本应用不含任何自定义的网络代码,也没有我们的服务器。只有两处会产生网络流量,都由 Apple 的系统框架发起:
反查地名。当你在查看器里打开一张带 GPS 位置的照片时,本应用会通过 Apple 地图把这张照片的坐标换成可读的地名,显示在标题上。这一步会把该照片的坐标发送给 Apple,由 Apple 按其隐私政策处理;我们收不到、也不保存这次查询。不带位置的照片不会触发这一步;你也可以在拍摄时不给位置权限,从源头上避免。
购买。App 内购买、价格显示与交易记录由 Apple 的 StoreKit 与 App Store 完成(见第 7 条)。
For the 圆神相机 app for iPhone and iPadEffective: 20 September 2026Last updated: 20 September 2026
The short version
We have no servers. Your photos, videos, and edits are never uploaded — there is nowhere to upload them to.
No accounts, no ads, no analytics SDKs, no trackers, no third-party code. The app uses only Apple's system frameworks.
Exactly two things reach the network, both Apple system services: looking up a place name for a geotagged photo you open (the photo's coordinates are sent to Apple), and purchases handled by the App Store. Nothing else leaves the device.
Your originals stay as they are. Edits are saved as a hidden recipe file next to the original. An original is only rewritten if you explicitly choose "Overwrite original" when exporting.
1. Who provides this app
圆神相机 ("the app") is developed and published by gwongsam ("we"), an individual developer, and runs on iPhone and iPad. It captures RAW and HEIF photos and video, combines multiple frames on the device into long exposures, star stacks, star trails, focus stacks, and time-lapses, and edits and exports photos and video non-destructively.
This policy explains how the app handles your information. The premise running through all of it: we operate no backend servers, so your photos, videos, and edits never reach us. What follows describes how data moves on your own device.
2. What data the app handles
The following is created or read while you use the app. Apart from the two items listed in section 5, all of it stays on your device:
Category
Details
Photos and video you capture
The image and sound produced by the camera and microphone when you press the shutter, plus capture time, camera and lens, exposure settings, and — if you allow location — GPS coordinates
Existing material you select
Pixels and metadata read in order to show thumbnails and previews, edit, combine, and export — from the system photo library, the app's own folder, or a folder you point it at in Files
Edit recipes
The parameters you set across the lens-filter, tone, LUT, and palette layers, plus video trim points
Resources
Recipe presets, the filter library (including .cube files you import), and video restore LUTs you import
Copyright and credit
The author, copyright notice, contact, and terms of use you enter
Settings and memory
Capture format, resolution, stabilization, save location, the settings each workflow last used, and interface preferences
Free-use ledger
How many times each Pro workflow has been used. Counts only — no photos, no timestamps, nothing that identifies you (see section 7)
Purchase state
Whether you have purchased, which option, and when a pass expires — read from Apple's transaction records and cached locally (see section 7)
The app does not request or collect: government ID numbers, phone numbers, payment details, contacts, calendars, health data, advertising identifiers, or device fingerprints. The app has no account system; there is nothing to register or sign in to.
3. Where the data lives
All on your own device, in four places:
The app's sandbox container. Captures are saved by default to a Captures folder inside it; settings, credits, the filter library, presets, and the cached purchase state live there too. Thumbnail caches sit in its Caches folder, which the system may clear at any time and which is rebuilt on demand.
Next to the original. An edit recipe is stored as a hidden file named after the original with a .crrecipe extension (for example .IMG_0001.heic.crrecipe beside IMG_0001.heic), so the recipe travels with the file.
The system photo library. If you set the save location to the photo library, or save a result to it, photos and videos are written to the Photos app and also placed in an album named 圆神相机. From then on those files are managed by Photos and follow your iCloud Photos settings.
The keychain. Only the free-use ledger from section 2 (for example "focus stack used twice"). It lives in the keychain so that the count is not reset by reinstalling; it contains nothing that identifies you.
