Privacy Policy
Photo Footprints · updated 27 July 2026
The short version
Footprints builds a map of the places you’ve been by reading the date and location that your camera already saved inside your photos.
All of that happens on your phone. There is no account to create, nothing to sign in to, and no server that stores your photos, your locations, or your trips. We cannot see your map, because it only exists on your device.
What Footprints reads
With your permission, Footprints reads the following from your photo library:
- the date and time a photo was taken
- the GPS coordinates saved in the photo, if there are any
- the camera's make and model
- the file name and file type
- the photo's dimensions and a small numeric fingerprint used to spot duplicates
It uses these to work out where you were and when, group nearby photos into places, and group places into trips.
Footprints does not read, copy, upload, or transmit the pictures themselves. It reads the information stored alongside them. When the app shows you the photos from a trip, it is asking iOS to display images that are already on your phone.
Photos without a location, and screenshots, are never turned into places on your map.
Where that information goes
Nowhere. It stays in a database on your device, inside the app’s own storage, which iOS protects like any other app’s private data.
Place names are worked out on your phone too. The app carries its own offline list of around 135,000 cities and towns, so turning coordinates into “Lisbon” or “Kansas City” does not involve asking anyone.
What does leave your phone
We want to be exact about this, because “nothing leaves your phone” is almost true but not completely.
Map tiles.The map’s background — coastlines, borders, roads, place labels — is not stored in the app. It is downloaded as you look at it from a map service run by CARTO (basemaps.cartocdn.com). Like any web request, that service receives your device’s IP address and can see which square of the world map you asked for. It does not receive your photos, your pins, your trips, or any information about them: those are drawn by your phone, on top of the map, after the map arrives. CARTO’s own privacy policy governs what they do with that request.
If you use the app with no network connection, the map background will be blank and everything else still works.
Crash reports and App Store statistics. If you have turned on sharing analytics or crash data with developers in iOS Settings — or if you are testing the app through TestFlight, where Apple provides crash reports automatically — Apple may send us reports about crashes and basic usage. These come from Apple, are governed by Apple’s privacy policy, and contain diagnostic information about the app, not your photos or your locations. You can turn this off in Settings › Privacy & Security › Analytics & Improvements.
That is the complete list.
What Footprints does not do
- No account, no email address, no password, no sign-in.
- No advertising, no ad identifiers, no tracking across apps or websites.
- No analytics or telemetry of our own, and no third-party analytics SDK.
- No selling or sharing of personal information, under any definition, because none is collected.
- No data broker relationships.
- No cloud backup of your map by us. Your map is not stored on any server we operate or rent, because we do not operate or rent one.
Permissions the app asks for
Photo library. Required, because photos are the entire source of the map.
Choosing Full Access lets the app map your whole library. Choosing Limited Access also works — the app simply sees only the photos you selected and maps those. Access can be changed or revoked at any time in Settings › Privacy & Security › Photos.
Footprints does not ask for location access. It does not track where you are; it reads where your photos say you were.
Your data and your control
Because everything lives on your device, you control it directly:
- Settings › Start over in the app deletes every place, trip, and record Footprints has built. Your photos are untouched.
- Deleting the app removes all of it at once. Nothing is left behind on a server, because there is no server.
- Settings › Excluded photos shows anything the app filtered out and lets you put it back.
- Any place or trip on the map can be removed, renamed, or corrected by hand.
Your rights under GDPR, UK GDPR, and CCPA/CPRA
These laws give you the right to know what personal information a company holds about you, to receive a copy, to correct it, to delete it, and to opt out of its sale or sharing.
We hold none. We have no account records, no server-side database, and no profile of you, so there is nothing for us to disclose, export, or delete, and nothing to sell or share. Exercising these rights against Footprints requires no request to us: deleting the app deletes everything.
We are not a “data broker” under any applicable law and have never sold or shared personal information.
Children
Footprints is not directed at children under 13 and does not knowingly collect information from anyone, of any age. There is no sign-up, no profile, and no content shared with us or with other users.
Security
Your map is stored using the operating system’s own app data protection, in the app’s private container, encrypted at rest by iOS along with the rest of your device when a passcode is set. Since nothing is transmitted to us, there is no account to be breached and no server holding your history to be compromised.
Changes to this policy
If the app ever changes what it reads or where anything goes, this policy will be updated before that change ships, and the date at the top will change with it.
Two changes are worth naming in advance, because they are being considered:
- Optional iCloud sync, which would let your map move between your own devices. If it ships, your data would go to your own private iCloud database under your own Apple Account. Apple would hold it; we still would not be able to read it.
- Optional visit detection, which would use Apple’s location services to notice places you stayed even when you took no photos. It would require your explicit permission and would be off unless you turned it on.
Neither is active in the current version.
Contact
Questions about this policy, or about anything the app does: hello@photofootprints.com.
For how this website — as opposed to the app — handles cookies, analytics and server logs, see the privacy summary.
Footprints is made by Pickup and Play LLC, United States.