Privacy Policy for MomentFold
Effective Date: September 5, 2026
Developer: Shanhe Yi
Contact: ysh@yishanhe.net
Website: https://yishanhe.net
MomentFold (MomentFold(折影)) is an iPhone photo-culling and organization application designed for privacy, speed, and user ownership. We believe that your personal photo library is deeply private and belongs solely to you.
MomentFold is built with a local-first architecture: the app operates without user accounts, without third-party tracking frameworks, and without remote servers operated by MomentFold. This Privacy Policy details how data is handled on your device, how PhotoKit and Apple Vision operate, and what happens when optional iCloud synchronization is active.
1. No Accounts, No Tracking, No Ads
- No User Accounts: You do not need to register, provide an email address, or sign in to use MomentFold.
- No Third-Party Trackers: MomentFold contains zero third-party analytics SDKs, advertising libraries, tracking tools, or device-fingerprinting frameworks.
- No Data Brokering: We never collect, sell, rent, monetize, or transmit your personal data or photos to third parties.
- No Remote Application Servers: MomentFold operates without custom application backends or cloud servers. All application processing occurs directly on your iPhone.
2. On-Device PhotoKit Access & Media Privacy
MomentFold requests access to your photo library through Apple’s official PhotoKit framework (either Full Access or Limited Access, as selected by you):
- Local Reading & Display: Photos and videos are loaded, rendered, and grouped entirely on your device.
- No Media Uploads: Your photos, videos, and visual assets are never uploaded to any external server or cloud service operated by the developer or any third party.
- Optional PhotoKit Favorite Synchronization: If you opt in to “Link Keep with Photos Favorites” in App Settings, MomentFold will synchronize your “Keep” actions with your Apple Photos Favorites using PhotoKit. This synchronization occurs strictly on-device between MomentFold and the system photo library.
3. On-Device AI & Computer Vision
MomentFold uses Apple’s native Vision framework to provide intelligent photo management features:
- Aesthetic Scoring & Hero Selection: Quality scores (such as sharpness, exposure, and overall composition) are computed on-device to help highlight the best shot in a sequence.
- Duplicate & Burst Grouping: Visual feature prints and capture timestamps are analyzed locally to detect bursts and similar variants.
- Private Processing: All Vision analysis and feature extraction execute entirely on your iPhone’s Neural Engine / GPU / CPU. No image data, facial patterns, or embeddings ever leave your device.
4. Staged Decisions & Two-Step Deletion Safety
MomentFold is intentionally designed to prevent accidental loss of photos:
- Staged Actions: Marking a photo as Keep, Trash, or Archive only stages that decision in MomentFold’s local SwiftData database.
- No Silent Deletions: MomentFold never silently or automatically deletes photos from your photo library.
- Explicit System Confirmation: Photos staged as “Trash” are only removed when you open the Review screen and tap Purge. This prompts Apple Photos’ official system deletion dialog, requiring your explicit authorization before any photo is moved to Recently Deleted in Apple Photos.
- Undo & Recovery: You can undo actions or return items from Archive/Trash back to unreviewed before confirming purge.
5. Local Storage & Optional iCloud Sync
Local Storage
All app-specific state (review decisions, custom albums, moment clustering indices, and cached scores) is stored in a private SQLite database managed by SwiftData inside MomentFold’s sandboxed container on your device.
Optional iCloud Sync
MomentFold provides an optional iCloud sync toggle in App Settings for multi-device continuity:
- Private CloudKit Container: Synchronization uses your personal Apple iCloud account via container
iCloud.net.yishanhe.momentfold.app. - Non-Media Data Only: Only app settings and lifetime purge event counts (
SyncedSetting,SyncedPurgeEvent) are synchronized. Your photos, videos, thumbnails, and metadata are never synchronized through CloudKit. - Developer Inaccessibility: CloudKit data is stored in your private database, encrypted by Apple, and is completely inaccessible to the developer.
- Opt-Out: You can disable iCloud Sync at any time in MomentFold’s App Settings.
6. Apple Privacy Manifest Compliance
In accordance with Apple App Store guidelines, MomentFold includes a standard privacy manifest (PrivacyInfo.xcprivacy):
- Tracking: Marked as
false(NSPrivacyTracking: false). - Data Collection: Marked as
none(NSPrivacyCollectedDataTypes: []), consistent with the “Data Not Collected” App Store Connect declaration. - Accessed API Reasons: Declares
UserDefaultsunder reasonCA92.1solely to persist your local user preferences (such as display toggles, developer mode, and playback settings) on your device.
7. Data Portability & Retention
- App Deletion: Deleting the MomentFold app from your device deletes the local SwiftData database and cached indexing metadata. Your original photos and videos in the Apple Photos library remain untouched and safe.
- Data Control: Because MomentFold does not maintain remote user databases or servers, your data is always under your direct physical and account control.
8. Children’s Privacy
MomentFold does not knowingly collect or solicit personal information from children under the age of 13.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the app or applicable regulations. Any updates will be posted on this page with an updated “Effective Date.”
10. Contact Us
If you have questions, feedback, or concerns regarding this Privacy Policy or MomentFold’s privacy practices, please contact:
Shanhe Yi
Email: ysh@yishanhe.net
Website: https://yishanhe.net