Effective date: 17 July 2026
Controller (Article 4(7) GDPR):
Seyedmohammad Farrahi, Einzelunternehmer, trading as
"Gleaner"
Schützenstr. 3, 35398 Gießen, Hessen, Germany
Email: kabok.company@gmail.com
Full provider details are in the Impressum.
This Policy explains how Gleaner handles information in the mobile app and on its website and help pages. Photo analysis happens on your device. Your photos are not uploaded. On iOS and Android, optional pseudonymous Firebase Analytics starts only after your explicit opt-in. Firebase Functions and App Check are required for purchase security on mobile. macOS does not send remote Analytics. Gleaner has no account, ads, advertising identifiers, or cross-app tracking.
Mandatory rights under applicable privacy and consumer law remain unaffected.
Similarity grouping and quality scoring run locally. We do not receive your photo pixels, thumbnails, filenames, file or PhotoKit/MediaStore identifiers, album names, faces, EXIF, GPS, precise location, or photo timestamps. Gallery photos are never Analytics or model-training data.
When Pro is purchased or restored, Firebase Functions and Firebase App Check process a random installation identifier, app/device attestation, platform, product identifier, Play purchase token or signed StoreKit transaction, and entitlement and expiry state. The backend verifies the proof with Google's Play Developer API or Apple's App Store Server API and retains the minimum pseudonymous lifecycle records needed for renewals, refunds, holds, expiration, chargebacks, and notification replay protection. It receives no photos or payment-card details. This required processing is separate from Analytics consent.
If you opt in, Google Firebase Analytics assigns an app-instance identifier. It is pseudonymous, not anonymous: it can distinguish an app installation but Gleaner does not associate it with a name, email, account, advertising ID, IDFA, IDFV, or Analytics User-ID.
Firebase may then process:
Custom values pass through a strict allow-list and range bucketing. Gleaner does not use Crashlytics, Firebase Performance Monitoring, Remote Config, AdSupport, an ads SDK, IDFA, IDFV, User-ID, or tracking. macOS keeps its diagnostics local and does not initialize Firebase.
The two stores use different names for required purchase security and optional Analytics:
| Apple App Privacy | Google Play Data Safety |
|---|---|
| Coarse Location; Purchase History; Device ID; Product Interaction; Other Usage Data; Performance Data; Other Diagnostic Data | Approximate location; Purchase history; App interactions; Other actions; Diagnostics; Other app performance data; Device or other IDs |
| Required Purchase History and Device ID for App Functionality and fraud prevention | Required Purchase history and Device or other IDs for App functionality and fraud prevention |
The first row is optional Analytics data; the second row is required purchase-security data. Both are encrypted in transit. Apple categories are described as not linked to identity and no tracking only while the technical and account safeguards in this Policy remain true. Gleaner does not collect crash reports.
Apple or Google processes payment under its own terms. The app receives the purchase result and entitlement status needed to unlock Pro, but not your card details. If Analytics is enabled, the product, price, and currency may also be included in the optional purchase event described above.
If you email us, we process your address, message, attachments, and normal email metadata to answer you and, where needed, establish or defend legal claims.
The site is static and has no advertising or analytics tracker. Firebase Hosting may process IP address and request metadata in necessary server or CDN logs to deliver and secure the site.
Withdrawal of consent does not affect processing that was lawful before withdrawal.
Gleaner's local models group similar photos and suggest a quality score. They do not generate media or make decisions with legal or similarly significant effects. You review every suggestion and decide what to keep or delete. Photo content is not sent to Gleaner or a third-party AI service and is never used to train or fine-tune models. Optional coarse Analytics may inform product and model evaluation, but contains no gallery photo or file data.
Analytics is off by default in every country on iOS and Android. Firebase collection is disabled before a valid opt-in. The prompt names Firebase, describes the categories and purpose, and provides equally available Allow and No thanks choices. Closing or declining does not enable Analytics and does not limit any app or paid feature.
You can withdraw or grant consent in Settings → Help improve the AI. Withdrawal disables future collection after the setting is applied; it does not automatically erase data already received by Google. Advertising consent remains denied. A materially changed purpose or data use requires a new choice.
