For the FotoNest mobile app (iOS; Android when available).
Version: 1.0 (store listing)
Effective: date of first publication on the app stores
Operator: Sonicwell Technology Limited (Room 704, 7/F., Tower A, New Mandarin Plaza, 14 Science Museum Road, TST East, Kowloon, Hong Kong)
Support: fotonest.app/support.html
This public URL is required by Apple App Store and Google Play. By using FotoNest you agree to this policy.
1. Summary
Original photos stay on your device by default.
Most AI organization runs on-device; face feature vectors are uploaded only when you separately consent, to support filtering by person within a shared album (see §7).
Collaboration uses share-size images (~2048px); full originals upload only when needed — in friends/shared albums you approve each time; in family albums, joining grants standing consent for family members to fetch your originals on demand (you can turn this off anytime in Family Settings, after which each request needs your approval). Originals stay on your device and are uploaded encrypted only when fetched, then deleted after use.
Only when you use cloud restore, approve an original request, or use another explicit feature is that single image temporarily uploaded.
We do not sell your personal information or use your photos to train third-party commercial models.
Private and public are kept apart. The link between your on-device photos and a place never reaches the public surface; only content you publish yourself is visible to others, it goes through content-safety review, and you can withdraw it anytime.
2. Information we collect
You provide
Account: phone number, Sign in with Apple identifier and email address (if you choose "Hide My Email", we receive Apple's private relay address, which is still tied to your account), and/or WeChat openid, unionid, nickname, avatar if you choose.
Collaboration group name, invite codes, display names.
What you publish publicly: a visit photo, rating and short review for a place (visible to all users; you can withdraw it anytime).
Feedback and optional diagnostic logs (no photo originals).
With your permission
Photo library: local organize, albums, scan (see §6).
Location from photo EXIF, for place grouping and themed albums.
Device location, only while you use Nearby: to find photos taken nearby and to resolve nearby places. To resolve places, your coordinates go to our server and are passed to Amap. We do not track you continuously or record your movement history.
Automatic & operational
Server access logs (time, request path, status code, source IP). Search terms and coordinates for place lookup are redacted in access logs, never logged verbatim.
Push token (APNs device token), so we can deliver collaboration invites and original-photo requests. Used for push only, never for profiling.
Device model, OS version and app version are not collected automatically — they are sent only with feedback you submit yourself.
No crash-reporting or behavioral-analytics SDK is integrated: crash logs and performance data are never uploaded, and nothing is reported automatically.
3. How we use information
To provide the service, security, product improvement (aggregated), and legal compliance. Not for unrelated behavioral advertising.
4. Sharing
Collaboration members: only what you explicitly import to shared albums.
Other users (public surface): only the visit photo, rating and short review you publish yourself — your reviews show your nickname (or "Traveler" if you have not set one). They never see your on-device photos, visit records or photo-to-place links.
Processors under contract: cloud hosting, SMS, payment, and the content-safety service that reviews the photos and text you publish publicly.
Authorities when required by law.
5. Your rights & account deletion
Where available in the app, you may view and correct account information, delete specific cloud data, withdraw content you published publicly (visit photos and reviews, from the place page), manage face-data sharing, revoke system permissions, and delete your account.
Delete account: Profile → Privacy center → Delete account. We delete or anonymize cloud account data within 7 business days (except where law requires retention). We do not delete photos in your device’s Photos app.
Data export: We do not offer bulk export of account or cloud data, and we do not accept data-export requests by email or other out-of-app channels. To stop using the service and remove cloud data, use in-app account deletion.
6. Permissions
Permission
Purpose
Photos / media
Core features
Camera
Optional scan/capture
Location (only while using Nearby)
Finds photos taken nearby and resolves nearby places; to resolve places your coordinates go to our server and are passed to Amap. Optional.
Network
Sync, login, cloud restore
Notifications
Optional invites & notices
7. Face data
What face data does the app collect?
FotoNest computes mathematical face feature vectors (512-dimensional embeddings) from photos in your device's photo library. These vectors are irreversible — they cannot be used to reconstruct the original face image. No raw face images are extracted, stored, or transmitted as part of face data processing.
How is face data used?
Face embeddings are used by default on your device — grouping photos of the same person together so you can browse your library by person. This clustering runs on your device using the Apple Vision framework and InsightFace MobileFaceNet (CoreML); with your separate consent, embeddings are also used to support filtering by person within a shared album (see below). No face data is used for advertising, profiling, or any purpose beyond organizing your personal photo library.
Is face data shared with any third parties? Where is it stored?
By default, face data does not leave your device. Face embeddings and cluster data are stored locally in the app's private Application Support directory, which no other app can access. They are uploaded in only two cases:
When you add photos to a shared album: if faces are detected and you have given separate consent to upload face features, we upload the feature vectors of every face detected in those photos (never the original images) so members with add permission can filter by person within that album. Every shared album (including family albums) asks for your consent before the first upload; declining means nothing is uploaded and adding photos still works normally.
When you explicitly share a person with your family group: we upload that person's vector summary (centroid and exemplar vectors) so the same person can be recognized across devices in your family. A person you have not shared produces no such vector summary; note, however, that uploads are counted per detected face — if that person appears in a photo you upload, their feature vector in that photo is still uploaded under item 1 above. Upload does not distinguish whether you have shared that person.
All transfers are encrypted with TLS. Your original photos, location data, and edit history are not uploaded by these operations.
How long is face data retained?
On-device face data is retained as long as the app is installed; deleting the app permanently clears it.
Server-side face feature vectors are retained along with the photo or person they belong to. You can reduce or clear them by:
Revoking a person's family sharing: that person no longer participates in matching, and their centroid and exemplar vectors are deleted from our servers;
Deleting your account or submitting a deletion request: server-side face data is deleted within 7 business days.
Note: because vectors in a shared album serve the collaborative "filter by person" feature, moving a photo out of a shared album stops that photo from being visible to members, but does not automatically delete the face vectors already uploaded. To remove them completely, do so when deleting your account or submitting a deletion request, or contact us.
Where in the privacy policy is this described?
This section (§7 Face data) describes our face data practices in full. Additional detail on on-device processing can be found in §1 (Summary) and §6 (Permissions).
8. Children
Not directed at users under 14. We do not knowingly collect data from children under 14. Contact support@fotonest.app or use in-app feedback to request deletion.
9. Security & retention
TLS in transit; access controls on servers. Mainland China users’ data is stored in China where applicable. Temporary uploads are deleted per product rules.
10. Third-party SDKs
SDK
Purpose
Sign in with Apple
Login (identifier and email address — Apple's private relay address if you hide your email)
Place search and reverse geocoding: the coordinates and place keywords you use in Nearby, proxied by our server, used only to return nearby places and addresses
Content-safety service
Reviews the visit photos and text you publish publicly (machine review, with human fallback)
No third-party ad tracking SDKs in current builds.
11. Changes
Material changes will be announced in-app or on this page before taking effect where required.