Privacy

Private photo work stays centered on your device.

Your device

Vestigra separates local photo processing from the online services used for accounts, subscriptions, consent, and advertising.

Vestigra does not upload your gallery photos to its backend for OCR, visual classification, or search.

At a glance

Clear boundaries for a private library.

Photos are processed locally

OCR, supported visual recognition, and search run on the device.

Recognized text stays local

OCR and search-index information is stored in the app’s local database.

No photo-search history

Vestigra does not keep a history of queries made within the photo library.

Core use needs no account

Gallery browsing, OCR, and photo search are available without signing in.

Data architecture

Local photo content and online services have different jobs.

The private photo workflow runs inside the device. A limited backend supports account-related and operational services, not gallery analysis.

Your device

  • Authorized photos
  • OCR and text positions
  • Supported visual categories
  • Search index
  • Voice reading

Private photo content is not uploaded to Vestigra for analysis

Online services

  • Account
  • Subscription state
  • Consent
  • Advertising
  • Operational backend

What happens on the device

Photos, OCR, supported visual recognition, search, cropping, and voice-reading related processing operate locally. Indexing stops when the app process closes; Vestigra does not continuously scan photos in the background.

Authorized photographs

Vestigra accesses images allowed through Android. It does not send them to its backend for OCR, classification, or search, and it does not keep a private copy of the full library.

Previews without a second catalog

Previews are decoded locally when needed. Vestigra does not maintain a second persistent thumbnail library, although temporary memory or system caches can exist.

Sharing is an explicit action

A photo can leave Vestigra’s context when you intentionally use the Android selector to share it with another application.

What Vestigra stores locally

The local Room database keeps the information needed to recognize and retrieve photos without sending that private search material to Vestigra’s backend.

  • Original and normalized recognized text
  • Text and number search indexes
  • Recognized blocks and bounded positions
  • Beach, Car, Dog, Cat, and Person categories
  • Processing state and minimal image identity data
  • Favorites, settings, and local consent state when applicable

Vestigra does not store a history of your photo-search queries.

Accounts and online services

Vestigra has a backend for limited online operations. That does not turn the backend into a photo-processing service.

Optional accounts

Accounts use Google Credential Manager and Firebase Authentication. They are optional for the gallery, OCR, and photo search.

Limited backend purpose

The backend supports accounts, installations, subscription state, advertising eligibility, consent, account deletion, and related operations. It does not process or store the gallery for OCR, classification, or search.

When Internet is used

Internet access may be needed for sign-in, account operations, subscriptions, consent, advertising, and backend communication. Core photo functions can operate offline.

Analytics and technical diagnostics

Firebase Analytics is disabled, and Vestigra does not run first-party analytics on photo content, OCR text, or photo-search queries.

Google SDKs may still collect technical information such as device or app details, performance, API configuration, input/output size metrics, errors, diagnostics, or usage events.

Advertising data is separate from photo content.

Google AdMob and the User Messaging Platform may operate according to consent and configuration. Their technical and advertising data is not used to recognize photo contents.

Private photo content
Photos, recognized text, search queries, filenames, geometry, and private image metadata are not uploaded to Vestigra’s backend for the private photo functions described here.
Advertising and technical data
Depending on consent and configuration, this can include advertising identifiers, ad interactions, diagnostics, IP address, approximate general location, and consent information.

Android permissions

Access is requested for a defined purpose.

Vestigra directly declares photo access and Internet permissions appropriate to Android versions. Permission labels can vary by device.

PermissionPurposeAndroid declaration
PhotosAccess images you allow Vestigra to use.READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGE (up to API 32)
Selected photosSupport limited access to user-selected images on newer Android versions.READ_MEDIA_VISUAL_USER_SELECTED
InternetConnect accounts, subscriptions, consent, advertising, and online services.INTERNET

Permissions Vestigra does not directly request

Camera, microphone, precise location, contacts, videos, and MANAGE_EXTERNAL_STORAGE.

The merged release manifest can include technical permissions from SDKs, such as network state, advertising identifiers, Privacy Sandbox, READ_GSERVICES, WAKE_LOCK, or FOREGROUND_SERVICE. This does not mean Vestigra continuously indexes photos in a background service.

Deletion choices

Deleting the app and deleting an account are different actions.

Android removes local app data on uninstall, while original media and a remote account have separate lifecycles.

Uninstall Vestigra

Android removes the local Room database, OCR data, recognized categories, favorites, settings, local consent state, caches, and local credentials. App backups are disabled.

What remains

Original MediaStore photos and cropped copies explicitly saved there remain. Uninstalling also does not automatically delete a remote account.

Technology transparency

Third-party technologies with specific roles.

These services support recognition, sign-in, advertising consent, or speech. They do not all receive the same kind of information.

Google ML Kit

Text Recognition, Image Labeling, and Language Identification support on-device features. Relevant models are integrated in the app; Google SDKs can still produce technical diagnostics and usage metrics.

Firebase Authentication and Credential Manager

These technologies support optional sign-in and account operations.

Google AdMob and UMP

These services support advertising and consent flows and can process advertising-related and technical data according to configuration and consent.

Android text-to-speech

Vestigra uses the installed Android speech engine and chooses an offline voice when available and configured. Reading text does not require microphone permission.

Public information

Availability details stay separate from privacy claims.

See the confirmed platform and the information Vestigra can responsibly publish today.

Check availability