Privacy Policy

Effective date: August 20, 2026  ·  Last updated: August 20, 2026

SquatchPix ("SquatchPix", "we", "us", "our") is a photo-organization application published by JM Squatch LLC. This policy explains what personal information SquatchPix collects, why, who it is shared with, and how you can exercise your privacy rights. It applies to the SquatchPix mobile apps (Android and iOS), the web client, and the backend API (together, the "Service"). The full, canonical version of this policy is maintained in our repository; this page reproduces it for the web.

If you use the separate J.M. Squatch Tech consulting products (SMS, IVR, voice-assistant, payments), the policy at tech.jmsquatch.com/privacy-policy governs those — not SquatchPix.

1. Who controls your data

JM Squatch LLC (brand: SquatchPix) is the data controller under the GDPR / UK GDPR / FADP, and the business under the CCPA / CPRA.

2. The short version

  • We sync the photos and videos you choose — from your phone, Google Drive, Google Photos, Microsoft OneDrive, and Dropbox — and store copies on our infrastructure so we can organize them for you.
  • We read EXIF metadata, including GPS coordinates when present.
  • We generate AI captions and tags using Microsoft Azure OpenAI and Azure AI Vision.
  • We compute face embeddings (mathematical fingerprints, not images) to group photos of the same person. Face embeddings are biometric data and we only compute them with your explicit opt-in.
  • We never sell your data. We never use your photos to train any AI model.
  • You can delete your account and all associated data from inside the app at any time.

3. Information we collect

You give us directly:

  • Account identifiers. When you sign in we receive your name, email address, and a unique account identifier from your identity provider (Google Sign-In or Microsoft Entra). We never receive or store your password.
  • Photos and videos. Files you upload from the in-app picker or a connected cloud source. We store copies on our infrastructure to provide the Service.
  • File metadata. EXIF tags including capture date/time, camera make/model, lens, exposure, orientation, and GPS coordinates and altitude when present.
  • Cloud-source credentials. OAuth refresh tokens for Microsoft Graph (OneDrive), Google (Drive and Photos), and Dropbox, stored in our access-controlled backend database and encrypted at rest. Tokens are scoped to the minimum permissions required and deleted when you disconnect the source or delete your account.
  • Location text you type into the place picker. If you edit a photo's location, the app opens Google Places Autocomplete to suggest places. The characters you type are sent directly to Google to return those suggestions, and the place you pick (name, address, coordinates) is saved with your photo. That search text goes to Google, not to our servers — we receive only the place you select. The picker is optional; if you do not use it, no text is sent.
  • Support communications. Anything you send us.

We generate from your photos: perceptual hashes (deduplication); AI captions and tags (Azure AI Vision + Azure OpenAI); face embeddings (only if you explicitly enable "Group photos by person" — these are derived vectors, not reversible to a photo of your face); and content-safety classifications used only to screen in-app chat prompts (we do not run content-safety classification over your library).

We collect automatically: a pseudonymous install ID derived from your device's Android identifier (so your data survives an app reinstall; a random ID is used where that identifier is unavailable), plus OS/app version and a coarse device fingerprint to bind your session; diagnostic telemetry — crash reports and error traces via Google Firebase Crashlytics (tagged with your install ID so we can correlate a crash to a specific install for triage) and request timings via Microsoft Application Insights — which never includes your photo contents; a device push token registered with Google Firebase Cloud Messaging if you enable notifications; and an approximate IP-derived region used only for security. We do not use third-party advertising SDKs and do not track you across other apps or websites.

You choose to share (opt-in): If you turn on Settings → Privacy → Help improve search (off by default), you can rate chat-search results with a thumbs up or down. Each rating contains the search text you typed, your rating, an optional comment, how many results matched and their relevance scores, the app's search-configuration values, and the calendar date. It contains no account or device identifier, no photos, thumbnails, or captions, and no timestamp finer than the date — so it cannot be linked back to you. The search text itself is included as you typed it and may contain names or other personal details you chose to type.

4. Why we use your information (legal bases)

  • Provide the Service (organize, search, deduplicate) — Contract (GDPR Art. 6(1)(b)).
  • Group photos by person (face recognition) — Explicit consent (Art. 9(2)(a)), revocable any time in Settings → Privacy → Face grouping. Withdrawing stops new face processing and deletes stored embeddings.
  • Authenticate and protect the Service — Legitimate interests (Art. 6(1)(f)).
  • Diagnose crashes/performance — Legitimate interests (Art. 6(1)(f)).
  • Improve search quality (opt-in feedback) — Consent (Art. 6(1)(a)), revocable any time in Settings → Privacy.
  • Legal obligations — Art. 6(1)(c).

For California residents: we have not sold or shared personal information for cross-context behavioural advertising in the last 12 months and do not intend to.

