Privacy Policy

Effective 23 September 2026 · Applies to the Perfect Photos app for iPhone and iPad and to this website.

The short version. Perfect Photos is a photo gallery with an optional paid feature, Remaster. Browsing, searching and organizing happen on your device and nothing from your library is uploaded. When you choose to remaster a photo, only that photo, with its location and camera metadata removed, is sent to our service and to our AI processing partner. We never store your photos on our servers, we do not sell your data, we do not show ads, and we do not train our own models on your photographs.

1. Who we are

Perfect Photos is published by Majar, an individual based in Switzerland (“we”, “us”). We are the controller of the personal data described in this policy under the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR).

Contact: perfectphotosapp@gmail.com

2. What the app can access on your device

Photos library. Perfect Photos is a gallery, so it asks iOS for access to your photo library in order to show, search, organize and edit your photos and videos. You choose whether to grant full access or a limited selection, and you can change this at any time in the iOS Settings app. Access is used on the device only. We do not enumerate, upload, index or back up your library to any server.

On‑device features. Search, duplicate review, Live Photo handling, HDR display, local editing and the version history of your remasters all run on your device. They send nothing to us.

Location. The app does not request your device location. Photos in your library may contain location metadata written by the camera; the app displays it locally and, as described below, removes it before any photo is sent for remastering.

3. What is sent when you remaster a photo

Remaster is optional and paid. Before your first remaster, the app explains what is sent and asks for your permission. You can withdraw that permission at any time in Remaster Settings inside the app.

When you tap Remaster, the app prepares a copy of that single photo and sends the following to our service over an encrypted connection:

  • the selected photo, downsized to at most 3072 pixels on its longest edge, with all location (GPS), camera (EXIF/XMP) metadata, face data and file names removed;
  • the mode and optional look you chose, and any short direction you typed;
  • a random request identifier and a signed proof of your App Store purchase, which is used only to verify your allowance.

Our service verifies your purchase with Apple, independently strips metadata again, and forwards only the sanitized image and the editing instruction to our AI processing partner, OpenAI, which generates the remastered image. OpenAI does not receive your purchase proof, your identity, or any identifier from your Photos library.

Please note that the visible content of a photograph can itself reveal personal information, for example a face, a street sign or a landmark. Removing metadata does not anonymize a picture. Remaster only the photos you are comfortable sending.

Videos are never sent. A Live Photo is remastered from its still frame only.

4. How long data is kept

On your device

Remastered results and their version history are stored in the app’s private storage on your device and are excluded from iCloud backup. Your original photo is never modified. A copy is written to your Photos library only when you choose Save Copy; that copy is then managed by Photos, not by us. You can delete any remaster in the app, and removing the app removes all of its local data.

On our servers

Our servers do not keep the photo you send: it is processed in memory and is not written to disk or to logs. The remastered result is encrypted and stored on our server only until your device has downloaded and accepted it, and for at most 24 hours, so that it can still reach you if you leave the app or lose your connection. It is then deleted. Accepting or rejecting a result in the app deletes it immediately.

At our processing partner

OpenAI processes API data to generate the result and, under its standard API terms, does not use it to train its models. OpenAI may retain API inputs and outputs for up to 30 days for abuse and safety monitoring, with the legal and safety exceptions described in its policies. We are working to place this processing under OpenAI’s Zero Data Retention option; when that is confirmed, this section will be updated. See OpenAI’s data controls.

5. Purchases and account records

Subscriptions and credit packs are sold through Apple’s App Store. Apple handles payment; we never see your card or bank details. To deliver what you bought, prevent double charging and stop abuse, our service keeps a small ledger:

  • a pseudonymous account identifier derived from your App Store transaction (we do not know your name or Apple ID);
  • your plan, billing periods, allowance, credits and each credit event (reserved, charged, released, refunded);
  • for each remaster request: a random request ID, the image dimensions, the mode chosen, timestamps, a digest of the output and a cost estimate. Never the photo, never your full direction text, never location or face data.

These records are kept for as long as needed to operate your subscription and to meet our financial and anti‑fraud obligations, and are deleted or anonymized afterwards.

