Journey Poster
CompanyProductPrivacyTermsPaid ServicesSupport中文

Legal

Journey Poster Privacy Policy

Learn how Journey Poster handles selected photos, location, accounts, purchases, and service data, including U.S. privacy choices.

Version: 2.0.4
ContentsPlatform ScopeImportant Summary1. Who We Are and Scope2. Information We Process and Why3. Sources, Purposes, and Disclosure Categories4. Device Permissions and System Capabilities5. Service Providers and Platform Services6. U.S. State Privacy Disclosures and Rights7. Retention8. Security9. International Processing10. Your Choices and Account Deletion11. Children and Teens12. Changes to This Policy13. Contact and Complaints

Platform Scope

This set of legal documents uses common text across platforms. Platform-specific features and system capabilities apply only where actually provided on the relevant platform and permitted by applicable rules. The current iOS version does not provide invitation-code display, invitation-code sharing, invitation rewards, or custom gift-code redemption. Provisions about using those features do not apply to the current iOS version. Retaining those provisions does not mean that another platform has launched or that those features will be offered in the future.

These feature limitations do not exclude processing of account identifiers, entitlement sources, or necessary records that actually exist in the shared account system. Data processing, account merge, deletion, and necessary retention remain governed by the relevant rules in this set of documents and the records that actually exist. The absence of a user interface does not remove our personal-information protection obligations.

Important Summary

Journey Poster is the App's English display name. The same App is displayed as Photo Atlas in Simplified Chinese. Both names refer to the same operator, Bundle ID, account system, services, and this Policy and are collectively referred to as the “App.”

Journey Poster helps you organize photos you select into Journeys, map routes, and shareable works. The following points are especially important:

  1. Journey Poster does not scan your entire photo library. It processes only photos you select through the iOS photo picker and does not request camera, microphone, or continuous device-location access.
  2. Selected photos, embedded photo coordinates, place details, route geometry, drafts, and generated files are stored on your device and, if iCloud sync is enabled, in your own CloudKit private database. These items are not stored in our Alibaba Cloud business database.
  3. Apple MapKit processes coordinates necessary to display maps, resolve places, and calculate routes. Photo originals are not included in map requests.
  4. Our servers store account and security data, a limited Journey summary, membership and export-credit records, Apple transaction-verification data, consent records, and minimal operational events. The Journey summary may include the city associated with the first photo to analyze geographic feature coverage and improve the product. It excludes photos, photo asset identifiers, precise coordinates, automatically resolved detailed addresses, and route geometry.
  5. You may delete your Journey Poster account in the App. The App disables the server account, removes related local App data, and sends Apple a request to delete the custom CloudKit Record Zone assigned to that Journey Poster account. Completion depends on the device, network, current iCloud account, and Apple services. The App retains a retry task until Apple confirms success and does not claim completion before confirmation. Originals and works saved in the system Photos library are not deleted.
  6. We do not sell personal information, share it for cross-context behavioral advertising, or use photos or location data for third-party advertising.

If you do not agree with this Policy, do not register, sign in, or use a feature that requires the relevant information.

1. Who We Are and Scope

The entity responsible for the Journey Poster service is:

  • Legal name: Shanghai Chongmu E - Commerce Co., Ltd.
  • Chinese legal name: 上海冲沐电子商务有限责任公司
  • Unified Social Credit Code: 91310113MA7F7N8C39
  • Address: Floor 1-2, No. 148, Lane 999, Xiner Road, Baoshan District, Shanghai 200000, China
  • Privacy email: zack@chongmuec.com
  • Privacy Policy: https://chongmuec.com/en/privacy/

This Policy covers the Journey Poster iOS App, account services, support website, and processing directly related to those services. Apple, Google, Alibaba Cloud, and other providers may independently process information under their own terms and privacy policies. Their policies do not replace the obligations we have under applicable law.

For U.S. users, the terms “personal information” and “personal data” include information protected by applicable U.S. federal or state privacy law. References to a particular state right apply only if and to the extent the relevant law covers us, the user, and the processing. We may choose to honor a request more broadly even when a specific statute does not require it.

2. Information We Process and Why

2.1 Account registration, sign-in, linking, and account merge

Depending on the login methods actually offered in your version and region, we may process:

  • a mainland China mobile number, SMS verification request, and verification result;
  • an email address, an irreversible digest of the email verification code, and the verification result;
  • a stable account identifier, verified email, and limited authorization information provided by Apple or Google;
  • App installation identifier, device platform, session information, token digest, request IP address, request time, failure reason, and security signals; and
  • identity verification, selected primary account, source-account identifiers, and merge result when you link, unlink, or merge login methods.