5. Who we share your information with (sub-processors)

We never sell your information. We share it only with the sub-processors that make the Service possible, each contractually bound to use it only on our instructions:

  • Microsoft Corporation — Azure hosting/storage, Azure OpenAI (captions and chat; Microsoft commits this data is not used to train OpenAI's models and not shared with OpenAI), Azure AI Vision, Azure AI Content Safety, Microsoft Graph/OneDrive. United States (Microsoft 365 tenant region for OneDrive).
  • Google LLC — Sign-In, Drive API, Photos Library API, Play Integrity, Play Services, Places API (Autocomplete — receives the text you type in the photo location picker), and Firebase (Crashlytics for crash diagnostics, Cloud Messaging for push notifications). United States.
  • Dropbox, Inc. — Dropbox API (cloud-sync source you opt into). United States.
  • Apple Inc. — App Store, App Attest. United States.

We do not share your data with advertising networks, data brokers, or marketing services.

Google API Services Limited Use. SquatchPix's use of information received from Google APIs (including Google Drive and Google Photos) adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use Google user data to provide and improve the photo-organization features you request; we do not transfer it to third parties except as necessary to provide those features (our sub-processors above) or as required by law; and we do not use it for advertising or to train generalized AI/ML models.

6. International data transfers

Our infrastructure is in Azure data centers in the United States. For transfers from the EU/EEA, UK, or Switzerland we rely on the EU Standard Contractual Clauses (2021/914), supplemented by the UK International Data Transfer Addendum and Swiss FADP equivalents.

7. How long we keep your information

  • Photos, videos, EXIF, AI captions, hashes — until you delete them, delete your account, or 30 days after account deletion.
  • Face embeddings — until you disable face grouping (immediate deletion) or delete your account.
  • OAuth refresh tokens — until you disconnect the source or delete your account.
  • Authentication/security logs and diagnostic telemetry — 30 days (crash reports in Firebase Crashlytics are retained up to 90 days per Google's schedule).
  • Anonymized search feedback (opt-in) — up to 24 months, then automatically deleted.
  • Backups — encrypted, retained 7 days, after which deleted data is unrecoverable.
  • Support communications — 24 months from last contact.

When you delete your account we purge production data immediately; the backup window expires within an additional 7 days, after which no copy of your personal information remains.

8. Your rights

Depending on where you live you may have rights to access, portability, correction, deletion, restriction/objection, and withdrawal of consent, plus the right to lodge a complaint with your data protection authority. To exercise them:

  • In-app account deletion: Settings → Account → Delete account (irreversible; removes account, photos, embeddings, captions, tokens).
  • In-app face-grouping opt-out: Settings → Privacy → Face grouping → Off (deletes all stored embeddings).
  • In-app search-feedback opt-out: Settings → Privacy → Help improve search → Off immediately stops future sharing. Feedback already submitted is fully anonymous, so it cannot be individually retrieved or deleted; it is purged automatically within 24 months.
  • Web deletion: squatchpix.com/delete (requires the signed link generated in-app, valid 24 hours).
  • Data export / portability: email privacy@squatchpix.com and we will provide an export within 30 days. Your originals also remain in the cloud archive folder you connected, so you retain a directly-accessible copy at all times.
  • Any other request: email privacy@squatchpix.com. We respond within 30 days (extendable per GDPR/CCPA).

We will not discriminate against you for exercising any of these rights.

9. Children

SquatchPix is not directed to children under 13 (or under 16 where that is the digital-consent age). We do not knowingly collect their information. If you believe a child provided us information, contact privacy@squatchpix.com and we will delete the account.

10. Security

  • TLS 1.2+ in transit for every API request.
  • AES-256 encryption at rest for all blobs, database tables, and Key Vault secrets.
  • Managed-identity authentication between our services — no shared API keys for storage or database.
  • Postgres Row-Level Security so one user's queries cannot reach another user's rows.
  • Azure Key Vault for all secrets, with audited access.
  • Play Integrity / App Attest to bind sessions to genuine app installs.
  • Continuous monitoring and alerting via Azure Monitor, Application Insights, and Log Analytics.

No system is perfectly secure. If we discover a breach affecting your personal information we will notify you and the appropriate regulators within the timeframes required by applicable law (72 hours under the GDPR).

11. AI processing

We use Microsoft Azure OpenAI, Azure AI Vision, and Azure AI Content Safety. Microsoft contractually commits that data sent to Azure OpenAI is not used to train OpenAI's models and not shared with OpenAI. We do not use any third-party AI model that trains on customer data. Captions and tags are best-effort and may be inaccurate; you can correct or delete them. We do not use your chat history to train any model. If you opt in to search-quality feedback, your anonymized thumbs-up/down ratings help us tune how search matches your queries; they are never sold or shared and are not used to train any generalized AI model.

12. Cookies

The web client uses first-party cookies and local storage only — to keep you signed in, remember preferences, and provide CSRF protection. No third-party tracking cookies, no advertising.

13. Do Not Track

Our web client honours the Global Privacy Control (GPC) signal. We do not respond to legacy Do-Not-Track headers because there is no industry consensus on their meaning.

14. Changes to this policy

When we make a material change we update the "Last updated" date, notify you in-app and by email at least 14 days beforehand, and — for changes requiring fresh consent (e.g. a new category of biometric processing) — prompt you in-app and process nothing under the new basis until you grant it.

15. Contact

Email privacy@squatchpix.com. EU/EEA users may lodge a complaint with their local supervisory authority; UK users with the ICO; California residents with the CPPA.