Skip to main content

Privacy Policy

Effective date: [ 2026/8/16]  


Photo Steward (the “App”) is built around on-device processing and user choice. This Privacy Policy explains how the App accesses, uses, stores, and deletes information and how you can manage permissions.


## 1. Scope


This Policy applies to Photo Steward for iOS, version 1.0. It does not apply to Apple or to other apps and services you choose through system sharing features. Those third parties process information under their own privacy policies.


## 2. Whether We Collect Data


Version 1.0 does not require an account, include advertising or cross-app tracking, or send your photos, videos, people-grouping results, location metadata, recordings, contacts, calendars, Private content, PIN, or storage trends to servers operated by us.


The App does not include third-party SDKs for advertising, attribution, behavioral analytics, or remote crash reporting. The content described above is primarily processed and stored on your device.


If you contact us by email or another channel, we receive the contact details, description, and attachments you choose to provide. We use them only to answer your request, troubleshoot issues, and improve support. Please do not send unnecessary sensitive content.


## 3. Information the App Accesses and Uses


### Photos and Videos


With your permission, the App can read photos, videos, and existing metadata in Apple Photos, such as capture time, media type, and location. It uses this information to create Photo Days, People, Places, Moments, album views, and storage trends.


The People feature uses Apple frameworks on your device to detect and cluster similar faces. It does not establish real-world identity and does not upload face features to us. Names you assign to people groups are stored on your device.


To turn coordinates already stored with a photo into a readable place name, the App may call Apple’s system geocoding service. Apple may process those coordinates under its privacy policy. The result is stored locally, and we do not receive the coordinates or place result through a server operated by us.


Only when you choose an action may the App mark favorites, create or update albums, save a copy exported from Private, or submit a deletion request to iOS. Photo deletion uses the standard system confirmation flow. Deleted items follow Apple Photos Recently Deleted rules. The App does not delete photos automatically or empty Recently Deleted.


### Microphone and Recordings


The App requests microphone access only after you open the recording feature and begin recording. Saved recordings are encrypted locally, with encryption keys protected by the iOS Keychain. The App does not secretly record in the background or upload recordings to us.


### Contacts


The App requests Contacts access only after you open a contact tool or choose to import or export a contact through Private. Contact information may be processed on device to find duplicates, preview, merge, delete, create a local backup record, or restore contacts. Merge and delete actions occur only after you choose them.


Local contact backup records are stored by the App for a restore action you initiate and are not sent to us. Once contacts are written to the system address book, they are managed by iOS and the contact accounts you configured.


### Calendars


The App requests Calendar access only after you open the calendar organization tool. Calendar information is processed on device to find older events and present them for your selection. Events are deleted only when you choose that action. System calendar accounts may sync under your iOS and provider settings.


### Files and Private


You may use the system document picker to add selected files to Private. Photos, videos, files, contacts, and voice content saved in Private are encrypted locally and accessed through a six-digit PIN you create. PIN verification data and encryption keys are stored in the iOS Keychain. We cannot read or recover your PIN and cannot decrypt the content for you.


When you choose Save or Export, the App temporarily decrypts the selected item and hands it to the system location or third-party app you select. Exported copies are no longer protected by Private, so choose the destination carefully.


### Device Storage and App Settings


The App reads available device storage and local photo and video growth to present storage trends. Permission status, tutorial completion, people names, forecast history, and other preferences are stored on device.


## 4. Permission Choices


You may deny optional permissions and can change Photos, Microphone, Contacts, or Calendar access at any time in iOS Settings. Denying or revoking a permission affects only features that depend on it.


Revoking permission does not automatically reverse changes you previously approved, such as favorites, albums, deleted photos, merged contacts, or deleted calendar events. Manage those changes in the relevant Apple app or account.


## 5. Retention and Deletion


Local data generally remains until you delete the relevant item in the App, clear the associated setting, or uninstall the App. You can use the relevant feature to delete Private items, recordings, contact backup records, and other manageable content.


Deleting a Private item or local recording may be permanent. Photo deletion generally moves an item to Recently Deleted in Apple Photos; the retention period and recovery options are controlled by Apple and your settings.


Uninstalling generally removes data in the App sandbox, but the iOS Keychain, Apple Photos, Contacts, Calendars, and system backups follow their own retention rules. Reinstalling does not guarantee recovery of Private or recordings. Export anything you need before uninstalling, replacing, or resetting your device.


## 6. System Backups and Apple Services


The App does not actively sync your content to a cloud service operated by us. Your iPhone may be included in iCloud or computer backups according to your settings with Apple. Apple Photos, Contacts, and Calendars may also sync through accounts you enable. When you view or share a photo or video whose original is available only in iCloud, Apple Photos may download it under your system settings. Place-name resolution may use Apple’s system geocoding service. Apple or the relevant account provider is responsible for that system-level processing under its own terms and privacy policy.


## 7. Security


The App uses Apple CryptoKit AES-GCM encryption for Private content and saved recordings and uses the iOS Keychain to protect PIN verification data and encryption keys. It also uses system permissions, the app sandbox, and automatic locking to reduce unauthorized access.


No storage or security method can guarantee absolute security. An unlocked device, operating-system vulnerability, jailbreak, malware, user export, or sharing a PIN can increase risk. Protect your device passcode and App PIN and keep iOS updated.


## 8. Children’s Privacy


The App is not designed to collect personal information from children and does not ask for age or identity. Minors should use the App with the permission and guidance of a parent or legal guardian and should process only content they are authorized to access.


## 9. International Transfers


Because version 1.0 does not send the device content described above to servers operated by us, we do not perform international transfers of that device content. Information you send to support or share with a third-party service may be processed under the channel and provider you choose.


## 10. Changes to This Policy


We may update this Policy if features, data practices, or legal requirements change. We will post the updated effective date and provide an appropriate notice for material changes. Where law requires separate consent, we will request it.


## 11. Contact Us


For privacy questions, withdrawal of consent, support, or requests relating to data we actually hold, contact:



- Email: support@aiphotosteward.com



Because most content remains only on your device, we generally cannot access or restore it from a server.