PixSweep is an offline-first photo and video cleaner for Android. Media analysis happens on your device, and PixSweep does not upload your photos or videos to servers operated by The Rising Dev. The app does use Google services for advertising, consent management, analytics, crash diagnostics, purchases, machine-learning diagnostics, and configuration. This policy explains both the local processing and those network data flows.
The controller for the processing described in this policy, within the meaning of Article 4(7) of the EU General Data Protection Regulation (GDPR), is the individual developer operating under the name The Rising Dev, based in the Federal Republic of Germany.
Privacy questions and data-subject requests: pixsweep@gmail.com. No data protection officer has been appointed; requests are handled by the developer personally.
Google provides several of the third-party services used by PixSweep. Depending on the service and processing activity, Google may process information as a processor on our behalf or as an independent controller under its own terms and privacy policy. The applicable roles and processing are described in Google's documentation and terms for the relevant service.
With your permission, PixSweep reads photos, videos, and related media metadata such as file name, album or folder, path, media type, size, dimensions, duration, and date taken. When you open a media-information view, PixSweep may also read GPS coordinates embedded in that photo or video.
The app locally performs duplicate and blur detection, face grouping, screenshot and GIF detection, semantic search, object and text recognition, and detection of documents and of identity or payment cards. That last check is a keyword and label heuristic over text the app already recognized on your device, looking for things like a passport, an identity card, a driving licence or a card or account number, so it can offer to move the item to the Vault. It does not classify health, beliefs, political opinions, ethnicity or sex life, and it never acts on its own. Local results can include hashes, labels, quality scores, search indexes and feedback, face and visual embeddings, group assignments, review decisions, and vault or archive metadata. PixSweep stores this analysis data, including embeddings and search indexes, locally on your device to provide its features. It is not uploaded to The Rising Dev or any PixSweep server. PixSweep does not send the media itself or these media-derived results to The Rising Dev, Firebase, AdMob, or ML Kit. Certain Google services may nevertheless receive technical information about their operation, as described in Section 4. If you view GPS information embedded in media, the coordinates may also be sent to a device geocoding service as described in Section 4.
Face grouping deserves a specific word. It works by computing a numeric representation of a detected face and comparing it with others, so that shots of the same person can be grouped. Depending on how it is used, that can amount to biometric data used to tell one person apart from another, which European law treats as a special category. All of it is computed and kept on your device: the embeddings never leave it, and we never receive them. The on-device analysis is optional and off until you start it. You can turn it off again at any time under Settings > AI performance by choosing "Off", which stops further analysis; clearing the app's data removes the stored results. If you use PixSweep solely on your own photos for your own private purposes, this processing may fall within the household-activity exemption under applicable data-protection law. To the extent it is nevertheless subject to the GDPR and we are regarded as responsible for it, we rely on the consent you give by switching the analysis on, and you withdraw it by switching it off.
Media and analysis data held only on your device stay under your control. We never receive them, so we cannot access, export, or delete them for you; you do that with the app and Android's app-data and media tools.
PixSweep does not require or provide a user account. The Rising Dev does not operate a cloud service for your media and does not receive or store your photos, videos, gallery metadata, face embeddings, search index, or AI results.
Depending on your region, choices, build configuration, and the features you use, the following services may receive information. Network traffic is sent using encrypted HTTPS/TLS connections; the app blocks unencrypted (cleartext) connections. These services do not receive your photos, videos, recognized text, face embeddings, or other media-derived AI results, except where specifically described in this Section 4.
The recipients are Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and Google LLC and their affiliates, depending on the service and your location; the geocoding provider built into your device or Android distribution; and, only if the trusted-time fallback is used, Apple. These are the recipients PixSweep uses for the purposes described in this policy, and we do not sell personal data.
Google describes its processing in the Google Privacy Policy and its explanation of data from partner apps.