The app itself does not use iCloud sync and writes to no server. Whether photos saved to the system library sync to iCloud is decided by your iCloud Photos setting, independently of this app.
4. What each permission is for
Permission
What it's for
If you decline
Camera
The viewfinder and capture — the core of the app
You cannot shoot, but can still browse and edit existing material
Microphone
Recording sound alongside video
Video has no audio; nothing else changes
Photo library
Reading photos you select for editing and combining; saving results back to the library
Only material in the app's own folder is available, and results can only be saved inside the app
Location (while using)
Writing the current location into the GPS metadata of the photo or video you just captured
Photos carry no location; everything else works exactly the same, and no feature is lost
Location is read once, at the moment of capture, and used only to write into that file. The app does no background location, keeps no location history, and sends location to us nowhere (we have nothing that could receive it). All four permissions can be turned off at any time in Settings › Privacy & Security.
5. Network access: only two things
The app contains no custom networking code and we run no servers. Exactly two things produce network traffic, both issued by Apple's system frameworks:
Place-name lookup. When you open a photo that carries GPS coordinates in the viewer, the app asks Apple Maps to turn those coordinates into a readable place name for the title. This sends that photo's coordinates to Apple, who handle them under their own privacy policy; we neither receive nor store the query. Photos without location never trigger it, and declining the location permission at capture time avoids it at the source.
Purchases. In-app purchases, price display, and transaction records are handled by Apple's StoreKit and the App Store (see section 7).
Beyond these, the app uploads no photos, downloads no content, checks for no updates, sends back no logs, and connects to no advertising, analytics, or attribution network.
6. What your files carry
Whether a result carries the original's metadata depends on how it was produced:
Result
Metadata
Photos and video you capture directly
Capture time, camera and lens, exposure settings; and GPS location if you granted the location permission
Single and batch photo exports, video exports
The original's descriptive metadata: capture time, camera and lens, exposure settings, IPTC, and the GPS location if the original had one
Long-exposure and stack HEIC or DNG
The reference frame's metadata, including GPS if present; exposure time is written as the cumulative exposure
Focus stacks and time-lapse video
EXIF capture settings, but not the original's GPS
Every result also records the processing software's name and version and the standard "re-rendered" marker. If you enabled writing credits (off by default) and filled in an author, your author, copyright notice, contact, and terms of use are written into the file too.
This information travels with the file. Before sending a result to someone or posting it online, check its metadata if you would rather not reveal where it was taken or how to reach you. The app currently has no "strip location on export" option; to keep location out entirely, decline the location permission when shooting.
7. Free uses and purchases
The app is free to download. Shooting, browsing, editing, exporting, and sharing are always free.
Seven workflows — long exposure (standard, star sky, star trails), focus stacking, time-lapse stacks, library stacks, and time-lapse video stacks — each include 3 free full-quality results that never expire. Lens filters and the color palette stay live in the viewfinder until unlocked; they simply don't reach the saved file.
To keep using them there are three options: a 30-day pass (one-time, does not auto-renew), a yearly subscription (auto-renewing), and a one-time lifetime purchase. All three are handled by Apple through the App Store, and we never see your Apple Account, payment method, or billing details.
The app reads transaction records locally through Apple's StoreKit, solely to determine whether you have purchased, which option, and how many days remain on a pass, and caches that conclusion on the device so the paywall doesn't flash at every launch.
The free-use ledger is kept in the device keychain and holds counts only — which workflow was used how many times. No photos, no timestamps, nothing identifying, and it never leaves the device.
Purchases belong to your Apple Account: after reinstalling or moving to another device, sign in with the same account and tap Restore Purchases. Free uses are tied to the device rather than the account and carry over from the local keychain record.
Renewal, cancellation, and refunds are handled by Apple under their rules, and subscriptions can be managed in Settings › Apple Account › Subscriptions.
8. Diagnostics and crash data
The app includes no crash-reporting or performance-analytics SDK and sends back no logs of its own.
