At a glance: Chroma does not run its own account server, sell personal information, or serve ads. The app uses Firebase Analytics and Crashlytics to understand feature usage and diagnose reliability problems. Advertising-ID collection and ad-personalization signals are disabled. The legal website does not set cookies or run analytics.
1. Scope
This Privacy Policy explains how the Chroma Android application and this legal website (together, “Chroma”) handle information. Chroma is an independent client built with the Unsplash API and is not owned, endorsed, or operated by Unsplash.
By using Chroma, you may also interact directly with Unsplash, Google Play, RevenueCat, Android, and Firebase Hosting. Those providers handle information under their own policies.
2. Information processed
Information stored on your device
Chroma stores app preferences, search history, wallpaper settings, wallpaper history, and other feature state locally on your Android device. If you sign in with Unsplash, Chroma also stores your Unsplash access token and a cached copy of basic profile information on the device. The access token is excluded from Android backup and device transfer.
Photos you choose to download are saved to your device. Wallpapers you apply are handled by Android’s wallpaper services.
Unsplash account and content information
You can browse without creating a Chroma account. If you choose Unsplash sign-in, the authentication flow is provided by Unsplash. Chroma receives an access token and profile details that Unsplash makes available, such as your username, name, profile image, links, location, and public profile metadata. Chroma uses the token to perform the actions you request, including viewing account information, liking photos, and managing collections.
Network and interaction information
When Chroma requests content, image files, or account actions, service providers may receive technical data needed to answer the request, such as your IP address, request time, app or device details, and the requested resource. Unsplash may receive image views, searches, likes, and download or wallpaper events as required by its API rules.
App analytics and diagnostics
Firebase Analytics automatically processes app interaction and technical information, such as app launches, session and engagement activity, device and operating-system details, approximate location derived from IP address, and an app-installation identifier. Chroma disables collection of the Android advertising ID and does not allow Analytics data to be used for ad personalization.
Firebase Crashlytics processes crash stack traces, relevant app state, device metadata, and installation identifiers when the app crashes or stops responding. Analytics events may also appear as diagnostic breadcrumbs leading up to a Crashlytics report. Chroma does not intentionally attach your Unsplash access token, payment details, or Firebase user identifiers to analytics or crash reports.
Purchase information
If Chroma+ is available and you view, buy, or restore a plan, RevenueCat and Google Play process information needed to show products and verify access. This may include an app-scoped identifier, device and operating-system information, product and entitlement status, transaction dates, a Google purchase token, and subscription status. Chroma does not receive or store your payment-card details.
3. How information is used
Information is processed only as needed to:
- browse, search, display, download, and attribute Unsplash content;
- complete Unsplash sign-in and perform account actions you request;
- remember preferences, wallpaper schedules, and local history;
- apply wallpapers and run scheduled wallpaper changes under your chosen device constraints;
- show, purchase, restore, and verify Chroma+ access;
- measure app usage, diagnose crashes and reliability problems, and improve Chroma;
- operate, secure, troubleshoot, and comply with legal obligations for Chroma and its hosting.
Chroma does not use your information for targeted advertising and does not sell personal information.
5. Storage and retention
Local app data remains on your device until you clear it, remove it within Chroma where that option exists, or uninstall the app. Downloaded photos may remain after uninstalling and must be deleted through your device’s file or photo tools. Depending on your Android settings, eligible non-authentication app data may be included in Android backup or device transfer.
Unsplash account data remains with Unsplash until you change or delete it there. Purchase records and entitlement information are retained by Google Play and RevenueCat according to their policies and legal obligations. Firebase retains Analytics data according to the retention settings configured for the Analytics property. Crashlytics keeps crash stack traces and associated identifiers for 90 days before beginning deletion from live and backup systems. Firebase Hosting may temporarily retain request and security logs according to Google’s retention practices.
6. Your choices and rights
- You can use core browsing features without signing in to Unsplash.
- You can sign out to remove the stored Unsplash token and cached profile from Chroma.
- You can clear Chroma’s local storage or uninstall the app through Android settings.
- You can disable notifications and scheduled background behavior in Chroma or Android settings.
- You can manage or cancel subscriptions through Google Play.
- You can manage your Unsplash profile and account through Unsplash.
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal information. For information held by Unsplash, Google, or RevenueCat, contact that provider directly. For a Chroma privacy request, use the contact method below. Do not include access tokens, payment details, or other sensitive information in a public issue.
7. Children
Chroma is not directed to children under 13, and the developer does not knowingly collect personal information from children. If you believe a child has provided information through Chroma, contact the developer so the concern can be reviewed. Third-party services may impose a higher minimum age in some countries.
8. Security
Chroma uses encrypted HTTPS connections, keeps its Unsplash token in private app storage, excludes that token from Android backup and transfer, and does not allow cleartext network traffic. No system is completely secure, so absolute security cannot be guaranteed. Keep your device updated and protected, and sign out before giving another person access to it.
9. Changes and contact
This policy may be updated when Chroma’s features, providers, or legal obligations change. The effective date at the top will be revised when an update is published. Material changes may also be communicated in the app or release notes where appropriate.
Questions, privacy requests, or concerns can be sent through Chroma’s developer support. GitHub issues are public, so do not post confidential or sensitive information. If private follow-up is needed, request a private contact channel without including sensitive details.