Gallery Cleaner

Legal documents

View the Project on GitHub GalleryCleanerPro/gallerycleaner-legal

Privacy Policy

Last updated: June 22, 2026

Effective date: June 22, 2026

This Privacy Policy describes how information about you is handled when you use the mobile application Gallery Cleaner for iOS (the “App”), distributed through the Apple App Store.

The data controller for the limited information handled in connection with the App is:

Ali Burak Baraç (“we”, “us”, “our”) Republic of Türkiye Contact: aliburakbarac@gmail.com

If you do not agree with this Privacy Policy, please do not download or use the App.


1. Summary

We designed the App to keep your photos and videos on your device. The App scans your photo library locally on the iPhone. We do not upload, copy, transmit, or store the contents of your photos or videos on any server we operate.

The information that leaves your device is limited to:

We do not collect your name, e-mail address, postal address, payment card numbers, precise location, contact list, or any device advertising identifier, unless you voluntarily provide them to us in correspondence.


2. Scope

This Privacy Policy applies to:

This Privacy Policy does not apply to:


3. Information We Process

3.1 Information processed only on your device (never leaves the iPhone)

When you grant the App access to your photo library, iOS provides the App with access to the photos and videos in your library. The following information is processed only locally on your iPhone and is not transmitted to us or to any third party we operate:

These items are stored only on your iPhone. They are not synchronized to a server we operate. Uninstalling the App, or using the in-app “Clear History” action, removes the App’s local storage of these items.

3.2 Information processed off your device

The following information leaves your iPhone:

Category Source Purpose Recipient
In-app purchase transaction data (anonymous purchase identifier, product identifier, store country, purchase / renewal timestamps) Apple App Store, in response to your subscription Process and verify your subscription, restore purchases, and operate the paywall Apple Inc.; RevenueCat, Inc.
Anonymous customer identifier generated by RevenueCat RevenueCat SDK in the App Associate your device with your subscription status across reinstalls and restores RevenueCat, Inc.
App version, iOS version, device model, locale, and other diagnostic fields that the RevenueCat SDK transmits as part of its standard operation Generated by the SDK on launch and on purchase events Operate the subscription service and detect abuse RevenueCat, Inc.
Pseudonymous app instance identifier generated by Firebase Analytics on first launch, the fact that the App was opened, and the identifiers of the screens you visit and the actions you take (for example “paywall_viewed”, “scan_started”, “purchase_completed”), together with non-identifying parameters describing those actions (such as the subscription plan you selected or the source that triggered the paywall) Firebase Analytics SDK in the App Understand aggregate usage of the App, measure conversion funnels, debug crashes and performance issues, and improve the product Google LLC / Firebase
Device model, operating system version, App version, language, country (derived from your IP address at the time of the request), and an approximate region based on the same IP Firebase Analytics SDK in the App Group usage statistics so they can be reported per device class and per region Google LLC / Firebase
Your subscription state (free or premium) and the App build version, kept as a “user property” attached to your pseudonymous app instance identifier so that statistics can be segmented Set by the App after a successful purchase or restore Distinguish free-tier from premium audiences in aggregate reports Google LLC / Firebase
Crash reports describing an abnormal termination of the App: stack trace, the iOS exception or signal type, the App version and build, the device model and operating system version, the locale, the amount of free memory and storage at the time of the crash, and a Crashlytics-generated pseudonymous installation identifier Firebase Crashlytics SDK in the App, sent automatically the next time the App is launched after a crash Diagnose and fix the bug that caused the crash, and measure the stability of each App release Google LLC / Firebase
Your current subscription state (free or premium), attached to a crash report as a custom diagnostic key so that we can tell whether a bug is specific to a particular tier Set by the App when the subscription state is known Filter crash dashboards by free vs. premium so we can prioritise fixes Google LLC / Firebase
The contents of any e-mail you voluntarily send to our support address You Respond to your message Us, and the e-mail provider we use

Firebase Analytics does not receive your photos, your photo metadata, your cleanup decisions, your library size, or any other content of your library. It receives the fact that a feature was used, not what that feature operated on.

Firebase Crashlytics does not receive your photos, your photo metadata, your cleanup decisions, or your cleanup history. A crash report contains the technical context of the crash, not the content of your library.

3.3 Information we expressly do not collect


4. Photo Library Permission

When you first use the cleaning features, iOS asks for your permission to access your photo library. iOS gives you the choice of granting Full Access or Limited Access.