Where the GDPR applies, we rely on the legal bases below. Where a processing operation also involves storing information on your device or accessing information already stored there, Section 25 of the German Digital Services Data Protection Act (TDDDG) applies in addition to the GDPR.
| Purpose | Legal basis |
|---|---|
| Providing the app's core features: reading your media, on-device analysis, review, archive, vault, deletion assistance | Performance of the contract for use of the app, Art. 6(1)(b) GDPR. The data stays on your device and we receive none of it. |
| Personalized or non-personalized advertising and the associated device identifiers | Your consent, Art. 6(1)(a) GDPR and Section 25(1) TDDDG, collected through Google's consent form where required. Withdrawable at any time. |
| Firebase Analytics usage events and Crashlytics crash diagnostics | Your consent, Art. 6(1)(a) GDPR, given by switching on "Diagnostics & crash reports" in Settings, which is off by default. Withdrawable at any time by switching it off. |
| Firebase Remote Config and Firebase Installations: delivering the ad-frequency limits and supplying the per-installation identifier the Firebase services need | Your consent, Art. 6(1)(a) GDPR and Section 25(1) TDDDG: Remote Config is reached only once the advertising-consent flow permits ads, and Installations only when a Firebase service actually runs. Withdrawing ads consent stops it. The identifier is pseudonymous and is not used for profiling. |
| ML Kit operational and error metrics | Our legitimate interest in on-device machine-learning features that work, stay secure and can be maintained, Art. 6(1)(f) GDPR. Google's own processing rests on its own legal basis, described in its documentation. |
| Processing the "Remove ads" purchase and restoring the entitlement | Performance of the contract for that digital product, Art. 6(1)(b) GDPR. |
| Reverse geocoding embedded GPS coordinates when you open a media-information view | Performance of the contract, Art. 6(1)(b) GDPR: it happens only on your request, to show you the feature you opened. |
| One HTTPS date-header request per app process for trusted time | Our legitimate interest in features that an incorrect device clock must not be able to defeat, Art. 6(1)(f) GDPR. |
| Answering an email you send us, including handling a data-subject request or a defect report | Our legitimate interest in replying to the person who contacted us, Art. 6(1)(f) GDPR; for a data-subject request or a statutory defect claim, compliance with a legal obligation, Art. 6(1)(c) GDPR. |
| Complying with legal obligations and defending legal claims, where applicable | Art. 6(1)(c) and Art. 6(1)(f) GDPR. |
Providing data is neither a statutory nor a contractual requirement. Granting media access is necessary for the app's core purpose, so refusing it means those features cannot work. Consent to advertising or diagnostics is entirely optional, and refusing it does not restrict any other functionality.
PixSweep does not request contacts, microphone, camera, or live device-location permission, and it does not receive your Google account password or payment credentials.
PixSweep does not automatically delete your photos or videos. The app only makes recommendations; you confirm deletions through the Android system's deletion confirmation.
Deleted items are handled by Android's trash or recycle-bin mechanism and may be restorable during the retention period set by Android or your media provider. Permanently emptying trash cannot be undone.
Archives are ZIP files stored locally on the device. They can contain copies of selected media and related metadata and may remain after PixSweep is uninstalled until you delete them.
The optional Private Vault hides selected photos behind a PIN or biometric authentication. The Vault is a convenience lock and is not file encryption.
Vaulted files remain ordinary files stored on your device. Depending on your device, file manager, other applications, or cloud backup services such as Google Photos may potentially access or back up those files. If you do not want vaulted files included in cloud backups, review the backup settings provided by your backup service.
The Vault is designed to keep selected photos out of sight in your gallery and behind a lock inside PixSweep. It is not a substitute for device-level encryption. PixSweep stores a salted PBKDF2 hash of the PIN rather than the PIN itself, and offers no PIN reset and no way to open the Vault inside the app without your PIN or a working biometric unlock. Because the vaulted files themselves are not encrypted, someone with direct access to your device storage, for example through a file manager, a connected computer or a backup, can still reach them without knowing the PIN.
Local analysis records and settings remain until PixSweep replaces or deletes them, you clear the app's data, or you uninstall the app. There is no fixed local retention period, because this data is a working cache for the features you are using. Android backup or device transfer may preserve ordinary preferences such as theme, AI mode, streaks, and the Remove Ads flag. PixSweep excludes its analysis database, the vault PIN and lockout state, onboarding and album-selection state, and Google SDK shared preferences from Android cloud backup and device transfer.
Clearing app data or uninstalling may not delete original media, items already placed in Android's trash, vaulted files in shared device storage, or exported archives. Delete those items with PixSweep, Android's media tools, or a file manager as applicable. Because PixSweep has no user account or media server, there is no PixSweep cloud-media account to delete.
For the data described in Section 4, Google determines and applies the retention periods under its own policies and the settings of the Firebase project. We hold no copy of that data, and there is no channel through which we could delete an individual user's records inside Google's systems. Instead PixSweep gives you a direct control, described immediately below. You can also use Google account and Android advertising controls at any time.
