Hatch
How it worksStickersAI sticker guideSupportDownload
← Back to Hatch

The short version: your pack, not our photo album

Privacy Policy

Last updated: August 11, 2026

Hatch turns a photo into a pixel-art sticker pack. We upload only after you confirm a chosen photo or explicitly tap Surprise Me, use it to provide the generation service, and delete Hatch's source and delivery bytes under the retention rules below. Your installed sticker library lives on your device.

1. Who we are

Hatch is provided by FOF Labs LLC ("Hatch," "we," "us," or "our"). This policy applies to the Hatch iPhone app, Messages extension, website, generation service, account features, and support communications.

2. Information we process

Depending on how you use Hatch, we may process:

  • Source photos.The photo you select and confirm from Photos or from the one contact you choose in Apple's contact picker, or the safe recent photo selected on device after you tap Surprise Me. Before upload, the app resizes the image and removes metadata. Chosen photos are shown before confirmation; Surprise Me starts immediately from your explicit tap without another preview. If a friend sends you a private sticker-board link, the browser shows your selected photo before you explicitly submit it for the same generation service. The board service validates and normalizes that upload, including removing embedded photo metadata, before generation.
  • Sticker content and pack details. Generated sticker images, a pack name you provide, generation status, and the identifiers needed to deliver the completed pack to the correct installation. Private sticker boards also process the board title and any contributor name or context the contributor chooses to provide.
  • Optional account information. If you sign in, we may process your email address, display name, username, Apple-provided account identifier, account status, policy-acceptance versions, and account creation time.
  • Authentication and security information. Session and installation tokens, token hashes, Sign in with Apple verification data, an encrypted Apple refresh token retained only to disconnect Sign in with Apple if you delete your account, email-verification challenges, App Attest keys and assertions, rate-limit records, request timestamps, and network information needed to prevent abuse and unauthorized paid generation.
  • Egg purchases and wallet records. When you use Eggs, Hatch may process a server-generated wallet identity and Support ID, an App Store account token assigned to that wallet, hashed Apple app and purchase transaction identifiers, the product tier and quantity, purchase and refund status and timestamps, gift status, and the grant, reservation, and ledger records needed to maintain your balance. Apple processes your payment details; Hatch does not receive your card or bank-account information.
  • Product analytics. To understand audience size, retention, and whether core sticker features work, Hatch may process an app-generated random installation identifier, app-open dates, completed share categories, aggregate daily Messages-extension opens and sticker-use interactions grouped by a stable reaction or authored-base category, fixed Make Video actions and styles, fixed Egg Store actions, destination and tier choices, app version, build number, and release channel. The service also records aggregate product outcomes such as packs generated or installed, shared packs saved, boards created or contributed to, accounts created, verified purchases grouped by fixed Egg tier, and one-time offer claims. Analytics does not include photo, sticker, video, or message content; recipients; contacts; pack or board titles; prices; raw product, wallet, purchase, or gift identifiers; error details; conversation identifiers; or advertising identifiers. Client observations do not carry optional account identifiers. Server outcome facts use only a namespaced one-way deduplication key instead of the raw source account, pack, board, claim, job, submission, or purchase identifier.
  • Operational information. App version, build number, request and job identifiers, provider request identifiers, job timing, file sizes, retry counts, terminal status, failure codes, delivery acknowledgements, and other diagnostics needed to run and secure the service. We do not place photo bytes or credentials in application logs.
  • Support messages. If you contact us, we receive your message and any screenshots or diagnostics you choose to send. The in-app feedback form also sends the Hatch app version, build number, message time, and a random submission identifier used only to prevent duplicate email delivery. It does not include your optional account or email address. If you contact us by email, we also receive your email address. If you explicitly share Egg Store diagnostics, the message may also contain a bounded checkout stage and error category, the fixed tier and destination, catalog state, and your non-secret wallet Support ID. It does not include a raw transaction, debug journal, photo, prompt, optional-account identity, or email address.

3. What stays on your device

  • Your installed sticker library. Completed packs, favorites, hidden stickers, pack order, and recent-use information are stored locally in the App Group shared by Hatch and its Messages extension.
  • Your photo library. Hatch does not upload your library. Random candidate scanning and rejection happen on device. Only the source you preview and confirm, or the result selected after you explicitly tap Surprise Me, is sent.
  • Your contacts.Hatch does not request ongoing address-book access or upload your contact list. If you use the new-user contact shortcut, Apple shows the picker and Hatch receives only your final selection. We use the selected name temporarily on device and never save or upload the contact's phone number, email address, or identifier. Only a selected profile photo that you subsequently preview and confirm enters the source-photo flow described above.
  • Local preferences. Onboarding state, display settings, and the recent-photo cooldown used to avoid repetitive random choices stay on device.

Signing in does not currently upload, merge, back up, or restore the local sticker library. Deleting the app can remove locally installed packs that have not been saved elsewhere.

4. How we use information

We use information described in this policy to:

  • Create and deliver the sticker pack you requested or contributed.
  • Operate private sticker boards and deliver each result to the contributor and the installation that created the board.
  • Restore an interrupted generation or download.
  • Create and secure optional accounts and sign-in sessions.
  • Process Egg purchases, maintain and restore wallet balances, deliver gifts, settle refunds, prevent purchase fraud, and resolve support requests.
  • Enforce generation limits, control provider spend, and prevent abuse.
  • Measure aggregate app activity, exact-day retention, and use of core pack, sharing, board, account, and Messages features.
  • Diagnose failures and improve the reliability of Hatch.
  • Respond to support, rights, safety, and account requests.
  • Comply with law and enforce our Terms of Service.

