Privacy
policy.
Redact is an app that automatically anonymises faces in photos. This privacy policy describes which data Redact processes — and, more importantly, which data it does not.
01 What data does Redact process?
Your photos and videos never leave your device.
Redact only processes the images that you actively load into the app from your photo library or your file system. Those images are analysed and anonymised locally on the device, then either saved back to your photo library or exported as a file — at your explicit request.
There is exactly one thing Redact can ever send off the device, and only when you write it yourself and confirm it by hand: a message through the optional feedback form. Nothing about you or your images travels with it — see section 08.
Redact collects none of the following:
- No account creation, no sign-in
- No analytics, no usage statistics
- No crash reports
- No advertising IDs, no tracking
- No location data
- No contacts, no calendar, no microphone, no camera
- No cloud synchronisation
02 Face data
Redact uses an on-device Core ML model to detect the location of faces in your photos. The detection result is a set of bounding-box coordinates that indicate where a face appears in the image — no facial features, biometric templates, face prints, or other identifying information is ever extracted.
Face data is not collected, stored, or retained. Bounding-box coordinates exist only in volatile memory for the duration of the active editing session and are discarded as soon as you close the image or quit the app. They are never written to disk, never uploaded, and never transmitted over a network.
Face data is not shared with any third party. Redact contains no third-party SDKs and no analytics services, and detection and anonymisation involve no server connection whatsoever. The only network request the app can make at all is a feedback message you write and confirm yourself (section 08), and no face data is part of it. Because no face data is shared, there are no third-party recipients and therefore no third-party storage or retention practices to disclose.
03 Where is data processed?
Entirely and exclusively on your iPhone, iPad or Mac. Face detection runs through Core ML directly on the device. Importing, detecting, anonymising and exporting need no connection to any server — that whole workflow runs in airplane mode.
The one exception is the optional feedback form: if you write a message there and confirm it, that message is transmitted. It is the app's only network request, it is never triggered automatically, and it carries none of your images (section 08).
Temporary copies of imported photos are stored in the app's own cache directory to speed up processing, and are cleaned up when the app exits, or at the next launch at the latest.
04 Third parties
Redact bundles no third-party SDKs. No ad networks, no analytics services, no crash reporters, no cloud back-ends.
Feedback messages are the only data the app ever sends, and they go to a server the developer of Redact operates personally rather than to a third-party service. Like any server, it does rely on outside companies to run: a hosting provider and a reverse proxy, both acting as processors, both named in section 08.
05 Purchases & in-app purchases
Redact is available as a freemium app on the App Store: the core features are free, and Redact Pro can be unlocked through an auto-renewing subscription (monthly or yearly) or a one-time lifetime purchase.
All purchases are handled exclusively through Apple's App Store / StoreKit. This means:
- The developer of Redact never receives your payment data (credit card, Apple ID, name, billing address). That information stays with Apple.
- The app only receives, from Apple, the information about whether a particular in-app purchase is valid for your Apple ID. This check (receipt validation) happens locally on the device — Redact runs no licensing or activation server of its own.
- Apple provides the developer with aggregated, anonymised sales and download statistics in App Store Connect. None of this data can be linked back to an individual person.
For the processing of your payment data, Apple's privacy policy applies.
06 Permissions
Redact requests two iOS permissions, both exclusively for the core feature:
| Permission | Purpose |
|---|---|
| Photo library (read) | So that you can pick photos to anonymise. |
| Photo library (add) | So that the anonymised image can be saved back to your library. |
Both accesses happen locally — the images are never uploaded.
07 Storage & retention
Original images stay where you keep them (the Photos app, the Files app). Redact creates short-lived working copies inside the app container's cache during processing; those are cleaned up automatically.
Anonymised results are only saved if you explicitly trigger it — either back into the photo library or as a file export.
08 Feedback form
Redact has an optional feedback form, reachable under Settings → Send feedback. It is the only place in the app where anything is sent over the network — and it only sends when you say so.
Nothing is ever sent automatically. The form works in two steps: you write your message, and then you see a confirmation screen that lists, word for word, every single field that would be transmitted. Only when you tap “Agree and send” does anything leave your device. Close the form before that, and nothing is transmitted at all.
What is transmitted — this list is complete and final:
- The message you wrote yourself
- The category you picked (problem, idea, or other)
- The app version (for example “1.1”)
- The platform in coarse form (for example “iOS 18” or “macOS 26”) — deliberately without your device model and without the patch level, so the combination cannot turn into a fingerprint
- Optionally a contact address, only if you want a reply. The field starts out empty; leave it empty and your report is anonymous.
What is not transmitted:
- No device or installation identifier, no IDFA or IDFV
- No location
- No photos, no videos, nothing about the images you edited
- No usage or analytics data
- No timestamp fingerprint
Because a report carries no identifier of any kind, two reports sent from the same device are not recognisable to the recipient as belonging together — unless you enter a contact address yourself. The app also uses a stateless network session with no cookies and no cache, and sends a neutral user agent, so that on a technical level, too, nothing beyond the fields listed above goes out.
Who receives it. The message goes to a server the developer of Redact runs personally — an n8n instance on their own VPS in a data centre in Falkenstein, Germany — which forwards it to a private mailbox and to a self-hosted Matrix room. It is not passed on to anyone for their own purposes, and it is never used for analytics, tracking or advertising. The server keeps no processing history at all — neither of successful nor of failed submissions. Your message is kept in the mailbox and the Matrix room for as long as it takes to deal with it, and for twelve months at the very most.
Two companies help run that path, both as processors. The machine is rented from Hetzner Online GmbH in Germany, under a data processing agreement pursuant to Art. 28 GDPR. In front of it sits Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) as a reverse proxy, which handles delivery and shields the server from attacks and overload. Neither company may use your message for purposes of its own; both act on the developer's instructions.
What Cloudflare means for your message. Cloudflare terminates the encrypted connection, so it sees the request — your message and your IP address — before passing it on, and it keeps connection logs of its own. Its network is global: your request is handled by whichever edge location is nearest, and that is not necessarily one in Germany or even in the EU. A report sent from Germany may be processed in London. Your message can therefore be processed outside the EU, including in the USA, where Cloudflare has its headquarters. Cloudflare's Data Processing Addendum covers that transfer on the basis of the EU-US Data Privacy Framework and the EU Standard Contractual Clauses. Having attack protection in front of a small self-hosted server is ordinary practice; it is named here because it is the one part of the path that is not under the developer's own roof.
One point worth being plain about: as with every HTTP request, your device's IP address is technically necessary for the request to reach the server at all. It is not stored alongside your message, not evaluated, and never linked to it — not even when a submission fails. The developer's server keeps no web-server access logs either, so no IP addresses are recorded there. Cloudflare, sitting in front of it, logs connections independently of that — outside the developer's control and governed by Cloudflare's own privacy policy.
Legal basis: your consent under Art. 6(1)(a) GDPR, given by the explicit confirmation in the form. You can withdraw it at any time with effect for the future, simply by not sending anything further; if you would like a report you already sent to be deleted, write to hello@vortex-labs.de. Every other feature of Redact works exactly the same if you never touch the form at all.
09 Children
Redact is rated 4+. Redact collects no data by itself, and the only thing that can ever be transmitted is a feedback message written and confirmed by hand (section 08), so there are no special rules for minors.
10 Changes to this policy
If anything in this privacy policy changes, the updated version will be published at the same URL. The date at the top of this document indicates the version currently in effect.
11 Contact
For privacy questions or notes, please reach out at hello@vortex-labs.de.