KiroPhotos · Documents

Privacy Policy

Effective Date: August 9, 2026

Last Updated: September 23, 2026

Before you begin using KiroPhotos (Chinese name: "时光相册"; hereinafter referred to as the "App"), please read and fully understand this Privacy Policy (the "Policy"). The App is operated by Peng Zong (彭棕), an independent developer (hereinafter referred to as "I," "me," or "my"). I value your personal information and privacy and will process relevant information in accordance with the principles of lawfulness, fairness, necessity, good faith, openness, and transparency.

Important Information

  1. Local-first processing. Photo browsing and editing, face and person analysis, photo semantic feature generation, natural-language search, memory management, and workout routes are processed primarily on your device. Your original photos, videos, face or person-appearance features, photo semantic features, search records, health and workout data, and local indexes are not uploaded to servers operated by me. Local processing still constitutes processing; Section 2 describes the scope in detail.
  2. Some features require network access. Examples include downloading photo assets from iCloud Photos, loading maps, place search and reverse geocoding, downloading or using Apple system translation language resources, retrieving App Store product and purchase status information, and viewing online help and legal documents. Online documents are available on a website operated by me; some App versions may still open Feishu documents. See Sections 4 and 5 for details.
  3. Permissions and feature controls. The App requests photo-library access, location while using the App for map positioning and manual footprint recording, "Always" location access for automatic background footprint recording, and read-only Apple HealthKit access for specific features. Footprint recording and health-data access are independent, optional features. Face recognition and photo semantic analysis use photos you have authorized the App to access and do not trigger a separate iOS face-recognition permission. You can limit photo access, revoke a permission, turn off footprint recording, or pause new image-recognition and natural-language indexing tasks in the App's settings. Features that do not depend on the relevant data remain available.
  4. Sensitive personal information. Photo and video content, precise location, biometric-related information such as face and person-appearance features, and health, workout, and route information may constitute sensitive personal information. I process such information only as necessary for the purposes stated in this Policy. I do not use it for advertising, marketing, cross-app tracking, use-based data mining, establishing real-world identity, or identity authentication, and I do not sell it or upload it to a third-party artificial intelligence service. Where separate consent is required by law, I will obtain it separately.
  5. No account registration required. The current version does not provide an account registration or sign-in system operated by me. Membership purchases, subscriptions, purchase restoration, and entitlement verification are handled through the Apple App Store and StoreKit. I do not collect your Apple ID, bank card number, or payment password.
  6. Protection of minors. If you are under 14 years of age, please use the App only after your parent or legal guardian has read and agreed to this Policy.

1. Scope and Operator Information

This Policy applies when you use the App and its related services on an iPhone or iPad.

The operator and personal information processor is:

This Policy does not apply to products or services independently provided by Apple, Feishu when used by some App versions, or any other third party you select through the system share sheet. Each third party's processing of personal information is governed by its own privacy policy.

2. How I Process Your Personal Information

2.1 Photo Library Browsing, Organization, and Editing

With your authorization, the App uses Apple PhotoKit to read and process the following information on your device:

  • Photos and videos, thumbnails, Live Photos, and related resources;
  • System photo asset identifiers, file names, media types, creation and modification dates, dimensions, duration, favorite status, album membership, and other library information;
  • Location information embedded in a photo or video;
  • Technical metadata such as camera and lens model, file format, file size, ISO, focal length, aperture, exposure time, exposure compensation, and video frame rate.

The purposes of this processing include browsing photos and videos; displaying timelines and photo maps; filtering and statistics; creating memories; viewing technical information; marking or unmarking favorites; managing albums; adjusting dates or locations; deleting or duplicating photos; editing photos; applying LUTs and frames; and exporting or sharing creations.

These reading, analysis, and editing activities are performed primarily on your device. The App writes changes to the system photo library through PhotoKit only when you expressly perform an action such as marking a favorite, deleting an asset, managing an album, changing a date or location, saving an edited result, duplicating an asset, or exporting content. Deletions and similar actions are subject to the confirmation process provided by iOS.

If an original asset is stored only in iCloud, the App requests Apple, through PhotoKit, to download that asset from your iCloud Photos library. Apple provides this process, and I do not obtain your iCloud or Apple ID credentials.

You may grant full or limited access to your photo library. With limited access, the App can process only the photos and videos you select. Certain full-library statistics, filters, memories, or batch-management features may be unavailable or may produce incomplete results.

