Privacy Policy for the FotoSafe app and website
Last updated: 2026-08-09
App: FotoSafe
Package name: at.weidi.fotobackup
Applies to: Version 0.18.0 / Version Code 35
1. Summary
FotoSafe helps you back up photos and videos from your Android device locally to a USB drive or storage folder that you select.
FotoSafe works locally on your device:
- no user accounts,
- no cloud upload,
- no advertising,
- no tracking,
- no automatic disclosure of your photos or videos,
- no deletion of your original files on the device.
FotoSafe offers one successful free backup run with up to 100 photos and videos. A run that is deliberately cancelled in the app or completes with errors does not use up this trial run. After that, the optional lifetime purchase “FotoSafe Pro” through Google Play is required for further backup runs. Payment and purchase processing take place through Google Play; FotoSafe does not operate its own payment server.
Your photos and videos are read only to copy them to the storage location you explicitly select, such as a USB drive with the folder /FotoSafe/.
2. Controller
The controller responsible for FotoSafe is:
Peter Weitgasser Austria E-Mail: fotosafe.app@gmail.com
3. What data does FotoSafe process?
FotoSafe can access the following data locally if you grant the relevant Android permissions:
| Type of data | Purpose |
|---|---|
| Photos and images on the device | Local backup to the USB or storage location you select |
| Videos on the device | Local backup to the USB or storage location you select |
| File names, folder paths, file sizes, modification date | Identifying files already backed up, progress, backup log |
| Device manufacturer and device model | Written locally to the backup log to facilitate support and troubleshooting |
| Selected USB or destination folder | Saving the backup destination so that you do not have to select it again each time |
| Backup log and index file at the destination | Traceability and faster skipping of files already backed up |
| Time and name of the last successful backup | Local display of when and where the last fully successful backup was made |
| Local trial-run and Pro status | Limiting the free backup run and unlocking purchased Pro features |
FotoSafe processes this data locally on your Android device and at the storage destination you select.
4. FotoSafe app: no media cloud, no account, no tracking
FotoSafe does not upload your photos or videos to servers operated by the app provider. The app does not require a user account. The current version does not include any advertising, analytics or tracking SDKs.
For the optional Pro purchase, the app connects to Google Play through the Google Play Billing Library. Google processes the data required for the purchase, payment and restoration in accordance with the Google Play privacy terms. FotoSafe receives product, price and purchase-status information from Google Play and stores the most recently confirmed Pro status locally. Payment data such as credit card numbers is not processed or stored by FotoSafe.
If optional crash reporting or support features are added later, they will be enabled only following a transparent explanation and, where required, your consent. Photos and videos are not intended to form part of crash reports.
5. Permissions
FotoSafe requires certain Android permissions to provide its core function.
| Permission | Why FotoSafe needs it |
|---|---|
| Read photos/images | So that your photo library can be found and backed up |
| Read videos | So that your videos can also be backed up |
| Partial access to selected photos/videos from Android 14 | Android may grant access only to selected media; FotoSafe identifies partial access, lets you select more media and recommends full access through Android app settings for a complete backup |
| Notifications | Shows progress during longer backups and indicates that the backup is still running |
| Foreground service / data synchronisation | Keeps a user-initiated backup visible and running more robustly, even when the display is off |
| Wake lock during an active backup | Prevents a large backup in progress from immediately going to sleep when the display is off |
FotoSafe does not use general all-files access (MANAGE_EXTERNAL_STORAGE). You select the destination folder through the Android file picker.
6. Destination folder and USB drive
You select the storage location yourself through the Android file picker. FotoSafe creates or uses the following folder there: /FotoSafe/.
The following files may be created on the destination medium:
- copies of your photos and videos,
- a backup log,
- an index file that enables files already backed up to be identified more quickly.
Anyone with access to the USB drive or destination folder can view the backup copies stored there. Please keep the USB drive appropriately secure.
7. Deleting data
FotoSafe does not delete your original photos or original videos on the Android device.
You can delete backup copies by opening the USB drive or destination folder yourself and removing the files there. You can revoke the app’s access to photos/videos or the destination folder through the Android system settings.
Local app settings, including the trial-run status and the most recently confirmed Pro status, can be removed by deleting the app data or uninstalling the app. A purchase held by Google Play remains in the Google account and can be checked again using “Restore purchase”. Google’s management and deletion options apply to payment and purchase data held by Google.
8. Legal basis
Where applicable, your data is processed locally to perform the backup function that you explicitly initiate. You decide whether to grant permissions and which destination medium is used.
9. Children and family use
FotoSafe is intended as a simple local backup app. The app has no social features, advertising or user account. Parents or guardians should ensure that USB drives containing private photos are kept secure.
10. Public website and optional website analytics
The public website is provided through GitHub Pages. GitHub may process technically necessary connection data, particularly IP addresses, to deliver and secure the service. Information is available in the GitHub Privacy Statement.
Voluntary statistics with Umami
Website analytics using Umami are loaded only after you have explicitly consented through the “Allow statistics” notice. If you decline or have not yet made a choice, no connection to the Umami analytics service is established. The website and all help content remain fully functional.
After consent, the following privacy-conscious information in particular may be processed:
- a controlled page key instead of the full page URL,
- language and technical device, browser and operating-system categories,
- the IP address technically generated during the connection and any approximate location information derived from it,
- a broad source category instead of the full referrer link,
- views of help sections, FAQ openings and broad reading-depth levels,
- clicks and visible impressions of labelled affiliate recommendations with internal product and position identifiers.
Photos or videos, email addresses, support messages, free-text search entries, full affiliate destination addresses, unknown URL parameters or URL fragments are not sent to Umami. We do not use heat maps, session recordings, fingerprints or self-assigned persistent user identifiers. Affiliate clicks are not linked to purchases or commissions on a personal basis.
Purpose and legal basis: Improving the website help and assessing whether labelled recommendations are useful; your consent under Article 6(1)(a) GDPR and, where applicable, Section 165(3) TKG 2021. According to the provider’s current information, analytics data available under the Umami Hobby plan is retained for six months.
Your choice
The decision is stored with version information and an expiry time in your browser’s local storage for no more than 180 days. This is necessary so that the website does not ask for your choice again on every page view. A refusal is not transmitted as a statistics event.
You can change your decision at any time through “Privacy settings” in the footer. If consent is withdrawn, the analytics service is removed by immediately reloading the page and remains disabled for subsequent page views. If your browser sends Global Privacy Control (GPC) or “Do Not Track” (DNT), optional statistics remain disabled regardless of any previous choice.
Recipient and third-country transfer: The processor is Umami Software, Inc., 28 Geary St, Suite 650 #243, San Francisco, California, USA. Under its current terms, Umami’s Data Processing Agreement becomes part of the agreement through use of the service. For necessary transfers from the EEA to countries without an adequacy decision, it provides for the EU Standard Contractual Clauses. Umami uses subprocessors in the USA and the EU. Further information: Umami Privacy Policy, Data Processing Agreement and subprocessors.
11. Affiliate links
Some links clearly labelled “Advertising · Affiliate link” lead to external retailers. If you make a purchase through them, FotoSafe may receive a commission; this does not change the price you pay. The respective retailer’s privacy terms apply when you open the link. FotoSafe does not measure the click without consent to statistics.
12. Changes to this Privacy Policy
This Privacy Policy may be amended if functions, permissions or legal requirements change. The current version should be available at the URL stated above.
13. Contact and data subject rights
For questions about data protection, your rights of access, rectification, erasure, restriction or objection, or about the app:
fotosafe.app@gmail.com
You also have the right to lodge a complaint with the Austrian Data Protection Authority.