Privacy Policy
1. Information we access
- Your media library. The app reads photo and video files from folders you choose. All processing, including face detection and grouping, happens locally on your computer.
- Google account (if you sign in). When you use "Sign in with Google" we receive your name, email address and your Google account identifier. These are stored in the app's local database on your device and are used to identify your account within the application. Your email address and Google account identifier are also recorded by our licensing service, so that an entitlement can be issued to your account — see section 6.
- Connected services (optional). If you connect Google Drive, Google Photos or YouTube, the app receives access tokens for those services. Tokens are stored encrypted in the local database on your device and are used only to perform actions you request, such as importing media or uploading a video you created.
2. Information we do not collect
- We do not upload your photos or videos to our servers.
- We do not receive face images, face embeddings, names you assign to people, tags, albums or location data.
- We do not have access to the contents of your Google Drive, Google Photos or YouTube account. Those requests go directly from your computer to Google.
- We do not sell personal information.
3. Google API Services — Limited Use
eMotion Picture's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Data obtained through Google APIs is used only to provide features you have explicitly requested within the application, is never sold, is never used for advertising, and is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition.
4. Anonymous usage analytics
The application uses Google Analytics to understand how it is used in aggregate (for example, which screens are opened). Each installation generates a random, memorable handle such as brave-otter-42. This handle contains no name, email address or other identifying information, and we cannot connect it to you unless you tell us your handle yourself.
5. Software updates
The application periodically contacts daam.ai to check whether a newer version is available, and downloads updates from there. These requests reveal your IP address and the application version you are running, as any web request does. Updates are cryptographically signed and are rejected by the application if the signature does not verify.
6. Account and licensing service
To establish which features an installation is entitled to, the application contacts a licensing service we operate. This happens only if you sign in with Google, and it is the only part of the application that sends account information to a server we control.
What is sent. Immediately after a successful sign-in, the application sends the identity token Google issued for that sign-in, together with a random identifier for that installation. The identity token proves to our service that Google — not the application — vouched for who you are. It is valid for about an hour, is passed straight through, and is never stored by the application or by our service.
What is retained. The service keeps your Google account identifier, your email address, the installation identifier, and the subscription tier associated with your account, along with the dates those records were created and last used. Nothing else is retained: no media, nothing derived from media, and no Google Drive, Google Photos or YouTube content or credentials.
The installation identifier is a random value generated on your own computer. It is not derived from your hardware and contains no personal information. It exists so an entitlement can be issued to one installation rather than to a machine we would otherwise have to recognise.
In return the service issues a short-lived signed entitlement, which is stored on your computer and remains valid offline for 14 days. If the service cannot be reached, the application continues with the entitlement it already holds; once that lapses, only features that depend on our server are withheld. Your library, your database and all local processing remain available indefinitely, with or without a network connection.
7. Where your data is stored
All application data — your media index, face data, tags, settings, account record and any connected-service tokens — is stored in a database file on your own computer. Apart from the account record described in section 6, it is not replicated to us. Backups the application creates before an update are also written to your own storage.
8. Protection of sensitive data
This section describes the mechanisms that protect sensitive data, including all data obtained through Google APIs under sensitive and restricted scopes.
We treat the following as sensitive data:
- Google user data obtained under restricted scopes — Google Drive file content and metadata accessed with the drive scope.
- Google user data obtained under sensitive scopes — YouTube account data accessed with the youtube scope.
- OAuth credentials — the access and refresh tokens that authorise the above.
- Your Google profile — name, email address and account identifier received when you sign in.
- Your personal media — photos and videos, and everything derived from them, including face detections, biometric face embeddings, tags and location data.
The strongest protection is structural: eMotion Picture processes sensitive data on your own computer. Your media, everything derived from it, and every OAuth credential are never transmitted to, stored on, or accessible from any server we operate. We hold no copy of them, and no employee, contractor or third party can access them. The mechanisms below protect them on your device and in transit to Google.
The one deliberate exception is the account record described in section 6: if you sign in with Google, your email address and Google account identifier are held by our licensing service. That record is limited to what is listed there, and it never includes media, data derived from media, or credentials for any connected service.
Encryption in transit
- All communication with Google APIs uses HTTPS/TLS. Certificate validation is always enabled and is never bypassed.
- Requests to Google Drive, Google Photos and YouTube go directly from your computer to Google. They are not proxied through our servers.
Encryption at rest
- OAuth access and refresh tokens are encrypted before being written to the local database, using Fernet (AES-128-CBC with HMAC-SHA256 authentication) from the cryptography library. Tokens are never stored in plain text.
- The encryption key is machine-local. It is held either in an environment variable or in a key file stored outside the database and created with owner-only permissions, so a copied or backed-up database is unusable without the key from that machine.
Access control
- The application requires you to sign in. Every internal service refuses requests that do not carry a valid session.
- Session tokens are stored only as SHA-256 hashes — the raw token exists solely in your browser cookie, which is set HttpOnly and SameSite so it cannot be read by scripts or sent cross-site.
- Where a local password is used, it is stored as a PBKDF2-HMAC-SHA256 hash with 240,000 iterations and a unique per-user salt. Passwords are never stored in a recoverable form.
- Changing credentials invalidates all existing sessions.
Data minimisation
- The application requests only the permissions needed for the features you use, and connecting Google Drive, Google Photos or YouTube is optional and initiated by you.
- Signing in requests only your basic profile (name, email address and account identifier). It does not request access to your files.
Software integrity
- Application updates are cryptographically signed with an Ed25519 key. The application verifies the signature and checksum of an update before it is written to disk or applied, and refuses anything that does not verify. The signing key is held offline and is never present on a server.
Retention and secure deletion
- Sensitive data is retained only for as long as you keep the application installed and the relevant service connected. Other than the account record in section 6, there is no server-side copy with an independent retention period.
- Disconnecting Google Drive, Google Photos or YouTube deletes the stored credentials for that account from the local database immediately.
- Revoking access at myaccount.google.com/permissions invalidates the tokens at Google, after which they cannot be used even if a copy of the database still exists.
- Because tokens are encrypted with a machine-local key held outside the database, deleting that key renders every stored credential permanently unrecoverable.
Incident response
- We hold no copy of your media, of anything derived from it, or of your connected-service credentials, so a compromise of our systems cannot expose them. The account record in section 6 is the only user data on our systems. Should we become aware of an incident affecting user data, we will notify affected users at the address associated with their account and describe the impact and the steps taken, without undue delay.
- Security concerns can be reported to support@daam.ai.
9. Data retention and deletion
- You may disconnect Google Drive, Google Photos or YouTube at any time from within the application, which deletes the stored tokens for that account.
- You may revoke the application's access to your Google account at any time at myaccount.google.com/permissions.
- Uninstalling the application removes the program. Your media files and the application database remain on your computer until you delete them.
- To have the account record described in section 6 deleted from our licensing service, write to support@daam.ai from the email address you signed in with. Deleting it does not affect anything stored on your own computer, and you can sign in again afterwards.
10. Children's privacy
eMotion Picture is not directed to children under 13, and we do not knowingly collect personal information from children.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "last updated" date above and, where appropriate, noted in the application's release notes.
12. Contact
Questions about this policy can be sent to support@daam.ai.