photoWhisper Privacy Policy
1. Who we are
photoWhisper (“the App”) is an on-device steganography tool. You can encrypt text, embed it in image pixels, and later extract it from a lossless PNG using your password.
2. What data do we collect?
We do not collect personal data. The current App:
- does not require accounts or sign-in;
- does not transmit photos, text, passwords, or usage logs to developer servers;
- does not integrate third-party analytics, advertising, social login, or crash-reporting SDKs;
- does not use IDFA or engage in cross-app / cross-site tracking.
In App Store Connect App Privacy, the developer declares Data Not Collected.
3. How your content is used on device
The following stays on your device (or places you explicitly choose, such as Photos or the pasteboard). It is not collected by us:
3.1 Photos
- Read: via the system photo picker to select a cover or stego image for local embed / extract.
- Write: after you confirm, save a lossless PNG to your Photo Library.
- You can revoke Photos access anytime in iOS Settings.
3.2 Text you enter
Message text is handled in memory: encrypted with your password, then written into image LSBs. We have no remote access to that text.
3.3 Passwords
Passwords you create are used only on device for key derivation (PBKDF2) and AES-GCM. They are not uploaded to us and not used for advertising. If you forget the password, hidden content may be unrecoverable—this is expected for local encryption.
3.4 Pasteboard
Decrypted text is written to the system pasteboard only when you tap Copy on the decode screen.
4. Encryption (transparency)
The App uses standard cryptography so content cannot be trivially read without the password. Encryption is local and does not change the fact that we do not collect your data. Export-compliance disclosures are handled separately in the App Store submission flow.
5. Sharing and sale
We do not share, sell, or rent personal data to third parties. Because we do not collect it, there is nothing to disclose to ad networks or data brokers.
6. Children
The App does not collect data from children. We do not knowingly collect personal information from children under 13.
7. Retention and deletion
We do not store your content on servers, so there is no cloud copy to delete via a developer request. You can remove local materials by deleting the App, deleting related photos, and clearing the pasteboard.
8. Third parties and this website
The App binary does not embed third-party data-collection SDKs. If this privacy site is hosted on GitHub Pages, GitHub may process standard web logs under its own policies—separate from in-app processing.
9. Changes
If a future version introduces optional data collection (for example, diagnostics), we will update this policy and the App Store privacy labels.
10. Contact
Privacy questions: Support.
11. App Store privacy label mapping
| Data type | Collected? | Notes |
|---|---|---|
| Contact Info | No | — |
| Health & Fitness | No | — |
| Financial Info | No | — |
| Location | No | — |
| Sensitive Info | No | — |
| Contacts | No | — |
| User Content (photos / text) | No* | On-device only; not received by developer |
| Browsing / Search History | No | — |
| Identifiers | No | No IDFA / account ID reporting |
| Usage Data / Diagnostics | No | No analytics or cloud crash reports |
*Under Apple’s definition, “collection” generally means transmission off device to a developer- or third-party-controlled environment. photoWhisper keeps photos and text on the user’s device and Photo Library; hence “Data Not Collected.”