Privacy Policy: AllPix
AllPix is in development. This policy describes how the service is built to work, including its encrypted storage format (version 1), and it applies from the first time you use AllPix.
Last updated: 1 October 2026
This policy explains what data AllPix holds, why, who processes it, and what your rights are under the EU General Data Protection Regulation (GDPR). If something here is unclear, or you spot a contradiction with how the app behaves, email support@kedigital.dev.
1. Who is responsible (the controller)
AllPix is operated by Koray Elbek, trading as KE Digital, Copenhagen, Denmark. For privacy questions, access requests or deletion requests, contact support@kedigital.dev.
2. The short version
Your photos, videos, thumbnails and the facts about them (when, where, what file) are encrypted on your phone before they leave it. We cannot see them. The same is true of Railway and Backblaze, who host the service, and of anyone who breaks into either. The exceptions are listed in sections 4 and 5, because they matter.
3. What we hold
| Data | Why | Readable by us? |
|---|---|---|
| Account: your email address and plan | Sign-in, billing status, notices | Yes |
| Items: how many, their sizes, when each was uploaded, and whether it is a photo or a video | Backup scheduling, storage limits, Trash | Yes |
| Photos, videos, thumbnails, file names, dates, places and albums | The service itself | No. Only ciphertext and random ids |
| Sign-in history and account events (new device, export started, deletion requested) | Security notices | Yes |
| Subscription status from Google Play | To give you the plan you bought | Yes. Google handles your card, we never see it |
| IP addresses of requests | Operating the service | Only in hosting logs, kept for the hosting provider’s log retention |
Upload time roughly tracks when photos were taken. We keep it because backup scheduling, quotas and Trash need it.
4. Keys, and the one way your photos can be exposed
Your encryption key is created on your phone and never leaves it in plain form. It can be unlocked three ways:
- This phone. The key is wrapped by a key that never leaves the phone’s secure hardware (Android Keystore).
- Google recovery (on by default). A copy of your key, wrapped, is stored in a hidden folder in your own Google Drive. We hold the other half needed to open it, and release it only to you when you sign in. Google holds the wrapped key but cannot open it. We hold our half but cannot see the Drive file. If someone takes over your Google account, they can restore your library. Use two-step verification on your Google account, or switch to the next option.
- Recovery key. 24 words shown when you sign up. Keep them somewhere safe. With Recovery key only mode, Google recovery is switched off. If you then lose both your phone and the 24 words, your library cannot be recovered by anyone.
A malicious update to the app itself could also read your photos, as with any encrypted app that you trust to run on your phone. Builds are produced by CI from a public commit.
5. Importing from Google Photos
If you import a Google Photos library, the import runs on our server, in its own service. This is the one place a server sees photos in the clear:
- You export with Google Takeout and share the folder with the import service’s Google account. The service reads it in place.
- While the import runs, the service sees each photo and its Takeout metadata (file names, dates, places, captions, album names), because it must encrypt them. It gets a key for that one import from your phone, holds it in memory only, and wipes it when the job stops.
- It stores counts, sizes and states. Everything else about a photo is sealed under a key derived from your import key, so the database cannot read it.
- Removing access in the app removes the service account’s permission on your Google Drive folder.
6. Who processes your data (sub-processors)
| Processor | Role | What it sees |
|---|---|---|
| Railway Corp. | Hosts the API and the database | Account data, item counts and sizes, ciphertext metadata |
| Backblaze, Inc. | Stores the encrypted photos and videos | Ciphertext and random ids only |
| Google LLC | Sign-in; hidden Drive folder for recovery (your account); Takeout import folder (your account); Play billing | As described in sections 4 and 5; subscription status |
| Scaleway | Sends notice and reminder emails | Your email address and the message text |
| GitLab Inc. | Source code and build hosting | No end-user data |
Where data is stored. The encrypted files are stored with Backblaze in its EU Central region. Railway runs the API and the database, and its region is not pinned. Railway, Backblaze and Google are US-based companies, so transfers to them rely on the EU-US Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses (GDPR Art. 46).
7. How long we keep it
| Data | Retention |
|---|---|
| A photo or video you delete | In Trash for 30 days, then removed. Hidden storage versions are removed after 30 days |
| Your account | Until you delete it |
| A deleted account | 7-day undo window, then your keys are destroyed, every object and every version is removed, then your database rows. A deletion receipt with no personal data is kept |
| Database backups | Expire within 30 days, so deleted rows leave the backups too |
| An ended paid plan with more than the free 2 GB stored | Read-only for 180 days (view, export, delete), then ordinary account deletion starts |
8. Your rights
You can access, rectify, erase, restrict, object to and port your data, and lodge a complaint with Datatilsynet.
- Export your library: Settings → Export my library writes your decrypted originals, with real file names and with dates and places written back, plus a
metadata.json, to a folder you choose. - Export what we hold in plain text: your profile, plan, usage, sign-in history and payments are available from the account export.
- Delete your account: see Delete your AllPix account.
- Anything else: email support@kedigital.dev. We aim to reply within 30 days.
9. Notices we send
We email you about account events that look like a takeover (a new device unlocking your library, a recovery change, a deletion request, a bulk delete), about backups that stopped, about payment and plan changes, and about storage limits. Security emails cannot be turned off. Our emails never ask for your recovery words and contain no links to click.
10. Payments
Plans are bought through Google Play. Google collects the payment and handles card details. We receive the subscription status only.
11. Children
AllPix is not directed at children. We do not knowingly hold data from children.
12. Changes to this policy
When we change this policy materially, we update the date above and tell signed-in users in the app.
13. Contact
Koray Elbek, KE Digital support@kedigital.dev Copenhagen, Denmark