Privacy Policy
- Service: IMgest (the "App")
- Provider: LIMOD
- Contact: [email protected]
1. Summary
IMgest safely copies photos and videos from SD cards into a library folder you choose. The guiding principle is "safety over convenience": originals are never modified or deleted (except via an explicit opt-in option).
- Your original, full-resolution photos and videos remain on your device. They are not uploaded; AI naming uses only the stripped, downsized analysis copies described below.
- Only when you use AI folder naming, a small number of downsized images (≤768px wide, with all metadata and GPS removed) and text metadata (date, clip count, representative filename, etc.) are sent to an AI service.
- Pseudonymous error reporting is initially enabled. Scrubbed diagnostics are sent only when an error or crash occurs, and you can turn reporting off anytime in Settings.
- Payments are handled by Paddle; the App never sees your card details.
2. What we process
2.1 On-device only (never transmitted)
- Photo/video files and their contents
- File paths, sizes, hashes (for integrity verification), capture times
- App settings stored locally on your computer
- Import job reports written inside your own library folder
2.2 Sent only when AI folder naming is used
- Downsized images: a representative frame/photo re-encoded to a JPEG ≤768px wide with EXIF/GPS and all other metadata stripped. The original file, original resolution, and location data are never sent.
- Text metadata: date, clip count, time of day, device type, representative filename, media type, and the existing folder name when one is reused (which may be a name you chose yourself). Representative filenames and existing folder names may contain personal information such as user-chosen names or places. Full file paths are not included.
- A random pseudonymous installation identifier (
install_id, a random UUID — not tied to hardware or account). It is sent to the LIMOD hosted service (api.actioncam.dev) with the naming request for quota accounting, and is not forwarded to AI model providers. - Detailed AI-usage metering records:
install_id,request_id, usage month and job/date bucket, app/model/prompt/pricing versions, quota source, status and error code, frame count and dimensions, token and cost data, whether quota was charged, latency, and record time. These records are kept in Cloudflare D1 for cost, quality, and error analysis for up to 90 days, then deleted. They do not store images or full file paths. - AI-request deduplication records: to prevent duplicate charges or model calls and replay a result after response loss, Cloudflare D1 stores the pseudonymous IDs, request-payload SHA-256, status, internal charge token, and a sanitized result. The sanitized result is deleted after up to 90 days. A minimal tombstone is retained as needed to prevent duplicate calls, charges, or refunds. Prompts, images, and full file paths are not stored in this record.
- Current quota balances and charge, refund, and duplicate-processing markers are separate from detailed metering records. They are retained only for as long as necessary to provide entitlements and prevent duplicate charges or refunds.
2.3 Pseudonymous error reporting (initially enabled, can be turned off anytime)
- Reporting is enabled on first run. While enabled, anonymized diagnostics (error kind,
anonymized stack trace, app version, OS version, random
install_id) are sent only when an error or crash occurs. - On receipt, the server derives an approximate country from the request IP and stores it; the IP address itself is not stored.
- Your username, file paths, API keys, and email are scrubbed before sending.
- You can turn it off anytime in Settings › Diagnostics.
2.4 Payments & licensing
- Payments are processed by Paddle as Merchant of Record. The App does not store or read card data.
- When restoring on a new device, the email address you enter is sent to verify your license.
- LIMOD keeps a minimal pseudonymous Paddle transaction index
(
paddle_transactions) in Cloudflare D1: Paddle transaction and subscription IDs, the randominstall_id, product ID, quantity, entitlement kind and lot reference, event time, and record time. It is used to grant and restore entitlements and reconcile refunds or chargebacks. Each transaction-index row is deleted 5 years after it is recorded. - Separate current entitlement state and markers for refunds or chargebacks, entitlement transfers, and duplicate-grant prevention are also kept in D1. They are retained only for as long as necessary to provide active entitlements, prevent re-grants, and meet legal or dispute-resolution needs.
- If a Paddle webhook cannot be matched to an installation, a recovery record may temporarily contain the Paddle event and transaction IDs, product and entitlement kind, purchaser email when supplied by Paddle, the original webhook payload, failure reason, timestamps, and any resolution installation ID. This is used only to recover or reconcile the purchase and is deleted after 90 days whether resolved or unresolved.
2.5 Optional diagnostic sharing (per-case opt-in, nothing sent by default)
- When the AI names a folder oddly, you can send that single case, with your explicit consent, to the developer to help improve naming quality. There is no bulk logging and no automatic sending. You must tap [Send] on screen for each folder; if you cancel, nothing is transmitted.
- What is sent is the same shape used for AI naming: up to 3 downsized JPEGs (≤768px wide, with EXIF/GPS and all metadata stripped) plus naming metadata (the AI's candidate name, your corrected name, confidence, model and provider, reason and cues, and optionally the classification prompt) and a free-text note you write. Original photos, full resolution, file paths, and volume names are never sent.
- It includes the same random pseudonymous
install_idused for metering. This feature is separate from AI usage metering and does not consume any quota (no charge). - The destination is developer-controlled Cloudflare (R2/D1,
api.actioncam.dev), and cases are retained for up to 30 days, then automatically deleted. You may request deletion anytime at [email protected].
