Privacy notice
What we collect, what we deliberately don't, and how to get your data out. Effective 21 September 2026 (revision 3). This notice takes precedence over the short summary in the terms.
1. Who is responsible
Function Desk LLC, a Florida limited liability company, runs Wallpaper maker at freewallpapermaker.com. Questions and requests go to support@functiondesk.com.
Function Desk LLC11100 SW 93rd Crt Rd, Ste 10-228
Ocala, FL 34481-5188
United States
2. What we collect, and why
- Account. When you sign in with Google or GitHub we receive the email address, display name and avatar the provider shares, plus a provider account id so we can recognise you next time. We do not receive your password. Email sign-in, where offered, uses a single-use link sent to the address you give.
- Your designs. The wallpapers you save, the prompts and notes you write, imported source text you choose to attach, and the history of AI drafts produced for you. These are stored as text and JSON so they can be edited later.
- Payments. Subscriptions and credit packs are handled by Stripe. Stripe collects your card and billing details and calculates applicable tax at checkout; we see a customer id, the plan, amounts and status, never the card number.
- Server logs. IP address, browser identifier, request path and timestamps, kept briefly for security, abuse prevention and keeping the service running.
- Reports. If you report a shared wallpaper we keep the report, the reason and any contact details you give us so we can act on it and reply.
3. What stays in your browser
Photos you add as a background never leave your device. The app stores them in your browser's own storage and only ever uploads the design instructions around them. Manual edits and offline drafts stay in your browser until you request AI help, cloud saving or sharing. Those actions send the relevant design text to our servers, even if you have not saved the draft. Clearing site data removes local copies; we cannot recover work that was only stored in your browser.
4. AI processing
When you ask for AI help, the relevant prompt, notes, reference text and
the wallpaper's own text are sent to the configured model provider —
OpenAI, or Amazon Bedrock where configured — to produce a draft. Inputs
and outputs are also sent for automated safety screening. Generated
results and their prompts may be kept in your account history, as described
above. We do not use your content to train models. OpenAI does not train
on API content by default. We send store: false with response
requests; this is not a zero-retention guarantee. OpenAI may retain abuse
monitoring logs for up to 30 days, or longer for legal or safety reasons,
and encrypted prompt-cache data for up to 24 hours. See OpenAI's data controls. Amazon Bedrock does not use customer content to train the models it
hosts. Provider retention rules also apply after you delete work from
this app. Your background photos are never included in these requests.
We use your country, supplied by our hosting provider, to check AI availability. We record your adult-eligibility and terms confirmation, and send a hashed account identifier to OpenAI for abuse prevention. It does not contain your email address. Queued AI work keeps its country check; sharing checks are kept privately with the submission and removed when the account is deleted.
5. Screening shared wallpapers
A wallpaper stays private until you choose to share it. Before a share link works, the exact version you submitted — its text and metadata — is screened automatically by the same kind of provider, and may then be looked at by a person on our side, who sees it drawn in their own browser from that text. We keep no image of it. Uncertain or flagged results stay private until reviewed. Private prompts and raw source notes are excluded from the public submission and its sharing review; they may still be screened when you request AI help, as described above. Any text you put on the wallpaper itself is part of the shared content.
6. Cookies and similar storage
- One essential cookie keeps you signed in. It carries no tracking id and expires after 30 days of inactivity.
- On private preview deployments, a second cookie remembers that you were let in.
- One local setting remembers your analytics choice (below). It never leaves your browser.
- Only if you say yes to analytics, Google Analytics sets its own cookies
(
_gaand_ga_…, up to two years) to tell returning visits apart. We do not run advertising.
6a. Analytics, only if you agree
We use Google Analytics 4 to count visits and see which pages and examples people use, so we know what to improve. It is strictly opt-in: nothing from Google is loaded, and no analytics cookie is set, until you choose “Yes, count me” in the banner. Choosing “No thanks” keeps it off, and a browser that sends the Global Privacy Control or Do-Not-Track signal is treated as a no without asking. You can change your mind at any time with the “Analytics choices” link in the footer.
When it runs, Google receives the pages you view on this site, rough timing, your browser and device type, an approximate location derived from an IP address that Google truncates, and a random visitor identifier stored in the cookie. We have turned off Google’s advertising features, cross-site “signals” and ad personalisation, we send nothing that identifies you (no email, name or account id), and we do not use analytics on the account pages that show your data. Google processes this data for us under its Google Business Data Responsibility terms and its privacy policy; you can also block it with the Google Analytics opt-out browser add-on. User-level and event-level analytics data is kept for up to 14 months. Aggregated reports can remain longer.
We keep aggregate operational counts (signups, sign-ins, authenticated API requests and AI calls) and email a daily summary to the operator. These counts are scheduled for automatic deletion after 90 days. The summary excludes customer emails, prompts and wallpaper content. Refund and dispute records are restricted to administrators and retained with necessary billing records.
7. Who else sees data
Only the services needed to run the product: our hosting provider (Amazon Web Services, in the United States), Stripe for payments, the model providers named above, Google or GitHub when you sign in with them, and Google Analytics if — and only if — you have agreed to it. We do not sell personal data and we do not share it with advertisers. We will disclose information if the law requires it, or to act on a credible report of harm or infringement.
8. How long we keep things
Your designs and history stay while your account exists. After we verify and begin an account-deletion request, sign-in and shared links are disabled, subscriptions are canceled and saved content is queued for removal. Active requests finish before cleanup; removal normally completes within a day. We aim to resolve failed cleanup within 30 days. Restricted backups may retain earlier copies for up to 35 days and are not used to restore deleted accounts. Necessary financial and security revocation records remain. Server logs are retained for up to 30 days. Browser-local drafts and photos must be cleared on your device; copies already downloaded by others cannot be recalled.
9. Your choices and rights
You can export or delete your data, correct your account details, or ask what we hold about you at any time by writing to support@functiondesk.com. We answer within 30 days. Where the law where you live gives you further rights — access, portability, correction, erasure, restriction, or the right to complain to a supervisory authority — this notice does not limit them. We do not discriminate against anyone for exercising them.
10. Children
Accounts and AI features are for people aged 18 or older. We do not knowingly collect account information from anyone under 18. If you believe an underage person has created an account, contact us so we can restrict access and remove their information as appropriate.
11. Security
Connections are encrypted, sessions are signed, secrets are kept out of source control, and access to production data is limited to the people who need it to run the service. No system is perfectly secure; if we learn of a breach affecting you, we will tell you.
12. Changes
When this notice changes we update the effective date above and record it in the changelog. Continued use after a change means you accept it; if you don't, close your account and we will delete your data as described.
Function Desk LLC · freewallpapermaker.com · privacy notice effective 21 September 2026 (revision 3)