You may change your permission at any time in iOS Settings → Privacy & Security → Photos → Gallery Cleaner. Revoking the permission will prevent further scans and cleanup actions until access is restored, but does not delete any local data the App has already stored.

The system prompts that ask you to confirm deletion, hiding, or moving items in your Photos library are displayed by iOS itself, not by us. We never bypass these prompts.


5. How We Use Your Information

We use the limited information described in Section 3.2 to:

We do not use your information to build a profile of you, to deliver advertising, or to make decisions that produce legal effects concerning you.


If you are in the European Economic Area, the United Kingdom, or another jurisdiction that applies the General Data Protection Regulation (“GDPR”) or an equivalent framework, our legal bases for processing personal data are:

Processing activity Legal basis (GDPR Article 6)
Operating your subscription and unlocking paid features Performance of the contract under our Terms of Service (Art. 6(1)(b))
Storing the anonymous customer identifier and similar service-operational data Our legitimate interest in operating the App and the subscription service (Art. 6(1)(f))
Collecting pseudonymous usage analytics through Firebase Analytics to understand product usage, debug issues, and improve the App Our legitimate interest in maintaining and improving the App (Art. 6(1)(f)). We have weighed this against your reasonable expectation of privacy, taking into account that the data is pseudonymous, that the contents of your photo library are never collected, and that the IDFA is deliberately not requested.
Collecting crash reports through Firebase Crashlytics to detect and fix bugs that cause the App to terminate abnormally Our legitimate interest in providing a stable, working product (Art. 6(1)(f)). Reports are sent only when the App crashes, contain technical diagnostic data and not the content of your photo library, and are used solely to identify and fix the bug.
Responding to your support correspondence Performance of pre-contractual or contractual steps you have requested, and our legitimate interest in providing support (Art. 6(1)(b)/(f))
Retaining records to comply with tax, accounting, and consumer-protection law Compliance with a legal obligation (Art. 6(1)(c))
Voluntary cooperation with public authorities Compliance with a legal obligation (Art. 6(1)(c)) or our legitimate interest in cooperating (Art. 6(1)(f))

We do not rely on consent under Article 6(1)(a) as a legal basis for the routine processing described in this Policy, because the analytics we collect is pseudonymous and not used for advertising or for any decision-making that would produce legal effects concerning you. You always have the right to object to processing carried out on the basis of our legitimate interests, as described in Section 11. We do not process special categories of personal data under Article 9.


7. Third-Party Services

We use the following third parties to operate the App. Each acts as a separate data controller or processor in relation to the data it receives, under its own privacy notice and contract with us.

7.1 Apple Inc.

Apple operates the App Store, the Photos framework, the StoreKit subscription system, the iCloud library that may host some of your photos, and the device the App runs on. Apple’s handling of your information is governed by the Apple Privacy Policy. When you subscribe, your payment goes to Apple under your Apple ID; we never see your payment instrument.

7.2 RevenueCat, Inc.

We use RevenueCat to manage subscription receipts, to verify that your subscription is active, and to restore purchases across reinstalls. The RevenueCat SDK transmits the data described in Section 3.2 to RevenueCat’s servers. RevenueCat acts as a data processor on our behalf for that data. RevenueCat is based in the United States. Its handling of personal data is governed by the RevenueCat Privacy Notice and the data processing addendum we have entered into with RevenueCat.

We do not transmit your photos, your photo metadata, your cleanup decisions, or your cleanup history to RevenueCat.

7.3 Google LLC (Firebase Analytics and Firebase Crashlytics)

We use two Google LLC services from the Firebase platform: Firebase Analytics for pseudonymous usage statistics, and Firebase Crashlytics for crash and stability reports. We act as the controller of the data we configure these services to collect; Google acts as a processor with respect to the parts of that data that are personal data, and as an independent controller for the parts that it uses for its own purposes as described in the Google Measurement Controller-Controller Data Protection Terms.

Firebase Analytics. The data Firebase Analytics receives from the App is limited to the events and parameters we have chosen to log (Section 3.2), together with the device and locale information that the Firebase SDK adds by default. Firebase Analytics generates a pseudonymous “app instance identifier” the first time the App is opened on a device. This identifier is reset if you reinstall the App.

We have configured Firebase Analytics so that:

Firebase Crashlytics. The data Firebase Crashlytics receives is limited to the technical context of an abnormal termination of the App, as listed in Section 3.2: stack trace, exception or signal type, App version and build, device model and OS version, locale, free memory and storage at the time of the crash, a Crashlytics-generated pseudonymous installation identifier, and the subscription-state custom key we attach. Crashlytics does not receive any content from your photo library, any cleanup decision, or any non-crash event.