We do not sell data, provide it to data brokers, or share it for targeted or cross-context advertising. We may disclose information where law strictly requires it or where needed to protect legal rights and safety.
Google and other processors may handle data outside the EEA, including in the United States. Depending on the recipient and transfer, safeguards may include an applicable adequacy decision, the EU Standard Contractual Clauses, and supplementary measures. See Firebase privacy and security information. You may request information or a copy of applicable transfer safeguards by emailing us; legally protected content may be redacted.
GA4 user-level and event-level data is configured for a 2-month retention period, with reset on new activity disabled. Google applies expiration through a monthly deletion process, so deletion is not promised on exactly day 60. Standard aggregate reports may remain longer because the user-level or event-level record is no longer separately available there.
Turning Analytics off stops future collection, not prior processing. Support messages are kept while needed to answer the request and for applicable legal limitation or retention periods. Purchase-security records are kept while needed to provide Pro, process store lifecycle changes, prevent fraud, and meet legal accounting or claims obligations. Hosting logs are retained as needed for site security and operation. We retain no photo data because it is never sent to us. Google's retention-control explanation is available here.
Analytics is encrypted in transit. Collection is consent gated, app-defined parameters are allow-listed and bucketed, access is restricted, and gallery content remains on the device. No system is completely secure. Report a concern to kabok.company@gmail.com.
Subject to applicable conditions, you may request access, rectification, erasure, restriction, objection, and data portability, and may withdraw consent at any time. Analytics is not associated by Gleaner with an account or direct identity. We may be unable to locate a specific pseudonymous Analytics record from the information you provide, but will act where data can reasonably be identified and the request verified.
Depending on where you live, additional rights may apply. Gleaner does not sell personal information, use targeted advertising, or discriminate because you exercise a privacy right. Send requests to kabok.company@gmail.com.
You may complain to a competent supervisory authority. A competent supervisory authority for the controller in Hessen is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI), Postfach 31 63, 65021 Wiesbaden, Germany · datenschutz.hessen.de
Gleaner is not designed for children. If a child has provided support data or used the app in a way that concerns you, contact us. Applicable parental-consent and child-protection rules remain unaffected.
The site sets no advertising or analytics cookies and runs no third-party tracker. Necessary server or CDN technology may be used to deliver it securely. The app uses no advertising SDK. On iOS and Android, Firebase App Check and Functions are required for purchase security; Analytics remains optional and disabled until consent. macOS does not initialize Firebase.
The site does not engage in targeted advertising or sale or cross-context sharing for a browser signal to stop. Legacy Do Not Track has no common standard. Where a legally binding browser signal applies to a future site activity, we will honour it as required.
Gleaner has no account to delete. You can clear local app data through your operating system and uninstall the app. Disable Analytics in Settings to stop future collection. You may also email a deletion request, although a specific pseudonymous record may not be identifiable without a direct identifier. Ask us to delete support data; statutory retention duties may require limited retention.
The app never sends us your photos. iOS and Android 11 or later use the operating system's Recently Deleted or Trash recovery path. Android 8 through 10 and macOS folder cleanup can delete permanently after an explicit warning.
We may update this Policy and will change the effective date. We will provide notice and request a new Analytics choice where a material change requires it.
Controller: Seyedmohammad Farrahi,
Einzelunternehmer
Email:
kabok.company@gmail.com
Postal and provider details: Impressum
| Data | Purpose and basis | Recipient |
|---|---|---|
| Photos and gallery content | Local cleanup; contract | None; stays on device |
| Installation attestation and store purchase proof | Provide Pro and prevent fraud; contract or legitimate interest | Google Firebase, Apple or Google Play |
| Optional mobile Analytics categories listed in Section 1 | Product, reliability, algorithm and model evaluation; consent | Google Firebase |
| Purchase result and entitlement | Provide Pro; contract | Apple or Google processes the store transaction |
| Support communication | Respond and handle claims; contract or legitimate interest | Email provider |
| Site request metadata | Deliver and secure the site; legitimate interest | Firebase Hosting |