1. Data stored on your device
Rakop stores your shelf profile and avatar selection, shelf photographs and records, arrangement preferences, AI results, local coin balance, purchase recovery records, consent choices, and app settings on your device.
If you record a shelf voice note, the audio file is stored only in the app's local storage. Rakop does not upload voice-note audio to its servers or AI providers.
2. Online session and device information
When Rakop connects to its services, it sends the app version, a randomly generated persistent device identifier, and an available push notification token to Rakop's backend. The identifier is stored in local preferences and the iOS Keychain so the app can recognize the same installation after a restart.
We use this information to establish and restore an online session, deliver remote configuration and content, authorize real-time purchase messages, prevent duplicate purchase credit, process account deletion, maintain service security, and diagnose failures. The identifier is not Apple's advertising identifier and Rakop does not use it for cross-app advertising tracking.
3. Shelf photos and AI analysis
Camera and photo-library access occur only after you choose to capture or import a shelf photo. Photos remain local unless you actively request AI shelf analysis or an arrangement plan.
After you accept the AI Usage Agreement and start an AI feature, Rakop sends the selected shelf photo, selected arrangement style, and technical instructions to Rakop's backend. The backend may pass that content to an AI service provider to produce color, spacing, style, and arrangement guidance. Declining or withdrawing AI consent prevents new AI requests without disabling non-AI shelf tools.
4. Purchases and real-time delivery
Apple processes in-app purchases. For purchase verification and recovery, Rakop may send the Apple transaction identifier, signed transaction payload, H5 order number, product identifier, and device identifier to its backend. Pending verification records are retained locally so an unfinished purchase can be checked again after the next successful login.
Rakop uses Ably for authenticated real-time messages related to purchase initiation and status. Ably may process a temporary access token, channel or room identifier, connection metadata, and the purchase-event payload required to deliver that message.
5. Remote pages, images, and caching
Rakop loads remote configuration, text, product information, legal pages, promotional web content, and image URLs from its backend and hosting providers. The promotional page receives the persistent device identifier in its URL so the page and app can coordinate the requested purchase. Web and hosting services may receive standard connection information such as IP address, request time, device/browser user agent, and diagnostic logs.
Remote images are downloaded and cached on the device using Kingfisher to improve loading performance. Clearing the app or its cache removes locally cached copies according to iOS behavior.
6. Permissions
- Camera: used only to photograph a bookshelf arrangement you choose to record.
- Photo Library: used only to select a shelf image you choose to import.
- Microphone: requested only when you tap Record for a private shelf voice note; the recording remains on your device.
- Notifications: the available push token supports service messages when notification delivery is configured.
You can change system permissions in iOS Settings. Refusing microphone access does not affect photo records or other shelf features.
7. Service providers and recipients
Depending on the feature you use, data may be processed by Rakop's backend and hosting providers, Apple for StoreKit purchases and push notification delivery, Ably for real-time messaging, Cloudflare for legal-page hosting and content delivery, remote image hosting/CDN providers, and the AI provider used by Rakop's backend. Each provider receives only the information needed for its role.
8. Retention, sign out, and deletion
Local shelf records, photos, voice notes, and settings remain until you delete them, delete account data from Rakop, or remove the app, subject to iOS Keychain behavior. Signing out ends the active session but preserves local shelf data for your next sign-in.
Delete Account sends a deletion request to Rakop's backend and, after confirmation, clears the local profile, shelf records and photographs, voice notes, book-locator entries, projects, wallet state, AI consent and caches, and cached remote configuration. The installation device identifier, available push token, pending purchase-verification records, and processed-transaction ledger may remain locally for session security, purchase recovery, and duplicate-credit prevention. Keychain-backed values may also remain after app removal according to iOS behavior. Backend security, transaction, and deletion records may be retained where reasonably necessary for fraud prevention, accounting, dispute handling, or legal compliance.
9. Children and sensitive content
Rakop is not directed to children under 13. Do not submit a child's personal information or images for AI analysis without appropriate authority. Rakop does not sell personal information and does not use personal information for cross-app tracking.
10. Your choices and questions
You may decline optional permissions, withdraw AI consent in the app, delete individual voice notes, sign out, or use Delete Account. Privacy questions and deletion concerns may be submitted through the support contact listed on Rakop's App Store product page.