Skip to content
KE KE Digital
  • Products
  • Studio
  • Contact
Get in touch

Privacy Policy: AllPix

AllPix is in development. This policy describes how the service is built to work, including its encrypted storage format (version 1), and it applies from the first time you use AllPix.

Last updated: 1 October 2026

This policy explains what data AllPix holds, why, who processes it, and what your rights are under the EU General Data Protection Regulation (GDPR). If something here is unclear, or you spot a contradiction with how the app behaves, email support@kedigital.dev.

1. Who is responsible (the controller)

AllPix is operated by Koray Elbek, trading as KE Digital, Copenhagen, Denmark. For privacy questions, access requests or deletion requests, contact support@kedigital.dev.

2. The short version

Your photos, videos, thumbnails and the facts about them (when, where, what file) are encrypted on your phone before they leave it. We cannot see them. The same is true of Railway and Backblaze, who host the service, and of anyone who breaks into either. The exceptions are listed in sections 4 and 5, because they matter.

3. What we hold

Data Why Readable by us?
Account: your email address and plan Sign-in, billing status, notices Yes
Items: how many, their sizes, when each was uploaded, and whether it is a photo or a video Backup scheduling, storage limits, Trash Yes
Photos, videos, thumbnails, file names, dates, places and albums The service itself No. Only ciphertext and random ids
Sign-in history and account events (new device, export started, deletion requested) Security notices Yes
Subscription status from Google Play To give you the plan you bought Yes. Google handles your card, we never see it
IP addresses of requests Operating the service Only in hosting logs, kept for the hosting provider’s log retention

Upload time roughly tracks when photos were taken. We keep it because backup scheduling, quotas and Trash need it.

4. Keys, and the one way your photos can be exposed

Your encryption key is created on your phone and never leaves it in plain form. It can be unlocked three ways:

  1. This phone. The key is wrapped by a key that never leaves the phone’s secure hardware (Android Keystore).
  2. Google recovery (on by default). A copy of your key, wrapped, is stored in a hidden folder in your own Google Drive. We hold the other half needed to open it, and release it only to you when you sign in. Google holds the wrapped key but cannot open it. We hold our half but cannot see the Drive file. If someone takes over your Google account, they can restore your library. Use two-step verification on your Google account, or switch to the next option.
  3. Recovery key. 24 words shown when you sign up. Keep them somewhere safe. With Recovery key only mode, Google recovery is switched off. If you then lose both your phone and the 24 words, your library cannot be recovered by anyone.

A malicious update to the app itself could also read your photos, as with any encrypted app that you trust to run on your phone. Builds are produced by CI from a public commit.

5. Importing from Google Photos

If you import a Google Photos library, the import runs on our server, in its own service. This is the one place a server sees photos in the clear:

  • You export with Google Takeout and share the folder with the import service’s Google account. The service reads it in place.
  • While the import runs, the service sees each photo and its Takeout metadata (file names, dates, places, captions, album names), because it must encrypt them. It gets a key for that one import from your phone, holds it in memory only, and wipes it when the job stops.
  • It stores counts, sizes and states. Everything else about a photo is sealed under a key derived from your import key, so the database cannot read it.
  • Removing access in the app removes the service account’s permission on your Google Drive folder.

6. Who processes your data (sub-processors)

Processor Role What it sees
Railway Corp. Hosts the API and the database Account data, item counts and sizes, ciphertext metadata
Backblaze, Inc. Stores the encrypted photos and videos Ciphertext and random ids only
Google LLC Sign-in; hidden Drive folder for recovery (your account); Takeout import folder (your account); Play billing As described in sections 4 and 5; subscription status
Scaleway Sends notice and reminder emails Your email address and the message text
GitLab Inc. Source code and build hosting No end-user data

Where data is stored. The encrypted files are stored with Backblaze in its EU Central region. Railway runs the API and the database, and its region is not pinned. Railway, Backblaze and Google are US-based companies, so transfers to them rely on the EU-US Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses (GDPR Art. 46).

7. How long we keep it

Data Retention
A photo or video you delete In Trash for 30 days, then removed. Hidden storage versions are removed after 30 days
Your account Until you delete it
A deleted account 7-day undo window, then your keys are destroyed, every object and every version is removed, then your database rows. A deletion receipt with no personal data is kept
Database backups Expire within 30 days, so deleted rows leave the backups too
An ended paid plan with more than the free 2 GB stored Read-only for 180 days (view, export, delete), then ordinary account deletion starts

8. Your rights

You can access, rectify, erase, restrict, object to and port your data, and lodge a complaint with Datatilsynet.

  • Export your library: Settings → Export my library writes your decrypted originals, with real file names and with dates and places written back, plus a metadata.json, to a folder you choose.
  • Export what we hold in plain text: your profile, plan, usage, sign-in history and payments are available from the account export.
  • Delete your account: see Delete your AllPix account.
  • Anything else: email support@kedigital.dev. We aim to reply within 30 days.

9. Notices we send

We email you about account events that look like a takeover (a new device unlocking your library, a recovery change, a deletion request, a bulk delete), about backups that stopped, about payment and plan changes, and about storage limits. Security emails cannot be turned off. Our emails never ask for your recovery words and contain no links to click.

10. Payments

Plans are bought through Google Play. Google collects the payment and handles card details. We receive the subscription status only.

11. Children

AllPix is not directed at children. We do not knowingly hold data from children.

12. Changes to this policy

When we change this policy materially, we update the date above and tell signed-in users in the app.

13. Contact

Koray Elbek, KE Digital support@kedigital.dev Copenhagen, Denmark

© 2026 KE Digital · No analytics. No cookies.

  • LingoDrive privacy
  • AllPix privacy
  • Delete your LingoDrive account
  • Delete your AllPix account