Privacy

Field by field: what travels, where it goes, and whether it is kept.

Your original photos never leave your phone. To read a photo, the app sends a small copy that is described in words and not stored. What is kept is a description, in an index that belongs to your account — and, since 2.5, in a copy of that index held on the phone itself. On a plan without vector search no copy of any photo is sent at all.

YOUR PHONEOriginal photos, fullsizeEXIF and GPS read hereAPI key,Keystore-encryptedYour tags and wordingThumbnails, from thephoneA copy of the index, novectorexcluded from phonebackups OPENSOLR.COMSign-in and approvalCreate index, uploadconfigPlan limits and usage API.OPENSOLR.COMCLIP on a 640 px copyWords, printed text,vector, placeThe copy is notstored YOUR OPENSOLRINDEXLabels (the meaning)Printed text (OCR)The people named on itYour tags and yourwordingSearch vectorDate, camera, placePath, folder, size,copy keysRemoved with the photoone per phone, in youraccount direct to Solr: HTTPS + indexpassword Every arrow is HTTPS. No analytics, no ads, no crash reporting, no third-party SDK that talks tothe network.Two other hosts, carrying nothing about you or your photos: api.github.com for the update check,and tile.openstreetmap.org for the map tiles, only while the map screen is open.
YOUR PHONEOriginal photos, fullsizeEXIF and GPS read hereAPI key,Keystore-encryptedYour tags and wordingThumbnails, from thephoneA copy of the index, novectorexcluded from phone backups OPENSOLR.COMSign-in and approvalCreate index, uploadconfigPlan limits and usage API.OPENSOLR.COMCLIP on a 640 px copyWords, printed text,vector, placeThe copy is not stored direct to Solr: HTTPS +index password YOUR OPENSOLRINDEXLabels (the meaning)Printed text (OCR)The people named on itYour tags and yourwordingSearch vectorDate, camera, placePath, folder, size,copy keysRemoved with the photoone per phone, in youraccount Every arrow is HTTPS. Noanalytics, no ads, no crashreporting, no third-party SDKthat talks to the network.Two other hosts, carryingnothing about you or yourphotos: api.github.com for theupdate check, andtile.openstreetmap.org for themap tiles, only while the mapscreen is open.

Figure 1 — where each piece of data lives.

01 · What leaves the phone
The faces found in a photo: their frames, the names you gave them and a short numeric fingerprint of each, as text, with no picture attached

Yes, in your own index, until the photo leaves the phone or you empty the index

Goes to
Your Opensolr Index, with the photo's other facts, so a reinstall or a new phone gets them back without reading the photos again. The faces are found and measured on the phone; no picture and no face is sent to be recognised, and nothing but your phone compares the fingerprints
A 1024 px JPEG copy of each new photo, re-encoded from pixels and carrying the original's EXIF (time, camera, position), with the file's name, folder and size, the names of any people already written on the file, and your tags and words for it when this phone has them — only on a plan with vector search

No

Goes to
api.opensolr.com photos_ingest. Without vector search on the plan no picture is sent: a photo is indexed by its date, camera, place, file name and your own words, and search is lexical. The printed text in the photo is read from this same copy, on api.opensolr.com: the picture is handed to tesseract in memory and never written to disk, and the reading is kept against the picture’s fingerprint so the same photo is never read again
The tags, people and wording of photos you edited, carried by the next sync

No

Goes to
api.opensolr.com photos_words, in calls of up to 50 photos with no picture attached, because only the words changed. Saving is done on the phone first and is finished there; the sync that starts straight after carries the change up. Only those fields are written: the photo is not read again and the rest of its document stays as it is
Your typed searches — since 2.5 close to the only thing the app asks for at read time

Not by the app; the query goes to your own index

Goes to
photos_select, which searches your index with it. On a plan without vector search there is no photos_select call and the query goes to the index alone. Plain browsing, tag and name suggestions and the list of what the selected photos already carry send nothing at all: they are answered from the copy on the phone
Your tags and your wording of what a photo shows

