Platform Scope
This set of legal documents uses common text across platforms. Platform-specific features and system capabilities apply only where actually provided on the relevant platform and permitted by applicable rules. The current iOS version does not provide invitation-code display, invitation-code sharing, invitation rewards, or custom gift-code redemption. Provisions about using those features do not apply to the current iOS version. Retaining those provisions does not mean that another platform has launched or that those features will be offered in the future.
These feature limitations do not exclude processing of account identifiers, entitlement sources, or necessary records that actually exist in the shared account system. Data processing, account merge, deletion, and necessary retention remain governed by the relevant rules in this set of documents and the records that actually exist. The absence of a user interface does not remove our personal-information protection obligations.
Journey Poster is the App's English display name. The same App is displayed as Photo Atlas in Simplified Chinese. Both names refer to the same operator, Bundle ID, account system, services, and these Instructions and are collectively referred to as the “App.”
1. How to Request Account Deletion
- Sign in to Journey Poster.
- Open “My Account.”
- Open “Settings” > “Account & Security.”
- Tap “Delete Account.”
- Review the effects on the account, membership, local data, and private iCloud data.
- Select “I understand that account deletion is irreversible.”
- Tap “Confirm Account Deletion.”
The App uses the current authenticated session to confirm the requester. We do not delete an account based solely on a one-line email, and we will not ask for an SMS verification code, Apple Account password, Google password, full payment-card number, or card security code.
If you cannot sign in, email zack@chongmuec.com. To protect the account and other people, we will ask for identity verification proportionate to the risk of the request.
2. What Happens Immediately
Scope note: invitation and gift-code references below concern only applicable features or records that actually exist, subject to Platform Scope above. They do not offer an invitation reward or redemption service in the current iOS version.
After you confirm deletion:
- the Journey Poster server account is disabled;
- phone, Apple, email, Google, or other login identities associated with that account are disabled;
- active sessions, refresh tokens, and registered devices are revoked;
- the invitation code stops working;
- membership and export entitlements in the deleted account stop being available and do not automatically move to a newly created account;
- Journeys, route caches, drafts, App photo copies, and the local generated-work index on the current device are deleted; and
- the App sends Apple a request to delete the private CloudKit namespace assigned to that Journey Poster account and retains a retry task until Apple confirms success.
“Irreversible” means the old Journey Poster account, its login relationships, and its account entitlements cannot be restored by registering again. It does not mean every transaction, security, consent, refund, backup, or legal record is physically erased at the same instant. It also does not limit a privacy right you continue to have under applicable law.
Registering again creates a new account and does not automatically restore the prior account's login methods, Journeys, membership, export credits, gift codes, or invitation relationship.
3. Private iCloud and CloudKit Cleanup
The deletion request targets only the custom Record Zone assigned to the current Journey Poster account within the App's CloudKit container and in the CloudKit Private Database of the iCloud Apple ID currently signed in on the device.
The Zone may contain synced Journeys, selected photos and thumbnails, photo times and locations, route data, template drafts, synced works, deletion tombstones, sync state, and integrity information. The request does not delete:
- the entire iCloud account;
- a custom Record Zone assigned to another Journey Poster account;
- an original photo in the system Photos library; or
- a Journey Poster work already saved to the system Photos library.
CloudKit cleanup requires the device to remain signed in to the original iCloud Apple ID, network availability, and Apple service availability. If Apple has not confirmed the deletion, the App stores a persistent retry task and retries on relevant events, such as App launch, account-state change, return to foreground, or network recovery.
The App reports cloud cleanup as complete only after Apple confirms success. “Server account disabled” does not by itself mean that the former private iCloud copy has been confirmed as removed.
If you switch to a different iCloud Apple ID, Journey Poster cannot access the former Apple ID's Private Database, and our server cannot delete across Apple accounts on your behalf.
4. Items Not Deleted or Canceled
Account deletion does not delete or cancel:
- originals in the iPhone system Photos library;
- Journey Poster works already saved to the system Photos library;
- copies you sent through the iOS share sheet to another app or person;
- an auto-renewing subscription in your Apple Account; or
- an Apple billing or refund record, including a refund request already pending with Apple.
If you have a monthly membership and do not want another renewal, cancel it before deletion in iPhone Settings > Apple Account > Subscriptions > Journey Poster. Deleting the Journey Poster account, uninstalling the App, or signing out does not cancel or refund an Apple subscription.
5. Necessary Records We Retain
We retain only information reasonably necessary for transaction validation, refund handling, accounting or tax requirements, account security, fraud prevention, legal consent evidence, disputes, and other legal obligations. Depending on the record, this can include:
- a disabled internal account identifier and deletion timestamp;
- Apple transaction, product, refund, revocation, and entitlement-adjustment facts;
- export-credit grants, use, and final-work settlement facts;
- accepted document ID, version, locale, time, App version, Build, public URL, and source digest;
- necessary verification, security-incident, API, and product-event records; and
- support correspondence needed to handle a request or dispute.
A phone number in the deleted account record is retained for no more than 30 days solely to limit abusive repeated deletion and registration, then removed from the main account record or deidentified. Ordinary SMS and email verification audit records are generally retained for no more than six months from the request. Direct login identifiers are deleted or deidentified when no longer needed.
Transaction, entitlement, refund, consent, confirmed-security-incident, and dispute records follow the purpose, retention, and access limits in Section 7 of the Privacy Policy. Apple independently retains Apple Account, payment, billing, subscription, and refund records under Apple's policies and applicable law. The App Store rules alone do not authorize us to retain Journey Poster data indefinitely.
Retention does not mean the deleted account remains available. Retained records are restricted from ordinary account use and are deleted or anonymized when the applicable purpose and legal period end.
6. Timing and Help
The server account is normally disabled immediately after the App confirms the deletion request. Local and private iCloud cleanup time depends on the device, file count, network, current iCloud status, and Apple services. The App displays the actual state and does not claim complete cloud deletion before confirmation.
For a failed deletion, a CloudKit cleanup that remains pending, an Apple subscription that continues billing, or a privacy-right request:
- Email:
zack@chongmuec.com - Support:
https://chongmuec.com/en/support/ - Operator: Shanghai Chongmu E - Commerce Co., Ltd.
- Address: Floor 1-2, No. 148, Lane 999, Xiner Road, Baoshan District, Shanghai 200000, China
We normally answer a general support inquiry within 15 business days after receiving enough information. A verified U.S. privacy request is handled within the period required by applicable law, generally 45 days unless a shorter period applies.