Your photos never leave your device. Tidy processes all photos and videos entirely on your iPhone or iPad. No images are ever uploaded to any server, ever.
This Privacy Policy describes how NFO LTD ("we", "us", or "our") collects, uses, and protects information when you use Tidy - Photo Cleaner ("Tidy", "the App"). We are committed to protecting your privacy and being fully transparent about our data practices.
This policy complies with major international privacy regulations, including: GDPR (EU General Data Protection Regulation), CCPA/CPRA (California Consumer Privacy Act), LGPD (Brazil's General Data Protection Law), PIPEDA (Canada's Personal Information Protection and Electronic Documents Act), POPIA (South Africa's Protection of Personal Information Act), and APP (Australian Privacy Principles).
Table of Contents
1. Information We Collect
Tidy collects a minimal amount of anonymous, non-personal data to help us improve app performance and stability. We do not require you to create an account, sign in, or provide any personal information to use Tidy.
Analytics Data
We use Firebase Analytics to collect anonymous usage data, including:
- Screen views and navigation patterns within the app
- Feature usage (which tools and filters are used most)
- Session duration and frequency
- Device type, model, and operating system version
- App version
- General region or country (derived from IP address, but IP addresses are not stored)
This data is collected in aggregate and cannot be used to identify you personally.
Crash Reports
We use Firebase Crashlytics to collect crash reports when the app encounters an error. These reports include:
- Device model and operating system version
- App version and build number
- Stack traces and error logs
- General information about app state at the time of crash
Crash reports do not contain photos, personal files, or personally identifiable information.
Performance Data
We use Firebase Performance Monitoring to measure app performance, including:
- App startup time
- Network request response time (for subscription verification only)
- Screen rendering performance
Push Notification Tokens
If you choose to enable push notifications, we receive a device token through Firebase Cloud Messaging. This token is used solely to send notifications about app updates and features. You can disable notifications at any time through your device settings.
Subscription Information
If you subscribe to Tidy Gold, your subscription is managed entirely by Apple through StoreKit 2. We receive confirmation that your subscription is active, but we do not have access to your payment details, Apple ID, or billing information. All payment processing is handled by Apple in accordance with their Privacy Policy.
Information We Do Not Collect
We want to be clear about what Tidy does not collect:
- Photos and Videos - Your photos and videos are not uploaded, transferred, or sent to any server. All processing happens entirely on your device.
- Personal Identification - We do not collect your name, email address, phone number, or any other personally identifiable information. No account or login is required.
- Location Data - We do not track your location. Tidy's photo map feature uses existing location metadata (EXIF data) already embedded in your photos, and this data is read and displayed on-device only.
- Contacts - We do not access or collect your contacts or address book.
- Camera or Microphone - Tidy does not access your camera or microphone. We only access your photo library with your permission.
- Browsing History - We do not track your browsing activity outside the app.
2. How We Use Information
The limited anonymous data we collect is used to:
- Improve the App - Understanding which features are used most helps us prioritize development
- Fix Bugs - Crash reports help us identify and resolve issues quickly
- Optimize Performance - Performance metrics help us ensure the app runs smoothly
- Send Notifications - Delivering relevant updates about new features or improvements (only if you consented)
- Verify Subscriptions - Confirming your Tidy Gold subscription status through Apple
We do not use your data for advertising, profiling, selling to third parties, or any purpose other than improving Tidy.
Fully On-Device AI Processing
All of Tidy's artificial intelligence and machine learning features run entirely on your device using Apple's Vision and Core ML frameworks. This includes:
- Blur and Quality Detection - Analyzes image sharpness and quality scores locally
- Duplicate and Similar Photo Detection - Compares photos on-device to find duplicates
- Face Detection and Beauty Filters - Identifies faces and applies enhancements locally
- Smart Categorization - Groups photos by content type using on-device models
- AI-Enhanced Editing - Applies creative filters and enhancements locally
No image data, image analysis results, or derived information is ever sent to any external server.
