Home / Privacy policy

Privacy policy

Updated September 15, 2026

Your photos and choices

Photo review and visual recognition run on your device. The app reads the photos you allow through iOS and records their Photos identifiers and your keep or delete choices. Original photos stay in the system photo library.

Local storage and widgets

Review choices, statistics, preferences, stories, drafts, photo clues and previews are stored locally. Only explicitly saved stories supply story summaries and selected previews to Home Screen widgets. An account is not required.

Footprints and keepsakes

Your keepsakes, earned dates, saved story dates and completed share dates stay on this device. Resetting review history keeps these lifetime records. Sharing a keepsake is always your choice.

Invitations and allowance sync

When you are signed in to iCloud, review allowance and reward records sync to your private iCloud database. Invitations use public codes and confirmations linked to an opaque iCloud identity. These records contain no photos, story text, names, email addresses or local photo identifiers. One account can confirm one invitation. No advertising ID, device fingerprint or automatic clipboard reading is used.

Gifts and your iCloud account

When gifts are enabled, accepting one uses a CloudKit identity proof and a trusted service hosted on Cloudflare. The service keeps an opaque account identifier, gift amount, dates, note and issuance record in CloudKit; it receives no photos, story content or photo identifiers. Signed receipts also sync to your private iCloud database. The operator sees gift status, not your Apple identity. Authentication proofs are cleared within seven days; gift records are kept for permanent restoration. Connection data is used to deliver and protect the service, not for advertising.

Deleting gift data

In Invitations & gifts, you can confirm a request to delete gift credits, receipts and account links. Processing cannot be undone. Permanent reviews already used remain deducted, including from future permanent grants. Spent-code markers prevent reuse; a minimal account marker prevents old receipts from returning. Private receipts and device caches are cleaned when devices reconnect. Photos, stories, invitation records and Pro purchases are kept.

Places and weather

If a photo has location metadata, you can ask for place and weather notes. Only then are its rounded coordinates and date sent to Apple geocoding and Open-Meteo. Daily regional weather is a source note, not a record of your experience. Your device’s current location is not requested.

Story share cards

Card layout happens on this device. A story card includes the text and selected photos or video covers shown in its preview. It leaves the app only when you choose a system share destination or save it to Photos. Context notes and photo identifiers are not printed. Story sharing does not upload to a PicLoom service or earn review rewards.

Optional cloud stories

Writing help is optional. Only tapping Help me write sends your current writing, note and chosen material notes to your configured service. Local photo identifiers and coordinate keys are omitted. Up to six selected still images or video covers are included only with separate consent. No video sound or motion is sent. Opening a day or saving settings does not call AI.

API keys

Your cloud API key is kept in the iOS Keychain and is sent to your chosen endpoint to authorize requests. To remove it, clear the API Key field in Story generation and save. Cloud services apply their own privacy and billing terms.

Your controls

You can change photo access in iOS Settings. Reset review history clears keep and delete choices; it does not delete photos, saved stories, lifetime statistics, or daily allowance usage. Removing photos from the library requires a separate confirmation through iOS.

Purchases, reminders and diagnostics

Apple processes Pro purchases and restores through your App Store account. Daily reminders are optional and scheduled on this device. Paywall views, quota blocks, share previews and claimed rewards are counted locally. Copying version details includes only the version and software Build ID, stays on this device and expires after ten minutes. Email drafts also include device model, system version and app language. Diagnostic reports can be previewed before sharing; local activity counts are optional and off by default. Reports exclude developer and source metadata. The Build ID identifies a software package, not you or your device. No automatic diagnostic uploads, advertising or tracking SDKs are included.

Backups and saved stories

Stories, drafts, moods, photo clues and review records are local app data included in device backups when enabled. This is not live sync. API keys remain on this device. Drafts are kept separately from saved stories; failed saves can be retried without generating again. Available previous versions can be restored.

This website and support

Cloudflare hosts this site and processes connection data, such as IP addresses, to deliver and protect it. We add no advertising trackers or analytics scripts. Your language preference and first automatic language choice are stored in your browser. Interactive examples use public media and fictional stories; they do not access or upload your photos or send them to AI. If you contact support, we use the information you choose to send to respond to your request.

Invitation and gift pages

Invitation pages read a code from the link query; gift pages read it from the fragment. They do not store codes or send claim or attribution requests. They write to the clipboard only when you choose Copy. The gift service may include a private issuer note that the developer can remove separately. Temporary identity proofs are scheduled for deletion within seven days, subject to the service operating normally.

Contact the developer

Contact the developer : [email protected]