We have configured Firebase Crashlytics so that:

Google’s handling of personal data under both services is governed by the Google Privacy Policy, the Firebase Privacy and Security Information, and the data processing terms applicable to Firebase customers.

We do not transmit your photos, your photo metadata, your cleanup decisions, or your cleanup history to Firebase Analytics or Firebase Crashlytics.


8. Data Retention


9. Data Security

The App relies on the security model that iOS provides:

No security measure is absolute. You are responsible for protecting your iPhone with a passcode and for keeping iOS up to date.


10. International Data Transfers

Because RevenueCat and Google are based in the United States, the data described in Section 3.2 may be transferred to, stored in, and processed in the United States and, in Google’s case, in other countries where Google operates infrastructure. Where these transfers involve personal data of users located in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction that restricts international transfers, we rely on the following safeguards:

You may request a summary of the safeguards in place by contacting us at the address in Section 17.


11. Your Rights

Subject to your jurisdiction and to any conditions set out in the applicable law, you may have the following rights with respect to personal data we hold about you:

To exercise these rights, contact us at aliburakbarac@gmail.com. We will respond within the time limits required by the law that applies to you (typically one month under GDPR, extendable by two further months for complex requests).

We may need to verify your identity before acting on your request, including by asking you to confirm details that match the information we hold (for example, the device or e-mail address from which the support correspondence originated, or the transaction identifier of an in-app purchase). If we cannot verify that the request comes from you or someone you have authorized, we may decline to act on it.

11.1 European Economic Area, United Kingdom, and Switzerland

If you are located in the EEA, the UK, or Switzerland, the rights above apply to you. You may also contact your national data protection authority.

11.2 California, USA

If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”):

You may exercise these rights by contacting us at aliburakbarac@gmail.com. You may authorize an agent to make a request on your behalf; we may require the agent to submit proof of authorization.

11.3 Türkiye

If you are located in the Republic of Türkiye, the Personal Data Protection Law No. 6698 (“KVKK”) applies. Under Article 11 of the KVKK, you have the right to:

To exercise these rights, send your request in writing to aliburakbarac@gmail.com or by registered mail to the contact address you obtain by writing to that same address. We will respond within thirty (30) days as required by the KVKK.

11.4 Other regions

If you are located in another jurisdiction whose data protection law gives you rights similar to the above, you may also contact us at aliburakbarac@gmail.com to exercise those rights.


12. Children

The App is not directed to children under the age of 13, and we do not knowingly collect personal information from children under that age. If you are a parent or guardian and you believe that a child under 13 has provided personal information to us, please contact us so that we can take appropriate action.

In the European Economic Area and the United Kingdom, the App is not directed to children under the age of 16. In jurisdictions where the digital age of consent is higher than 13, the higher age applies.


13. Apple App Tracking Transparency

The App does not engage in “tracking” as that term is defined by Apple’s App Tracking Transparency framework. We do not request, store, or share the iOS device advertising identifier (IDFA), and we do not link the data we collect to a profile maintained by any third party for cross-app advertising. We have deliberately omitted the Firebase Analytics IDFA component to keep this guarantee explicit. Accordingly, we do not display the App Tracking Transparency prompt. If we ever introduce features that constitute tracking under Apple’s definition, we will update this Policy and present the system prompt before doing so.


14. Do Not Track and Global Privacy Control

Because the App does not engage in cross-context behavioral advertising and does not use web cookies inside its native screens, we do not have a meaningful response to browser “Do Not Track” signals or the Global Privacy Control header.


15. Automated Decision-Making and Profiling

The App’s classification of photos and videos as candidates for cleanup is performed by automated computation on your iPhone. The classification is presented to you as a suggestion. We do not make any decision about you that produces legal effects or similarly significant effects within the meaning of Article 22 of the GDPR. You always make the final decision about each cleanup candidate, except where you have explicitly enabled the automatic cleanup mode in the App’s settings.


16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the App, in applicable law, or in our practices. When we make a material change, we will update the “Last updated” date at the top of this Policy, and we will provide additional notice within the App or by other appropriate means where required by law. The version posted at the URL where you obtained this Policy is the current version.


17. Contact

If you have questions about this Privacy Policy or wish to exercise the rights described above, please contact:

Ali Burak Baraç E-mail: aliburakbarac@gmail.com Subject line: “Gallery Cleaner Privacy Request”

If you are not satisfied with our response, you may also contact the data protection authority of your country of residence.