Legal

Privacy Policy

Last updated August 16, 2026 · Review draft — see note below

This page publishes Nitro Photos' privacy policy at a public URL. The legal entity name, contact email, and jurisdiction details below are placeholders pending the publisher's final review; this document is not legal advice.

Scope

This policy describes the Nitro Photos Mac, iOS, and companion server software (collectively, "Nitro Photos"). Nitro Photos is designed to connect to a server selected and controlled by the person operating the library. The publisher is [insert legal entity name and contact email] ("we," "us," or "our").

Information handled

Where information goes

By default, Nitro Photos sends media and library operations only between your clients and the local/configured server. The publisher does not receive a copy merely because the app is installed. If you configure a remote server, a local-network share, or an optional AI provider, that destination then receives the information required for that feature.

Optional AI processing

AI tagging is optional. The Mac tagging flow sends filename/title text to Google Gemini only when you provide a Gemini API key. The companion server can also send uploaded media to Gemini when its GEMINI_API_KEY integration is configured. The server falls back to local heuristics when AI is unavailable. Review Google's terms and privacy practices and remove the key if you don't want this processing.

Use and retention

Information is used to authenticate accounts, pair and revoke devices, store and synchronize your library, generate thumbnails/posters, apply requested edits, provide sharing, and maintain local operation. You control retention by deleting media, emptying trash, revoking devices, deleting the local library/server data, and removing configured API keys. Server backups or copies made outside Nitro Photos are controlled by the server operator and must be deleted separately.

Sharing and security

Sharing is user-initiated. Bearer tokens are stored in the Mac Keychain, not displayed as ordinary account metadata; the local server maintains revocable sessions. No security system is perfect — protect your server, recovery phrase, passwords, API keys, and network access, and use HTTPS when connecting beyond a trusted local network.

Children

Nitro Photos is not directed to children and does not knowingly collect personal information from children through a publisher-operated service.

Privacy requests and changes

For privacy questions or deletion requests, contact [insert privacy contact email]. Because the library is self-hosted, requests may need to go to the person or organization operating that server. We may update this policy when the product's data practices change and will update the date above.


Questions about this policy? See the support page for contact details.