Draft for product structure only — requires legal review before production use. Not legal advice.
Privacy Policy
Effective date: [MONTH DAY, YEAR]
This Privacy Policy explains how [LEGAL ENTITY NAME] (“FotoBay,” “we,” “us,” or “our”) handles information in connection with the FotoBay desktop software, mobile applications, local web interface, website, licensing and download services, and related support services (together, “FotoBay”).
FotoBay follows a strict data-minimization philosophy. We intentionally design FotoBay to collect as little information as reasonably possible to operate licensing, purchases, downloads, software updates, security, fraud prevention, and user-initiated support.
1. Data minimization
FotoBay is intentionally designed to collect only the information reasonably necessary to:
- activate licenses;
- validate purchases;
- provide software updates and downloads;
- investigate user-submitted bug reports;
- provide customer support;
- protect against fraud; and
- maintain service security.
We do not collect information merely for broad “product improvement” analytics, behavioral profiling, advertising, or engagement tracking.
2. Your photos stay on infrastructure you control
FotoBay is a personal photo-management and backup system. Your photos, videos, thumbnails, albums, tags, notes, captions, search history, GPS/EXIF metadata, face-related data, folder names, and other library content are primarily stored on computers, phones, and storage devices that you own or control.
FotoBay does not ordinarily upload or store your full photo or video library on FotoBay-operated cloud storage. Local transfer and synchronization normally occur across your local network between your own devices.
You choose the computer on which FotoBay runs, the drives and folders used for storage, which devices connect, and which libraries or folders are imported. If you use third-party backup, remote-access, NAS, VPN, or cloud-storage tools, those tools are outside FotoBay’s control and are governed by their own terms and privacy policies.
3. No continuous telemetry or usage analytics
FotoBay does not continuously collect diagnostic information. FotoBay does not continuously upload logs. FotoBay does not continuously upload telemetry. FotoBay does not continuously monitor how you use the application.
The desktop software and mobile applications operate locally without ongoing telemetry. No diagnostic information is transmitted automatically during normal use.
FotoBay currently does not collect usage analytics. FotoBay does not track feature usage, session duration, clicks, user behavior, navigation, engagement metrics, photo counts for analytics, or marketing analytics.
Only services necessary for software updates, licensing, purchases, downloads, or user-initiated support communications interact with FotoBay-operated online services during ordinary product use.
If analytics or continuous telemetry are ever introduced in a future release, this Privacy Policy will be updated and disclosed before deployment.
4. Information processed for website, licensing, and purchases
When you use FotoBay’s website or related online services, we may process limited information needed to operate those services. Depending on what you do, this may include:
- purchase and license information, such as the email address you provide for license delivery or recovery, license entitlement records, and activation-related identifiers;
- download and release information processed by our servers when you request a software download (for example, platform and release version);
- information you voluntarily submit in a support or bug report, such as a subject, description, optional contact email, and any diagnostics you consent to attach; and
- information needed for security, fraud prevention, and basic service operation of the website and APIs.
Payments may be processed by a third-party payment processor or merchant of record such as Stripe, Paddle, Apple, Google, or another provider. We do not necessarily receive or store full payment-card numbers. Those providers process payment information under their own privacy policies.
[Developer verification required before publication: confirm the live checkout, license-activation, and update endpoints and the exact fields each endpoint stores once payments and production licensing are enabled.]
[LEGAL DECISION REQUIRED: retention periods for purchase records, license records, support tickets, and server logs.]
5. Diagnostic data is collected only when you submit a report
Diagnostic information is collected only when you explicitly choose to submit a bug report or support request and, where diagnostics are attached, provide the required consent.
FotoBay may keep short-lived diagnostic logs on your own device to make a later bug report useful. Those local logs are not uploaded unless you choose to submit a report with diagnostics attached.
Bug reports are limited to technical diagnostics reasonably necessary to investigate the reported issue. They are not a channel for collecting your photo library.
6. Information that may be included in a bug report
When you consent to attach diagnostics, a report may include technical information such as:
- FotoBay app or Bay version;
- operating system and version;
- device model (on mobile apps);
- platform (for example, Windows, macOS, iOS, or Android);
- error codes and exception or error details;
- recent diagnostic event messages and timestamps;
- internal application state useful for troubleshooting, such as connection state, sync progress counts, permission status, preference flags related to backup behavior, job status, and license/entitlement status;
- available disk space or free storage indicators, when applicable;
- temporary cache size indicators, when applicable;
- network status useful for local-connection troubleshooting, such as connection state and masked local-network address information; and
- randomly generated or internal identifiers that are not intended to identify you personally, such as a device identifier or Bay installation identifier.
These identifiers are randomly generated or internal identifiers used to correlate technical state across devices and reports. They are not advertising identifiers, tracking identifiers, or marketing identifiers.
[Developer verification required before publication: confirm whether bug reports currently include CPU architecture, dedicated stack traces, database schema version, feature flags, memory usage, anonymous installation identifiers, anonymous library identifiers, or other fields beyond the verified list above. Do not publish unverified examples as current practice.]
