Only These Privacy Policy

Your photos stay on your phone. This app has no internet access, no accounts, no trackers, and zero telemetry.

App & Game Specific Declarations

Target Platforms:
ios android
Third-Party Analytics & Telemetry:

Zero telemetry, zero trackers, zero network requests. The app does not ask for internet permissions and operates 100% offline.

App Permissions:

Camera, Microphone (video capture only), Biometric unlock (Face ID / Touch ID / fingerprint), and Photo Library access strictly when choosing Move.

Age Rating & Data Collection:

Everyone (4+ / PEGI 3). Zero data collected, stored, or transmitted.

Data Retention & Storage:

Zero server retention. Selected photos and albums remain entirely on your local device.

1. Your photos stay on your phone

Only These (and its sister app Just These) keeps a private, separate set of photos and videos on your device. It is built so that the things you put in it do not travel. This app has no internet access. It makes no network requests of any kind. On Android you can verify this yourself before you install: the app does not request the INTERNET permission, so the operating system will not allow it to connect even if it tried. There is no account to create, nothing to sign in to, and no server on the other end. If you look at the full Android permission list you will see ACCESS_NETWORK_STATE (declared by the bundled video player, harmless and cannot connect without INTERNET) and USE_FINGERPRINT (for biometric unlock compatibility).

2. What the app stores, and where

Everything lives in the app's own private storage on your device: • The photos and videos you import or capture: They are copied into the app's sandbox. No other app can read them, and the app never writes them back to your phone's photo library. • The details that go with them: Which set a photo is in, the order you arranged, whether you marked it a favourite, view counts. • Your PIN, as a one-way hash: The PIN itself is never stored. What is kept is a salted PBKDF2 hash, held in the operating system's secure store (Keychain on iOS, Keystore on Android). Biometrics belong to the OS and the app never sees them. • A local diagnostic log: Stored locally so a problem you report can be diagnosed. It records operational events — never your photos — and is never transmitted anywhere.

3. Permissions, and exactly what each is for

The app asks for very little, and only at the moment it needs it: • Camera: Take a photo or record a video directly into the app without passing through your phone's photo library. • Microphone: Only when recording video, so the video has sound. • Face ID / Touch ID / fingerprint: Optional convenience for unlocking. Your PIN always works on its own. • Photo library (iOS): Only when you choose Move, which deletes the originals you picked after copying them in. Copying never asks for this.

4. When something does leave the app, you are the one moving it

There are two ways content leaves, both initiated strictly by you: • Sharing: Hands the files you picked to your phone's own share sheet, and from there to whichever destination you choose. • Exporting a backup: Writes a single .otvault file wherever you tell it to (e.g. Files app or cloud drive). That file is encrypted with a passphrase you choose using AES-256-GCM with a key derived by PBKDF2 (100,000 iterations). Without that passphrase, the file cannot be decrypted.

5. Contact

For privacy inquiries or audit questions, email support@drawcode.com.

🎨