1. Scope and contact
This Privacy Policy applies to the Vignetra mobile application, this website, and related support and account services (together, the “Service”). In this policy, “Vignetra,” “we,” “us,” and “our” refer to the operator of the Vignetra Service.
Questions, privacy requests, and complaints can be sent to privacy@vignetra.com. Please do not email photos, face images, passwords, authentication codes, or other sensitive media. The legal name, postal address, and governing establishment of Vignetra’s operating entity will also appear in the applicable app-store listing and will be added here before general commercial release.
This policy does not govern the privacy practices of Apple, Google, Firebase, OpenStreetMap, your device manufacturer, your mobile carrier, or other independent services you choose to use.
2. Vignetra’s privacy architecture
Vignetra separates sensitive library intelligence from account metadata:
- On-device processing. Authorized media, thumbnails used by the app, local media references, visual embeddings and labels, face feature representations and groups, person names, and search indexes are processed and stored locally.
- Optional account sync. If you sign in, profile information and selected organizational metadata—such as titles, notes, corrected locations, hidden or viewed state, and preferences—can be stored in Firebase so supported details can follow you to another device.
- No Vignetra media cloud. Vignetra does not use Firebase Storage or another Vignetra-operated media store for your original photos or videos.
Because your original media and local indexes are not backed up by Vignetra, they may be unavailable if you lose access to the device or remove the media from its photo library.
3. Information Vignetra processes
3.1 Information you provide
- Account and profile details: first name, unique username, email address or private relay address, provider account identifier, and authentication status when you choose Apple or Google sign-in.
- Moment metadata: titles, notes, location corrections or labels, hidden state, viewed state, and other organizational choices you add or authorize.
- Preferences: settings needed to preserve your chosen experience, such as feature and display preferences.
- Communications: the email address, message, and any information you voluntarily include when contacting support.
- Purchase information: if paid features are introduced, the applicable app store handles payment credentials. Vignetra may receive a transaction identifier, product, entitlement, price region, purchase status, and validation result, but not your full payment-card number.
3.2 Information processed on your device
Depending on the permissions and features you enable, Vignetra may process the following locally:
- photos, videos, thumbnails, and media identifiers you authorize through system photo permissions;
- capture dates, media type, dimensions, duration, favorites or album-related state made available by the platform, and embedded location coordinates;
- calendar event titles, times, and locations when you separately authorize calendar access;
- visual embeddings and machine-generated scene, object, and color signals used to match natural-language searches;
- detected face regions, numerical face feature representations, similarity groups, review state, and the person names you choose to add;
- local database records, caches, viewed history, and operational state used to make indexing and swiping responsive.
These local results are used to organize and search the library on that device. Local face-related data, visual embeddings, and media thumbnails are not synced to your Vignetra account.
3.3 Information stored with an account
If you sign in, Vignetra may store the following in Firebase:
- your Firebase user identifier, sign-in provider, profile name, email or private relay email, and unique username;
- moment titles, notes, corrected place or country names, coordinates you authorize as a correction, hidden state, viewed state, and related timestamps;
- account-safe derived keys used to associate metadata with the corresponding library item where the app can resolve it on another authorized device;
- app settings, preferences, usage allowances, entitlement state, and anti-abuse or account-integrity records.
If you begin as a guest and later sign in to an existing account, Vignetra asks whether you want to merge supported local titles, notes, locations, and viewed history. Declining leaves the account unmerged and returns you to the guest session. Face names and recognition data stay on the device either way.
3.4 Service and network information
When you use online account, map, support, or website features, Vignetra and its service providers may automatically process standard request information such as IP address, approximate region derived from IP, device and operating-system type, app or browser version, timestamps, language, requested endpoint or map tile, authentication and App Check tokens, and security or error logs. Vignetra does not currently use advertising SDKs or a cross-app advertising identifier.
4. How information is used
Vignetra uses information to:
- provide moments, timeline, map, local visual search, local familiar-face grouping, notes, titles, and other features you request;
- create and secure an optional account, enforce unique and protected username rules, and sync supported metadata;
- show relevant dates, locations, and calendar context where authorized;
- process account deletion, privacy requests, subscription validation, and customer support;
- maintain security, prevent fraud and abuse, diagnose failures, and protect the Service and its users;
- comply with legal obligations and enforce the Terms of Use;
- improve performance and reliability using aggregated or de-identified information where reasonably possible.
Vignetra does not sell personal information, does not share it for cross-context behavioral advertising, and does not use your photo library, local face data, or private moment metadata to train a general-purpose model.
5. Legal bases for processing
Where laws such as the GDPR or UK GDPR require a legal basis, Vignetra relies on:
- Performance of a contract to provide requested app, account, metadata-sync, support, and purchase features.
- Consent for system permissions, optional people grouping, and other processing where the law requires consent. You can withdraw consent through the app or system settings, although this does not make earlier lawful processing unlawful.
- Legitimate interests in securing the Service, preventing abuse, troubleshooting, enforcing rights, and improving reliability, balanced against your rights.
- Legal obligations when processing is necessary to comply with applicable law, a valid legal request, tax, accounting, or consumer-protection duties.