2.2 Photo Indexes, Memories, and Personalization Settings

To improve the responsiveness of browsing, filtering, maps, and memories, the App creates local indexes and caches on your device. These may include:

  • Photo asset identifiers, dates, media types, favorite status, pixel dimensions, file sizes, album membership, and photo location coordinates;
  • Photo technical metadata and reverse-geocoding results such as place names, addresses, countries, provinces or states, cities, and districts;
  • Text recognized locally in photos, text regions, and recognition confidence, used to match text content in photo search;
  • Memory titles, descriptions, tags, date ranges, cover photo identifiers, and photo associations that you create or edit;
  • LUT files you import, LUT names, and sorting information;
  • Preferences such as app language, appearance, default screen, and photo list sorting and filtering;
  • Task status and synchronization progress generated while performing local background indexing.

This information is stored in the App's sandbox on your device and is not synchronized to servers operated by me by default. The photo index database is marked for exclusion from device cloud backups. Whether other local data is included in a device backup depends on the iOS backup mechanism and your system settings.

The App creates local caches such as thumbnails, previews, and temporary export files. You can delete cached files by selecting "Clear Cache" in the App's settings. Clearing the cache does not delete original photos in the system photo library, saved edits, exported creations, or memories and imported LUT data stored in the App's Application Support directory.

2.3 Face Recognition and Person Organization

When image recognition is not paused and photo resources are available, the App may progressively analyze photos you have authorized it to access on your device. This feature may process and store:

  • Photo thumbnails or appropriately sized images used for analysis, photo asset identifiers, and content revision information;
  • Detected face location, size, quality, landmarks, and face feature vectors;
  • Person body or appearance regions, quality and feature vectors, and associations between faces and person appearance;
  • Model-generated face clusters, person profiles, cover-photo identifiers, and photo associations;
  • Person names you add and manual organization records such as merges, splits, hiding, and cover selection;
  • Model versions, processing states, and rescan progress.

Face and person-appearance feature vectors are mathematical representations generated from images rather than original face photographs, but they may still constitute biometric-related sensitive personal information. The App uses this information only to discover photos in your library that may depict the same person, display and organize people, find photos by person, and attempt to associate other photos of a person when the person's face is temporarily not visible.

Detection, feature generation, comparison, and clustering are performed on your device using models included with the App. The models do not obtain or infer a person's real name from a photo; you add person names yourself. Person clusters indicate only similarity among photo features. They are not used to unlock a device, verify an account, establish a natural person's real-world identity, advertise, market, profile users, perform use-based data mining, or train a model operated by me or a third party. They are not uploaded to servers operated by me or a third-party artificial intelligence service.

If a photo is stored only in iCloud, the App may, according to your image-recognition download setting, ask Apple through PhotoKit to download a version suitable for analysis. Apple handles the request and asset transfer. I do not obtain your Apple ID or iCloud credentials.

You can pause image recognition in the App's settings to stop new recognition tasks. Pausing recognition, hiding a person, and rescanning are not deletion: features, clusters, and manual organization records generated before pausing may remain locally stored and continue to support existing results, while rescanning may rebuild automatic recognition results. After a source photo is deleted or access to it is revoked, related derived records are progressively updated through local photo-index synchronization. To delete all person-recognition data in the App's sandbox in the current version, uninstall the App. Uninstalling does not delete original photos in the system photo library.

2.4 Natural-Language and Semantic Search

When natural-language search is not paused and photo resources are available, the App may progressively process photos you have authorized it to access and store the following locally:

  • Photo asset identifiers, content revision information, and photo semantic feature vectors generated by a local model;
  • A local vector index used to accelerate similarity searches, together with index versions and processing states;
  • Natural-language descriptions, places, people, dates, and other search conditions that you enter or select, together with similarity thresholds, search times, and cover-photo identifiers for search results;
  • Semantic category names, natural-language rules, display text, thresholds, and cover caches that you create.

Photo semantic feature generation and similarity matching are performed on your device using models included with the App. Photos, photo semantic features, and search terms are not sent to servers operated by me or a third-party artificial intelligence service and are not used for advertising, marketing, cross-app tracking, user profiling, or model training.

