Privacy Policy
Effective June 28, 2026
Your photos are processed entirely on your device and are never uploaded. We collect only a little anonymous, aggregate data to understand whether the product is useful and to fix crashes.
The short version
Pholara is a RAW photo editor that runs entirely in your web browser. Your photos, their EXIF/GPS metadata, and your edits are decoded, rendered, and stored on your own device. They are never sent to us or to anyone else — there is no server to upload them to.
The only information that ever leaves your browser is a small amount of anonymous product analytics (to see how many people try the editor and come back) and crash/error diagnostics (to find and fix bugs), both described in detail below. Neither contains your photos or anything that identifies you personally. You can turn analytics off, and we honor your browser's Do Not Track signal automatically.
Who we are
Pholara is operated by Dimitrios Apostal, an individual (the sole developer of Pholara), based in New Hampshire, USA. In this policy, "we", "us", and "our" refer to that operator, and "the app" or "the service" refers to the Pholara web application and the pholara.com website. For the purposes of the EU/UK General Data Protection Regulation (GDPR), we are the data controller for the limited data described below.
This policy covers both the pholara.com website and the Pholara editor. Where something is collected only on the website (such as a waitlist sign-up) and never inside the editor, we say so.
Privacy questions and data-subject requests: privacy@pholara.com
Your photos never leave your device
This is the core design of the product, not just a promise. RAW files are decoded in your browser with a WebAssembly build of LibRaw, and every adjustment is rendered on your device's GPU. There are no upload endpoints and no accounts. We never receive, see, store, or transmit your image files, their pixel data, or their embedded metadata (including any GPS location in your photos).
Your imported files, edits, undo history, and thumbnails are saved locally in your browser's storage so your session is still there when you come back. That data stays on your device and is under your control: clearing your browser's site data for the app removes it.
What we collect, and why
We practice data minimization (GDPR Art. 5): we collect as little as possible, and only for the purposes below.
1. Anonymous product analytics. We measure one simple, aggregate funnel — how many visits land on the app, how many open a file (“activate”), and how many return on a later day — together with basic context: the page you are on, the referring website, and any campaign tags in the link you arrived from. This is processed by PostHog. To keep it honest: there is no third-party tracking script, no cookies, and no user-level profile. A random identifier with no link to your identity is stored in your browser's localStorage so a return visit can be counted; the URL's query string is dropped before sending; and we replace your IP address with a non-identifying placeholder on every event, so PostHog neither stores your IP nor derives your location from it. You can switch analytics off at any time (see “Your rights” below).
2. Crash and error diagnostics. When something goes wrong, the app can send an anonymized error or performance report so we can fix it. This is processed by Sentry. Before any report leaves your browser we remove your IP address and strip out file names, URLs, request/response bodies, headers, cookies, and any typed input — so a diagnostic report can describe that a decode failed without ever revealing which photo or anything about you.
3. Bug reports and feedback you choose to send. The in-app “report a bug / send feedback” feature opens your own email client with a message you write and send yourself. We receive only what you type and choose to include (optionally, basic browser/screen details you tick a box to add). Your photos are never attached automatically.
4. Waitlist / early-access list (optional, website only). If we offer a waitlist for paid features and you choose to join it on our website, we collect the email address you give us and your stated interest, solely to contact you about Pholara. It is entirely optional, never pre-ticked, and you can unsubscribe or ask us to delete your entry at any time. The editor itself has no sign-up and asks for no email.
Cookies and local storage
We do not use cookies, and we do not use any cross-site, advertising, or fingerprinting trackers. The on-device storage we do use (listed below) is limited to running the app and to first-party, aggregate analytics you can switch off — it is never used to profile you or track you across other sites.
We do use your browser's own on-device storage to make the app work. None of it is transmitted to us:
- localStorage — a random anonymous analytics id, the date of your last visit, and your analytics opt-out preference.
- sessionStorage — short-lived flags so a per-visit analytics event fires at most once per browser tab.
- IndexedDB — your imported files, edit settings, undo history, and thumbnails, so your work is restored when you return.
Legal bases for processing (GDPR)
- Legitimate interests (Art. 6(1)(f)) — for the anonymous, aggregate analytics, to understand and improve the product. It is minimized heavily and kept non-identifying (no cookies, no stored IP address, no profile); we honor Do Not Track and give you an in-app opt-out, so it stays balanced against your interests.
- Legitimate interests (Art. 6(1)(f)) — for the crash/error diagnostics, to keep the app working. The balance is preserved by data minimization: each report is stripped of your IP address, file names, URLs, request bodies, and any typed input before it is sent.
- Consent (Art. 6(1)(a)) — if we offer the optional waitlist and you join it by giving us your email; you can withdraw consent at any time.
- Performance of a request / legitimate interests — when you email us a bug report or question, to respond to you.
Who processes data on our behalf
We keep our list of processors (sub-processors) short, and we use them only for the narrow purposes above. We do not sell your data, and we never share your photos with anyone — we don't have them.
The third parties that may process the limited data described above, with their own privacy policies:
Our static site and these documents are hosted on Cloudflare Pages, our web host and content-delivery network, which necessarily processes basic request data (such as your IP address) to deliver the page, as any website does. When you email us at one of our published addresses (such as privacy@ or support@), that message is delivered and stored by Google Workspace, our email provider. If you join the waitlist or, in future, make a payment, the email or payment provider that powers that form will process the details you submit for that purpose.
International data transfers
Our analytics and diagnostics processors may process data in the United States. Where data about EU/EEA or UK users is transferred outside your region, that transfer relies on the appropriate safeguards offered by the processor (such as the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework). Because the data involved is anonymized and minimized, the privacy impact of any transfer is low. Where a processor offers EU-region hosting we prefer it.
How long we keep data
- On-device data (your files, edits, thumbnails) stays on your device until you delete it or clear your browser's storage for the app. We never hold a copy.
- Anonymous analytics is retained in aggregate to observe trends over time; it isn't tied to you and can't be traced back to an individual.
- Crash/error diagnostics are retained only as long as useful for debugging, subject to our processor's default retention, then deleted.
- If a waitlist exists and you joined it, your email is kept until you unsubscribe or ask us to delete it.
Your rights
If you are in the EU/EEA, the UK, California, or a similar regime, you have rights over personal data we hold about you — including access, correction, deletion, restriction, objection, and data portability, and the right to withdraw consent or lodge a complaint with your local data-protection authority.
In practice we hold very little that could identify you: the analytics is anonymous and the diagnostics are stripped of identifiers, so for most people there is no personal record to retrieve or erase. The clearest data we may hold about you is a waitlist email, if you gave us one. You can turn analytics off yourself at any time using the toggle shown with this Privacy Policy in the app (About → Privacy Policy), or by enabling Do Not Track in your browser, which we honor automatically; and you can remove all on-device data by clearing the app's site data. For anything else, contact us and we will help.
We do not sell or share your personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA), so there is no sale to opt out of.
We respond to data-subject requests without undue delay and in any case within one month of receiving them, as required by GDPR Art. 12(3). If a request is especially complex or you have made several, we may extend this by up to two further months and will tell you why within the first month.
To exercise any of these rights, email: privacy@pholara.com
Children
The app is a general-audience photo-editing tool and is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as the product evolves (for example, when cloud features arrive). When we do, we will change the effective date above, and for material changes we will make the update prominent. Continuing to use the app after an update means you accept the revised policy.
Contact us
Privacy and data requests: privacy@pholara.com
General support: support@pholara.com
Security / vulnerability reports: security@pholara.com
This Privacy Policy is governed by the laws of New Hampshire, USA, and should be read alongside our Terms of Service.