← AlphaGallery

AlphaGallery — Privacy Policy

Effective 22 August 2026. AlphaGallery is published by Alphazulu LLC. Questions, requests and complaints: [email protected].

This policy describes what the app does with your photographs. It is written to be checked against the app rather than to reassure you, so where something is uncomfortable it is stated plainly — see Encryption and Legal requests.


The short version


What stays on your phone

Scanning is local. The app reads your photo library through the operating system's own photo permission and computes, on the device:

The results are kept in local caches on the device so the work is not repeated. The Recycle Bin, the deletion log, your event folders, your Hidden folder and your settings are likewise stored on the phone.

None of this is transmitted anywhere. If you never turn on Cloud Backup, the app sends no photograph, and no description of a photograph, off your device.

What can leave your phone, and only if you allow it

1. Place names (on by default, switchable off in Settings). To label a photograph with a place, the coordinates already recorded inside it are passed to the operating system's geocoder — Apple's on iOS, Google's on Android. Those coordinates leave the device as part of that lookup and are handled under Apple's or Google's own privacy policy. Turning this off stops the lookups; your photos keep their coordinates and simply show no place name.

2. Map tiles (off by default). If you turn on the map, map imagery is fetched from OpenStreetMap. Your IP address and the area you are looking at are visible to them, as with any web map. Your photographs are not sent.

3. Cloud Backup (off by default). Described below.

Nothing else in the app uses the network. Sharing a photo hands it to whichever app you pick, which is then governed by that app's policy.


Cloud Backup

Cloud Backup is off until you turn it on, and it is the only part of AlphaGallery that has servers or an account. This section covers it in full; the service also publishes its own policy at cloud.alphagallery.app/privacy, which says the same things in more operational detail. If the two ever disagree, this one governs the app. If you turn it on:

What is stored. Full-quality copies of the photographs and videos you choose to back up, together with a small preview image (about 320 pixels) so that browsing your backup does not have to download the originals. We also store the file's size, type, checksum, the date it was backed up, which of your phones sent it and which of your event folders it belongs to.

Originals include their metadata. A photograph carries EXIF data inside the file — most importantly precise location, plus the date and camera details. We do not strip it, because removing data from your own originals would make the backup something other than a copy. If that matters to you, it is a reason to leave Cloud Backup off, or to turn off your camera's location tagging.

Where it is stored. Files are held in Backblaze B2 in the United States; the service that coordinates uploads runs on Cloudflare. If you are outside the United States, your files are stored there.

Identical files are stored once. Objects are addressed by their checksum, so the duplicates this app exists to find do not consume your storage twice.

Hidden. Photographs in your Hidden folder are backed up only if you tick that option on the backup options screen; it is off by default. When ticked they are uploaded and stored like any other file, and no preview is generated for them. They are not returned by search, and reaching them on the website requires your PIN.

Encryption — please read this part

Files are encrypted on our servers, using keys that we hold. This is not end-to-end encryption. Two consequences follow, and we would rather you learn them here than assume otherwise:

Nothing in the app claims otherwise, and if you ever see AlphaGallery marketing that says "end-to-end encrypted", it is wrong.

Legal requests

We disclose stored content only where we are legally required to, and only to the extent required. We do not volunteer user content to anyone.


Your account

Cloud Backup uses an account. There are two ways to hold one.

This phone only. The app generates 32 random bytes on your device, shown to you as a recovery code. The server stores only a hash of it — we cannot read your code back, and we cannot recover it for you. If you lose it and have not signed in, the backup cannot be recovered by anyone, including us. In this mode we hold no name, no email address and nothing else that identifies you.

Signed in with Google or Apple. Optional, and what allows more than one phone and access to the website. We receive and store your email address and the account identifier the provider gives us. We do not receive your password. We use the address to sign you in, to send the six-digit codes described below, and to contact you about the service — never for marketing.

Sign-in codes. Signing in on the website requires a code emailed to that address as a second step. Codes are stored as hashes, expire in ten minutes, and are swept from the database afterwards. Email is sent via Cloudflare.

Your Hidden PIN is stored on the phone, and — when Hidden is backed up — as a hash on the server so the website can check it. We cannot read your PIN.

Your phones. Each phone gets an identifier so we can record which one sent which file, and so a restore puts things back on the right device. You can see, rename and remove your phones in the app and on the website.

Payments. Subscriptions are bought through the App Store or Google Play and managed for us by RevenueCat. We are told what you are entitled to. We never see your card details — the store handles payment and we have no access to it.


What we never do

Keeping and deleting

Backed-up files are kept until you delete them or delete your account. Sessions, sign-in codes and Hidden unlocks expire and are then removed by a scheduled cleanup rather than left to sit.

Deleting your account deletes it. From the app or the website, deletion removes your files from storage and every database record that names you, including your email address. Where we hold an email address it requires a six-digit code sent to it; where we hold none — because you have never signed in — it requires you to type the word DELETE. Either way a browser session alone can never erase your photographs.

One deliberate exception: an internal audit ledger records that administrative actions happened, storing account identifiers as plain text so that deleting an account never rewrites the record of what was done to it. It holds no photographs and no email addresses.

Your rights

Depending on where you live you may have rights to access, correct, export or erase the personal data we hold. Deletion and export are available in the app and on the website; for anything else write to [email protected] and we will answer.

Children

AlphaGallery is not directed at children under 13, and we do not knowingly hold data from them. If you believe a child has an account, write to us and we will remove it.

Changes

If this policy changes materially we will say so in the app before the change takes effect. The effective date at the top always reflects the current version.

Contact

Alphazulu LLC[email protected]