Privacy Policy
Last updated: July 2026
Wombow respects your privacy. This policy explains what we collect, why, and what control you have over it. It covers both Wombow for iPhone and Wombow for Windows; where the two differ, each is called out separately.
What we collect
Automatically, while you use Wombow
- Device identifier — an anonymous UUID generated the first time you launch the app, stored only in your iOS Keychain. It is NOT linked to your Apple ID unless you explicitly sign in with Apple.
- Camera frames — while a session is active, a JPEG image is captured every 2 seconds and sent to our servers. Frames are processed by the upstream vision model and dropped; we do NOT store the images themselves.
- Photos you attach in chat — if you choose to attach photos (from your library or camera) to a chat message, they are sent with that message to the cloud model you picked, processed for that one reply, and dropped. We do NOT store them. Attaching is always your explicit action; on-device models never receive photos.
- Voice transcripts — when you speak, iOS transcribes on-device using SFSpeechRecognizer. The transcribed text (not the raw audio) is sent with the next frame so the AI can respond.
- Chat messages — text you type or speak in Chat mode is sent to the AI provider you select so it can generate a reply. If you choose an on-device model, the conversation itself runs entirely on your phone; when you are signed in, the text of the conversation is also saved to your account (see “Your account”) so you can continue it on another device.
- Usage metadata — game preset, daily minute counter, subscription tier. Used for rate limiting and aggregated analytics.
- Ambient sound classification (opt-in only) — when you enable "Suggest a mode" in Settings, while the Home screen is visible Wombow runs Apple's on-device sound classifier on the microphone input to detect whether a TV, sports broadcast, or movie is nearby. The classification runs ENTIRELY on your device with Apple's bundled model — no audio bytes, waveforms, or spectrograms leave the phone, and the suggestion is not logged anywhere. Default is OFF.
If you sign in with Apple
- The opaque Apple user ID. We use it only to let your subscription survive device reinstalls.
- Your email address only if you choose to share it.
If you purchase a subscription
- Apple tells us your subscription product ID, transaction ID, and expiration date. Payment itself is handled by Apple — we never see your card number.
Wombow for Windows
The Windows companion works the same way in spirit, but it reads your screen instead of a camera, so the specifics differ:
- Screen frames — while a watch session is running, Wombow captures your screen roughly every 2 seconds. On the cloud tier each frame is sent over an encrypted connection, processed by the vision model, and dropped — we do NOT store frames. On the local tier the frame never leaves your PC at all: it is analysed by a model running on your own graphics card.
- Standby (chat-only) mode — frames are held in memory only (the most recent few seconds) and are never analysed, never written to disk, and never uploaded. They are sent only if and when you type a message yourself, so the AI can see what you were just looking at.
- Game-published match data — on a few games (League of Legends, CS2, Dota 2) Wombow reads the read-only match state the game itself publishes on your PC — score, clock, who is alive. On the local tier it never leaves your PC; on the cloud tier it is included, as text, in the request that produces a line of commentary, and is not stored. For CS2 and Dota 2, Wombow writes one small integration file into that game's own config folder to switch the feed on; you can delete it any time.
- Highlight screenshots — when a moment is flagged as a highlight, that single frame is saved to
Pictures\Wombow Highlightson your PC only. It is never uploaded. You can switch this off in Settings. - Device identifier — an anonymous UUID generated on first launch and stored in
%AppData%\Wombow. - Spoken commentary text — to give Wombow a natural voice, the text of a line (never the frame) is sent to the voice service you pick in Settings: our server-side neural voice (Alibaba Qwen3-TTS), Microsoft's free Edge voices, or a voice built into Windows. Choosing a Windows voice keeps the text on your machine.
- Usage metadata — game preset, usage counters, subscription tier, for rate limiting and aggregate analytics.
Your account (both apps)
- Email and password — if you register with an email address, your credentials are held by Supabase, a specialist authentication provider, and never stored on Wombow's own servers. We keep only an internal user ID and your email address.
- Sign in with Google — we receive your Google account's email address and an opaque user ID, used solely to identify your account across devices.
- Whichever way you sign in, one email address is one account: signing in through a different method with the same verified email links to the same account rather than creating a second one.
- Saved conversations — when you are signed in, the text of your chat conversations is saved to your account so you can find them and continue them from any device, like any modern assistant. This archive is text only: camera frames, screen frames, screenshots, and attached photos are never part of it. Each conversation is kept until you delete it in the app or delete your account. Signed out, conversations stay on the device they happened on and nothing is uploaded.