When input is not in Chinese, the App may use system language-identification and translation capabilities provided by Apple to convert the query to Simplified Chinese before local semantic matching. The system may need to download relevant language resources. Apple's processing for the system translation feature and necessary network information is governed by Apple's rules and privacy policy. I cannot access network logs independently processed by Apple to provide the system service.

You can pause natural-language search indexing in the App's settings to stop generating new semantic features for photos. Pausing or rescanning does not automatically delete existing photo semantic features, category rules, or search history. To delete all semantic indexes and search records in the App's sandbox in the current version, uninstall the App. Uninstalling does not delete original photos in the system photo library.

2.5 Photo Map, Current Location, Place Search, and Geocoding

  1. Locations embedded in photos. The App reads latitude and longitude already stored in your photo library to display photos on a map, filter by place, generate location statistics, and create memories.
  2. Current location. After you grant the "While Using the App" location permission, the App can read your current location to center the photo map. Centering the map alone does not enable footprint recording. Manual footprint recording uses the same permission; automatic background recording requires "Always" access, as described below.
  3. Place search. When you enter a place-related search term, the term and nearby coordinates used to limit the search area, if any, are sent to Apple Maps services to return place suggestions.
  4. Reverse geocoding. To convert photo coordinates into readable place names and addresses, the App may use Apple's geocoding services to process latitude and longitude stored in photos. This may occur when a local photo index is created or updated, and the results are cached on your device.
  5. Writing a photo location. The App writes a new location to a photo only after you expressly choose to apply, copy, or remove a location.

Maps, place search, and reverse geocoding require network access. Apple may receive search terms, location coordinates, IP addresses, device information, and network information necessary to provide these services. Apple's handling of this information is governed by its privacy policy. I do not store these requests on servers operated by me.

Footprint Recording and Background Location

The footprint feature uses Apple Core Location to record the device's movements. It is separate from workout routes read from Apple Health and does not require HealthKit authorization. The App offers automatic background recording and manual precise recording. Manual recording requires only "While Using the App" access: after you start recording in the foreground, it may continue in the background or while locked, subject to system limits. With this permission alone, location events cannot relaunch the App after system termination. Automatic background recording requires "Always" access. After you first grant "While Using the App" access through footprints, the App requests an upgrade to "Always"; declining the upgrade does not prevent manual recording. Granting or regranting "Always" access enables automatic background recording. You can turn it off in footprint settings, and reopening the App alone will not turn it back on. With "Always" access and recording still enabled, significant location changes and region-exit events may resume recording where the system permits.

To store and display footprints, the App may process and retain the following locally:

  • Route-point latitude, longitude, timestamps, horizontal accuracy, and available altitude, speed, and speed accuracy;
  • Automatic or manual recording source, recording preferences and state, session identifiers, start and end times, and the latest location time;
  • Route segments, compressed tracks, endpoints, distance, moving duration, and statistics and map-display data derived from tracks.

These data support footprint maps, historical routes and trip retrospectives, distance and speed displays, and matching photos by capture time to restore their locations. Footprints may reveal your home, workplace, itinerary, and activity patterns; authorize access carefully. The App does not upload footprints to servers operated by me or third-party artificial intelligence services, use them for advertising, marketing, or cross-app tracking, or sell them. Loading maps may involve Apple services, as described in Section 5.

Pausing or ending manual precise recording does not automatically turn off automatic background recording. Turning off automatic background recording does not end an active manual recording. To stop all footprint recording, turn off automatic background recording and end manual recording, or set the App's location permission to "Never" in iOS Settings. Changing only from "Always" to "While Using the App" stops automatic background recording but does not stop an active manual recording. Recording preferences and session state are stored locally; recording that remains enabled may resume when you reopen the App or restore permission. Turning off recording, revoking permission, or leaving the screen does not delete existing tracks.

During manual recording, if permitted by the system, a Live Activity may display recording state, start time, distance, speed, and the latest update time on the Lock Screen or Dynamic Island. Its display data does not include complete route coordinates and is not updated through a developer-operated push server. Anyone able to view the screen may see these summaries. Disabling or dismissing a Live Activity does not stop location recording.

2.6 Apple HealthKit, Workout Routes, and Photo Matching

When you choose a health-workout feature and complete Apple HealthKit authorization, the App requests read-only access to only these two health data types:

  • Workout records, including workout identifiers, activity type, start and end time, duration, total distance when available, pause intervals, and elevation metadata;
  • Workout-route coordinates and timestamps associated with those workouts.

