What runs where
Everything runs on your device: the library scan, the inference, the clock matching, the map review, the writes and the undo journal. Photo Geotag makes no network requests on your photos' behalf. The map tiles you see are rendered by Apple's MapKit under Apple's privacy terms — your photos and their coordinates are not sent anywhere to draw them.
What we collect
Nothing. No accounts, no analytics, no crash-reporting SDKs, no advertising identifiers, no “anonymised usage data”. We cannot see your photos, your locations, or the fact that you use the app at all.
What the app stores
- Proposals and decisions — which groups you confirmed, skipped or ignored — in a local database on your device.
- The undo journal — each written photo's prior location, kept locally so Undo works across launches.
- Clock offsets you confirmed, per camera.
Deleting the app deletes all of it.
What the app writes
Only the location field of photos you explicitly confirmed, only when you press Apply, through Apple's Photos framework. Every write is journalled first and reversible with Undo. If you'd rather nothing be written at all, export a GPX file instead.
Permissions
The app asks for full photo-library access because its method — reading the timeline around each untagged photo — does not work honestly on a partial library. It asks for nothing else: no location services, no contacts, no notifications.
Questions
Ask anything: sgumz@me.com.