Help / Reference
Privacy & security
The iPhone & iPad companion app is in release testing — it isn't on the App Store yet, and this guide describes the current test build.
The Android companion app is in release testing — it isn't on Google Play yet, and this guide describes the current test build.
LocalPhotos has no account or hosted photo cloud, and LocalPhotos itself collects no analytics. Optional Places sends exact photo coordinates to Apple or Google for place names and sends map viewport requests to the platform map provider. Android's ML Kit may send Google anonymous technical diagnostics. Sync and NAS traffic goes directly to devices or storage you choose. The site-wide privacy policy has the full details.
- Your photos and all derived data (faces, places, search text) live in the folders you chose, on your own disks.
- Companion Sync runs over TLS with a pre-shared key, plus a per-device pairing token — an unpaired device can’t read anything.
- Synced libraries: thumbnails and metadata in the app’s private storage; full originals only if you download them.
- The pairing token lives in the Keychain — never in plain files.
- Device-made libraries: the index and thumbnails; your photos stay in the folder you picked.
- The pairing PIN rotates every 30 seconds and is never stored.
- Synced libraries: thumbnails and metadata in the app’s private storage; full originals only if you download them.
- Pairing tokens and NAS passwords: in encrypted storage backed by the Android Keystore — never in plain files.
- Folder and NAS libraries leave photos at their source. Camera Roll libraries copy originals into the managed phone, USB/SD, or NAS archive you choose.
- The pairing PIN rotates every 30 seconds and is never stored.
Was this page helpful? Tell us what’s missing — it goes straight to a human, not a tracker.