The App does not request read access to heart rate, step count, sleep, blood oxygen, body weight, or other independent health data types, and does not request health-data write access. The workout summaries described above come from authorized workout records. Displayed values such as distance and pace may also be calculated from routes on the device; they do not imply access to additional health data types.

The App uses this information locally to create workout routes, route maps, distance, pace and split metrics, and to match photos taken during a workout based on capture time. It writes a matched location to a photo only after you expressly confirm. A local workout-route snapshot may contain the workout identifier and time, route points, summary metrics, splits, associated photo identifiers, map images, a title you edit, and hidden status so that the App can display the route promptly and preserve your organization choices.

Photo-route matching can use either locally recorded footprints or authorized HealthKit workout routes. You can skip HealthKit authorization and use existing footprints alone. Refusing Health access does not affect footprint recording or photo features that do not require health data. Matches are estimates based on photo times and available route points; reading workouts or completing matching does not automatically modify photo locations.

After you confirm applying a matched location, the route-derived coordinate becomes location metadata in the system photo library. That coordinate may synchronize according to your iCloud Photos settings or be disclosed to recipients when you share or export photos with location information. Review matches and location-sharing options before proceeding. These actions do not modify the original workout or route in Apple Health.

The current version does not write or modify data in the Health app; upload health, workout, or route data to servers operated by me or a third-party artificial intelligence service; or use such data for advertising, marketing, user profiling, use-based data mining, insurance or credit decisions, medical diagnosis, or a purpose unrelated to workout routes and photo matching. Health data and workout-route snapshots remain in the App's sandbox on the device. The App does not actively write them to an iCloud container or a cloud synchronization service operated by the Developer.

When the App generates or displays a workout route map, it invokes Apple Maps capabilities. Apple may process the route-coordinate range, IP address, device information, and network information necessary to provide the map service. Apple's privacy policy governs this processing. I do not receive or store these map requests on servers operated by me.

For privacy reasons, Apple does not tell apps whether you have denied read access to a particular type of health data. You can adjust the App's health data permissions at any time in the privacy settings of the Health app.

To update workout retrospectives, the App may query authorized workouts and routes again and respond to changes. Revoking read access prevents further reads but does not automatically delete existing local snapshots, titles, or hidden settings. A missing workout in a query is not proof that it was deleted, so the App does not automatically remove these results solely because they are absent from a query. Sections 7 and 8 describe retention and deletion.

2.7 Network Access and Online Features

The App uses the network when necessary to:

  • Download photo or video assets from iCloud Photos;
  • Load Apple Maps, search for places, and perform reverse geocoding;
  • Allow the system to download Apple Translation language resources needed for natural-language search;
  • Retrieve App Store products, purchases, and subscriptions; restore purchases; and verify membership entitlements;
  • Load online documents such as the Privacy Policy, Terms of Use, Frequently Asked Questions, and Release Notes; some App versions may still use Feishu links;
  • Access a network connectivity test endpoint provided by Apple to determine whether a network connection is available.

I do not independently collect unique device identifiers or advertising identifiers, or create a user profile through this network access. Network service providers may automatically process IP addresses, request times, device or browser types, network types, cookies, and other necessary network logs in accordance with their own privacy policies.

2.8 In-App Purchases and Membership Entitlements

The App offers in-app purchase products including monthly membership, annual membership, and a one-time lifetime membership. Product display, ordering, payment, refunds, subscription management, and purchase restoration are handled by the Apple App Store.

Through StoreKit, the App receives information including product identifiers, product names and prices, purchase results, transaction verification results, subscription status, expiration dates, renewal status, and offer or trial eligibility. This information is used to display products, complete purchases, restore entitlements, and unlock membership features. StoreKit processes this information on the device. I currently do not upload orders or transaction receipts to servers operated by me or maintain an order database linked to your identity.

I do not have access to your Apple ID password, bank card number, payment password, or complete billing information. Apple determines how long purchase records are retained and how they are managed under its own rules. You can manage or cancel an auto-renewable subscription in your Apple ID subscription settings.

2.9 Sharing, Exporting, and External Files

When you actively use a sharing or export feature, the App generates the photo, video, or edited result you selected and passes it to the iOS system share sheet. The content is sent to a recipient only after you select a receiving app, contact, or storage location. The App does not control how a recipient processes the information. Before sharing, please confirm the recipient and review its privacy practices.

