Skip to content
PhotoKeeper
Why back upFeaturesHow it worksFAQ
EN
简体中文繁體中文English日本語한국어DeutschFrançaisEspañolPortuguês (Portugal)Português (Brasil)ItalianoNederlandsPolskiРусскийSvenskaDanskNorsk bokmålไทยTiếng ViệtBahasa IndonesiaBahasa MelayuFilipino
Buy PhotoKeeper
Why back upFeaturesHow it worksFAQBuy PhotoKeeper
PhotoKeeper policies Terms & EULA Privacy Policy Refund Policy Support & lifecycle
Legal

PhotoKeeper Privacy Policy

Effective date: 2026-09-16

This Policy explains how PhotoKeeper, an independent software product operated from China, handles information when you use the PhotoKeeper desktop app, website, support channel, and License service.

1. Local photo processing

PhotoKeeper is local-first. Photo and video thumbnails, downloaded originals, backup files, indexes, task history, and most preferences are processed on your computer and chosen storage. Your photos, videos, filenames, local paths, raw iCloud DSID, Apple password, and MFA code are not uploaded to the PhotoKeeper License service. PhotoKeeper does not sell personal information.

2. Apple authentication

You enter Apple credentials only into the authentication flow used to access your own account. PhotoKeeper does not intentionally persist your Apple password or MFA code. Authentication session material is stored locally using operating-system protections where available. Apple independently processes information under its own policies.

3. License-service information

To issue, restore, and protect Licenses, the service may process:

  • a one-way account-binding identifier derived locally from the iCloud identity;
  • an encrypted Apple Account display label used for masked confirmation and support;
  • License plan, status, seat usage, entitlement version, and installation public-key thumbprint;
  • opaque Paddle customer, transaction, product, and price identifiers and billing status;
  • hashed recovery or invitation codes, request timestamps, and security audit events;
  • for website purchases, a keyed email index and masked label, or an encrypted activation code and its hash;
  • hashed purchase-receipt credentials and hourly keyed IP buckets used to limit new orders; and
  • country code supplied by Cloudflare for sales eligibility and localized checkout behavior.

The raw iCloud DSID does not leave your computer. The License service is not designed to receive your photos, videos, Apple password, MFA code, or authentication cookies. Activation and recovery codes are processed over HTTPS for redemption; website activation codes are also encrypted in storage so the purchasing browser can retrieve them after confirmed payment. The website's account-linking form does not send your Apple Account email to Paddle.

4. Payments and infrastructure

Paddle acts as Merchant of Record and processes checkout, payment, tax, receipt, fraud, and refund information under its Privacy Policy. Cloudflare hosts the website and License service and processes network and security data under its Privacy Policy. We do not receive or store complete payment-card details.

Paddle's Merchant-of-Record role covers the resale transaction. PhotoKeeper remains responsible for PhotoKeeper-controlled information and the obligations described in this Policy.

On the website home address, we use the language preferences sent by your browser to select a supported language. If you choose a language from the menu, a first-party preference cookie stores that language code for up to one year. This cookie contains no account or photo data. Clear the site's cookies to return to browser-based language selection. A direct language URL continues to show the language specified in that URL.

Website checkout uses browser session storage to keep a private purchase-receipt credential across payment redirects. While preparing an order it also temporarily retains your selected activation option and any entered email so an interrupted request can resume without creating another order. The email is removed from this browser record when checkout opens or payment is confirmed. Save your activation code before closing the purchasing tab. Clearing this storage removes the browser's ability to retrieve the code; you can contact support with your Paddle order if needed.

5. Purposes and legal grounds

We process information as necessary to provide the app and License you request, prevent fraud and unauthorized seat transfer, secure the service, respond to support and privacy requests, comply with law, and pursue legitimate interests that do not override mandatory privacy rights. Where consent is required, you may withdraw it for future processing.

6. Retention

  • License, binding, and transaction-linkage records are retained while needed to operate the License, enforce permanent seat limits, prevent abuse, and meet legal obligations.
  • An approved display-label erasure request removes the encrypted Apple Account label and email labels/indexes on website purchases already claimed by that account, but does not release or erase the one-way permanent binding record.
  • Routine security logs are generally retained for no more than 90 days unless needed to investigate an incident, fraud, or legal claim.
  • Support correspondence is generally retained for up to 24 months after closure unless a longer period is necessary for an unresolved License, dispute, security issue, or legal obligation.

7. Sharing and international processing

We share information only with service providers needed to operate PhotoKeeper, including Paddle and Cloudflare, or when required by law, security, fraud prevention, or a business transfer. These providers may process information in countries other than yours using safeguards required by applicable law. We do not sell or rent personal information for advertising.

8. Your choices and rights

Depending on your location, you may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent. Some License and anti-fraud records cannot be deleted while legally or operationally required. Send a request from the email connected to your transaction and do not include Apple passwords, MFA codes, recovery codes, or photos.

9. Security

PhotoKeeper uses encrypted transport, signed entitlements, one-way binding identifiers, hashed recovery codes, least-privilege service access, and local operating-system credential storage. No method is completely risk-free. Keep your operating system current and maintain independent backups.

10. Children

PhotoKeeper is not directed to children under 16, and we do not knowingly collect License-service information from children. Contact us if you believe a child supplied information to the service.

11. Contact

Privacy requests: [email protected]
PhotoKeeper · China

PhotoKeeper

A home of your own for your memories.

Terms & EULA (English)Privacy (English)Refunds (English)Support & lifecycle (English) Contact

PhotoKeeper is independently developed and is not affiliated with, sponsored by, or endorsed by Apple Inc. iCloud and Apple are trademarks of Apple Inc. Paddle is the Merchant of Record for purchases; the PhotoKeeper developer remains responsible for the product, technical support, and PhotoKeeper-controlled information.

© 2026 PhotoKeeper