IMAGO
Privacy policy
In short. Your photos are processed on your device and don’t pass through our servers. Your Immich server’s key and address stay on the device. If you create an IMAGO account — which is optional — we keep your email and your edits to sync them between devices, and we delete everything when you delete the account. There are no ads and no analytics tools.
- Who is responsible
- What stays only on the device
- The IMAGO account
- Where the data is kept
- For how long
- Your Immich server
- Android permissions
- What we don’t do
- Your rights
- This website
- Changes
Who is responsible
IMAGO is published by 742 Studio, which is the controller of the data described here. For any privacy question, or to exercise your rights, write to hello@742studio.eu.
What stays only on the device
Without an account, nothing you do in IMAGO leaves the device. With an account, these still stay only on the device:
- Photos and videos. Every adjustment is computed on the device’s GPU, from the original file. No pixel — no thumbnails, previews or exports — is sent to our servers.
- The Immich API key and addresses. They are stored encrypted on the device where you typed them (on Android, in the system’s encrypted storage; on Windows, with the user’s data protection). They are not synced.
- The library catalog and cached thumbnails. Each device reads its own library.
Android’s automatic backup is turned off for the app, so these keys don’t leave the device that way.
The IMAGO account
The account is for one thing: finding the same work on all your devices. For that, we keep:
| Data | What for |
|---|---|
| Email and password | Signing in. The authentication service keeps only a hash of the password, which can’t be turned back into it. The email is used to confirm the account and recover the password; we send nothing else. |
| Your devices: name, system, registration and last-use dates | Knowing where each edit comes from. The name is the device model by default, and you can change it. |
| Edit recipes | The adjustment values of each photo — exposure, color, curves, masks, crop. They don’t contain the photo. |
| The fingerprint (SHA-1) of each edited photo | Recognizing the same photo on another device, by its content. The fingerprint can’t be used to rebuild the photo. |
| For device photos you edited or used in a composition: file name, size, date taken and dimensions | Finding that photo on another device while its fingerprint hasn’t been computed yet. |
| For Immich photos: the photo’s identifier on your server | Pointing to the same photo from another device connected to the same server. The server’s address is not sent. |
| Your libraries: the type, the name you gave them and a fingerprint of the Immich account (HMAC, keyed with your IMAGO account’s identity) | Recognizing that two devices are connected to the same library, without knowing where it is or who you are on Immich. |
| The export record | Knowing that a photo exported to Immich came from an original, so they can be grouped. |
| Presets, templates, brand kit and composition projects | Having them on all your devices. They refer to the photos they use, but don’t contain them. |
| Earlier versions of the records above, up to 20 per record | Not losing an edit when two devices change the same record offline. |
The legal basis is the performance of the service you asked for when you created the account (Article 6(1)(b) of the GDPR). The technical security logs described below rely on the legitimate interest in keeping the service secure (point (f)).
Account data is not end-to-end encrypted: it is readable on the server, protected by rules that only let each account read and write its own records. That’s why we keep only what sync needs — never credentials, server addresses, pixels, GPS location or the photos’ full metadata.
Where the data is kept
The account and sync run on Supabase, a database and authentication service from Supabase, Inc., in a project hosted in a European Union region. Supabase processes this data as a processor, on our behalf. Confirmation and password recovery emails are sent through it.
As with any server, the provider logs technical request data — such as the IP address and time — for operation and security.
Communication between the app and the account is always encrypted (HTTPS).
For how long
- While the account exists. Account data is kept until you delete it.
- When you delete the account, everything it keeps on the server is deleted immediately and permanently: the email, the devices, the libraries, the recipes, the earlier versions and the rest of the table above. You can do it in the app, under Settings → IMAGO account → Manage account → Delete account, or on the Delete your account page.
- When you remove a device from the account, that device’s record is deleted.
- The provider’s technical logs expire according to its own retention periods.
What is on each device stays there until you uninstall the app or clear its data.
Your Immich server
When you connect IMAGO to an Immich server, the app talks directly to that server, with the key you gave it. We don’t see that traffic and have no access to the server. The photos you export there stay on your server, under its rules. If the address you set up is HTTP rather than HTTPS, the connection to the server isn’t encrypted — that depends on how the server is configured.
IMAGO works with Immich servers, but is not affiliated with the Immich project.
Android permissions
| Permission | Why |
|---|---|
| Photos and videos | Showing the device’s gallery in the library, editing photos, and using photos and videos in compositions. You can give access only to the photos you choose. |
| Internet and network state | Talking to your Immich server and, if you have an account, syncing when there’s a network. |
| Foreground service (data sync) | Letting a long composition export finish after you leave the app, with a visible notification while it lasts. |
| Run at startup and keep awake | Used by Android’s background task system, to resume a pending sync or export. |
What we don’t do
- We don’t show advertising.
- We don’t use third-party analytics, tracking or crash reporting tools.
- We don’t sell or share data with third parties, other than the infrastructure provider described above.
- We don’t use your photos or your edits to train models, or for any purpose other than syncing them for you.
IMAGO is not directed at children.
Your rights
At any time, you can:
- Access and take your data. In the app, under Settings → IMAGO account → Manage account → Export data, you get an archive with one JSON file per type of data.
- Correct it, by editing it in the app, or by asking us by email.
- Delete it, by deleting the account in the app or on Delete your account.
- Object to or ask to restrict a processing activity, by email.
If you believe your data hasn’t been handled as it should, you can lodge a complaint with the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD).
This website
This website uses no cookies or analytics tools, and the fonts are served by the website itself. It is hosted on Firebase Hosting, a Google service: Google processes the IP address of each request as a processor, on our behalf, to detect abuse and produce usage statistics, and keeps it for a few months. Firebase Hosting runs on Google’s global infrastructure, so this data may be processed outside the European Union. On the Delete your account page, the email and password you type are sent directly to the account service, only to confirm that you are the account holder, and are not stored in the browser. If you close the language suggestion at the top of the page, that choice is remembered in your browser’s local storage, and nowhere else.
Changes
If this policy changes, the new version is published on this page, with the date it takes effect.