If you have enabled "Share with App Developers" under Settings › Privacy & Security › Analytics & Improvements, Apple may provide developers with aggregated, non-identifying crash reports and performance metrics. That data is collected and de-identified by Apple, contains none of your photos or edits, and can be turned off at any time in Settings.
9. Third parties: what we don't do
Stated item by item, to leave no ambiguity:
We do not sell your personal information (including "sale" and "sharing" as defined by US state laws);
We do not use or disclose your information for targeted advertising, and the app contains no advertising SDK;
We integrate no analytics, event-tracking, A/B testing, crash-analytics, attribution, or profiling service;
The app contains no third-party SDKs and uses only Apple's system frameworks;
We do not use your photos, videos, or edits to train any model, and make no automated decisions;
We receive no information from you, so there is no cross-border transfer initiated by us.
The only third party involved is Apple: in-app purchases and transaction records are handled by the App Store, and place-name lookups by Apple Maps (section 5). See the Apple Privacy Policy.
10. Retention and deletion
We hold none of your data, so there is no retention period on our side. How long anything lives is entirely up to you:
Photos and video you captured: select and delete them in the app's media view; for anything saved to the system library, delete it in the Photos app.
Edit recipes: tap Reset while editing, or return every parameter to its initial value, and the recipe file is removed. Deleting an original also removes its recipe.
Filter library, presets, restore LUTs: delete them in their own panels. Copyright and credit: clear the fields or turn the write switch off.
Everything on the device (settings, thumbnail caches, and the free-use ledger): delete the app. Note that the keychain copy of the free-use ledger may survive an ordinary uninstall; erasing the device or removing that keychain item clears it.
Files saved to the system library: managed by Photos, and not removed when you delete the app.
Purchase records: they belong to your Apple Account and are managed by Apple.
You can do all of the above without contacting us, and we have no copy to delete.
11. Your rights
Under applicable law — including China's PIPL, the EU GDPR, and California's CCPA/CPRA — you have rights to be informed about, access, copy, correct, supplement, delete, and port your personal information, and to withdraw consent.
In this app, exercising those rights requires neither contacting us nor waiting for our approval, because the data has been in your hands all along:
Right
How to exercise it
Access / copy
Photos, videos, and results are ordinary files on your device, readable and copyable through Files or the Photos app
Portability
Recipes travel with the original; results are standard HEIF, DNG, TIFF, or PNG images and MOV or MP4 video
Correction
Change the recipe, preset, or credits directly in the app
Deletion
See section 10 above
Withdraw consent
Turn off camera, microphone, photo library, or location in Settings › Privacy & Security
Object to automated decisions
The app makes no automated decisions and builds no profiles
If you believe your rights have not been honoured, or have any question about this policy, contact us as described in section 15. We answer within 30 days of receipt. You also have the right to complain to your local data protection authority.
12. Children
The app is not designed for children and does not knowingly collect children's personal information. Because it sends us nothing, we hold no age information about any user. If you are under 14, please use the app with the consent and guidance of a guardian; parents can manage in-app purchases through Apple's Screen Time and Ask to Buy.
13. Security
The app runs in the iOS application sandbox and can reach only its own container and the library and files you have authorised.
The app has no custom networking code, so there is no channel through which your photos or edits could be sent out by it.
We hold none of your data, so there is no "our database was breached" risk to speak of.
Captured and exported files carry metadata, possibly including GPS location (see section 6) — keep that in mind before sharing.
At the same time, please note: the security of the device itself underpins all of this. Set a passcode, enable Face ID or Touch ID, and keep the system updated. No technical measure can guarantee absolute security.
14. Changes to this policy
If the way the app handles data changes, we will update this page and the "Last updated" date at the top. For material changes we will say so prominently inside the app and, where required, ask for your consent again. Earlier versions of this page can be read in this site's public code repository.
15. Contact
For any question about this policy or your data, email gwongsam@gmail.com
Mentioning the app version and your iOS version helps us answer faster.