Settings > Delete my data. This runs, on your device and without contacting us: it switches "Diagnostics & crash reports" off, discards crash reports that have not yet been sent, resets Firebase Analytics, deletes this installation's Firebase installation ID and the data Google associates with it, and clears your stored ads-consent answer so you are asked again on the next launch. You can tick a second option in the same dialog to delete the on-device analysis data as well: labels, quality scores, face groups, embeddings, object detections and the search indexes. Your photos and videos are never touched, and vault entries are kept so that hidden files can still be restored.
What that action cannot do, stated plainly: usage events and crash reports that have already reached Google cannot be recalled by the app. Deleting the identifiers stops them being linked to your installation and Google then deletes them under its own retention rules, but they are not erased on the spot. For analytics events there is a further step available to you: when the deletion runs, PixSweep shows you the analytics identifier that applied before the reset, because Google's own per-user deletion is keyed on it. Email us that identifier and we will submit a deletion request to Google for it. We do not store the identifier ourselves, which is why it is shown once and only once: keeping a record of it would mean running exactly the kind of server this app is built to avoid. For crash reports there is no equivalent per-installation mechanism at all, so the retention rules are the only route. Your Google Play purchase record remains, because Google keeps it as a payment record and is entitled to. Your Android advertising ID belongs to the operating system rather than to PixSweep, so only you can delete or reset it, under Android Settings > Privacy > Ads; the dialog links you there.
Email you send us is kept only as long as needed to deal with what you wrote about, and then deleted. Where we have to be able to show that we handled a request or a defect claim properly, we keep the correspondence for as long as the relevant statutory limitation or record-keeping period requires, and delete it afterwards. You can ask us at any time to delete your correspondence, and we will do so unless one of those periods still applies.
The Rising Dev does not sell personal information for money. Information may be disclosed to Google and other third-party service providers described in Section 4 solely for the purposes described in that section. Depending on applicable law, personalized advertising or disclosure of identifiers to an advertising provider may be treated as a "sale," "sharing," or targeted advertising. Where available, use Settings > Privacy options and Android's advertising controls to change those choices.
Google, Apple, and device service providers may process information outside the European Economic Area, including in the United States. For such transfers, reliance is placed on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on the European Commission's Standard Contractual Clauses together with supplementary measures, in line with Chapter V GDPR. The relevant safeguards are published by each provider, and we will help you locate them on request.
PixSweep limits media access to Android permissions, keeps analysis in the app sandbox, excludes sensitive app records from Android backup as described above, blocks cleartext network traffic, trusts only the system certificate authorities, and uses TLS for permitted network connections. No security measure is perfect. In particular, the Private Vault is an access-control convenience and does not encrypt its media files.
PixSweep carries out no automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. The on-device AI only suggests items for review; every deletion, archive, or vault action needs your confirmation, and the suggestions are never used to evaluate you as a person. Where advertising is personalized, that personalization is carried out by Google on the basis of your consent and is described in Google's own privacy policy.
Where the GDPR applies, you have the right to:
To exercise a right, write to pixsweep@gmail.com. We reply within one month and may extend that by up to two further months for complex requests, as Art. 12(3) GDPR allows. Because PixSweep has no account system, we may need enough information to identify the processing you are asking about; we do not ask for more identification than necessary and we do not use what you send for any other purpose. Exercising a right is free of charge, and we do not discriminate against you for it.
Under applicable US state privacy laws you may also have the right to opt out of certain forms of targeted or cross-context advertising involving advertising identifiers, to know what is processed, to have it deleted, and to appeal a denied request.
For erasure specifically, use Settings > Delete my data, described in Section 8: it is faster than writing to us and it does what we could not do on your behalf in any case. Beyond that, PixSweep cannot retrieve or delete information held only on your device; you control that with the app and Android's app-data and media tools. The one thing we delete by hand is any email you have sent us.
PixSweep is not directed toward children under 13, or the higher minimum age applicable in certain countries, and we do not knowingly collect personal information from children. If you believe a child has provided information through a third-party service used by PixSweep, contact us so we can help address the request.
We may update this Privacy Policy, for example when a feature, a service provider, or the legal framework changes. We will update the effective date and, for material changes, notify users through the app or the Google Play listing. Where a change needs your consent, we will ask for it before that change takes effect. Please review the current version before relying on it.