3. Third-Party Sharing
Tidy uses the following third-party services for analytics and app improvement purposes only. None of these services receive your photos or personal content.
Firebase Analytics (Google)
We use Firebase Analytics to understand how people use Tidy so we can improve the app. Firebase Analytics collects anonymous usage data such as screen views, feature interactions, and session information. For more details, see Firebase Privacy Information and Google's Privacy Policy.
Firebase Crashlytics (Google)
Crashlytics helps us identify and fix bugs by collecting crash reports. These reports include device information and technical logs but never include photos or personal content. See Crashlytics Terms.
Firebase Cloud Messaging (Google)
Cloud Messaging delivers push notifications to your device. It uses a device token (not linked to your personal identity) for routing notifications. You can opt out of notifications at any time in your device settings.
Apple StoreKit 2
Subscription management is handled entirely by Apple through StoreKit 2. Apple processes all payments and manages subscription status. We do not receive or store your payment details. See Apple's Privacy Policy.
AppLovin MAX (Advertising)
For free (non-Gold) users, Tidy displays advertisements through AppLovin MAX, an ad mediation platform. AppLovin may collect:
- Device identifiers (IDFA, if tracking is authorized via Apple's ATT prompt)
- Coarse location data (derived from IP address, for geographic ad targeting)
- Ad interaction data (impressions, taps)
This data is used solely for serving and measuring ads. Tidy Gold subscribers do not see ads, and no ad-related data is collected for them. For more information, see AppLovin's Privacy Policy.
No Sale of Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes. All data sharing with third parties is limited to what is required to provide the services described above.
4. Cookies and Tracking Technologies
In the App
Tidy does not use traditional cookies since it is a native app, not a website. However, we use the following tracking technologies:
- Firebase Analytics SDK - Uses anonymous device identifiers to track app usage
- Advertising Identifier (IDFA) - If you grant permission through Apple's App Tracking Transparency (ATT) prompt, your IDFA may be used for personalized advertising. You can change this at any time in Settings > Privacy > Tracking
On the Website
Our website (tidy.gallery) uses cookies and similar technologies:
- Essential Cookies - Required for basic website functionality
- Analytics Cookies - Google Analytics for traffic analysis (if you consent)
- Marketing Cookies - For measuring campaign effectiveness (if you consent)
You can manage your cookie preferences through the cookie banner on the website or through your browser settings.
Opting Out of Tracking
You can opt out of tracking in the following ways:
- In the App - Choose "Ask App not to Track" when the ATT prompt appears, or go to Settings > Privacy > Tracking
- On the Website - Use your browser's cookie management options or the cookie consent banner
- Reset Device Identifiers - On iPhone, go to Settings > Privacy > Advertising > Reset Advertising Identifier
5. Data Security
We take the security of your data seriously and implement appropriate technical and organizational measures:
- On-Device Processing - Since photos are processed entirely on your device, they benefit from iOS's built-in security features, including hardware encryption and Secure Enclave
- No Server-Side Storage - We do not maintain servers that store your personal content or photos
- Encrypted Transmission - The minimal analytics and crash data we collect is transmitted to Firebase over encrypted connections (HTTPS/TLS)
- No Personally Identifiable Data - The data we collect through Firebase is anonymous and cannot be used to identify you
- Apple Infrastructure - Subscription and payment data is protected by Apple's security infrastructure
- Limited Access - Only authorized personnel can access aggregate analytics data
While no method of electronic transmission or storage is 100% secure, our privacy-by-design approach - on-device photo processing and anonymous analytics collection only - significantly reduces risk.
Data Breach Notification
In the unlikely event of a data breach that may affect your information, we will notify you and relevant supervisory authorities in accordance with applicable laws (such as 72 hours under GDPR) and provide information about the steps we are taking to address the breach and mitigate its impact.
