← Back to PhotoPop
PhotoPop privacy policy
Last updated: September 1, 2026
PhotoPop doesn't collect any personal data. No analytics, no telemetry, no accounts. Browsing, importing, exporting, and editing all happen on your Mac, against your own Photos library. Your photos never leave your device.
One optional feature sends something off your Mac: place-name search, which is switched off until you turn it on. It sends photo coordinates — never photos — to Apple's geocoding service so it can match place names. One more reaches the network without sending anything: to search by what's in a photo, PhotoPop fetches scaled-down copies of photos that iCloud holds for you, down from your own library. Details on both below.
What PhotoPop does on your machine
- Reads your Photos library, with your permission. PhotoPop uses Apple's PhotoKit to show your albums and photos. macOS asks you to grant access the first time; you can change it any time in System Settings → Privacy & Security → Photos. Your library stays on your Mac.
- Builds a local search index on-device. To let you search by content, PhotoPop runs Apple's Vision framework over your images to recognize scene labels and any text (OCR), and caches the results in a small file in its Application Support folder. The analysis runs entirely on your Mac; no image, label, or recognized text is ever uploaded.
- Fetches photos that live only in iCloud, so it can look at them. With Optimize Mac Storage on, macOS keeps only a small thumbnail of most photos on your Mac — too small to recognize anything in. PhotoPop asks iCloud for a scaled-down copy of those, never the full-size original, purely to index them; the copy comes from your own iCloud library through Apple's PhotoKit, and nothing about your photos is sent anywhere. This is on by default and can be switched off under Index photos stored in iCloud in Preferences, in which case only photos already stored in full on this Mac are indexed.
- Looks up place names, only if you ask it to. Photos store raw coordinates, not the name of anywhere. If you switch on Search photos by place name in Preferences, PhotoPop passes those coordinates to Apple's geocoding service (
CLGeocoder) to get names back, and caches the results on your Mac so it doesn't ask twice. Only coordinates are sent — never your photos, and nothing that identifies you or your Mac. It is off by default, it's the only feature that sends anything about your photos off your Mac, and switching it back off deletes every place name PhotoPop looked up. PhotoPop never reads your Mac's own location; it only reads coordinates already stored in a photo.
- Imports, exports, and edits locally. Dragging photos out writes temporary copies on your Mac; dropping images in adds them to your library; rotating or opening a photo in an external editor and saving writes the change back to your library as a non-destructive edit. All of this stays on your device.
- Stores your preferences — small settings such as your sort choice and hotkey — in your local
UserDefaults. They never leave your device.
Network connections PhotoPop makes on its own
PhotoPop makes three kinds of network request, and only three:
- Place-name lookups — every build, and only if you turn them on. Described above: coordinates out, place names back, off by default. If you never enable it, this request never happens.
- Fetching your own iCloud photos to index them — every build, on by default. Described above: PhotoKit hands PhotoPop a scaled-down copy of a photo iCloud is storing for you. Nothing is sent but the request for your own image, and it stops entirely if you switch Index photos stored in iCloud off.
- Update checks — direct-download build only. The Sparkle framework periodically fetches
https://bendansby.com/apps/photopop/appcast.xml to see if a newer version is available. The request carries only a User-Agent string and the current PhotoPop version — no identifiers, no telemetry, no tracking.
What we don't do
- No analytics or telemetry of any kind.
- No user accounts, login, or remote configuration.
- No advertising, third-party tracking SDKs, or fingerprinting.
- No cookies, no server-side logs about you.
- No uploading of your photos — they never leave your devices, including with place-name search and iCloud indexing switched on. Indexing only pulls your own photos down; it never pushes anything up.
- No reading of your Mac's location, and no location permission requested.
Contact
ben.dansby@gmail.com
Changes
If anything material changes about what PhotoPop collects, this page updates and the next version's release notes call it out explicitly.