7. Information never intentionally included in bug reports
FotoBay does not intentionally include any of the following in diagnostic reports:
- photos;
- videos;
- thumbnails;
- preview images;
- album names;
- Bay names;
- device names chosen by the user;
- folder names;
- tags;
- notes;
- captions;
- search history;
- user-created metadata;
- GPS metadata;
- EXIF metadata;
- face recognition data;
- user names;
- contact information, except an email address you voluntarily provide for a response; or
- file names.
Server-side sanitization also strips certain sensitive keys such as filenames, thumbnail fields, EXIF/GPS fields, album titles, and paths before storage when those keys appear in a diagnostics payload.
[Developer verification required before publication: current mobile diagnostic export code includes a displayName field. Remove that field or disclose it before publishing the “device names chosen by the user” exclusion as an absolute current-state claim.]
If a future version introduces diagnostic collection of additional information, FotoBay will update this Privacy Policy and provide explicit user disclosure before implementation.
8. Internal identifiers instead of user-generated names
When diagnostic reports need to reference application objects, FotoBay is designed to use internal identifiers rather than user-generated names. Examples include AlbumId, BayId, LibraryId, DeviceId, ImportJobId, SyncJobId, and ErrorId.
These identifiers exist solely to help developers diagnose software issues. They are not intended to contain album titles, Bay names, device nicknames, folder paths, or other user-authored labels.
This design reduces the amount of personal information included in diagnostic reports whenever practical.
9. Logging design
Diagnostic logging is designed to avoid user-generated content whenever practical. Developers intentionally prefer internal identifiers over names. For example, logs are intended to use AlbumId instead of an album name, BayId or DeviceId instead of a Bay name, and DeviceId instead of a user-assigned device name.
Local diagnostic logs may remain on your device until rotated or cleared by the software. They are not sent to FotoBay unless you submit a report with diagnostics attached.
10. Website and cookies
The FotoBay website is used for downloads, documentation, support forms, licensing-related flows, and related product pages.
[Developer verification required before publication: confirm whether the production website sets any cookies, local storage keys, visitor IDs, or attribution parameters. Do not describe marketing cookies or analytics pixels that are not implemented.]
When you request a download through FotoBay’s download service, our servers may record operational details such as the requested release, platform, and version for service operation. This is not continuous application telemetry and does not include photo library contents.
11. Third-party services
FotoBay may rely on third-party services to operate online functions, such as payment processing, app-store distribution, email delivery, hosting, object storage for oversized support attachments, or update distribution. Those providers process information as needed to provide their services and under their own privacy terms.
FotoBay does not endorse, and is not controlled by, Apple, Microsoft, Google, Stripe, Paddle, or other third-party providers merely because FotoBay interoperates with them.
[Developer verification required before publication: list only the third-party processors actually used in production.]
12. How long we keep information
Local photo libraries remain on your devices until you delete them or remove the storage you control.
For information held by FotoBay-operated online services, retention depends on the purpose of the record.
[LEGAL DECISION REQUIRED: publish concrete retention periods for support tickets, diagnostic attachments, purchase and license records, download logs, and security logs.]
13. Your choices and rights
You can choose whether to submit a bug report, whether to include diagnostics, and whether to provide a contact email for a response.
Depending on where you live, you may have rights to request access, correction, deletion, or a copy of personal information we hold about you, or to object to or restrict certain processing. Those rights are subject to applicable law and legal exceptions.
Accepting software terms does not by itself constitute consent for every form of data processing. Where consent is legally required, FotoBay will request it separately.
[LEGAL DECISION REQUIRED: add jurisdiction-specific privacy rights language and a verified request process once the operating entity and support email are finalized.]
14. Children
FotoBay is not directed to children, and we do not knowingly collect personal information from children below the minimum age required by applicable law.
[LEGAL DECISION REQUIRED: insert the applicable minimum age and parental consent approach.]
15. International use
FotoBay may be used internationally. If you access FotoBay-operated online services from outside the country where those services are hosted, your information may be processed in the United States or another country where we or our service providers operate.
Where mandatory local privacy or consumer laws provide stronger protections, those protections continue to apply to the extent required by law.
[LEGAL DECISION REQUIRED: confirm hosting regions and cross-border transfer language for the production deployment.]
16. Changes to this Privacy Policy
We may update this Privacy Policy for legal, security, product, or operational reasons. If we make material changes, we will provide reasonable notice by posting the updated policy on the website and updating the effective date. If a change introduces a new category of data collection that requires consent, we will request that consent before the new collection begins.
17. Contact
Privacy questions and requests may be sent to:
- Email: [SUPPORT EMAIL] / [LEGAL NOTICE EMAIL]
- Mail: [LEGAL ENTITY NAME], [MAILING ADDRESS]
You can also use FotoBay’s in-product or website support report flow when you need help with a product issue.
18. Related documents
This Privacy Policy should be read together with the FotoBay Terms of Service and End User License Agreement, Refund Policy, and any storefront or payment-provider disclosures presented at purchase.