Privacy Policy
Last updated: August 1, 2026
1. Overview
PicSweep ("we", "our", "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Chrome extension and website to find and manage duplicate, near-duplicate, and blurry photos in your Google Photos and iCloud Photos libraries.
2. Information We Collect
2.1 Account Information
When you sign in to use PicSweep, we receive and store the following:
- For Google Photos: Your Google account ID, email address, display name, and profile picture URL (received via Google Sign-In, an OAuth flow).
- For iCloud Photos: Your Apple user ID, name, and email address (received via Sign in with Apple, an OAuth auth flow).
This information is used solely for authentication and account management.
2.2 Usage Data
We track the number of photos you scan and delete each day to enforce free-tier quotas. This is associated with your account, or with a random anonymous identifier generated by the extension if you are not signed in. We do not track which specific photos you analyze.
2.3 Payment Information
Premium payments are processed through Polar.sh. We do not store credit card numbers or payment details on our servers. Polar.sh handles all payment processing in accordance with their own privacy policy.
3. Information We Do NOT Collect
This is the most important section. PicSweep is designed with a privacy-first architecture:
- ❌ We do NOT access, download, or store your photos
- ❌ We do NOT transmit your images to our servers
- ❌ We do NOT use the Google Photos API or Apple's iCloud APIs to read your library — we only automate the browser session you already have open
- ❌ We do NOT sell or share your data with third parties
All core image analysis — including photo scanning, thumbnail loading, perceptual hashing, and blur detection — is performed entirely within your browser (client-side). Only minimal metadata is sent to our backend to run the similarity grouping algorithm: a perceptual hash (a mathematical "visual fingerprint"), a blur score, image dimensions, file size, filename, and capture time. This data is held in memory only, is never written to disk, and is automatically deleted once the analysis completes. Your actual photos never leave your device or browser.
4. Google Authentication (OAuth Only)
PicSweep uses Google Identity Services (Google Sign-In) solely for authentication. We do
not use the Google Photos API or any other Google API to access your photo library, and we do
not request the photoslibrary scope or any library-access permission. Our use of the limited
profile information received through Google Sign-In adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only request the OAuth scopes:
emailandprofile(basic identity for sign-in). - The extension works inside your own browser tab on photos.google.com and automates the same UI actions you would perform yourself (scrolling, selecting, and clicking "Move to trash").
- We do not use Google user data for advertising purposes.
- We do not transfer Google user data to third parties unless necessary for providing the Service.
- We do not use Google user data to train AI/ML models.
5. Apple / iCloud Authentication (Auth Flow Only)
PicSweep uses Sign in with Apple solely for authentication when you use iCloud Photos support. We do not use Apple's iCloud APIs, CloudKit, or any other Apple API to access your photo library. Our handling of the limited information received through Sign in with Apple adheres to the Apple Developer Program Privacy Guidelines and Apple's guidelines for Sign in with Apple.
Specifically:
- We only receive the user identifier and the name/email you explicitly authorize Apple to share with us.
- The extension works inside your own browser tab on icloud.com/photos and automates the same UI actions you would perform yourself — PicSweep never accesses or deletes photos through Apple's iCloud APIs.
- We do not use Apple user data for advertising purposes.
- We do not transfer Apple user data to third parties unless necessary for providing the Service.
- We do not use Apple user data to train AI/ML models.
6. Data Storage and Security
Account information is stored in a PostgreSQL database hosted on our secure server. Scan data (perceptual hashes and minimal metadata) is held temporarily in memory on our servers only for the duration of a scan analysis and is automatically purged after 30 minutes of inactivity. We implement industry-standard security measures including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- JWT-based authentication tokens with expiration
- Database access restricted to application services only
7. Data Retention
We retain your account information for as long as your account is active. Scan sessions are held in memory only and are deleted after the analysis completes or after 30 minutes of inactivity. Daily usage counters are retained to enforce quotas. If you wish to delete your account and associated data, please contact us at the email address below.
8. Cookies
We use a single functional cookie (picsweep_token) to maintain your authentication session. This
cookie:
- Contains only your authentication token
- Expires after 3 days
- Is not used for tracking or advertising
9. Third-Party Services
We use the following third-party services:
- Google Identity Services — For Google Sign-In authentication only (OAuth); PicSweep does not use the Google Photos API (governed by Google's Privacy Policy)
- Sign in with Apple — For iCloud Photos authentication only (auth flow); PicSweep does not use Apple's iCloud APIs (governed by Apple's Privacy Policy)
- Polar.sh — For payment processing (governed by Polar's Privacy Policy)
- Cloudflare — For content delivery and security (governed by Cloudflare's Privacy Policy)
10. Children's Privacy
PicSweep is not intended for use by children under the age of 13. We do not knowingly collect personal information from children.
11. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Object to or restrict processing of your data
- Data portability
To exercise these rights, contact us at the email address below.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date.
13. Contact Us
For privacy-related questions or requests, please contact us at:
[email protected]