When you import a file such as a LUT, the App reads the file you selected and stores it in the App's sandbox solely for the editing feature you choose to use.

2.10 Customer Support and Contact

When you contact me by email, I process your email address, message content, attachments, and any other information you choose to provide in order to verify and respond to your question, handle a rights request, or resolve a dispute. Do not include sensitive information unrelated to your request, such as identification documents, payment passwords, health data, or original photos.

Unless otherwise required by law or genuinely necessary to resolve a dispute, customer support records will be retained for no more than one year after the matter has been resolved and will then be deleted or anonymized.

2.11 Information Not Processed by the Current Version

The current version:

  • Does not provide an account registration or sign-in system operated by me and does not collect phone numbers, account passwords, or user avatars;
  • Does not request camera or microphone permission;
  • Does not integrate advertising, cross-app tracking, behavioral analytics, or third-party crash-reporting SDKs;
  • Does not use advertising identifiers or use personal information for targeted advertising or automated marketing;
  • Does not collect or store your photos, videos, face or person-appearance features, photo semantic features, search records, health, workout, or route data, local photo indexes, workout routes, or editing projects on servers operated by me;
  • Does not provide photos, face or person-appearance features, photo semantic features, search terms, or health data to a third-party artificial intelligence service or use them to train a model operated by me or a third party.

If any of these processing activities are introduced in the future, I will update this Policy before the feature is released and obtain your authorization or consent as required by law.

2.12 Meaning of "Collect" in the App Store Privacy Label

Apple defines "collect" for the App Store privacy label as transmitting data off the device in a way that allows the Developer or a third party to access it for longer than necessary to service a real-time request. Generating and storing face, person-appearance, or photo semantic features, search history, and workout routes only on your device is not "collection" under Apple's privacy-label definition. It is nevertheless local data processing by the App and is fully described in this Policy.

If relevant data will in the future be transmitted off the device and remain accessible to me or a third party, I will update this Policy and the App Store Connect privacy information before release and obtain any permission required by law. Information independently processed by Apple to provide system services such as iCloud, Maps, Translation, HealthKit, and StoreKit is governed by Apple's privacy policy and the rules for the relevant service.

3. System Permissions

Permission Purpose Required? Effect of Refusal or Revocation
Photo Library (Read and Write) Browse, filter, analyze, manage, edit, save, and export photos and videos; read and modify dates, favorites, albums, locations, and related information; generate face, person-appearance, and photo semantic features locally on the device Required for core photo features; person recognition and semantic search can be paused in the App You will be unable to browse or manage photos. With limited access, only selected photos can be processed, and some statistics, people, search, and batch features will be restricted.
Location (While Using the App) Map positioning and manual footprint recording; manual recording started in the foreground may continue in the background or while locked Optional; required for manual recording Current-location positioning and manual recording are unavailable. Existing photo locations and footprints remain available.
Location (Always, Including Background Access) Automatic background footprint recording and system-permitted recovery of enabled recording through location events; granting access enables automatic recording, which can be turned off in footprint settings Optional; required for automatic background recording Automatic recording stops. Manual recording remains available with While Using access, and existing footprints remain available.
Apple HealthKit (Read Only) Read workouts and workout routes for route display, local route metrics, photo matching, and restoring photo locations Optional Unauthorized health workouts and routes cannot be read or updated. Existing local footprints remain available for photo matching; footprint recording and other photo features are unaffected.
Network Access Download iCloud assets; use maps and geocoding; access the App Store and online documents; and perform connectivity checks Required for the relevant online features Cloud-based photos, location services, purchases, and online documents may be unavailable. Assets already available locally can still be processed.

You can manage permissions related to photos, location, and network access in iOS Settings, manage health data permissions in the Health app, and pause image recognition or natural-language search indexing in the App's settings. Disabling a permission or pausing a task does not affect processing already completed or automatically delete existing derived data, but it stops new processing that depends on the relevant data or feature control.

4. Cookies, Logs, Diagnostics, and Analytics

The App itself does not use cookies and does not integrate advertising analytics or user behavior analytics SDKs.

