Privacy policy

This is a draft prepared without a lawyer. A lawyer reviews it before launch.

Effective [date]. Version 0.1. [Company] is the controller for what this policy covers.

The short version

Your photographs never leave your Mac, and neither does anything derived from them. The app has no account, no sign-in and no upload. By default it sends us nothing at all. Two things we hold about you exist only because you gave them to us: an email address, if you joined the waitlist, and a purchase record, if you bought.

What the app processes on your Mac

All of this stays on your disk, in a folder you can copy or delete:

We never see any of it. There is no code path that sends it anywhere.

What leaves your Mac

By default, two network requests and nothing else. The app downloads the vision model once, from our file host, and asks once a day whether a newer version of the app exists. Neither request carries anything about your library, and neither needs an identifier.

Everything else is opt-in and described below.

The anonymous usage counts, if you turn them on

There is one switch, off by default, in Setup, labeled for what it does. Turn it on and the app records counts and durations. Every field of every event is a number. There are eight kinds of event and no others:

Each line carries a schema version and a timestamp to the second. A batch adds an anonymous install identifier, a random value made on your Mac when you turn the switch on and not derived from your hardware or your account, and the platform string. That is the whole payload. You can print the exact batch before it goes, from the app or the command line, through the same code that would send it.

What the counts never contain

This is enforced, not remembered. The code accepts an event name only from the list above, a field only from that event's own list, and a value only if it is a finite number. There is no field anywhere that accepts text, so a path cannot be recorded even by a caller that tries, and a test tries.

Turning the switch off deletes the pending records and the install identifier. Turning it on again mints a new identifier, so old and new records cannot be joined.

The website, the waitlist and buying

If you join the waitlist we store the email address you gave and the date. We use it to tell you when the app is ready and nothing else, we do not sell or rent it, and every message carries an unsubscribe link. Unsubscribing deletes the address.

If you buy, our payment provider acts as merchant of record and handles the transaction. We receive a purchase record: your email address, what you bought, when, the amount, and the country used for tax. We never receive your card number. The provider has its own privacy policy for what it collects.

The site uses no advertising or analytics cookies and runs no third-party trackers. Our host keeps standard server logs, including IP addresses, for a short period, for security and to keep the site up.

If you enable a feature that uses our servers

None of these exist today. If one ships it will be off until you turn it on, the app will say what it moves before it moves it, and this policy will be updated with the specifics first:

How long we keep things

Our lawful bases, where the GDPR applies, are your consent for the waitlist and the usage counts, performance of a contract for the purchase and the license, and legitimate interests for security and for keeping the service running.

Your rights

Wherever you live, write to [email] and we will act on it. You may ask us for a copy of what we hold about you, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on consent you may withdraw it at any time, which does not affect what we did before.

If you are in California: the categories above are all we collect, we collect them for the purposes stated, and we do not sell or share personal information as the CCPA and CPRA define those words. We have not in the preceding twelve months. We do not use sensitive personal information for inferring characteristics. You will never be charged a different price or given a worse product for exercising a right.

If you are in the EEA or the UK, you may also complain to your supervisory authority. Data we hold may be processed in [country] by us and by our providers, under standard contractual clauses or an adequacy decision where one applies.

We do not use your data for automated decisions with legal effects, and we do not profile you. The model the app fits is a model of your photographic taste, it is fitted on your machine, and we never receive it.

Children

Sieve is not for children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us something, write to [email] and we will delete it.

Security, changes and contact

We keep what little we hold on reputable providers, encrypted in transit, with access limited to the people who need it. No system is perfect, and we will tell affected people and the regulators where the law requires it.

If this policy changes materially we post it here with a new effective date and, where we have your address, email you. A change that would move data off your Mac in a new way will always be described before the feature that does it ships.

Contact: [Company], [address]. [email].