PrivyMark

Privacy Policy

The short version

PrivyMark collects nothing. Your photos are processed entirely on your device, are never uploaded anywhere, and we keep no copies. The app has no account system, no analytics, no ads and no tracking of any kind.

How your photos are handled

Scanning, redaction and export all run locally using Apple's on-device frameworks (Vision, Core Image, and on capable devices Apple's on-device foundation models). Photos never leave your device through PrivyMark. If a photo you pick is stored only in iCloud, iOS downloads it to your device through Apple's own system — it does not pass through any server of ours; we don't operate any.

Face data

PrivyMark detects faces only to draw a box around them so you can cover them. It uses Apple's on-device Vision framework, which returns nothing more than the rectangle a face occupies in the image. PrivyMark does not create, use, or store a faceprint, face template, or any other biometric identifier, and it cannot recognise or identify who a person is. Those rectangles exist only in memory while the photo is open in the editor and are discarded when you close it — nothing about a face is written to disk, included in an exported image, shared with any third party, or transmitted off your device. Because none of it is stored or sent anywhere, the retention period is the length of that one editing session.

On-device AI, no third-party AI services

On devices that support it, PrivyMark makes an extra pass over the text found in your photo using Apple's on-device foundation model (Apple Intelligence), to catch names and ID numbers the pattern rules miss. That model runs entirely on your device. PrivyMark does not use Private Cloud Compute, and it does not send your photos, the text found in them, or any other personal data to OpenAI, Google, Anthropic, or any other third-party AI service, cloud service, or server. The app has no backend of its own.

Permissions

PrivyMark asks for photo library access only to show your photo grid and to save results; Limited access is fully supported, and you can also use the app without any access via the built-in sample image. The app does not use the camera, microphone, or location.

Metadata in your exports

When you export, PrivyMark strips GPS location by default and lets you decide about other metadata (device model, timestamps, and so on). The optional hidden-mark scrub additionally clears pixel low-bits and removes all metadata from the exported file.

No tracking, no third parties

PrivyMark contains no analytics, no advertising SDKs and no third-party tracking of any kind. It sends no telemetry. There are no crash reports containing your images or recognized text.

Nothing is retained

PrivyMark keeps no history and no copies of your images. Photos handed to PrivyMark through the share sheet are stored briefly in the app's private container and deleted immediately after they are read.

Children

PrivyMark does not collect personal information from anyone, including children.

Changes to this policy

If this policy changes, the updated version will be posted on this page with a new date. Since the app collects nothing, changes are expected to be rare and editorial.

Contact

Questions about privacy? Email appstore@hz.do.

Last updated: July 20, 2026