We use this information to create and protect an account, maintain sessions, prevent verification-code abuse, link login methods, detect account conflicts, and carry out an irreversible account merge only after confirmation.

After a complete account merge, historical transactions, entitlements, and audit facts retain their original source-account references and are connected to the retained account. We do not rewrite original payment facts merely to simplify the interface.

Google Sign-In processing applies only when the App displays a Google Sign-In option and you choose it. A version that does not display that option does not send a Google OAuth request for sign-in.

2.2 Legal consent records

When you agree to the Terms of Service, this Privacy Policy, a separate photo-location notice, or the Paid Services Agreement, we record:

  • the permanent document ID, version, and locale presented to you;
  • the public URL and SHA-256 digest of the source document;
  • the action, time, App version, Build, and device record; and
  • the Journey Poster account associated with the action.

We use these records to identify the exact text presented, manage updates, and resolve disputes. The SHA-256 digest allows us to verify that a retained source file matches the text associated with the consent record. The digest does not contain the legal text, photos, or location information.

The production consent system must record the locale of the document actually shown before an English release is represented as fully integrated. Until that deployment is complete, the English documents remain publication candidates.

2.3 Photos you select and embedded metadata

When you use the system photo picker, the App processes the selected photo content, local asset identifier, capture time, dimensions, orientation, and any coordinates embedded in that photo. We use this information to order photos, create Journey nodes, display places, plan routes, apply templates, and export works.

Precise photo coordinates and a route inferred from several photo locations may be considered sensitive personal information under some laws. Before first using photo location to generate a map, the App provides a prominent separate explanation and obtains separate, affirmative consent. If you decline, the related map-generation flow is not enabled.

If a selected photo exists only in iCloud Photos, iOS may first download it to your device. Apple and your iOS settings control that process.

2.4 Journeys, local files, and private iCloud sync

The App stores Journey names, photo copies or references, capture times, coordinates, place labels, route geometry, map caches, template drafts, crops, and generated works locally.

When iCloud is available and sync is enabled, the App may write the following to the CloudKit Private Database associated with the iCloud Apple ID currently signed in on the device:

  • Journey metadata and complete snapshot versions;
  • selected photos and thumbnails;
  • photo times, coordinates, and place labels;
  • route segments, coordinate systems, and map-display data;
  • template drafts and synced works; and
  • deletion tombstones, sync state, file size, and integrity information.

iCloud sync is available to free users and members and is not conditioned on membership. The data is in the current user's private CloudKit database and is governed by Apple iCloud and CloudKit rules. After switching the iCloud Apple ID, the App cannot automatically access the former account's private database. Reinstallation or device migration can restore only Journeys whose complete snapshots were confirmed as synced.

Our servers keep a limited Journey summary for account lists, product limits, and reconciliation, such as a Journey ID, name, time range, photo count, distance, duration, transportation type, and installation ID.

The App also extracts the city from Apple's place-resolution result for the first photo in capture-time order and sends that city with the Journey summary to our Alibaba Cloud business server. We use it to analyze geographic feature coverage, identify underserved areas, and improve the product. If the city is unavailable, we leave it empty and do not substitute a street, house number, point of interest, district, county, full address, or coordinates. The city is linked to the account and Journey ID and is not anonymous. It does not represent your current device location.

This automatic upload excludes photo content, local photo asset identifiers, coordinates, automatically resolved detailed addresses, and route geometry. A Journey name you enter is still saved as part of the summary; do not include personal information you do not want uploaded in that name.

2.5 Apple Maps

Apple MapKit and Apple Maps process information needed for map display, reverse geocoding, place labels, and walking or driving routes. That information may include coordinates, origins, destinations, intermediate points, route type, map viewport, IP address, and basic device or network information.

Map requests do not include photo originals. Apple may use service providers depending on region, operating-system version, and its service arrangements. See Apple Maps & Privacy. Map results can be incomplete or inaccurate and must not be used for real-time navigation, emergency response, or safety-critical decisions.

2.6 Saving, sharing, and generated works

If you save a work, the App requests add-only Photos access and writes the generated file to the system Photos library. If you share a work, the App opens the iOS share sheet. You choose the recipient and destination, and we do not receive that selection in advance.

Generated materials and final works are stored in the App sandbox or system Photos library by default. You manage originals and saved works in iOS.