6. When information is disclosed
Vignetra does not disclose your information to data brokers. Information may be disclosed in these limited circumstances:
| Recipient | Purpose and information involved |
|---|---|
| Firebase / Google Cloud | Authentication, Firestore metadata, callable backend functions, App Check, account security, and hosting. Standard request and account metadata may be processed. |
| Apple and Google | Identity provider services when you choose Sign in with Apple or Google; app distribution, purchases, and platform security. Their policies govern their independent processing. |
| OpenStreetMap tile infrastructure | Map tile requests can include IP address, user-agent or device request details, requested tile coordinates, and timestamps. Attribution appears directly on the map. |
| Platform geocoding services | Coordinates may be sent through the operating system’s geocoder to obtain a human-readable place label. Availability and provider handling depend on the platform. |
| Authorities or affected parties | Information may be disclosed when reasonably necessary to comply with law, respond to valid process, protect safety or rights, investigate abuse, or defend legal claims. |
| Successor organization | If Vignetra is involved in a financing, reorganization, merger, acquisition, or sale, information may transfer subject to appropriate confidentiality and notice requirements. |
Service providers may use information only to perform services for Vignetra under contractual or legal restrictions. Open-source libraries running locally do not receive your information merely because their code is included in the app.
7. Face-related and potentially biometric data
When “People in your moments” is enabled, Vignetra uses platform face-detection technology and a local similarity model to detect face regions, create numerical feature representations, and group faces that appear similar. You can review a group and assign a name, ignore it, or remove a name.
- This feature is for organizing your own authorized library, not for authentication, surveillance, or identifying a person against a public or shared database.
- Face images, feature representations, similarity groups, and assigned names are designed to remain on the device and are not synced to Vignetra accounts.
- Vignetra does not sell, rent, disclose, or use this data to identify anyone for another user.
- Turning the feature off removes saved face groups, features, and names from Vignetra’s local database without changing your original photos or videos.
Depending on where you live, face feature representations may be treated as biometric or sensitive information. Only enable this feature for media you are entitled to process, and do not add a person’s name where doing so would violate their rights or applicable law.
8. Retention and deletion
- Local app data remains until it is replaced through normal indexing, you use a relevant deletion or feature-off control, clear app data, or remove the app. The operating system may preserve certain device backups according to your system settings.
- Account metadata generally remains while your account is active. Using “Delete account” requests deletion of the Firebase account and associated Vignetra cloud metadata, and clears Vignetra’s local indexes on that device.
- Security, legal, and backup records may remain for a limited period where technically necessary, required by law, or reasonably needed to prevent fraud, resolve disputes, enforce agreements, or document compliance. They are isolated from ordinary product use where feasible.
- Support communications are retained only as long as reasonably necessary to address the request, maintain support history, comply with law, and protect legal rights.
Deleting a Vignetra account or local index never deletes original media from your system photo library. Deleting an Apple or Google account does not automatically delete a separate Vignetra account; use Vignetra’s in-app deletion control or contact us.
9. Your choices and privacy rights
In-app and device controls
- Use Vignetra as a guest without creating an account.
- Choose full or selected photo access and change permissions in system settings.
- Authorize or deny calendar access separately.
- Turn People off and remove local face-related data.
- Edit or remove titles, notes, names, and corrected locations.
- Log out and choose the local-data behavior offered by the app.
- Delete your account and associated Vignetra metadata from the Privacy section.
Legal rights
Depending on your location, you may have rights to access, know about, correct, delete, restrict, object to, or obtain a portable copy of personal information; withdraw consent; opt out of certain sales, sharing, profiling, or targeted advertising; and appeal a refusal. Vignetra does not currently sell personal information, share it for cross-context behavioral advertising, or conduct legally significant automated decision-making.
Send a request to privacy@vignetra.com. Describe the right you want to exercise and the account email or username involved. We may need to verify that you control the account. Authorized agents must provide proof of authority, and we may verify the request directly with the account holder. We will not discriminate against you for exercising a privacy right.
You may also complain to your local privacy or data-protection authority. California residents may request the categories and specific pieces of personal information Vignetra holds, sources, purposes, recipients, correction, and deletion as provided by law. EEA, UK, and Swiss residents may contact their supervisory authority and may object to processing based on legitimate interests.
10. Security
Vignetra uses safeguards intended to protect information, including platform permission controls, local app storage, secure token storage, Firebase Authentication, Firebase App Check, per-user Firestore access rules, server-side validation, and restricted backend functions. We limit synced data by design and avoid a cloud copy of your original media.
No storage or transmission method is perfectly secure. Keep your device and provider account secure, use device authentication, install updates, and contact us promptly if you believe your Vignetra account has been compromised.
11. International processing
Vignetra and its providers may process account and service information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, Vignetra relies on approved contractual safeguards, adequacy decisions, provider certifications, or another lawful transfer mechanism. Mandatory local rights remain available.
12. Children
Vignetra is not directed to children under 13, or to anyone below the minimum age at which they can consent to an online service where they live. A parent or guardian must authorize use where required. Do not use Vignetra to unlawfully identify, track, exploit, or expose a child. If you believe a child provided account information without required permission, contact us so we can investigate and delete it where appropriate.
13. This website and cookies
This landing site is hosted on Firebase Hosting. At launch, Vignetra does not place advertising cookies, analytics cookies, or cross-site tracking pixels on this site. The hosting service may process standard request logs such as IP address, user agent, requested URL, response status, and timestamp for delivery, reliability, abuse prevention, and security.
Email links open your selected email service, whose privacy practices are independent. If Vignetra later adds optional analytics, a mailing-list form, or non-essential cookies, this policy and any required consent controls will be updated before those tools are enabled.
14. Changes to this policy
We may update this policy as Vignetra evolves or legal requirements change. The “Last updated” date will change, and material changes will be highlighted in the app, on this site, or by another appropriate notice before they take effect where required. Continued use after the effective date is subject to the updated policy, but Vignetra will request fresh consent where law requires it.
For questions or requests, email privacy@vignetra.com. You can also review the Terms of Use, Accessibility Statement, or Support page.