Privacy Policy
Last updated: [DATE]
Who is responsible
Deleterino is made by [NAME], [ADDRESS]. Questions about privacy? Write to [EMAIL]. This policy covers the Deleterino app on iOS and Android and explains what happens to your data when you use it. [NAME] is the controller under the GDPR.
The short version
No accounts. No servers of ours. No ads, no tracking, no analytics. Your photos are analysed and sorted on your device and they stay there. The only thing that leaves your phone without you doing anything is an anonymous error report when the app breaks. Everything else only leaves if you make it leave: by sharing a photo, by opening a map, or by buying a subscription.
What Deleterino stores on your device
To do its job, Deleterino keeps a small database on your phone. In it: the identifiers iOS or Android uses for the photos you have already swiped, whether you kept or deleted each one and how big it was, photos that are queued for permanent deletion, your streak, your counters for storage freed today and in total, and a yes/no flag saying whether your subscription is active. On top of that a marker that you finished the intro, and a cache of the thumbnails that have been shown. None of it is transmitted anywhere. Legal basis: Art. 6(1)(b) GDPR, because without this data the app cannot do the thing you installed it for.
How Deleterino sorts your photos
The categories (screenshots, selfies, documents, barcodes, blurry, animals, anime, Spicy and so on) come from analysing your photos directly on your device, using Apple's built-in Vision and Sensitive Content Analysis frameworks plus a small image model shipped inside the app. Deleterino explicitly forbids the system from downloading originals from iCloud for this, and no photo, no thumbnail and no crop is ever uploaded. What gets stored is only the result: a handful of yes/no markers and a blur score per photo, in the same local database.
The Spicy marker
One of those markers records whether a photo probably shows nudity. It is a guess, it is computed on your device, it is stored only on your device, and it is never sent to us or to anyone else. We have no way of seeing it. Because a marker like this can say something about your sex life, we treat it as the most sensitive thing in the database. You can wipe every marker at any time under Settings, "Reset classifications", and deleting the app takes them with it. One thing you should know: anyone who can unlock your phone can open the Spicy category. Deleterino does not put a separate lock in front of it.
Error reports (Sentry)
When Deleterino crashes or hits an error, it sends a report to Sentry so the error can be fixed. We use Sentry's EU region ([SENTRY LEGAL ENTITY, ADDRESS], hosted in Germany) as our processor, under a data processing agreement. A report contains the error and its stack trace, your device model, OS version, app version and language, rough device state such as free storage, memory, battery level and orientation, a trail of the screens you opened and the elements you tapped shortly before the error, and a random identifier generated for this installation of the app. It does not contain your photos, their file names, their identifiers, your name, your email address or your Apple ID. The SDK is configured not to send personal data, and error messages that would otherwise carry a photo identifier are rewritten before they are sent. Sentry also receives a sample of performance measurements (20 percent) and basic session data (app started, app crashed) so we can see how stable the app is. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in an app that does not crash. You can object at any time, just write to [EMAIL]. Reports are deleted after Sentry's retention period of [XX] days. In development builds error reporting is switched off entirely.
Buying Premium
The subscription is sold by Apple (App Store) or Google (Play Store), not by us. The purchase, your payment details and your Apple or Google account stay with them. We never see them, and we run no server that could store them. All Deleterino keeps is a yes/no flag on your device saying the subscription is active, which it re-checks with the store. For the purchase itself, Apple's or Google's privacy policy applies.
Maps
If you open a photo's info card and that photo has GPS coordinates in it, Deleterino draws a small map. Drawing that map means Apple Maps (iPhone) or Google Maps (Android) has to load map tiles for that exact spot, so at that moment the photo's coordinates go to Apple or Google, sent by their SDK, not by us. The same happens when you tap "Open in Maps". If you never open the info card, no coordinates go anywhere. Deleterino never asks for your current location and never uses it. Legal basis: Art. 6(1)(b) GDPR, you asked for the map.
Sharing a photo
When you share a photo out of Deleterino, iOS or Android hands it to the app you pick. From that moment it is out of Deleterino's hands and that app's privacy policy applies. Nothing is shared unless you tap share.
Reminders
If you turn on the daily reminder, Deleterino schedules the notifications directly on your device. There is no push server, no device token, no message travelling across the internet. Your phone reminds itself. You can switch reminders off again in your system settings whenever you want. Legal basis: Art. 6(1)(a) GDPR, your consent, which you can withdraw at any time.
Permissions
Deleterino asks for access to your photo library, because that is the entire app, and for permission to send notifications if you want reminders. That is it. iOS additionally shows a location purpose string for Deleterino. It only exists because the map component links Apple's location framework. Deleterino never requests your location.
Backups
Deleterino's database lives in the app's document folder, which means it ends up in your iCloud backup and in encrypted local backups if you have those enabled. Those backups are yours, and Apple's or Google's privacy policy covers them. If you do not want Deleterino's data in there, turn off backups for Deleterino in your system settings.
Deleting your data
Everything Deleterino stores sits on your device, so you are the one in control. "Reset swipes" in Settings clears your swipe history, your streak, your counters and the thumbnail cache. "Reset classifications" deletes every marker Deleterino derived from your photos, Spicy included. Deleting the app removes all of it, down to the fact that you ever finished the intro. There is nothing on our side we could delete for you. The one exception is error reports at Sentry, which are deleted automatically at the end of the retention period, or on request.
Your rights
Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16) or deleted (Art. 17), to restrict processing (Art. 18), to data portability (Art. 20) and to object (Art. 21), and you can lodge a complaint with a supervisory authority (Art. 77). A practical note: since we store nothing about you on our side and error reports contain no identity, we normally cannot tell which data belongs to which person and may not be able to act on an access or deletion request (Art. 11 GDPR), unless you can give us something to find it by, for example the date and time of a crash.
Children
Deleterino is not aimed at children under 16. There are no accounts and no sign-up, and we knowingly collect no data from children.
Changes to this policy
If what the app does with data changes, this text changes with it. The version that counts is always the one in the app, dated at the top. There is no notification for it, so have a look here after an app update.