The static document pages on this website do not set cookies or load third-party analytics scripts. If you manually change the document language, the page stores your language preference locally in the browser. When you visit this website, the server may record your IP address, access time, requested page, and browser information to serve pages and maintain service security; these records are not associated with your local photo index, health data, or current location. When some App versions open a Feishu document, Feishu may set cookies or generate access logs under its own privacy policy. Based on your device's Analytics & Improvements settings, Apple may also collect and provide developers with aggregated sales, performance, crash, or diagnostic information.

5. Third-Party Services and Open-Source Components

The App uses the following system or third-party services to provide its current features:

Service or Component Provider Purpose Information That May Be Processed Processing or Policy
PhotoKit and iCloud Photos Apple Inc., its affiliates, or service partners Access the system photo library and, according to user authorization and settings, download iCloud photo assets used for browsing, editing, face and person analysis, or semantic analysis Photos, videos, and metadata; Apple manages the relationship between an Apple ID and cloud assets Apple Privacy Policy
Core Location Apple Inc., its affiliates, or service partners Map centering, foreground and background footprint recording, significant location changes, and region-exit monitoring Coordinates, time, location accuracy, speed, altitude, and information needed for system location services; the App stores tracks locally Apple Privacy Policy
MapKit, Apple Maps, and geocoding Apple Inc., its affiliates, or service partners Photo, footprint, and workout-route maps, place search, and reverse geocoding Search terms, the coordinate range of a photo, footprint, or workout route, IP address, device information, and network information Apple Privacy Policy
ActivityKit and WidgetKit Live Activities Apple Inc., its affiliates, or service partners Display a manual footprint recording summary on the Lock Screen or Dynamic Island Session identifier, start time, recording state, distance, speed, and latest update time; updated on the device without developer-operated remote pushes Apple Privacy Policy
Apple Translation and Natural Language frameworks Apple Inc., its affiliates, or service partners Identify the language of a search term and, when needed, convert a non-Chinese search term to Simplified Chinese; the system may download language resources Search terms submitted for translation, language settings, and network information needed for the system service; the App does not upload this information to servers operated by me Apple Privacy Policy
HealthKit and the Health app Apple Inc., its affiliates, or service partners Obtain read-only access to authorized workouts and workout routes for local route display, photo matching, and restoring photo locations Workouts, workout times, and workout routes; the App processes this information only on the device and does not upload it to servers operated by me Apple Privacy Policy
StoreKit and the App Store Apple Inc., its affiliates, or service partners Product retrieval, purchases, subscription management, entitlement verification, and purchase restoration Apple processes payment and account information; the App receives necessary product and transaction status results Apple Privacy Policy
Apple network connectivity test Apple Inc., its affiliates, or service partners Determine whether a network connection is available IP address, request time, and necessary network logs Apple Privacy Policy
Feishu online documents in some App versions Beijing Feishu Technology Co., Ltd. and its affiliates Display the Privacy Policy, Terms of Use, Frequently Asked Questions, and Release Notes through Feishu links IP address, device or browser information, access logs, cookies, and information you actively provide on the webpage Feishu Privacy Policy

The App also integrates the following open-source components, which run only within the App:

Component Purpose Data Processing Project URL
GRDB.swift 6.24.1 Manage the SQLite photo index and memory database locally on the device The component itself does not provide networking, advertising, or data-reporting functionality; data remains in the App's sandbox GRDB.swift
JXPhotoBrowser 4.1.0 Photo and video browsing interactions It is not bound to the App's business data model, and the current integration does not upload information through this component JXPhotoBrowser
Brightroom 4.0.0-beta.1 Local photo cropping, rotation, filters, and related editing The current integration processes images only on the device and does not upload information through this component Brightroom

I evaluate third-party component versions and their data-processing behavior. Where I select a third party and provide user data to it, I will require the third party to provide the same or an equivalent level of protection under this Policy, Apple's rules, and applicable law. If an independent provider such as Apple or Feishu changes its name, processing scope, or privacy policy, its latest published information will apply. If the App's use of a third-party service changes materially, I will update this Policy and the App Store Connect privacy information and obtain your permission again where required.

6. Sharing, Transfer, and Public Disclosure of Information

6.1 Sharing

Except for the system or third-party services expressly described in this Policy, your active use of the system sharing feature, or as otherwise required by law, I do not share your personal information with other companies, organizations, or individuals. I do not sell your personal information.