2.7 Membership, export credits, and Apple in-app purchases

Platform and data-processing clarification: the shared account system may still generate, store, and return an invitation-code identifier for an iOS account through account or membership APIs. This does not mean that the current iOS version provides invitation or redemption features. Invitation relationships, gift-code records, and entitlement-source records that actually exist may still be processed as necessary for account association, entitlement reconciliation, abuse prevention, support, or disputes, and retained or deleted under the purposes, periods, and access restrictions in this Policy. Removing a user interface does not mean these records do not exist, and this clarification does not introduce a new collection purpose or extend retention.

To provide paid services, we process membership status and expiration, entitlement source, the export-credit ledger, work-settlement identifiers, invitation or gift-code records, and Apple-provided product ID, transaction ID, original transaction ID, App Account Token, purchase and expiration times, renewal state, environment, price, currency, and refund or revocation result.

Apple processes payment. We do not receive your Apple Account password, complete card number, or card security code. We verify signed Apple transactions and use App Store Server Notifications to prevent duplicate grants and to process renewals, refunds, and revocations.

2.8 Operations, security, product events, and support

We record limited events needed to secure and operate the service, such as account ID, Journey public ID and name snapshot, page or button event, template code, product code, success or failure, error class, timing, cache status, App version, and timestamp.

Operational events must not contain photo binaries, photo filenames, Photos asset identifiers, coordinates, detailed addresses, route geometry, verification codes, or login secrets.

When you contact support, we process what you submit, such as your email address, description, redacted screenshot, App and iOS versions, and necessary order details. Please remove unrelated photos, location, phone numbers, verification codes, and payment details before sending a screenshot.

3. Sources, Purposes, and Disclosure Categories

We collect information from you, your device and selected photos, Apple or Google when you choose their login or platform services, Apple transaction systems, and our security or operational systems.

CategoryMain examplesBusiness or service purposeRecipient categories
Identifiersaccount ID, phone or email, Apple or Google identifier, IP, installation IDaccount access, authentication, security, supportcloud infrastructure, verification providers, Apple or Google when selected
Customer and transaction recordsproduct, transaction, price, currency, membership, credit ledger, refundprovide and reconcile paid service, prevent fraud, accounting and disputesApple, cloud infrastructure, professional advisers when necessary
Internet or electronic activitysession, page or button event, error, timing, App versionsecurity, reliability, debugging, product operationcloud infrastructure
Coarse location derived from a selected photocity associated with the first photo, linked to the account and Journeyanalyze geographic feature coverage and improve the productcloud infrastructure in mainland China
Precise geolocation from selected photosembedded photo coordinates and derived routecreate the map and Journey requested by youApple Maps; your private CloudKit if sync is enabled
Audio, visual, or similar contentphotos you select and generated workscreate, store, sync, save, or share the requested workyour device; your private CloudKit; a recipient you choose through iOS
Inferences and Journey attributestransportation type, distance, duration, route displayprovide Journey organization and limitsyour device; limited summary in our cloud services
Sensitive account or security informationlogin credentials in hashed or tokenized form, verification and security eventsauthenticate, protect accounts, investigate incidentscloud infrastructure and verification providers

“Recipient categories” identifies service providers or independent platform providers necessary for the requested feature. It does not mean that every item in a row is sent to every recipient.

4. Device Permissions and System Capabilities

Permission or capabilityPurposeEffect if not allowed
Selected Photosread photos you choose, capture time, and embedded coordinatescannot create a Journey from photos
Add to Photossave a generated workcannot save directly to the system Photos library; viewing a Journey remains available
iCloud / CloudKitprivate sync and restoration of complete Journeys and workslocal use remains available, but private iCloud sync and restore do not
Networkaccount, Apple Maps, membership, transaction verification, and legal pagescorresponding online features do not work; available local content remains viewable where possible

This version does not request camera, microphone, or continuous device-location access. You can change permissions in iOS Settings. Withdrawal does not affect processing lawfully completed before withdrawal but can prevent the feature from continuing.

5. Service Providers and Platform Services

ServiceInformation involvedPurpose and provider policy
Apple iOS, Photos, iCloud/CloudKit, MapKit, Sign in with Apple, and StoreKitselected-photo access, private iCloud data, required map coordinates, Apple login identifier, and signed transactionsoperating-system functions, private sync, maps, Apple login, and in-app purchase; see Apple Privacy
Alibaba Cloud Function Compute, RDS MySQL, SMS, verification, and related infrastructureaccount, phone or email verification, session, security logs, limited Journey summary including the first-photo city, membership, credits, transactions, and minimal eventsaccount services, security, business ledger, service reliability, and city-level feature-coverage analysis; see Alibaba Cloud Privacy Policy
Google Sign-In, only when an option is displayed and selectedstable Google account identifier, verified email, authorization and validation informationlogin and account linking; see Google Privacy Policy

We require service providers acting on our behalf to use information only for the contracted service and to apply appropriate safeguards. Platform providers such as Apple and Google may also act independently under their own rules.

