Privacy policy
Last updated 14 August 2026
Imadeo is self-hosted. Your photos, videos, account details and generated library data go to the Imadeo server you choose — not to the Imadeo project. The project has no hosted media service and cannot see your library.
Who is responsible for your data
The person or organisation running the Imadeo server is the server operator. They control the server, its storage, user accounts, backups, network access and any optional integrations. Contact that operator for access, correction, export or deletion requests relating to your account or library.
The open-source Imadeo project publishes the software and mobile apps. It does not operate the server you connect to and does not receive your account details or media through normal use of the software.
Information Imadeo processes
Depending on the features you use, your chosen server may store:
- Account information, including your name, email address, password hash, sessions and registered devices.
- Photos and videos you upload or back up, including filenames and embedded metadata such as capture time, camera details and location coordinates.
- Library information, including folders, albums, favourites, descriptions, shares, trash and Locked items.
- Generated media data, including thumbnails, video previews, search embeddings, face and pet detections, groupings and names you assign.
- Operational information, such as upload state and technical logs kept by the server operator.
Passwords are stored as password hashes. The mobile app stores the server address and authentication credentials in the device's protected storage. The web app uses authentication cookies issued by your server.
Device permissions
Photo and video library
The mobile app requests library access so it can show your local media, compare it with your server, upload the items you choose and save media back to your device. Nothing is uploaded until you start a backup or upload action. Limited-library access is supported where the operating system offers it.
Location
Imadeo may request location-related permission to read and display place information associated with your media. It does not use this permission for advertising or continuous background tracking. Location metadata in an uploaded file may be stored on your chosen server with that file.
Where processing happens
Media storage, thumbnails, search analysis, face recognition and pet recognition run on the self-hosted server and machine-learning service selected by the server operator. Imadeo does not send media to a hosted Imadeo cloud or sell it to third parties.
Optional external services
A server operator can choose to configure services that receive limited data:
- Reverse geocoding can send media coordinates to the configured geocoding provider to obtain place names. It can be disabled or pointed at a self-hosted provider.
- Google or Apple sign-in sends authentication information through the selected identity provider when configured and used.
- Email delivery sends recipient addresses and invitation content through the SMTP provider configured by the server operator.
Those providers process data under their own terms and privacy policies. The server operator decides whether to enable them and which providers to use.
Sharing
Photos, albums and folders are private to an account unless a user shares them. Shared items and their metadata become visible to the selected recipients, or to anyone who has a public link when public-link sharing is used. Users should only share content they are authorised to share.
Retention and deletion
Data remains on the chosen server until a user or server operator deletes it. Items in Trash can remain recoverable for the server's retention period. Copies may remain in operator-managed backups until those backups expire or are replaced.
Deleting the mobile app removes its local app data but does not delete media or an account from the server. Use Imadeo's deletion controls or contact the server operator to remove server data.
Security and network transport
Imadeo supports local-network deployments over HTTP. HTTP does not encrypt traffic. For access across an untrusted network or the public internet, the server operator should provide HTTPS through a reverse proxy or require a trusted VPN. The security of the host, storage, database, credentials and backups remains the operator's responsibility.
Tracking, advertising and sale of data
The Imadeo project does not include advertising, cross-app tracking or a project-operated analytics service, and it does not sell personal data. A server operator may independently add infrastructure monitoring or logging; questions about that deployment should be directed to them.
Children
Imadeo is not directed to children. Account creation is controlled by the server operator, who is responsible for obtaining any consent required in their jurisdiction when the server contains information about children.
Changes and questions
This policy may change as Imadeo changes. The latest version and its date will remain on this page. For questions about a particular server or its data, contact its operator. For questions about the open-source project or this policy, open an issue in the Imadeo repository without posting private information.