Chestful

Privacy Policy

Last updated 23 September 2026

Chestful exists to look after photographs that cannot be replaced. That only works if you know exactly what happens to them. This policy says so plainly, and it describes what the app actually does today rather than everything a photo app could conceivably do. Chestful is operated by GoodOrc LLC, and “we” below means that company.

The short version

  • We do not sell or rent your personal information, ever.
  • We do not show ads, and we do not track you across other companies’ apps or sites.
  • We do not use facial recognition and store no biometric data of any kind.
  • Your photos are not used to train anyone’s AI models, ours or a vendor’s.
  • Deleting your account deletes your photos and your data. It is one tap inside the app.

What we collect

Information you give us

  • Your email address and password, to create and sign in to your account. Passwords are held by Amazon Cognito, our identity provider; we never see or store them.
  • The photos and documents you scan or import, including both sides of a print when you scan the back.
  • What you write about them — album titles, captions, tags, dates, and the names of people you tag. Names of people are typed by you; nothing about a face is measured or matched.
  • The email address of anyone you invite to an album, so we can send them the invitation and give them access.

Information created for you

  • Restored versions of your photos, kept alongside the original. The original is never overwritten.
  • Suggested captions, tags, and an estimated era, generated from the image. You can edit or delete any of them, and your edit wins over a later re-run.

Information collected automatically

  • Your subscription status — whether a purchase is active, and which one. Purchases are made through Apple or Google and reconciled by RevenueCat. We never receive your card details.
  • A push notification token, if you allow notifications, so we can tell you when a restoration or an export has finished.
  • Ordinary server logs — IP address, timestamp, and which endpoint was called — kept briefly for security and debugging. There is no analytics SDK in either app.

What we do not collect

No location data. No contacts, calendar, or health data. No advertising identifier (IDFA), no cross-app tracking, and no third-party analytics or advertising SDKs. Camera and photo library access are used only to capture and import the photos you choose; the app never browses your library on its own.

How photos are processed

Restoration and captioning are performed by Google’s Gemini API acting as our processor. When you ask for a photo to be restored or captioned, that image is sent to Google, processed, and returned. We use a paid Gemini tier, under which Google’s terms state it does not use your photographs or the results to train or improve its models, and no human reviewer reads them for quality purposes. Google does keep a log of requests for a limited period, to detect abuse of its service and to meet its own legal obligations — we would rather tell you that than claim nothing is retained at all. We do not train models of our own on your photographs.

If you never use restoration or captioning, your photos are never sent to an AI provider at all.

Sharing an album

Sharing in Chestful is private and invitation-only. When you invite someone to an album, that person can see the album’s photos and the captions, tags, dates, and people on them. A viewer can look and download; an editor can also add, change, and remove photos and details in that album. Collaborators see the email address of the album’s owner and of the other collaborators.

There is no public feed, no profile, no discovery of strangers’ photos, and no way for anyone to encounter your album unless you invited them. The owner can change a collaborator’s role or remove them at any time, and a collaborator can leave. Photos already downloaded or exported by a collaborator are, like any downloaded file, outside our control.

Who else sees your data

We use a small number of service providers, each only for the job named:

  • Amazon Web Services — storage, database, and hosting, in the United States. Photos are held in private storage and served over expiring, signed links.
  • Amazon Cognito — accounts, sign-in, and passwords.
  • Google (Gemini API) — restoration and captioning, as described above.
  • RevenueCat — reconciling purchases made through Apple or Google.
  • Apple and Google — the purchase itself, and delivery of push notifications.

We may also disclose information if we are legally required to, or to protect the safety and rights of our users. If Chestful is ever acquired, your data would move with it, and this policy travels with the data until you are told otherwise.

How long we keep it

Your photos and details stay until you delete them or delete your account. Deleted albums and items are removed from our database immediately and purged from storage shortly after. Backups roll off within 30 days. Server logs are kept for a short operational window.

Deleting your account

In the mobile app: Menu → Help and support → Delete my data. On the web: Help and support → Delete my data. This is permanent and immediate — it removes your account, every album you own, every photo and restored version, all captions and tags, your people, your export history, and your sign-in credentials. Albums shared with you are not deleted; you are simply removed from them.

You can also email support@chestful.app to ask for a copy of your data, a correction, or deletion. Depending on where you live you may have rights under the GDPR, the UK GDPR, or US state privacy laws — including access, correction, deletion, portability, and objecting to processing. We honour these requests wherever you live, not only where the law requires it. We do not sell or share personal information as those terms are used in US state privacy laws, so there is nothing to opt out of.

Children

Chestful is not directed to children under 13, and we do not knowingly create accounts for them or knowingly collect their personal information. If you believe a child has an account, write to support@chestful.app and we will delete it.

Security

Data is encrypted in transit (HTTPS/TLS) and at rest. Access to a photo requires a signed, expiring link issued only to someone with access to its album. Internal access to production data is limited to what is needed to operate the service.

Changes

If this policy changes in a way that matters, we will update the date at the top and tell you in the app before the change takes effect.

Who we are, and how to reach us

Chestful is operated by GoodOrc LLC, a limited liability company in the United States. For privacy law purposes GoodOrc LLC is the data controller for everything described in this policy, and it is who to contact about any of it: support@chestful.app.