Wrap Brush: Custom Car Wraps Privacy Policy

Last updated: September 14, 2026

Wrap Brush: Custom Car Wraps (also known as WrapBrush for Tesla) is an independent vehicle wrap design tool. This policy explains how the app handles information when you create wrap designs, use template downloads, make purchases, or send feedback.

No Account Required

The app does not require you to create an account or sign in to a developer-operated account. The app does not include advertising SDKs, analytics SDKs, or tracking SDKs.

Photos, Designs, and Exports

Photos you import, stickers you place, generated wrap images, and exported PNG files are processed locally on your device. Editing and exporting do not upload these files to a developer-operated server. If you choose to attach an image to an in-app feedback submission, that attachment is uploaded as described below.

Template and 3D Model Downloads

The Template tab may contact a developer-operated template service to download the latest template catalog and template PNG files. The app also downloads 3D vehicle model files when needed for a preview and caches downloaded resources on your device. These requests deliver app functionality and do not upload your photos, designs, or exported wrap files. Feedback uses a separate submission endpoint as described below.

Like most web services, the hosting and network providers used for the download service may process technical request information, such as IP address and request timing, to deliver files, prevent abuse, and maintain service security. We do not use this information for advertising or user tracking.

In-App Purchases and Subscriptions

Paid features are sold through Apple's App Store payment system. The app offers monthly and yearly auto-renewable subscriptions and a one-time lifetime unlock purchase. Purchase, subscription, cancellation, refund, and payment-card handling are managed by Apple. The app uses StoreKit to load product information, start purchases, restore purchases, verify entitlement status, and open Apple's subscription-management interface.

We do not receive or store your full payment-card details in the app.

In-App Feedback

Feedback is uploaded only when you choose to submit it. The feedback service runs on a developer-operated Hostinger VPS and is delivered through Cloudflare. Submissions may include the message you type, an optional contact email you choose to provide, screenshots or reference images you attach, selected vehicle and template-request details, app version, iOS version, device model, locale, and the app's current StoreKit entitlement category. When an active subscription or lifetime unlock is available, the app may also include Apple-signed transaction and renewal information so the service can verify paid access, including a configured billing grace period, and apply the correct request limit. We use an optional contact email only to reply to that feedback or send its resolution status. The feedback flow does not use the iOS Mail composer.

To prevent feedback abuse, the app also sends an anonymous, app-local installation identifier with a submission. The service converts that identifier and the request source IP address into non-reversible, server-keyed SHA-256 values used only for rate limiting. Raw installation identifiers and IP addresses are not stored in feedback records, and expired daily rate-limit rows are removed after two days. These values are not used for advertising, cross-app tracking, or analytics.

Apple-signed transaction and renewal information is verified while the feedback request is processed and is not stored in its original form or included in logs or email. Alongside the app-reported access category, the service stores the verified access category, product identifier, optional expiration date, and a non-reversible, server-keyed hash of the original transaction identifier for request-rate limiting. Free and unknown access categories do not include an App Store transaction identifier.

Feedback replies and resolution notifications are delivered through Resend, our transactional email provider. For these messages, the provider processes the recipient email address, the reply or resolution text, and delivery information. We retain message identifiers and delivery status to avoid duplicate notifications and handle delivery failures. Apple-signed purchase information is not included in these emails. We do not use feedback contact details for marketing.

Feedback messages, optional contact emails, attachment names, and attachment contents are encrypted at rest. Feedback marked completed or unable to complete, together with its attachments, is scheduled for deletion 180 days after that final status. Feedback still being handled is retained until it is resolved or a valid deletion request is completed. Anonymous daily submission counts may be retained for service capacity and reliability records.

Children's Privacy

The app is not designed to knowingly collect personal information from children. If you believe a child has submitted personal information through in-app feedback, contact us so we can delete it.

Changes to This Policy

We may update this policy when the app's features, services, or legal requirements change. The updated version will be posted on this page with a new "Last updated" date.

Contact

For privacy questions or deletion requests, email feedback@shawnsoft.com, or submit an in-app feedback request and mark it as a privacy question in the message.