Privacy
Bestkept looks at every photograph you own. That is exactly why it does the looking on your iPhone and nowhere else.
What never leaves
Your photographs, their thumbnails, their filenames, your album names, and every measurement the app makes about them — sharpness, exposure, faces, duplicates, dates. All of it is computed on-device and stored on-device. There is no server holding a copy, because there is no server.
The first request: place names
When you sort your library by place, the coordinates already stored in a photo's metadata are sent to Apple's geocoding service to get a city name back. No image is attached. If you never open the place view, this request never happens.
The second request: crash reports
Released versions of the app send crash reports through Sentry, hosted in the European Union. A report contains a stack trace and a device model. It is configured well below the defaults for this app in particular:
- No screenshots. A screenshot of Bestkept is a screenshot of your photo library.
- No view hierarchy, which would carry the labels around every thumbnail.
- No breadcrumbs, which would record which months and places you opened.
- No performance traces, and no IP address or device name.
There is no account to attach a report to, so none is attached.
The third request: which screens get reached
Released versions send nine counters through TelemetryDeck, hosted in Germany. They exist to answer one question — where people stop — and they are listed here in full, because a list you cannot read is not a disclosure:
- Onboarding started and onboarding finished, so the drop-off between them is visible.
- Preparation finished, because the first read of a large library is the app's longest wait.
- A pile opened, and whether it was a month, a place or the recent shots.
- The daily session claimed, and a decision blocked once it is spent.
- The paywall shown, with which of the four places it was raised from.
- A purchase completed, and a subscription restored.
What that is not: no photograph, no filename, no album, no place, no date from your library, no screen contents, no advertising identifier, no cookie, and no record of a single tap that is not on the list above.
The identifier attached to them is derived from an iOS value that already resets when you remove the app, then salted and hashed on your phone before it is sent, then salted and hashed again on arrival. Neither TelemetryDeck nor we can turn it back into a device or a person.
Nothing is sent from a build running on a developer's machine, and nothing is sent from TestFlight. These counters begin at the App Store version and nowhere earlier.
Purchases
Subscriptions are handled by Apple and by RevenueCat, which records an anonymous identifier and whether that identifier has an active subscription. It never receives your name, your email, your card, or anything about your photographs. Apple handles the payment; we never see it.
Photo library permission
Bestkept asks for access to your photo library because it cannot do its job without it. The permission is requested after the app has explained what it is for, and iOS asks you again before any photo is deleted. You can withdraw access at any time in iOS Settings.
Your rights
There is no account. The counters described above are irreversibly hashed twice before anyone can see them, so there is no record anywhere that can be traced back to you and therefore nothing to export or erase on request. Deleting the app removes everything Bestkept has ever stored about your library, and resets the identifier behind those counters at the same time.
Children
Bestkept is not directed at children under 13, collects nothing that identifies anyone of any age, and shows no advertising.
Changes
If this policy changes, the date at the top changes with it, and any change that affects what leaves your phone will be announced in the app before it takes effect.
Contact
Questions? Email support@bestkept.app.