Privacy Policy
Luz Photo · Last updated September 1, 2026
Luz Photo is built to collect nothing about you. This policy explains the few points at which it touches a network, and what the optional collection-sharing feature does.
What the app collects
Nothing. Luz Photo stores everything locally on your Mac. There are no accounts, no analytics, no telemetry, no advertising, and no tracking of any kind. The developer receives no data about you or your files.
Feedback you choose to send
The optional feedback form asks for your email address, a category, and the message you write. We use your email address and message to respond to your feedback. Feedback is also recorded in a private support spreadsheet.
Cloudflare provides form delivery and spam protection. The form uses Cloudflare Turnstile to check for bots, and the server uses your IP address to limit repeated submissions. Do not include private files, passwords, or other sensitive information.
When Luz Photo connects to a network
There are two app-initiated external network paths:
- Sharing a collection (optional, you initiate). When you sign in to Google and press Publish, the images you selected and the text you typed are uploaded to your own Google Drive, under your own Google account. The developer never receives these files or any information about them. Your use of Google Drive is governed by Google’s own Privacy Policy.
- Announcements (optional, on by default). Once per launch, Luz Photo fetches a single small static file containing any current notices. The request sends no information about you or your library, and the session is discarded afterwards. Turning announcements off in Settings disables the fetch itself — it does not merely hide the result.
Luz Photo’s search package is bundled with the app and runs on your Mac. On supported Macs, Apple’s on-device Foundation Models may also help name collections or turn a natural-language query into structured search filters; Luz does not send those requests to a developer service. StoreKit subscription transactions are handled by Apple’s system services, not sent to Luz Photo or its developer.
Connect AI (optional, you authorize)
Connect AI is an authenticated, loopback-only MCP connection between Luz and an AI client you choose. Luz does not provide an AI service, operate a cloud relay, retain AI conversations, or receive the data that a connected client requests.
Before you turn it on, Luz asks for one complete read-only library permission. It can make the connected client request library records, notes, file paths, precise locations, originals, and bounded renditions. The local connection is protected by a device-only credential stored in Keychain. Turning Connect AI off revokes that credential and stops the listener.
A connected AI client or its provider may transmit and retain the data you request under your account and its own terms. Review that provider’s privacy terms before connecting it to Luz.
How sharing a collection works
The link can feel like magic, so here is exactly what happens, step by step. The short version: the images and a small manifest go to your Google Drive, and the people who make Luz Photo never see any of it.
- You sign in to your own Google account. Luz Photo uses Google’s standard sign-in (OAuth, with PKCE and no shared secret stored in the app). It asks for the narrowest possible permission — drive.file — which lets Luz Photo see and manage only the files it creates in your Drive. It cannot read, list, or touch anything else you keep there. The resulting access token is stored in your Mac’s Keychain, on this device only; it is never written to logs, never synced, and signing out clears it from your Mac and asks Google to revoke it.
- Luz Photo uploads the images to your Drive. The pictures you selected are copied into a tidy folder in your own Drive, named for the collection and date. They live under your account and count against your storage — the developer has no copy and no access. Every image is stripped of its embedded metadata first, and the strip is verified before the upload proceeds; a file that cannot be verified clean stops the whole publish.
- Luz Photo builds the link. The title, captions, uploaded image IDs and availability details are stored in a small manifest in the share folder in your Google Drive. A separate layout file stores the default presentation. New links contain only the manifest’s Drive ID.
- You send the link. However you send it — Messages, email, anywhere — is your choice and outside Luz Photo.
- The recipient opens a plain static page. The page is a fixed file on Cloudflare Pages with no database, no API key, and no secret. Its bounded, credential-free bridge retrieves the anyone-readable manifest from Google Drive without storing it; the browser then loads each picture from Drive. The page runs under a strict content-security policy and treats manifest data as untrusted text.
- The recipient can print it to a PDF. “Save as PDF” uses their browser’s own print, at whatever paper size they pick. Luz Photo does not generate or upload a PDF.
- You stay in control. Take a share down anytime from Luz Photo’s Manage Drive Shares, which deletes the Drive folder it made, or delete the folder yourself in Drive. Luz Photo also sweeps expired shares for you. If your Luz subscription is inactive, the manifest makes the Luz URL unavailable; renewing can restore the same still-valid URL when its Drive contents remain intact.
What recipients of a link can see
A share link reveals the images and captions you chose to include — that is its purpose. One point is worth being explicit about: because the images live in your own Google Drive under your own account, a recipient who opens a shared image in Google Drive, or looks it up through Google’s Drive tools, can see the name and profile photo of the Google account you published from. This is how link sharing works for any file in Google Drive, and it is outside Luz Photo’s control — Google offers no way to share a file anonymously. The Luz Photo share page itself never shows your account; this only surfaces if a recipient deliberately looks the file up in Google Drive. If you would rather not reveal your identity, publish from a separate Google account created for sharing.
Your control over shared content
Anything you share lives in your own Google Drive. You can delete it there at any time, and Luz Photo’s Manage Drive Shares lets you unpublish a share.
Children
Luz Photo is not directed to children and does not knowingly collect personal information from anyone.
Changes
We may update this policy. The date above reflects the current version.
Contact
Questions about privacy: support@luz-photo.app.