Notifications

If you allow notifications, the app registers a push token with Apple and sends it to our service, together with a random installation identifier, so that we can tell you when a remaster is ready. The token is linked only to the pseudonymous purchase identity described above, is deleted when you turn notifications off in the app, and is removed automatically after 60 days without use. Notifications are delivered through Apple’s Push Notification service.

Anonymous usage statistics

To learn which features are useful, the app counts how often features are used each day, for example which Remaster mode or light was chosen, or whether a result was saved or shared, and sends those totals to our server. The counts carry the day, the app version, the iOS version and whether the device is an iPhone or iPad. They never include your photos or anything about their content, your directions, your location, or any account, device or advertising identifier, and we store them only as daily totals that cannot be linked to you. Our server uses your IP address only momentarily to limit abuse and does not store it with the statistics. You can turn this off at any time in the app under Settings → Privacy; this also deletes any counts waiting to be sent.

6. What we do not do

  • We do not sell, rent or share your photographs or personal data with advertisers or data brokers.
  • We do not use advertising SDKs, analytics that track you across apps, or the Apple advertising identifier.
  • We do not train our own models on your photographs.
  • We do not log photo content, GPS coordinates, faces or full editing directions on our servers.

7. Your choices and rights

  • Notifications: turn them off in the app’s Settings or in iOS Settings; your push token is then deleted from our service.
  • Usage statistics: turn them off in the app under Settings → Privacy.
  • Photos access: change or revoke it at any time in iOS Settings → Privacy & Security → Photos.
  • AI processing consent: revoke it in the app under Remaster Settings. Browsing continues to work.
  • Delete remasters: delete any version in the app, or delete the app to remove all local data.
  • Subscriptions: manage or cancel in your App Store settings. Deleting the app does not cancel a subscription.

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict its processing, and to lodge a complaint with a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), in the EU the data protection authority of your country. To exercise these rights, contact us at the address above. Because our ledger is keyed to a pseudonymous purchase identifier, we may ask you to make the request from within the app so that we can locate your records without collecting further identity information. Certain financial records may need to be retained for the period required by law.

8. Legal basis

We process personal data in line with the Swiss FADP. Where the GDPR applies, we process the selected photo and your editing direction to perform the contract you entered when you chose Remaster (Art. 6(1)(b) GDPR), with the explicit permission you give in the app beforehand. We keep purchase and anti‑abuse records to perform that contract, for our legitimate interests in securing the service and preventing fraud (Art. 6(1)(f)), and to comply with legal obligations (Art. 6(1)(c)). Push tokens are processed on the basis of your consent to notifications (Art. 6(1)(a)), and anonymous usage statistics on the basis of our legitimate interest in improving the app (Art. 6(1)(f)), which you can switch off at any time.

9. Service providers and international transfers

ProviderPurposeLocation
AppleApp Store purchases, subscription verification, push notificationsPer Apple’s terms
OpenAIGenerating the remastered image from the sanitized photoUnited States
Hetzner OnlineThe server that runs our service and briefly holds encrypted resultsAshburn, Virginia, United States
NeonThe database for the purchase ledger, push tokens and usage totalsNorthern Virginia, United States (AWS us‑east‑1)
CloudflareSecure connection to our service, protection against attacks; processes IP addressesGlobal network
VercelHosting this website; processes IP addresses in server logsGlobal network

Photos you remaster and the records described above are therefore processed in the United States. For transfers from Switzerland or the EU, we rely on the Swiss‑U.S. and EU‑U.S. Data Privacy Framework where the recipient is certified, and otherwise on the Standard Contractual Clauses in our providers’ data processing agreements, as recognized by the FDPIC and the European Commission.

10. Children

Perfect Photos is not directed at children under 13 (or the higher age of digital consent where you live), and we do not knowingly collect personal data from them.

11. Security

All connections use TLS. Photos are processed in memory; results are encrypted at rest and are accessible only to the account that requested them. Our service has no public URLs for results and no general request logging. No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed.

12. This website

This site is static and hosted by Vercel. It sets no cookies, loads nothing from third parties, and includes no analytics or tracking. Like any web host, Vercel receives your IP address and browser details to deliver the pages and may keep them briefly in server logs for security.

13. Changes

We will publish material changes to this policy on this page and update the effective date. Where a change materially affects how your photos are processed, the app will ask for your permission again.

14. Contact

Questions or requests about privacy: perfectphotosapp@gmail.com.