- What Wombow remembers about you (profile memory) — a small, capped set of preference facts (what to call you, the games you main, how you like to chat) distilled over time from your conversations, including things you say out loud during watch sessions. It exists so Wombow feels like the same companion on every device. It is on by default; in Settings you can see every fact, delete any single one, clear them all, or switch the feature off entirely. By design it never stores sensitive details — health, politics, religion, sexuality, or precise location are rejected before anything is saved.
If you subscribe on PC
- Payment is handled by Stripe in your browser. We never see or store your card details — Stripe tells us only your plan and its renewal date.
If you report a reply
- When you use Report on one of Wombow's messages, we receive that one line of text, any note you add, and a little context to reproduce it: which app and version, the game preset, and which model produced it. We keep reports for up to 90 days so we can investigate and fix the behaviour.
- A report never includes your screen, your camera, your highlight screenshots, or the rest of the conversation.
Third parties
We do not sell your data, and we do not share it with advertisers or data brokers. The companies below are service providers: each one receives only what a specific feature needs, and only while you use that feature.
- Third-party AI providers (via OpenRouter) — to generate Wombow's replies, your camera frames, voice transcripts, chat messages, and attached photos are sent through OpenRouter's API to a third-party AI model: Google Gemini for live screen commentary, and — in Chat mode — the model you pick (Google Gemini, OpenAI GPT, or Anthropic Claude). These providers process the data to return a reply and do not retain it to train their models. On-device chat models run locally and send nothing to any provider. Before any of this happens, the app asks for your explicit consent.
- Upstash Redis — stores your daily usage counter, subscription entitlement, and recent conversation history (last 16 turns, 7-day TTL).
- Sentry — crash and error reports. Reports contain only the error and a stack trace: they do NOT include camera frames, screen captures, photos, voice transcripts, or chat text; screenshots and view hierarchies are disabled.
- Resend — delivers our account email (verification, password reset) and forwards a content report to our review inbox when you send one. A forwarded report carries the reported line, your note, and the same context described above; it does not carry your account or device identifier.
- Supabase — holds email/password credentials for accounts registered with an email address, so those credentials never sit on our own servers. Its database also stores your saved conversations and profile memory when you are signed in (see “Your account”).
- Stripe — subscription payments made outside the App Store (PC). Card details go to Stripe directly; we never see them.
- Alibaba Cloud (Qwen3-TTS) and Microsoft (Edge voices) — turn a line of Wombow's text into speech when you pick one of the cloud voices. Only the sentence being spoken is sent; never a frame or an image. Picking a voice built into Windows keeps this on your machine.
- Google — for Sign in with Google, if you choose it.
- Apple — for Sign in with Apple, subscription billing, and App Store services.
What stays on this device
Some features store data locally on your iPhone only — it is never uploaded, and deleting the app deletes it:
- Chat history — your saved chat conversations (the drawer in Chat) live in the app's local database on this device. Signed in, the text also syncs to your account (see “Your account”); signed out, it stays here only.
- Notebook — session keepsakes, highlights, and recaps are stored locally; you can export or delete them from the app.
- On-device model chats — with a downloaded on-device model, the AI itself runs on your phone: no frames or photos ever leave it. Signed in, the text transcript syncs to your account like any other chat; signed out, it stays local.
On Wombow for Windows, the equivalent local-only data lives in %AppData%\Wombow and Pictures\Wombow Highlights:
- Watch and chat history — transcripts of your sessions, kept on your PC. Watch-session transcripts stay local; the text of typed chats additionally syncs to your account while you are signed in.
- What Wombow remembers about you — a small set of preferences it picks up over time (the games you main, what to call you). Viewable and erasable any time under Settings → “What Wombow remembers”. Signed in, this becomes your account-level profile memory, shared across your devices and controllable the same way.
- Highlight screenshots — yours alone, never uploaded.
- Local model sessions — with a local model selected, commentary and chat run entirely on your own machine and nothing about your screen leaves it. Signed in, the text of local chats syncs to your account; your screen never does.
- Uninstalling asks whether to delete all of this or keep it.
Your rights
- Ask what we have by emailing privacy@wombow.com.
- Ask for deletion by emailing privacy@wombow.com. We erase your Redis entries and the device ID regenerates on next launch.
- Delete any saved conversation right in the app; it is removed from your account, not just this device. Profile memory is deletable fact by fact or wholesale, and can be switched off in Settings. Deleting your account erases your saved conversations and profile memory with it.
- Opt out of crash reports in Settings.
- On PC: erase what Wombow remembers about you from Settings, turn highlight saving off, or delete every local trace by uninstalling and choosing to remove your data.
- Report an AI reply you find inappropriate — use “Report” on the message itself, and it comes straight to us.
Children
Wombow is not directed at children under 13. Do not use if you are under 13.