Privacy policy
- The app reads the photos and videos on your phone that the operating system lets it — all of them, or only the ones you picked.
- Everything it works out from them stays on your phone. There is no account and no server of ours.
- On the free plan, a banner ad is shown. The ad provider receives standard ad-request data. It never receives your photos.
- Pro removes ads. The app then makes no network requests of its own except to the App Store or Google Play.
- It does not recognise faces and never works out who is in a photo.
- Deleting the app deletes everything it learned.
1. Who this covers
This policy describes what PhotoShelf (the "app") does with information on your phone, and the small amount of information that leaves it. The app is published by [DEVELOPER LEGAL NAME], [ADDRESS, Haryana, India] (the "developer").
2. What the app reads
The app asks for permission to access your photo library, and it reads what the operating system grants: the photos and videos on your phone — all of them, or, if you chose "Selected photos", only the ones you picked. It reads them to sort screenshots onto shelves by what each one needs, to find duplicates, videos, old months and documents, and to make the grid and search work.
iOS and Android grant photo access at the library level, not per album, and the app uses it at that level. You can narrow or revoke it in system settings at any time; the app re-reads the level every time it opens and works on whatever it is given.
For each photo or video, the app reads the image (or one frame of a video), the date it was taken, its size and kind, whether it is a screenshot, and, where the operating system provides it, the albums it is in, whether you have favourited it, the name of the app a screenshot came from, and the place stored in the file — that last one only while you leave "Keep photo locations" on (§4).
3. What is processed, and where
All processing happens on your phone, using models that ship inside the app. Nothing is sent to a server for processing, and no model is downloaded after installation.
| Step | What it produces |
|---|---|
| Text recognition (OCR) | The text visible in the photo, with its position on screen |
| Entity extraction | Amounts, currencies, dates and relative times, phone numbers, links, codes such as order numbers or PNRs, person names and merchant names found in that text |
| Screen-type and scene classification | A label such as "chat", "payment", "product page", "ticket", "meme" |
| Intent classification | One of Pay, Buy, Read, Reply, Keep or Junk, with a confidence score |
| Ranking | Urgency and importance scores, and a one-line reason |
| Personalisation | Small adjustments to the classifier based on the corrections you make, per source app and intent |
On Android, text recognition uses Google's ML Kit with models bundled into the app. The models run on the device.
Faces. The app does not recognise faces. It builds no face template, no face signature and no "people" grouping, and it never works out who is in a photo — not on our servers, because we have none, and not on your phone either. Nothing in the app identifies a person from their appearance.
4. What is stored
The results above, together with the state of each item (active, snoozed, done, kept, archived, deleted) and the actions you take, are stored in a local database on your phone. Small thumbnails are cached locally to make lists fast.
- The database and cache are excluded from iCloud and Google backups. The text read from your photos does not travel with a backup.
- The database is stored in the app's private storage and protected by the operating system's file protection.
- Videos are handled like photos: the app reads the date, size and length and one frame, to make a thumbnail and to spot near-copies and large files. It does not transcribe audio and keeps no copy of a video outside a pack you made yourself (§4.2).
- The app writes to your photo library only when you ask, and only through the operating system's own dialogs: deleting photos (the system confirmation every time, one dialog per batch), adding to or removing from an album, setting the favourite flag, and Pack away / Unpack (§4.2). Nothing is copied, moved, changed or deleted as a side effect of anything else you do in the app.
- If you turn on "Show in Spotlight" or device search, item titles and thumbnails are handed to the operating system's on-device search index. That index stays on your phone and is removed when the app is deleted.
- Deleting the app deletes the database, the cache and everything the app learned.
4.1 Where a photo was taken
Many photos carry the place they were taken inside the file (EXIF GPS). The app reads it only while "Keep photo locations" is on in Settings → Privacy, and then keeps the coordinate in the local database so photos can be grouped by place. It is never turned into a place name, never used for advertising, and never leaves your phone. Turning the switch off removes every location the app has stored and stops it reading them.
What the app does with it: it works out roughly where your phone usually is — as a wide grid cell covering tens of kilometres, never a street address — and puts photos taken well away from there on the Places shelf. That is the only use. The app never turns a coordinate into a place name: doing so would mean sending it to a mapping service, and nothing in this app is sent anywhere. Any name a place has is one you gave it.
4.2 Pack away
Pack away copies the originals of a month you choose into a pack in the app's own storage on your phone, checks every copy against the original, and only then asks the operating system to remove those photos from your library. The system's own delete dialog is the only thing that removes them, and you see it every time. Unpack puts them back.
- A pack never leaves your phone, and the app cannot send one anywhere.
