CaptureKeep

Privacy policy

Draft release content. Provider configuration and critical language review are pending.

Who operates CaptureKeep

Thomas Scheiber, Universumstrasse 50, 1200 Wien, Austria. Contact support@thomasscheiber.com for privacy questions or deletion requests.

Screenshots and local analysis

CaptureKeep reads the photos you authorize and the images, PDFs, text, and links you import. OCR, barcode reading, classification, and available model assistance run on your device. Screenshot contents are not sent to a developer-hosted analysis service. An imported file is copied into protected app storage; original Photos assets remain in Photos. Saving or archiving changes local organization and does not delete an original.

Optional iCloud sync

If you purchase the lifetime unlock and enable sync, analysis metadata is stored in your private iCloud database. This includes titles, categories, recognized or supplied text, corrected fields, notes, organization, and available Photos cloud mappings. Imported image and PDF binaries and device-local file paths are not transferred by this sync. Photos availability on another device depends on your Apple settings and permissions. Sensitive captures are excluded; review that setting before enabling sync. Apple provides the iCloud service under its own terms.

Purchases

Apple processes the in-app purchase. RevenueCat helps validate and restore the entitlement using an app-scoped identifier and purchase information. CaptureKeep does not receive your payment card details. Losing an entitlement does not delete the local library.

Advertising and consent

The Free tier can show Google AdMob banners and bounded interstitials after useful work. Paid users do not receive ads. The provider may process device information, identifiers, IP address, ad interactions, and consent choices according to the selected consent and privacy options. Personalized advertising requires applicable provider consent and Apple tracking authorization. Declining tracking does not block local features or support. Advertising choices are available in Settings. No ads appear in widgets, the share extension, or support and recovery flows.

Reports you choose to send

A report sends only the text and optional reply email you review. Screenshots and extracted library content are not attached automatically. Cloudflare Workers and D1 receive the report and delivery receipt; a scoped GitHub integration creates an issue in the private support repository. A random receipt secret authorizes access to that receipt. The server stores its hash, not the secret. Security checks and bounded rate limits help protect the service. We do not add a product analytics service.

Retention

Unsent drafts are retained locally for up to 30 days. Delivered relay payloads are removed within seven days of confirmed delivery; terminal failed payloads are removed after 30 days. Receipt and deduplication records are retained for 90 days from acceptance. Content-free operational logs, if enabled, are kept for at most 14 days. Personal report text and contact details are removed from closed GitHub reports within 90 days of closure. An unresolved uncertain delivery is held for operator reconciliation rather than silently resent or erased. Provider backups and statutory obligations may limit immediate erasure.

Choices and rights

You can change Photos access in Apple Settings, organize or delete local analysis, control optional sync, and change advertising choices. Contact support@thomasscheiber.com for access, correction, deletion, restriction, portability, objection, or consent withdrawal concerning data received through support. Include your authorized receipt or enough contact information to verify the request. You may complain to the Austrian Data Protection Authority at dsb.gv.at. Mandatory privacy rights are not limited by this policy.

Service providers

Apple, Google, RevenueCat, Cloudflare, and GitHub have their own privacy information. Their processing locations, safeguards, and service availability can differ. Optional transfers for sync, advertising, purchases, and support are separate from local analysis. This policy must match the configured release; a developer preview with integrations disabled is not evidence that a production SDK collects no data.