Privacy policy
Updated October 6, 2026
Your photos and choices
Photo review and visual recognition run on your device. The app reads the photos you allow through iOS and records their Photos identifiers and your keep or delete choices. Original photos stay in the system photo library.
Adding photos to albums
When you swipe a photo up or save a trip as an album, PicLoom adds the photos to an album in your Photos library, creating a new album only when you ask. It only adds: nothing is removed from your library, edited or uploaded.
Blurry photos and duplicates
Finding blurry photos, duplicates and the largest items runs on this device. PicLoom reads small thumbnails that Photos already keeps on the device and the file size of local videos; it does not download originals from iCloud. Only a few numbers per item are kept, in this app, and nothing is uploaded. Photos you set aside go to To delete like any other choice, and iOS asks before anything is removed.
Sharing photos and videos
Sharing from the viewer sends only the selected media’s current edit through the iOS share sheet, without app text or links. Capture dates and location metadata may remain. Photos may download the item from iCloud under your download settings. Temporary copies are removed after sharing; interrupted copies expire. This sharing does not earn review rewards or keepsake progress.
Local storage and widgets
Review choices, statistics, preferences, journal entries, drafts, photo clues and previews are stored locally. Only explicitly saved entries supply entry summaries and selected previews to Home Screen widgets. An account is not required.
Pictures kept with your journal
Saving an entry keeps compressed copies of its chosen pictures in this app. Videos and Live Photos keep still covers without sound or motion. These copies remain after original photos are deleted or access is changed. They use local storage and are included in device backups when enabled. Deleting the app removes its local copies.
Footprints and keepsakes
Your keepsakes, earned dates, saved entry dates and completed share dates stay on this device. Sharing a keepsake is always your choice.
Footprints map
The Footprints map reads the location saved with your photos and videos on this device, and matches it to cities using a city list and province and state boundaries built into the app (GeoNames, geonames.org; geoBoundaries, geoboundaries.org; both CC BY 4.0). The globe is Apple Maps satellite imagery, so imagery for the area you are viewing is loaded from Apple Maps; when you are offline, a built-in globe (NASA Blue Marble) is shown instead. Your photos and your list of places are not sent. Only when you tap "See this place now" is that one photo's location sent to Apple to look for street imagery.
Invitations and allowance sync
When you are signed in to iCloud, review allowance and reward records sync to your private iCloud database. Invitations use public codes and confirmations linked to an opaque iCloud identity. These records contain no photos, journal text, names, email addresses or local photo identifiers. One account can confirm one invitation. No advertising ID, device fingerprint or automatic clipboard reading is used.
Gifts and your iCloud account
When gifts are enabled, accepting one uses a CloudKit identity proof and a trusted service hosted on Cloudflare. The service keeps an opaque account identifier, gift amount, dates, note and issuance record in CloudKit; it receives no photos, journal content or photo identifiers. Signed receipts also sync to your private iCloud database. The operator sees gift status, not your Apple identity. Authentication proofs are cleared within seven days; gift records are kept for permanent restoration. Connection data is used to deliver and protect the service, not for advertising.
Deleting gift data
In Invitations & gifts, you can confirm a request to delete gift credits, receipts and account links. Processing cannot be undone. Permanent reviews already used remain deducted, including from future permanent grants. Spent-code markers prevent reuse; a minimal account marker prevents old receipts from returning. Private receipts and device caches are cleaned when devices reconnect. Photos, journal entries, invitation records and Pro purchases are kept.
Places
A place clue is looked up only when you ask for it from a selected photo. PicLoom sends that photo's location rounded to about 1 km (0.01° of latitude and longitude) to Apple geocoding and keeps the returned place name as an editable clue. Photos are not uploaded and your current location is not requested. PicLoom does not request or show weather.
Journal cards
Card layout happens on this device. A journal card includes the text and selected photos or video covers shown in its preview. It leaves the app only when you choose a system share destination or save it to Photos. Context notes and photo identifiers are not printed. Sharing an entry does not upload to a PicLoom service or earn review rewards. If you added an activity stamp or card, it is printed below the text.
Journal pages, reminders and time capsules
Journal pages, auto pages and videos are laid out on this device from your photos, places and occasions; nothing is uploaded. Journal reminders (a new page, last year’s page, a month recap, a time capsule opening) are notifications scheduled on this device. You can turn off new-page, last-year and recap reminders in Settings; a time capsule always reminds you on the day you chose. Also add to Calendar opens the system event sheet: PicLoom cannot read your calendar, and the event holds only a title, the date and a link to the page, not its words, photos or place.
Optional cloud writing
Writing help is optional. Only tapping Help me write sends your current writing, note and chosen material notes to your configured service. Local photo identifiers and coordinate keys are omitted. Up to six selected still images or video covers are included only with separate consent. No video sound or motion is sent. Opening a day or saving settings does not call AI.
API keys
Your cloud API key is kept in the iOS Keychain and is sent to your chosen endpoint to authorize requests. To remove it, clear the API Key field in Settings → Writing assistant and save. Cloud services apply their own privacy and billing terms.
Activity from Apple Health
With your permission, PicLoom reads from Apple Health on this device only workout type, duration, distance and active energy, your step count and your activity rings. It does not read heart rate, routes or location, sleep or other health records, never writes to Health and never uses health data for advertising. Health data stays on this device: it is not synced to iCloud or sent to PicLoom. Add to this page saves an activity stamp or card with your entry, and the activity phrases above the keyboard place short words such as a workout or your steps into your text. Both appear in shared cards; writing help receives only your text. Pages with health content are excluded from device backups. Change access in Health at any time; removing the activity keeps your text.
Your controls
You can change photo access in iOS Settings. Removing photos from the library requires a separate confirmation through iOS. Health access is managed in the Health app: your profile → Apps → PicLoom.
Purchases, reminders and diagnostics
Apple processes Pro purchases and restores through your App Store account. Daily reminders are optional and scheduled on this device. Paywall views, quota blocks, share previews and claimed rewards are counted locally. Copying version details includes only the version and software Build ID, stays on this device and expires after ten minutes. Email drafts also include device model, system version and app language. Diagnostic reports can be previewed before sharing; local activity counts are optional and off by default. Reports exclude developer and source metadata. The Build ID identifies a software package, not you or your device. No automatic diagnostic uploads, advertising or tracking SDKs are included.
Backups and saved entries
Journal entries, drafts, moods, photo clues and review records are local app data included in device backups when enabled. Entries and drafts with added activity from Apple Health are excluded from device backups. This is not live sync. API keys remain on this device. Drafts are kept separately from saved entries; failed saves can be retried without generating again. Available previous versions can be restored.
This website and support
Cloudflare hosts this site and processes connection data, such as IP addresses, to deliver and protect it. We add no advertising trackers or analytics scripts. Your language preference and first automatic language choice are stored in your browser. Interactive examples use public media and fictional journal entries; they do not access or upload your photos or send them to AI. If you contact support, we use the information you choose to send to respond to your request.
Invitation and gift pages
Invitation pages read a code from the link query; gift pages read it from the fragment. They do not store codes or send claim or attribution requests. They write to the clipboard only when you choose Copy. The gift service may include a private issuer note that the developer can remove separately. Temporary identity proofs are scheduled for deletion within seven days, subject to the service operating normally.