Privacy Policy for Secure Photo Storage – Paranoid Photos

Effective Date: April 21, 2026
Last Updated: April 21, 2026

This Privacy Policy explains how Paranoid Photos ("Company," "we," "our," or "us") collects, uses, and protects information when you use the Paranoid Photos mobile application ("App") and related services.

1. Our Commitment to Privacy

Paranoid Photos is built on a foundation of zero-knowledge, end-to-end encryption. All photos, videos, and personal metadata are encrypted on your device before they leave it. We cannot decrypt, view, or access your content.

Your privacy is not merely a policy decision; it is enforced by the technical architecture of the App.

2. Information We Cannot Access

2.1 End-to-End Encrypted Content

The following information is encrypted on your device using encryption keys that only you control. Paranoid Photos has zero access to this data:

  • Photos and videos
  • Album names and descriptions
  • Tags, labels, and search keywords
  • Location data and GPS coordinates
  • EXIF metadata and device camera information
  • AI-generated descriptions and labels
  • Original file names

Because this information is encrypted with keys only you possess, we cannot decrypt, analyze, screen, moderate, or share it with any third party, including advertisers, artificial intelligence systems, or law enforcement.

3. Information We Can Access

3.1 Minimal Unencrypted Metadata

To operate the App and provide essential functionality, we collect limited unencrypted technical metadata:

  • Account information (email address, username, account creation date)
  • Upload and download timestamps
  • File sizes and file format information
  • Counts of stored items (number of photos, albums, or tags)
  • Sharing relationships (without access to content or album names)
  • Device and network information (IP address, device type, app version)
  • Authentication data (hashed passwords, two-factor authentication tokens)

This metadata cannot be used to reconstruct or infer the contents of your encrypted media.

4. How We Use Information

4.1 Encrypted Content

Encrypted photos and videos are stored solely to provide backup, synchronization, and availability across your devices. Because we cannot decrypt this data, we cannot:

  • Analyze content using artificial intelligence or machine learning
  • Use your content for advertising or profiling
  • Sell, license, or share your content with third parties

Due to encryption, we are unable to provide access to encrypted content. We may comply with lawful requests for account-level metadata where legally required.

4.2 Unencrypted Metadata

We use unencrypted metadata solely to:

  • Operate, maintain, and improve the App
  • Protect accounts and prevent fraud or abuse
  • Communicate security alerts and service updates
  • Comply with legal, billing, and tax obligations

We do not sell, rent, or share metadata with advertisers or data brokers.

5. Encryption Keys

Encryption keys are generated and stored on your device and are never transmitted to our servers in a form we can access.

You are responsible for securely backing up your encryption keys using the options provided within the App.

Important: If you lose your encryption keys, we cannot recover your data. There is no master key or backdoor.

6. Local AI Processing

AI-powered features such as automatic tagging, face detection, and object recognition run entirely on your device.

  • No photos are sent to cloud-based AI services
  • AI results are encrypted before storage
  • Zero-knowledge principles apply to all AI features

7. Data Retention and Deletion

  • Active accounts: Encrypted data is retained while your account remains active
  • Account deletion: All encrypted content and metadata are permanently deleted within 30 days
  • Backups: Encrypted backups are retained for up to 90 days for disaster recovery

You may request a copy of unencrypted metadata at any time. Encrypted content can be exported directly from the App.

8. Third-Party Services

We use a limited number of third-party service providers:

  • Cloud storage providers (encrypted data only)
  • Payment processors for subscriptions and billing
  • Analytics services providing anonymous usage statistics

All third-party providers are contractually required to protect data and are prohibited from using it for their own purposes.

9. Security Measures

In addition to zero-knowledge encryption, we implement:

  • TLS encryption for all network communications
  • Regular security audits and penetration testing
  • Multi-factor authentication options
  • Automated detection of suspicious activity
  • Encrypted, geographically distributed backups

10. Children's Privacy

The App is not intended for children under the age of 13 (or the applicable age of digital consent). We do not knowingly collect personal information from children.

If you believe a child has provided personal information, contact privacy@paranoid.com.

11. International Data Transfers

Encrypted data may be stored on servers in multiple geographic regions. Encryption ensures that server location does not compromise privacy.

Unencrypted metadata is processed in compliance with applicable data protection laws, including GDPR and CCPA.

12. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access operational metadata
  • Correct inaccurate account information
  • Delete your account and associated data
  • Export encrypted content
  • Opt out of optional analytics

Requests may be made through the App settings or by contacting privacy@paranoid.com.

13. Changes to This Policy

We may update this Privacy Policy periodically.

14. Contact Information

For questions regarding this Privacy Policy, contact:

Paranoid Photos
Email: privacy@paranoid.com
Support: support@paranoid.com
Website: paranoid.com