you press. When you press a page, a downscaled copy of the photo you chose is sent over an encrypted connection to our server, which passes it to OpenAI's image model (GPT Image 2.5 Sunburst) to draw the artwork. You are asked for permission before the first press. These ordinary generation inputs and outputs are deleted from our storage within 24 hours.
- An anonymous device identifier. A random ID created on your device tracks your page balance and purchases. It is not your name, email, or Apple ID; we have no accounts and cannot identify you from it.
- Purchase records. When you buy pages or subscribe, Apple processes the payment. We receive a signed receipt (no payment details) to credit your pages.
- Printed-book orders. If you choose to order a physical book, the app uploads the source photos for that locked book so the selected photo layout can be assembled and, when you include illustrations, print-resolution artwork can be prepared. A photo-only print order does not create another AI illustration. Stripe collects and processes your card, name, contact details, shipping address, and tax information. We receive an authorization result and shipping address, but not your complete card number. Lulu receives the book files, shipping address, and contact information needed to print and ship one copy. Lulu also returns delivery status and, when the selected service provides it, a carrier name, tracking number, and secure carrier link so we can show shipping progress in the app and private order-status page. Print ordering is optional and independent of page purchases and Pro.
- Notifications. When print ordering is available to your device, or you have an existing print order to recover, the app registers with Apple Push Notification service and we store the APNs device token. We use it only for print-order reminders and shipment alerts; alerts are shown only if you allow notifications. Notification text does not contain your name, address, book title, captions, photos, or tracking number. Apple-rejected tokens are deleted.
- Published books. If you tap Publish, the pages of that book are stored on our server and visible to anyone with the link, until you unpublish — unpublishing deletes them immediately. Publishing is always your explicit choice; original photos are only included if you turn that on.
- InkLink displays. Only when you choose to send pages or a book, the selected images and book metadata are transferred directly over local Bluetooth to your chosen InkLink display. Prepared copies are kept privately in this app on your phone and excluded from device backups. This export does not upload your pages to Field Book servers or add another server recipient. The display stores the synced book unencrypted on its removable microSD card; someone with access to the display or card can read it. Forgetting a display does not erase its images. “Remove book from display” deletes the managed InkLink book and unfinished transfer, but leaves older standalone cached images and unrelated files. This is ordinary deletion, not a secure wipe.
Usage analytics
We record anonymous product events — things like "a page was pressed in the ink-wash style" or "a book was published" — tied to the same random device ID as your page balance, and processed by Mixpanel on our behalf. These events never include your photos, artwork, captions, or location, and we do not store IP-derived location with them. You can turn analytics off any time in Settings inside the app.
What we do not do
- No Field Book account, no contact-list access, no advertising, no cross-app tracking, and no sale of data.
- We use service providers only for the functions described here: OpenAI for artwork, Apple for in-app payments and notifications, Stripe for physical-order payment and tax, Lulu for printing and delivery, Cloudflare for application storage and processing, and Mixpanel for optional anonymous usage analytics.
Retention & deletion
Ordinary generation inputs and outputs are deleted within 24 hours. Print source uploads expire within 24 hours and are deleted after print-resolution preparation. For print orders, book files, the encrypted shipping address, carrier names, tracking numbers, and tracking links are retained for no more than 90 days after shipment; canceled or expired order material is deleted after 7 days and rejected or refunded order material after 30 days. After the shipment period, carrier and tracking details are removed while a coarse shipped status and date may remain with order records. Order, payment-status, tax, cost, fraud-prevention, and accounting records may be retained longer when reasonably required for support, disputes, tax, security, and legal obligations. Published books remain until you unpublish or delete the book. Deleting the app removes your local library; to remove a published book first unpublish it in the app. Email us to request deletion of other eligible data.