6.2 Transfer

I do not transfer your personal information. If the personal information processor changes due to a business transfer, change of operator, or similar event, I will notify you of the recipient's name and contact information and require the recipient to remain bound by this Policy. If the recipient changes the original purposes or methods of processing, it must obtain your consent again as required by law.

6.3 Public Disclosure

I do not publicly disclose your personal information unless I have obtained your separate consent or disclosure is otherwise permitted by law.

6.4 Circumstances Where Prior Consent Is Not Required by Law

To the extent permitted by applicable laws and regulations, I may process relevant information without obtaining your prior consent where the processing is necessary to enter into or perform a contract to which you are a party, to perform statutory duties or legal obligations, to respond to a public health emergency, to protect an individual's life, health, or property in an emergency, or to process, within a reasonable scope, information that you have made public or that has otherwise been lawfully made public.

7. Storage and Security of Information

7.1 Storage Location

Data generated by the App, including photo indexes and recognized text, face and person-appearance features, person clusters and manual organization records, photo semantic features and vector indexes, search history, workout routes, memories, preferences, imported LUTs, and caches, is stored locally on your device. I currently do not operate any server that receives or stores this business data.

The local database directory that contains photo indexes, face and person features, and photo semantic features is marked for exclusion from device cloud backups. The App does not actively write health data or workout routes to an iCloud container or a cloud synchronization service operated by the Developer. Apple's handling of system photos and app data through device backups, iCloud Photos, and other system services depends on your system settings and Apple's rules.

Apple, Feishu, and other service providers determine where they store data in accordance with their own service arrangements and privacy policies. Website access logs on my server are separate from the business data stored on your device. Where personal information is transferred across borders, the relevant service provider is responsible for fulfilling applicable legal obligations. I do not use servers operated by me to actively transfer your local photos, health data, or photo indexes outside your jurisdiction.

7.2 Retention Periods

  1. Original photos, videos, edited results, and location or date changes in the system photo library are managed by you through the Photos app. Their retention depends on your settings and your iCloud settings. Uninstalling the App does not delete this content.
  2. Face and person-appearance features, person clusters, and manual organization records are retained locally while the related photos remain accessible and you use the people feature. After a photo is deleted, revised, or removed from the authorized scope, related automatically derived data is progressively updated through index synchronization. Named people or manual relationships may be retained during a rescan to preserve your organization choices.
  3. Photo semantic features, vector indexes, semantic categories, and search history are retained locally while you use the relevant feature. The App may automatically limit the number of search-history entries. Pausing or rescanning does not automatically delete existing data.
  4. Independently recorded footprint points, segments, sessions, and statistics, together with HealthKit workout identifiers, times, routes, metrics, photo associations, map snapshots, and personalization settings, are retained locally while you use the relevant features. Turning off recording, pausing, hiding, revoking permission, or deleting a source workout in Apple Health does not guarantee automatic deletion of existing App data. The App does not treat absence from a health query as proof of deletion. To delete all footprints and health-workout-derived data from the App's sandbox at once in the current version, uninstall the App. Short-distance or short-duration manual recordings that do not meet minimum saving requirements when ended may not be retained.
  5. Memories, preferences, and imported LUTs in the App's sandbox are retained while you use the App. When you delete a memory or LUT, the corresponding data is deleted. Uninstalling the App generally deletes its sandbox data, although copies retained by the system or a backup service may be handled under that service's rules.
  6. Thumbnails, previews, and temporary files are retained for as long as necessary to provide the relevant feature. You can clear the cache in the App's settings, and the system may also clear cached data when storage space is low.
  7. Apple retains App Store transaction records under its own rules. The App does not separately store order records on servers operated by me.
  8. Customer support records are handled for the period described in Section 2.10 of this Policy.

7.3 Security Measures

I use technical and organizational measures appropriate to the processing activities, including the iOS app sandbox, system permission controls, data minimization, restrictions on third-party components, system-level data protection for local databases and files, and timely remediation of known security issues.

No internet environment is completely secure. If personal information is or may have been leaked, altered, or lost, I will promptly take remedial measures as required by law and notify the relevant authorities and affected users of the incident, its possible impact, and the measures I have taken, as required.

8. Your Rights

To the extent provided by applicable law, you have the right to access, copy, correct, supplement, and delete your personal information; restrict or object to specific processing; withdraw consent; and request an explanation of the rules governing the processing of personal information.

