Your original photos never leave your phone. To read a photo, the app sends a small copy that is described in words and not stored. What is kept is a description, in an index that belongs to your account — and, since 2.5, in a copy of that index held on the phone itself. On a plan without vector search no copy of any photo is sent at all.
Figure 1 — where each piece of data lives.
Yes, in your own index, until the photo leaves the phone or you empty the index
No
No
Not by the app; the query goes to your own index
Yes, on the phone and in your index, until you change them
Yes, until the photo leaves the phone or you empty the index
Yes, permanently, as an anonymous position-to-place answer that is not tied to your account or your photo
Only as tile requests, not stored by the app
It is your account
Never sent anywhere: the original files, their metadata blocks as such, the thumbnails in the grid, and anything about how you use the app.
On a quiet day the app is silent. A sync with nothing new to index makes no requests at all, because it compares your folders with the copy on the phone instead of walking the index. Before 2.5 the same idle sync cost about 21 requests and 1.8 MB for a library of 10,000 photos, every time. Browsing the grid — years, months, days, their counts and the photos in them — makes no requests either. The filter lists are asked for once and kept until a sync actually writes something.
- No analytics, no advertising, no crash reporting.
- No third-party SDK that talks to the network. The dependencies are AndroidX, Jetpack Compose, OkHttp, Coil and osmdroid; osmdroid draws the map and fetches its tiles from OpenStreetMap only while the map screen is open.
- Once a day, and whenever you tap Check for updates, the app asks
api.github.comfor the latest release of Opensolr Photos: one unauthenticated request that carries nothing about you or your photos. - No access to anything but images. The app never moves your photos and never writes to a photo file: your tags, the people you name and your wording are kept on the phone and in your own index. It deletes a photo only when you select it and confirm.
- The account API key and the index password, encrypted with a key held by the Android Keystore.
- A copy of every document in this phone's index: the id, the path, the file name, the size, the dates, the camera, the EXIF, the place, the words the photo was read into, the printed text read out of it, the people, your tags and the file's md5. Everything the index holds except the search vector and the keys used to find duplicates. It is read down from the index once, at install or reinstall, and from then on every write keeps it in step. This is what makes browsing, suggestions and an idle sync cost nothing. It never leaves the phone, and Reset or uninstalling takes it with them.
- Your edits that have not gone up yet: the tags, the people and the wording you gave photos, saved here first and carried up by the sync that starts straight after.
- The faces: frames, names and fingerprints for every photo read, the faces you unticked for a person, and which photos were read. Every comparison between faces happens here.
- Settings: chosen folders, schedule, the last sync report.
- Answers your index gave that are not in the copy — searches, facets, duplicate groups — kept for as long as you choose so the same question is not paid for twice, and thrown away with Clear cache in the account screen. They never leave the phone and go nowhere near anyone else. Suggestions and the browsing counts are not cached answers at all: they are read out of the copy, which is permanent and is not what Clear cache touches.
Backups are switched off for the app and every kind of app data, the copy of the index included, is excluded from cloud backup and from phone-to-phone transfer. A restored or new phone signs in again and reads the whole index back down once to rebuild the copy. That one download is the only time your descriptions move in bulk.
Android removes GPS coordinates from photos unless the app is allowed to access photo locations. Allow it and photos are indexed with their position and the nearest place in words (city, region, country), so you can filter by place, search within a distance and see them on the map; decline it and photos are indexed without one. The choice can be changed in Android's settings at any time and applies to photos indexed from then on.
When this phone's index is created, Opensolr looks up the approximate place of the internet address the phone connects from, to put the index in the region nearest to you. The phone's own position is asked for only if you turn on Locate new photos, where a new photo without a position of its own takes the phone's.