3. Everywhere your data may go (sub-processors)
| Recipient | Purpose | What is sent | When |
|---|---|---|---|
| Anthropic | AI model (Claude) | metadata-stripped downsized images and text metadata (no install_id) | AI on |
| Google AI | AI model (Gemini) | metadata-stripped downsized images and text metadata (no install_id) | AI on |
| OpenAI | AI model (BYOK) | metadata-stripped downsized images and text metadata (no install_id) | When using your own OpenAI key |
LIMOD hosted service (Cloudflare Workers, api.actioncam.dev) | AI folder-name relay and detailed metering / license check / restore / pseudonymous error reports | metadata-stripped downsized images, text metadata that may contain user-chosen personal information, install_id, request_id, model/status and token/cost data, (restore) email, pseudonymized diagnostics | AI on / purchase / restore / an error or crash while error reporting is enabled |
Cloudflare (R2/D1, api.actioncam.dev) | Store optional diagnostic sharing (naming quality) | metadata-stripped downsized images (≤3), naming metadata, your note, install_id (no file paths or volume names) | Only when you tap [Send] for a folder yourself (per-case opt-in) |
| Paddle | Payments | payment info (collected by Paddle) | At purchase |
Update feed (updates.actioncam.dev) | Auto-update check | app version, IP (incidental) | Direct-distribution macOS/Windows builds only; not the Microsoft Store package |
The Windows Microsoft Store package does not contact updates.actioncam.dev.
Microsoft Store manages installation and updates for that package.
Google's official Gemini API abuse-monitoring policy states that Google may retain prompts, contextual information (which can include the stripped, downsized analysis images supplied as context), and model output for up to 55 days to detect and prevent prohibited-use violations, maintain service safety and security, and make required legal or regulatory disclosures. This is provider-side retention: LIMOD's hosted service handles automatic naming images in memory and does not persist them.
Each sub-processor has its own privacy policy (Cloudflare, Anthropic, Google, OpenAI, Paddle).
3.1 Cross-border transfer of personal data
When you use AI folder naming, some data is transferred outside Korea to recipients located in the United States. Under Korea's PIPA (Art. 28-8) we disclose the following:
- Items transferred: metadata-stripped downsized images (thumbnails, ≤768px
wide), text metadata (including capture date, a representative filename, and a reused existing
folder name), a random pseudonymous
install_id, and the detailed AI-usage metering fields described above. Representative filenames and existing folder names can be user-chosen strings and may contain personal information such as names or places. Original photos, full-resolution files, full file paths, and GPS location are not transferred. - Destination country: United States. (When: in real time while the AI naming feature is in use · How: via HTTPS API calls.)
- Recipients: Cloudflare, Inc. (infrastructure for the LIMOD hosted service), Google LLC (Gemini model), and Anthropic, PBC where applicable.
- Purpose and retention/use period: for folder-name classification. The LIMOD hosted service does not persist images from automatic naming requests; detailed AI-usage metering records are kept in Cloudflare D1 for up to 90 days. AI providers process request data under their respective API data policies. Google's Gemini API abuse-monitoring policy allows the provider-side retention described above for up to 55 days.
- How to refuse and the effect: turning off AI folder naming stops the AI naming transfer described above, and the app keeps working normally using date-based folders. Other service traffic may still occur when you make or restore a purchase, an error or crash occurs while error reporting is enabled, you opt in to a per-case naming report, or a direct-distribution build checks for updates.
For users in the EU/EEA, the terms and transfer safeguards relevant to transfers to the United States depend on the service provider and service used. Where applicable, a provider's terms may include standard contractual clauses or data processing terms. Contact [email protected] for current information about the providers and terms used for IMgest.
4. Retention & deletion
- On-device data is deleted when you remove the app, its settings, and job reports.
- Downsized images sent for AI naming pass through the LIMOD hosted service, are handled in memory only for the naming request, and are not persistently stored there.
- LIMOD does not store images from the automatic import and AI-naming pipeline. This does not override Google Gemini's provider-side abuse-monitoring retention of prompts, context, and output for up to 55 days. Only individual cases you deliberately share with LIMOD via the optional diagnostic sharing in §2.5 are retained for up to 30 days, then automatically deleted (metadata-stripped downsized images ≤3 plus naming metadata). Deletion requests: [email protected].
- Pseudonymous error reports are retained for up to 90 days, then deleted.
- Detailed AI-usage metering records (
ai_usage_events) are retained for up to 90 days, then deleted. - Sanitized results in AI-request deduplication records
(
ai_folder_requests) are deleted after up to 90 days. Minimal tombstones used to prevent duplicate calls, charges, or refunds remain in those records for as long as needed. - Current quota balances and charge, refund, and duplicate-processing markers are retained separately for only as long as necessary to provide entitlements and prevent duplicate charges or refunds.
- Paddle webhook recovery records, including the original payload and purchaser email when present, are deleted after 90 days whether resolved or unresolved.
- Each Paddle transaction-index (
paddle_transactions) row described in §2.4 is deleted 5 years after it is recorded. - Separate current entitlement state and markers for refunds or chargebacks, entitlement transfers, and duplicate-grant prevention are retained only for as long as necessary to provide active entitlements, prevent re-grants, and meet legal or dispute-resolution needs.
5. Your rights
Depending on where you live (e.g. EU GDPR, Korea PIPA, California CCPA) you may request access, correction, deletion, or to object to processing. Contact [email protected]. Most data lives on your device, so you can manage and delete it directly.
6. Children
The App is not directed to children under 14 (or your local minimum age).
7. Changes
This policy may change; we will notify you of material changes in the app or on the website.
8. Contact
LIMOD — [email protected]