Yes, on the phone and in your index, until you change them

Goes to
Your Opensolr Index, through photos_words
Words, vector, camera details, place, path, folder, file name, size

Yes, until the photo leaves the phone or you empty the index

Goes to
Your Opensolr Index, and everything but the vector into the copy on the phone. On a plan without vector search there are no read words and no vector, only the date, camera, place, file name and your own words
The GPS position of each photo that has one, rounded to about 10 m

Yes, permanently, as an anonymous position-to-place answer that is not tied to your account or your photo

Goes to
opensolr.com nearby_places
The area of the map you are looking at

Only as tile requests, not stored by the app

Goes to
tile.openstreetmap.org, only while the map screen is open
Account email and API key

It is your account

Goes to
opensolr.com, with each call

Never sent anywhere: the original files, their metadata blocks as such, the thumbnails in the grid, and anything about how you use the app.

On a quiet day the app is silent. A sync with nothing new to index makes no requests at all, because it compares your folders with the copy on the phone instead of walking the index. Before 2.5 the same idle sync cost about 21 requests and 1.8 MB for a library of 10,000 photos, every time. Browsing the grid — years, months, days, their counts and the photos in them — makes no requests either. The filter lists are asked for once and kept until a sync actually writes something.

02 · What the app does not have
  • No analytics, no advertising, no crash reporting.
  • No third-party SDK that talks to the network. The dependencies are AndroidX, Jetpack Compose, OkHttp, Coil and osmdroid; osmdroid draws the map and fetches its tiles from OpenStreetMap only while the map screen is open.
  • Once a day, and whenever you tap Check for updates, the app asks api.github.com for the latest release of Opensolr Photos: one unauthenticated request that carries nothing about you or your photos.
  • No access to anything but images. The app never moves your photos and never writes to a photo file: your tags, the people you name and your wording are kept on the phone and in your own index. It deletes a photo only when you select it and confirm.
03 · What stays on the phone
  • The account API key and the index password, encrypted with a key held by the Android Keystore.
  • A copy of every document in this phone's index: the id, the path, the file name, the size, the dates, the camera, the EXIF, the place, the words the photo was read into, the printed text read out of it, the people, your tags and the file's md5. Everything the index holds except the search vector and the keys used to find duplicates. It is read down from the index once, at install or reinstall, and from then on every write keeps it in step. This is what makes browsing, suggestions and an idle sync cost nothing. It never leaves the phone, and Reset or uninstalling takes it with them.
  • Your edits that have not gone up yet: the tags, the people and the wording you gave photos, saved here first and carried up by the sync that starts straight after.
  • The faces: frames, names and fingerprints for every photo read, the faces you unticked for a person, and which photos were read. Every comparison between faces happens here.
  • Settings: chosen folders, schedule, the last sync report.
  • Answers your index gave that are not in the copy — searches, facets, duplicate groups — kept for as long as you choose so the same question is not paid for twice, and thrown away with Clear cache in the account screen. They never leave the phone and go nowhere near anyone else. Suggestions and the browsing counts are not cached answers at all: they are read out of the copy, which is permanent and is not what Clear cache touches.
Excluded from backups

Backups are switched off for the app and every kind of app data, the copy of the index included, is excluded from cloud backup and from phone-to-phone transfer. A restored or new phone signs in again and reads the whole index back down once to rebuild the copy. That one download is the only time your descriptions move in bulk.

04 · Location

Android removes GPS coordinates from photos unless the app is allowed to access photo locations. Allow it and photos are indexed with their position and the nearest place in words (city, region, country), so you can filter by place, search within a distance and see them on the map; decline it and photos are indexed without one. The choice can be changed in Android's settings at any time and applies to photos indexed from then on.

When this phone's index is created, Opensolr looks up the approximate place of the internet address the phone connects from, to put the index in the region nearest to you. The phone's own position is asked for only if you turn on Locate new photos, where a new photo without a position of its own takes the phone's.

Opensolr Photos is open source and MIT licensed. Questions about your Opensolr account, index or plan go to opensolr.com/contact; questions about the app itself belong on GitHub.

Opensolr Photos Documentation