- iOS: the pack sits in the app's own container. It is included in your iPhone backup — they are your photos, and a backup that skipped them would be the wrong default — and it is hidden from the Files app unless you turn that on.
- Android: the pack is app-private storage. Android's auto-backup does not carry it, and uninstalling the app deletes it. Unpack first if you want those photos back in your library.
5. What leaves your phone
From the app itself: nothing. There is no server of ours, no account system and no over-the-air update mechanism, and the app sends us nothing at all — not your photos, not the text read from them, not your searches, not your actions. Nothing about how you use it reaches the developer.
Three things do involve the network:
5.1 Purchases
Buying Pro goes through Apple's App Store or Google Play. Apple or Google handles payment and sends the app a receipt that confirms your entitlement. The app never sees your card details. Apple's and Google's privacy policies apply to the purchase.
5.2 Ads on the free plan
On the free plan, one banner ad is shown on the home screen. Ads are served by the Google Mobile Ads SDK (AdMob). When an ad is requested, Google receives standard ad-request data: a device identifier, your approximate location inferred from your IP address, the ad's size and placement, basic device and app information, and whether the ad was shown or tapped. Google may also collect diagnostic data about the SDK itself.
- Ads are requested in non-personalised mode. The app does not ask for tracking permission and does not use the advertising identifier for cross-app tracking.
- In the EEA, UK and Switzerland, the app shows Google's consent form (UMP) before the first ad request, as required. You can reopen it from Settings → Ad preferences.
- Your photos and anything read from them are never part of an ad request.
- The ad SDK is only initialised when the banner is about to be shown. It is not started on the paywall, in onboarding, in Settings or when photo access is denied.
- Buying Pro stops all ad requests.
Google's collection is described in Google's privacy policy and in the "Data safety" and App Store privacy details for this app, which declare the SDK's data for every user because a single build serves both free and Pro users.
5.3 Google Play services (Android)
On Android, Google Play services and the bundled ML Kit library may send their own diagnostics to Google. This is part of the Android platform and is outside the app's control.
5.4 The complete list of who the app can talk to
- Google AdMob and Google's User Messaging Platform — on the free plan only, and only once a banner is about to be shown or a consent form is required.
- Apple's App Store (iOS) or Google Play (Android) — for purchases, for restoring them, and for the occasional "rate this app" prompt, which the store draws itself.
- Google Play services (Android only, §5.3) — platform diagnostics we do not control.
The app itself makes no other network request. There is nothing else to contact: no server of ours exists.
6. Notifications and calendar
All notifications are created and delivered on your phone. The app never uses a push service. If you tap "Add to Calendar", the app asks for permission to add an event and writes only that event; it does not read your calendar.
7. Children
The app is not directed at children under 13 and is not intended for them. We do not knowingly collect data from children; the app collects no personal data of its own from anyone.
8. Your controls
| Control | Where | What it does |
|---|---|---|
| Photos access | System Settings | Change or revoke photo access at any time. The app re-reads the access level every time it opens. |
| Reset what it has learned | Settings → Privacy | Clears the personalisation weights and per-app rules; keeps items. |
| Delete all app data | Settings → Privacy | Deletes the local database, cache and search index. Your photos themselves are untouched. |
| Export my data | Settings → Advanced | Creates a JSON archive of items, extracted text and actions and hands it to the share sheet. Nothing is uploaded by the app. |
| Ad preferences | Settings (free plan) | Reopens the consent form where applicable. |
| Remove ads and network use | Settings → Pro | Pro removes ads; the app then contacts only the App Store or Google Play. |
Because the app keeps no data off your phone, there is nothing for us to access, correct or delete on your behalf. The controls above do all of it locally.
9. Legal basis and your rights
Where data protection law applies (for example the GDPR in the EEA and UK, or India's Digital Personal Data Protection Act), the developer does not process your personal data: the app's own processing never leaves your device and is under your control. The ad SDK's processing on the free plan is carried out by Google under Google's privacy policy; the legal basis for it in the EEA and UK is your consent, given through the consent form, or Google's legitimate interest for non-personalised ads where allowed. You can withdraw consent from Settings → Ad preferences or by buying Pro.
10. Changes to this policy
If this policy changes, the new version is published at this address with a new effective date, and the app's "What's new" notes say so. The app never changes what leaves your phone without a store release and a note here.
11. Contact
[SUPPORT EMAIL] · photoshelf.dinosdev.com/support
Postal address: [ADDRESS, Haryana, India]
Change log
| Date | Change |
|---|---|
| 5 September 2026 | First version, published with app version 1.0. |