6. Data Retention
We retain data only as long as necessary for the purposes described in this policy:
- Analytics Data - Retained in Firebase Analytics for up to 14 months, then automatically deleted
- Crash Reports - Retained in Firebase Crashlytics for up to 90 days
- Performance Data - Retained in Firebase Performance Monitoring for up to 90 days
- Push Notification Tokens - Retained as long as notifications are enabled; automatically invalidated when you uninstall the app or revoke notification permission
- On-Device Data - All photo analysis data, caches, and local app data is stored only on your device and is removed when you uninstall Tidy
Data Deletion
You can request data deletion at any time by contacting us at [email protected]. Since we do not collect personally identifiable information, you can also effectively reset your data by reinstalling the app.
7. Your Rights
Depending on your location, you may have certain rights regarding your personal information. Below is a summary of key rights applicable in various jurisdictions:
Right of Access
You have the right to request a copy of the data we hold about you. Since we do not collect personally identifiable information, we may not be able to identify data associated with your specific device.
Right to Deletion
You have the right to request deletion of your data. You can also reset your analytics by reinstalling the app.
Right to Rectification
You have the right to request correction of any inaccurate data we hold about you.
Right to Data Portability
You have the right to request your data in a structured, commonly used format.
Right to Opt-Out
You have the right to opt out of tracking and personalized advertising. You can do this by:
- Declining the ATT tracking request when it appears
- Changing tracking settings in your device settings
- Using the "Do Not Sell My Data" toggle in app settings
Right to Restrict Processing
You have the right to request that we limit how we process your data.
Right to Object
You have the right to object to our processing of your data based on legitimate interests.
Right to Withdraw Consent
Where we rely on your consent (such as for push notifications or advertising), you can withdraw it at any time.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days (or sooner as required by applicable law).
8. GDPR Specific Rights (European Users)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have certain rights under the General Data Protection Regulation (GDPR) and related data protection laws.
Legal Basis for Processing
We process the limited data we collect based on the following legal grounds:
- Legitimate Interest - We collect anonymous analytics, crash reports, and performance data to maintain and improve Tidy. This processing is necessary for our legitimate interest in providing a reliable, high-quality app, and is balanced against minimal impact on your privacy since no personal content is collected.
- Consent - We obtain your consent before sending push notifications. You can withdraw consent at any time by disabling notifications in your device settings.
- Contract Performance - Processing subscription status is necessary to provide you with the Tidy Gold features you purchased.
- Consent for Advertising - For EEA/UK users, we obtain explicit consent before collecting advertising identifiers or sharing data with advertising partners for personalized advertising. You can withdraw this consent at any time using the "Do Not Sell My Data" toggle in app settings.
Additional GDPR Rights
- Right to Lodge a Complaint - You have the right to lodge a complaint with your local data protection supervisory authority
- Automated Decision Making - We do not use automated decision-making or profiling that significantly affects you
GDPR Representative
For GDPR-related inquiries, please contact us at [email protected].
9. CCPA Specific Rights (California Users) - Do Not Sell My Personal Information
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you specific rights regarding your personal information.
Your Rights
- Right to Know - You have the right to know what personal information we collect, use, and disclose. This privacy policy provides that information.
- Right to Delete - You have the right to request deletion of your personal information. Since we only collect anonymous, non-identifiable data, you can effectively reset your data by reinstalling the app.
- Right to Opt-Out of Sale/Sharing - Under CPRA, sharing your advertising identifier (IDFA) with advertising partners for targeted advertising may constitute a "sale" or "sharing" of personal information. You can opt out at any time using the "Do Not Sell My Data" toggle in Tidy settings, or by declining tracking permission when prompted.
- Right to Non-Discrimination - We will not discriminate against you for exercising any of your CCPA rights.
- Right to Correction - You have the right to request correction of inaccurate personal information.
- Right to Limit Use of Sensitive Information - We do not collect sensitive personal information.
