Privacy policy
This is a draft prepared without a lawyer. A lawyer reviews it before launch.
Effective [date]. Version 0.1. [Company] is the controller for what this policy covers.
The short version
Your photographs never leave your Mac, and neither does anything derived from them. The app has no account, no sign-in and no upload. By default it sends us nothing at all. Two things we hold about you exist only because you gave them to us: an email address, if you joined the waitlist, and a purchase record, if you bought.
What the app processes on your Mac
All of this stays on your disk, in a folder you can copy or delete:
- Your photographs, read from a Lightroom Classic catalog or a folder. The app opens them read only.
- File paths, names, capture dates, camera and lens, and the star ratings and rejects already in your catalog or in XMP sidecars.
- Renders it makes of your frames, and the embeddings it measures from those renders.
- The marks you make in the app, and the model it fits on them.
- A log of every sidecar write, so a write can be undone.
We never see any of it. There is no code path that sends it anywhere.
What leaves your Mac
By default, two network requests and nothing else. The app downloads the vision model once, from our file host, and asks once a day whether a newer version of the app exists. Neither request carries anything about your library, and neither needs an identifier.
Everything else is opt-in and described below.
The anonymous usage counts, if you turn them on
There is one switch, off by default, in Setup, labeled for what it does. Turn it on and the app records counts and durations. Every field of every event is a number. There are eight kinds of event and no others:
- app opened: how many seconds the app took to start.
- sources detected: how many photos, albums, renders, previews, unrated frames, rated frames and embeddings the library holds.
- frames embedded: how many frames were measured on demand, and how long it took.
- pick run: how many frames, picks, bursts, embedded frames and skipped frames a scoring run covered, and its duration.
- learn start: how many sets and training frames a run began with.
- learn finish: sets, frames, duration, labels, and whether the new model was kept, as a one or a zero.
- mark: that a mark was made, as a star from 0 to 5 and a flag as 0, 1 or 2.
- error: that something failed, as one of nine fixed words and a status number.
Each line carries a schema version and a timestamp to the second. A batch adds an anonymous install identifier, a random value made on your Mac when you turn the switch on and not derived from your hardware or your account, and the platform string. That is the whole payload. You can print the exact batch before it goes, from the app or the command line, through the same code that would send it.
What the counts never contain
- No file path, folder name, file name, album name or camera serial.
- No photograph identifier, no thumbnail, no pixel, no embedding, no score.
- No star tied to a frame. The mark event says a four-star mark was made. It has no field that could say which photograph got it.
- No name, host name, email address, IP address or anything else about you.
- No exception message and no traceback, because a message can contain a path.
This is enforced, not remembered. The code accepts an event name only from the list above, a field only from that event's own list, and a value only if it is a finite number. There is no field anywhere that accepts text, so a path cannot be recorded even by a caller that tries, and a test tries.
Turning the switch off deletes the pending records and the install identifier. Turning it on again mints a new identifier, so old and new records cannot be joined.
The website, the waitlist and buying
If you join the waitlist we store the email address you gave and the date. We use it to tell you when the app is ready and nothing else, we do not sell or rent it, and every message carries an unsubscribe link. Unsubscribing deletes the address.
If you buy, our payment provider acts as merchant of record and handles the transaction. We receive a purchase record: your email address, what you bought, when, the amount, and the country used for tax. We never receive your card number. The provider has its own privacy policy for what it collects.
The site uses no advertising or analytics cookies and runs no third-party trackers. Our host keeps standard server logs, including IP addresses, for a short period, for security and to keep the site up.
If you enable a feature that uses our servers
None of these exist today. If one ships it will be off until you turn it on, the app will say what it moves before it moves it, and this policy will be updated with the specifics first:
- Syncing your marks and your fitted model between Macs you own. That would move marks and a model, not photographs.
- Training on your embeddings in the cloud. Embeddings are measurements taken from a render, not the render. Your photographs would not be uploaded unless a feature says plainly that it uploads them and you turn it on.
- A web application or a mobile application, including reading favorites from a phone photo library.
- Sharing a set of picks with someone by a link, which would put the shared images on our servers for as long as the link lives.
- Diagnostics richer than the counts above.
How long we keep things
- Waitlist address: until you unsubscribe or ask us to delete it.
- Purchase records: as long as tax and accounting law requires, which is typically seven years.
- Usage counts, if you opted in: [retention period, intended 24 months] from receipt, then deleted.
- Server logs: [log retention, intended 30 days].
- Support email: until the matter is closed and a reasonable period after.
Our lawful bases, where the GDPR applies, are your consent for the waitlist and the usage counts, performance of a contract for the purchase and the license, and legitimate interests for security and for keeping the service running.
Your rights
Wherever you live, write to [email] and we will act on it. You may ask us for a copy of what we hold about you, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on consent you may withdraw it at any time, which does not affect what we did before.
If you are in California: the categories above are all we collect, we collect them for the purposes stated, and we do not sell or share personal information as the CCPA and CPRA define those words. We have not in the preceding twelve months. We do not use sensitive personal information for inferring characteristics. You will never be charged a different price or given a worse product for exercising a right.
If you are in the EEA or the UK, you may also complain to your supervisory authority. Data we hold may be processed in [country] by us and by our providers, under standard contractual clauses or an adequacy decision where one applies.
We do not use your data for automated decisions with legal effects, and we do not profile you. The model the app fits is a model of your photographic taste, it is fitted on your machine, and we never receive it.
Children
Sieve is not for children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us something, write to [email] and we will delete it.
Security, changes and contact
We keep what little we hold on reputable providers, encrypted in transit, with access limited to the people who need it. No system is perfect, and we will tell affected people and the regulators where the law requires it.
If this policy changes materially we post it here with a new effective date and, where we have your address, email you. A change that would move data off your Mac in a new way will always be described before the feature that does it ships.
Contact: [Company], [address]. [email].