100% On-Device Privacy Architecture

Privacy Policy

Your privacy is paramount. Zero data retention, zero cloud uploads, and 100% local processing.

Effective Date

August 2026 (Last Updated: September 2026)

Introduction

This Privacy Policy explains how Photo Organizer AI handles user photos, identity recognition, metadata, and local system information.

No Cloud Telemetry or Media Retention

Photo Organizer AI is architected from the ground up as a pure offline desktop application.

Specifically:

Optional Cloud Sync & DPAPI Protection

If you choose to link Google Photos, Microsoft OneDrive, or Contacts:

Offline / Local Processing Disclosure

All AI/ML processing (such as face recognition, face detection, ArcFace feature extraction, clustering, semantic multimodal embeddings, and scene classification) operates locally or offline on the user's device via Windows DirectML.

We explicitly affirm that Google user data is never transmitted externally or stored on remote servers, and is never used to train generalized models for third party or any external systems.

Google User Data: What Raw and Aggregated/Anonymized Data is Accessed

Photo Organizer AI provides optional cloud integration with Google services to allow users to sign in, synchronize their contacts to recognize friends and family in photos, and synchronize app preferences across their personal devices. We clearly state below exactly what raw and aggregated/anonymized Google user data is accessed by the application:

1. Raw Google User Data Accessed by the App

When you explicitly choose to connect your Google account, Photo Organizer AI requests scoped access via Google OAuth 2.0. The application accesses only the following specific items of raw Google user data:

2. Aggregated or Anonymized Google User Data Accessed by the App

Zero Aggregated or Anonymized Data Accessed: Photo Organizer AI does NOT access, collect, query, calculate, receive, or compile any aggregated, anonymized, de-identified, or pseudonymized Google user data. All data access is strictly limited to the direct, raw user data points explicitly listed above for the active user's local session. No demographic aggregates, population statistics, or anonymized usage datasets are accessed from Google or any intermediary.

Google Service & Scope Exactly What Raw Data is Accessed Aggregated / Anonymized Data Accessed How the Data is Used by the App
Google Account / Sign-In
email
profile
Google Account ID, primary email address, full display name, given name, family name, profile picture URL, and profile picture avatar image bytes. None. No aggregated or anonymized account data is accessed or collected. Used strictly on-device to authenticate your identity, display your account avatar and name in the application UI, and maintain your local active session.
Google Contacts
contacts.readonly
(Google People API)
Contact resource IDs, display names, given/family names, email addresses, phone numbers, job titles, companies, contact photo URLs, and downloaded contact photo image bytes. None. No aggregated or anonymized contact data is accessed or collected. Loaded temporarily into local memory to match contact photos against unlabelled face clusters in your local photos using local DirectML ArcFace AI. Confirmed matches auto-label the person cluster with the contact's name, email, and phone number in your local SQLite database.
Google Drive AppData
drive.appdata
(Google Drive API v3)
Restricted sandboxed content of the app's own configuration file (settings.json) inside the hidden appDataFolder. No access to personal Drive files. None. No aggregated or anonymized Drive data is accessed or collected. Used solely to sync your personal app preferences, custom tagging rules, and AI sensitivity thresholds across your own Windows devices running Photo Organizer AI.

Google User Data: How Raw and Aggregated/Anonymized Data is Used

Photo Organizer AI enforces strict purpose limitation, on-device local execution, and zero data monetization. Below is clearly how raw and aggregated/anonymized Google user data is used by the application:

1. How Raw Google User Data is Used by the App

2. How Aggregated or Anonymized Google User Data is Used by the App

No Use of Aggregated or Anonymized Data: Because Photo Organizer AI does NOT access, compile, generate, or receive any aggregated or anonymized Google user data, no aggregated or anonymized Google user data is used for any purpose whatsoever. The application does not perform telemetry analytics, user behavior analysis, trend aggregation, demographic profiling, market research, or advertising using Google user data.

3. Prohibitions on AI Model Training, External Transmission, and Sale

Limited Use Compliance Statement

Photo Organizer AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Google Workspace APIs / Google API Services User Data Policy, are for Limited Use requirements only:

Contact Us

If you have questions regarding this Privacy Policy, you can contact the developer via the official Microsoft Store listing page.