Categories of Information
In the preceding 12 months, we have collected the following categories of information:
- Device and Usage Data (anonymous analytics, crash reports, performance metrics) - Collected from Firebase services for app improvement purposes
- Notification Tokens - Collected from Firebase Cloud Messaging for push notification delivery
- Device Identifiers (IDFA, only if tracking authorized) - Shared with AppLovin for ad targeting; constitutes "sale/sharing" under CPRA
If you have authorized tracking, your IDFA may be shared with advertising partners for targeted advertising, which constitutes a "sale" or "sharing" under CPRA. You can opt out using the "Do Not Sell My Data" toggle in the app.
"Do Not Sell or Share My Personal Information"
To exercise your right to opt out of the sale or sharing of your personal information:
- In the App: Go to Settings > Privacy > "Do Not Sell My Data"
- At ATT Prompt: Choose "Ask App not to Track"
- Contact us at [email protected]
To submit a request under CCPA, contact us at [email protected].
Additional International Privacy Regulations
If you are located in other jurisdictions with privacy laws (such as LGPD in Brazil, PIPEDA in Canada, POPIA in South Africa, or APP in Australia), you may have similar rights. Please contact us at [email protected] to exercise your rights or obtain more information.
10. Children's Privacy
Tidy is not directed at children under the age of 13 (or under 16 in the EEA, or other minimum ages as required by local law). We do not knowingly collect personal information from children under these ages.
Since Tidy does not require an account or personal information collection, the risk of inadvertent collection of data from children is minimal. However, if you believe we have inadvertently collected information from a child, please contact us at [email protected] and we will take steps to delete such information promptly.
Tidy does not serve targeted advertising to children and complies with the Children's Online Privacy Protection Act (COPPA) and similar regulations. Users under the age of 13 (or 16 in the EEA) should not use the app.
Special Protections
- We do not collect persistent identifiers from children
- We do not allow children to post or share personal information
- We do not entice children by offering games, prizes, or other activities
11. International Transfers
NFO LTD is located in Israel. The anonymous analytics and crash data collected by Firebase may be processed and stored on Google servers, which may be located in the United States or other countries.
Safeguards for Transfers
When data is transferred outside the European Economic Area (EEA), Google relies on:
- Standard Contractual Clauses (SCCs) - Approved by the European Commission
- Supplementary Measures - Including encryption and access controls
Israel is recognized by the European Commission as providing an adequate level of data protection.
Since we do not collect personal content (photos, personal information, or identifiers), the data transferred internationally is limited to anonymous usage metrics, crash logs, and performance data.
Transfers by Jurisdiction
- EEA/UK - Transfers are protected by Israel's adequacy decision and SCCs for Google
- Brazil (LGPD) - Transfers occur only with appropriate safeguards
- Canada (PIPEDA) - Transfers are made to countries with comparable protection
- Australia (APP) - We ensure recipients meet comparable standards
12. Policy Changes
We may update this Privacy Policy from time to time. When we make changes, we will:
- Update the "Last updated" date at the top of this page
- Post the revised policy at tidy.gallery/privacy
- For significant changes, notify you through the app or via push notification (if enabled)
Types of Changes
- Material Changes - Changes that significantly affect your rights or how we process your data will require explicit notice and may require renewed consent
- Non-Material Changes - Minor corrections, clarifications, or wording updates will take effect upon posting
Your continued use of Tidy after any changes to this Privacy Policy constitutes acceptance of the updated policy. We encourage you to review this page periodically.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: [email protected]
- Company: NFO LTD
- Location: Israel
- Website: tidy.gallery
Response Times
- General Inquiries - We aim to respond within 30 days
- Data Subject Rights Requests (GDPR) - Within 30 days (extendable by 60 days for complex requests)
- CCPA Requests - Within 45 days (extendable by 45 days)
- Data Deletion Requests - Within 30 days
Filing a Complaint
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority:
- EU/EEA - Your country's Data Protection Authority
- UK - Information Commissioner's Office (ICO)
- California - California Attorney General
- Brazil - Autoridade Nacional de ProteΓ§Γ£o de Dados (ANPD)
- Israel - Privacy Protection Authority