PhotoKeeper Privacy Policy
Effective date: 2026-08-27
This Policy explains how PhotoKeeper, an independent software product operated from China, handles information when you use the PhotoKeeper desktop app, website, support channel, and License service.
1. Local photo processing
PhotoKeeper is local-first. Photo and video thumbnails, downloaded originals, backup files, indexes, task history, and most preferences are processed on your computer and chosen storage. Your photos, videos, filenames, local paths, raw iCloud DSID, Apple password, and MFA code are not uploaded to the PhotoKeeper License service. PhotoKeeper does not sell personal information.
2. Apple authentication
You enter Apple credentials only into the authentication flow used to access your own account. PhotoKeeper does not intentionally persist your Apple password or MFA code. Authentication session material is stored locally using operating-system protections where available. Apple independently processes information under its own policies.
3. License-service information
To issue, restore, and protect Licenses, the service may process:
- a one-way account-binding identifier derived locally from the iCloud identity;
- an encrypted Apple Account display label used for masked confirmation and support;
- License plan, status, seat usage, entitlement version, and installation public-key thumbprint;
- opaque Paddle customer, transaction, product, and price identifiers and billing status;
- hashed recovery or invitation codes, request timestamps, and security audit events; and
- country code supplied by Cloudflare for sales eligibility and localized checkout behavior.
The raw iCloud DSID does not leave your computer. The License service is not designed to receive your photos, videos, Apple password, MFA code, authentication cookies, or raw recovery code.
4. Payments and infrastructure
Paddle acts as Merchant of Record and processes checkout, payment, tax, receipt, fraud, and refund information under its Privacy Policy. Cloudflare hosts the website and License service and processes network and security data under its Privacy Policy. We do not receive or store complete payment-card details.
Paddle's Merchant-of-Record role covers the resale transaction. PhotoKeeper remains responsible for PhotoKeeper-controlled information and the obligations described in this Policy.
5. Purposes and legal grounds
We process information as necessary to provide the app and License you request, prevent fraud and unauthorized seat transfer, secure the service, respond to support and privacy requests, comply with law, and pursue legitimate interests that do not override mandatory privacy rights. Where consent is required, you may withdraw it for future processing.
6. Retention
- License, binding, and transaction-linkage records are retained while needed to operate the License, enforce permanent seat limits, prevent abuse, and meet legal obligations.
- An approved display-label erasure request removes the encrypted Apple Account label but does not release or erase the one-way permanent binding record.
- Routine security logs are generally retained for no more than 90 days unless needed to investigate an incident, fraud, or legal claim.
- Support correspondence is generally retained for up to 24 months after closure unless a longer period is necessary for an unresolved License, dispute, security issue, or legal obligation.
7. Sharing and international processing
We share information only with service providers needed to operate PhotoKeeper, including Paddle and Cloudflare, or when required by law, security, fraud prevention, or a business transfer. These providers may process information in countries other than yours using safeguards required by applicable law. We do not sell or rent personal information for advertising.
8. Your choices and rights
Depending on your location, you may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent. Some License and anti-fraud records cannot be deleted while legally or operationally required. Send a request from the email connected to your transaction and do not include Apple passwords, MFA codes, recovery codes, or photos.
9. Security
PhotoKeeper uses encrypted transport, signed entitlements, one-way binding identifiers, hashed recovery codes, least-privilege service access, and local operating-system credential storage. No method is completely risk-free. Keep your operating system current and maintain independent backups.
10. Children
PhotoKeeper is not directed to children under 16, and we do not knowingly collect License-service information from children. Contact us if you believe a child supplied information to the service.
11. Contact
Privacy requests: zhang.xun.fp@gmail.com
PhotoKeeper · China