We do not use third-party advertising SDKs in the described release. We do not sell personal information or share it for cross-context behavioral advertising or targeted advertising. We do not use or disclose sensitive personal information to infer characteristics about you or for advertising. If those practices materially change, we will update this Policy and provide any notice, consent, or opt-out required by law.

6. U.S. State Privacy Disclosures and Rights

Depending on your state and whether the applicable law covers the processing, you may have the right to:

  • confirm whether we process your personal data and access it;
  • obtain a portable copy of certain personal data;
  • correct inaccurate personal data;
  • delete personal data, subject to lawful exceptions;
  • opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling;
  • limit certain uses or disclosures of sensitive personal information;
  • appeal a refusal to act on a request; and
  • receive equal service and not be discriminated against for exercising a privacy right.

Journey Poster does not currently sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or make decisions producing legal or similarly significant effects through profiling. We therefore do not display a “Do Not Sell or Share” link for the practices described in this release. If a legally recognized preference signal becomes relevant to our practices, we will process it as required by applicable law.

To submit a request, use the in-App controls described below or email zack@chongmuec.com with “U.S. Privacy Request” in the subject line. State the request type, your state of residence, and the Journey Poster account involved. Do not send a password, verification code, full payment-card information, or unrelated photo original.

We will verify a request using information reasonably related to the account and the risk of the request. An authorized agent may submit a request where permitted by law, but we may require proof of authority and direct identity confirmation. For an applicable verified U.S. state-law request, we generally respond within 45 days or the shorter period required by law. If a lawful extension is necessary, we will explain it. You may appeal a refusal by replying to our decision with “Privacy Appeal.”

These rights are subject to exceptions, including information needed to complete a transaction, secure the service, prevent fraud, comply with law, establish or defend legal claims, or protect another person. We do not charge for a reasonable request unless applicable law permits a fee for requests that are manifestly unfounded, excessive, or repetitive.

7. Retention

We retain information for the shortest period reasonably necessary for the described purpose, subject to legal, security, transaction, and dispute requirements:

  • Local Journeys and files: until you delete them, delete the account and complete local cleanup, or uninstall the App. You control content saved in the system Photos library.
  • Private CloudKit copies: until you delete a Journey, delete the relevant iCloud private data, or the App sends and Apple confirms the account-Zone deletion request. If the request is not confirmed, the App retains a retry task; actual completion depends on the device, network, current iCloud account, and Apple services.
  • Active account and login identities: while the account remains active. On deletion, identities and sessions are disabled immediately and direct login identifiers no longer needed are deleted or deidentified.
  • Phone number on a deleted account: up to 30 days solely to limit abusive repeated deletion and registration, then removed from the main account record or deidentified.
  • SMS and email verification: a code or digest is valid only for the short period shown in the interface. Ordinary audit records, including destination phone or email, IP, device, result, and provider request ID, are generally retained no longer than six months from the request. Records directly related to a specific security event, complaint, or dispute may be isolated and retained until resolution or expiration of the applicable limitation period, then deleted or anonymized.
  • Refresh token: only a digest is stored, for no longer than 30 days, and it is revoked on logout, rotation, merge, or account deletion.
  • Consent, transaction, entitlement, refund, tax, and financial records: for the period necessary to perform the agreement, verify Apple transactions, meet accounting or tax requirements, protect consumers, and resolve disputes. Only necessary fields are retained.
  • Confirmed security incidents, complaints, and disputes: until the matter and applicable appeal, regulatory, or legal-claim period end, with restricted access and use.
  • Product and API events: only as long as reasonably needed for product operation, security, cost control, and debugging, with restricted access.

At the end of the applicable period, we delete or anonymize the information, or restrict processing to storage and necessary security where deletion must be deferred.

8. Security

We use measures such as HTTPS, token digests, access controls, least privilege, network isolation, verification-code rate limits, signed-transaction validation, idempotent entitlement ledgers, and necessary audit records. Photos, coordinates, detailed addresses, and route geometry must not be placed in ordinary server logs or product events.

No internet or storage system can be guaranteed absolutely secure. If personal information is or may have been compromised, we will investigate, mitigate, and provide any notice required by applicable law.