5. Photo generation and service providers

After you confirm a chosen source, tap Surprise Me, or explicitly submit a previewed photo through a private sticker board, Hatch sends the resulting source through our generation service to OpenAI's image API to create your sticker artwork. OpenAI processes that content as our service provider. OpenAI states that API data is not used to train its models by default. Under OpenAI's standard API controls, customer content may be retained in abuse-monitoring logs for up to 30 days. OpenAI documents those controls in its API data-usage policy.

We may also use providers for infrastructure hosting, security, email delivery, website hosting, and customer support. These providers may process information only as needed to provide their services to us and under their applicable agreements.

Apple processes photo-library and one-time contact-picker access, App Attest, Sign in with Apple, Messages, App Store downloads, and in-app purchases under Apple's own terms and privacy practices.

6. Retention and deletion

  • Source and raw generation bytes. Hatch deletes these when a job succeeds, fails, is blocked, or expires. We do not keep your source photo as a permanent server gallery.
  • Delivery files. Hatch deletes server delivery bytes after the app verifies the complete pack and acknowledges delivery. Unacknowledged files expire after a bounded fallback period, currently 24 hours.
  • Private boards and shared results. Board capabilities, submission receipts, and shared result files expire after a bounded period, currently no more than seven days. Revoking a board prevents new submissions. The server stores capability hashes rather than the private link tokens.
  • Product analytics. Client analytics events and product outcome facts are retained for no more than 30 days. The anonymous installation record keeps only its random identifier plus first- and last-activity timestamps while that installation remains active; it is deleted after 30 days without activity once no retained event references it. The random identifier is stored in the device Keychain and is not joined to an optional Hatch account; because Keychain data can survive reinstall, we describe this metric as first-seen installations rather than downloads or new people. Product outcome facts contain no source account, pack, board, message, or installation identifier.
  • Egg purchases and wallets. We retain wallet, purchase, grant, ledger, gift, refund, and App Store notification records as reasonably needed to maintain a durable balance, restore purchases, settle refunds and disputes, prevent fraud, provide support, and meet legal obligations. Hatch stores hashed Apple app and transaction identifiers rather than raw identifiers. These records belong to the Egg wallet, not an optional Hatch account, so deleting that account does not delete or transfer them.
  • Job and security records. We may retain limited job, request, quota, spend, safety, and abuse-prevention metadata for as long as reasonably needed to operate and protect the service or comply with law.
  • Account information. We retain account information while the account is active. In-app account deletion removes the account record, profile, Apple identity link and encrypted revocation token, email challenges tied to the account, and all Hatch account sessions. We may retain deidentified aggregate product facts and limited records required for security, disputes, fraud prevention, or legal obligations when permitted by law.
  • Feedback. A feedback message that cannot send stays in backup-excluded storage on your iPhone for no more than 30 days and retries when Hatch becomes active. Successful in-app messages are delivered by email to the Hatch team and are not stored in the Hatch application database. We retain support correspondence only as long as reasonably needed to respond, improve Hatch, protect the service, or meet legal obligations.

You can permanently delete an optional Hatch account from the account actions screen in the app. Hatch revokes its Sign in with Apple authorization when Apple provided the token needed to do so. An older account without that token is still deleted, and the app explains how to finish disconnecting Hatch in Apple Account Settings. Account deletion does not erase packs, boards, publication capabilities, or Eggs stored for the installation because they are separate from the optional account. Delete local packs in Hatch or remove the app if you also want to clear local data. For other personal-information requests, email support@hatchstickers.com from the email on the account when possible.

7. No sale or advertising tracking

We do not sell or rent personal information. We do not use source photos or sticker packs for third-party advertising. Hatch does not include ad networks or cross-app tracking SDKs.

This website does not add analytics cookies or advertising cookies. Hosting and security providers may process standard technical logs needed to serve and protect the site.

8. Children's privacy

Hatch is not directed to children under 13, and children under 13 may not use the Service. If we learn that an under-13 child provided personal information through Hatch, we will delete it or disable the associated account. Contact support@hatchstickers.com if you believe this occurred.

9. Your choices and rights

You choose and confirm a photo, explicitly ask Surprise Me to select and submit one immediately, or preview and submit one through a private sticker board. Before confirming a chosen or contributed photo, you may stop. Board creators may revoke an active board. You may delete packs from the local library, sign out of an optional account, or permanently delete that account in the app. Depending on where you live, you may have rights to access, correct, delete, or export personal information we hold. Send requests to support@hatchstickers.com.

10. Security

We use safeguards designed for the information Hatch handles, including encrypted transport, Keychain storage on iPhone, hashed server tokens, authenticated encryption for Apple revocation tokens, bounded upload and image limits, App Attest request verification, scoped delivery authorization, rate limiting, and deletion maintenance. No transmission or storage method is perfectly secure.

11. Changes to this policy

If this policy changes, we will update the date above. We will provide additional notice when required, including before a material change that alters how source photos or account information are used.

12. Contact

Questions about privacy at Hatch may be sent to support@hatchstickers.com. Your use of Hatch is also governed by our Terms of Service.

Hatch
AI sticker guidePrivacyTermsSupport

© 2026 FOF Labs LLC.