8.1 Managing Data Stored on Your Device

  • You can access, edit, or delete photos, videos, and related information in the system Photos app;
  • You can manage person names, merges, splits, covers, and hidden status; semantic categories and search conditions; and workout routes, memories, imported LUTs, albums, and related preferences in the App;
  • You can pause new image-recognition and natural-language indexing tasks in the App's settings. Pausing does not delete face, person-appearance, or photo semantic features, person clusters, categories, or search history generated before pausing;
  • You can clear cached data in the App's settings;
  • You can turn off automatic background footprint recording, pause or end manual precise recording, and manage location access and Live Activity display in system settings. These actions do not delete tracks. Clearing the cache also does not delete footprints or health-workout snapshots stored in the App's Application Support directory;
  • To delete all person-recognition data, photo semantic features, search records, and workout routes in the App's sandbox at once in the current version, uninstall the App. Uninstalling does not delete content already saved to the system photo library, Files app, another app, or a cloud service, and it does not cancel an App Store subscription.

8.2 Changing or Withdrawing Authorization

You can disable or adjust permissions related to photos, location, and network access in iOS Settings; withdraw the App's read access to workouts and workout routes in the Health app; and pause image recognition or natural-language search indexing in the App's settings. Footprint location access and HealthKit read access are independent; withdrawing one does not automatically withdraw the other. To stop all footprint recording, turn off the relevant recording modes or set location access to "Never" as described in Section 2.5. You may also stop using the relevant feature or uninstall the App.

Withdrawing consent does not affect processing already completed on the basis of your consent before it was withdrawn. In response to withdrawal, the App will stop new related processing. Changes you previously wrote to the system photo library and locally generated face or person features, photo semantic features, search records, workout routes, memories, or indexes are not all automatically deleted merely because a system permission is withdrawn and must be managed separately as described in this Section.

8.3 Purchase and Subscription Management

You can view or manage purchases on your Apple ID subscription and purchase history pages and request a refund through channels provided by Apple. Because I do not hold your Apple account or payment information, Apple must handle these requests.

8.4 Contacting Me to Exercise Your Rights

For information you provided through customer support email, or for a request you cannot complete yourself, email pengzong771@live.com. To protect information security, I may ask you to provide information sufficient to verify your identity and the scope of your request, but I will not ask for an account password or payment password.

I generally respond within 15 business days after receiving a request. I may be unable to fulfill a request that is unreasonably repetitive, requires disproportionate technical effort, may harm the lawful rights and interests of others, or may be refused under applicable laws and regulations. If so, I will explain the reason.

The current version does not have an account system operated by me and therefore does not provide an "Account Deletion" option. Deleting the App does not cancel an auto-renewable App Store subscription. To cancel a subscription, use your Apple ID subscription settings.

9. Protection of Minors

The App is intended for a general audience and is not specifically directed to minors. I do not actively determine users' ages or collect minors' information for advertising or profiling.

If you are under 14 years of age, please use the App only after your parent or legal guardian has carefully read and agreed to this Policy. A parent or legal guardian should exercise particular care in deciding whether to allow processing of biometric-related information such as faces and person appearance in photos and should guide and supervise minors in cautiously authorizing photo, location, and health-data access and in avoiding the sharing of content containing sensitive information about themselves or others.

If a parent or legal guardian learns that a child under 14 has provided personal information to me without consent, please contact me using the details in Section 11. After verification, I will delete the information or take other necessary measures as required by law.

10. Changes to This Policy

I may revise this Policy due to feature changes, changes to third-party services, or updates to laws and regulations. After an update, I will publish the new version on this page and update the effective date and last-updated date. If there is a material change to the purposes or methods of processing, the types of personal information processed, or the impact on your rights, I will notify you prominently, such as through an in-app notice, and obtain your consent again where required by law.

You can view the current version in the App under Settings > About > Privacy Policy.

11. How to Contact Me

If you have any questions, comments, complaints, or suggestions about this Policy or the protection of personal information, or if you wish to exercise your rights, please contact me at:

After verifying your identity, I will handle your request as soon as possible and generally respond within 15 business days. If you are dissatisfied with how I handle your request, you may also file a complaint with a personal information protection regulator that has jurisdiction or bring a claim before a court with jurisdiction in accordance with applicable law.