9. International Processing

Shanghai Chongmu E - Commerce Co., Ltd. is established in China. Account, authentication, security, purchase, consent, limited Journey-summary data (including the first-photo city), and operational data described in this Policy is primarily processed using infrastructure located in mainland China. If you use Journey Poster from the United States or another country, that information is transferred to and processed in China, where privacy laws may differ from those in your jurisdiction.

Private CloudKit information, Apple login, Apple Maps, and StoreKit information is processed by Apple according to your Apple account, region, and Apple's service arrangements. Google account validation, only when the App offers Google Sign-In and you select it, may be processed by Google outside your country.

Where law requires a transfer mechanism, notice, consent, contractual safeguard, or other measure, we will implement the applicable requirement. This section does not waive any mandatory local rights.

10. Your Choices and Account Deletion

You can:

  • manage login methods, iCloud sync, and Journeys in the App;
  • adjust Photos and iCloud permissions in iOS Settings;
  • delete a Journey or applicable local or iCloud content through the App;
  • delete your account under “My Account” > “Settings” > “Account & Security” > “Delete Account”; or
  • contact zack@chongmuec.com for access, correction, deletion, portability, consent withdrawal, explanation, complaint, or appeal.

Logging out revokes the current session but does not delete the account, server entitlements, local Journeys, or private iCloud copies.

Account deletion disables the server account, login identities, sessions, and registered devices, and removes Journey data, caches, and App photo copies from the current device. The App sends Apple a request to delete only the custom Record Zone for the current Journey Poster account in the App's CloudKit container and in the CloudKit Private Database of the iCloud Apple ID currently signed in on that device.

The Zone request includes synced Journeys, selected photos and thumbnails, photo times and locations, routes, drafts, synced works, deletion tombstones, sync state, and integrity data in that Zone. It does not delete the entire iCloud account, Zones for other Journey Poster accounts, originals in the system Photos library, or works already saved there.

The App retries an unconfirmed CloudKit deletion request. Completion depends on the device remaining signed in to the original iCloud Apple ID, network availability, and Apple services. The App displays cloud cleanup as complete only after Apple confirms success. Switching to another iCloud Apple ID prevents the App from accessing the former Apple ID's private database, and our server cannot delete across Apple accounts on your behalf.

Deleting the Journey Poster account does not cancel an Apple subscription or request a refund. Uninstalling deletes the App sandbox but does not delete the Journey Poster account, cancel a subscription, delete system Photos content, or automatically remove a synced private CloudKit copy.

11. Children and Teens

Journey Poster is a general-audience service and is not directed to children under 13. We do not knowingly collect personal information online from a child under 13. A child under 13 must not create an account or use account-based features.

If we learn that we collected personal information from a child under 13 without legally sufficient parental authorization, we will disable the account and delete the information as required, subject to limited security or legal retention. A parent or guardian may contact zack@chongmuec.com with “Child Privacy” in the subject line.

Users aged 13 through 17 may use the service only if permitted by the law of their location and with parent or guardian involvement where required. We do not knowingly sell or share personal information of users under 16 for cross-context behavioral advertising.

12. Changes to This Policy

We may update this Policy when features, data practices, providers, laws, or security needs change. If a change materially affects processing purposes, methods, information categories, third parties, international transfers, paid-service obligations, or important user rights, we will provide prominent notice and obtain renewed consent where required.

Formatting, typographical, or non-substantive link corrections generally do not require renewed consent. We retain historical versions, publication dates, public URLs, locales, and SHA-256 digests under our legal-document governance process.

13. Contact and Complaints

For privacy, account, iCloud, or personal-data questions:

  • Email: zack@chongmuec.com
  • Operator: Shanghai Chongmu E - Commerce Co., Ltd.
  • Address: Floor 1-2, No. 148, Lane 999, Xiner Road, Baoshan District, Shanghai 200000, China
  • Support: https://chongmuec.com/en/support/

General support inquiries are normally answered within 15 business days after we receive enough information. Applicable verified U.S. privacy requests are handled within the period required by the relevant law, generally 45 days unless a shorter period applies.

If you are not satisfied with our response, you may request an internal privacy appeal and may contact the attorney general, privacy regulator, consumer-protection authority, or court with jurisdiction in your place of residence. Nothing in this Policy limits a mandatory right or remedy under applicable law.

© 2026 Shanghai Chongmu E - Commerce Co., Ltd.
Privacy PolicyTerms of ServicePaid ServicesAccount DeletionSupport
沪ICP备2026039874号-1