Legal

Privacy Policy

Status: draft for legal review. This page describes what the AFTRIMGE software does with data. It has not been reviewed by a lawyer. Items shown as [TO BE DETERMINED: ...] have not been established and must be completed before this policy is relied on.

Applies to: AFTRIMGE 0.2.0 for Windows and Linux.

Provided by: [TO BE DETERMINED: legal name of the entity that distributes AFTRIMGE]

Summary

AFTRIMGE runs entirely on your computer. It has no account, no server, no telemetry and no analytics. AFTRIMGE's own code makes no network requests. The data it records stays on the device where it recorded it.

What AFTRIMGE records, and where

AFTRIMGE records data only about folders you choose to watch, and only on your device.

DataWhere it is keptHow long
Full paths of the folders you watchThe local archive databaseUntil you delete the project
File names and paths inside them, past and presentThe local archive databaseUntil you delete the project
File contents, for each version keptThe local object storeUntil released by retention and removed by a sweep, or the project is deleted and a sweep runs
Sizes, times and the history of changesThe local archive databaseUntil you delete the project
Image metadata read from images you investigate, such as EXIF fieldsThe local archive databaseUntil the archive is deleted. There is no command to remove one investigated image's record
Measurements and relationships AFTRIMGE computesThe local archive databaseMeasurements of watched files go with their project; those of investigated images remain until the archive is deleted
Bytes of images you choose to archiveThe local object storeUntil you release custody and a sweep runs
Preservation decisions you recordThe local archive databaseUntil you withdraw them
Thumbnails and rendered comparisonsLocal cache foldersUntil the cache is cleared
Engine log files, which include file paths and project folder pathsLocal logs folder, one file per dayThe newest 14 days are kept; older days' logs beyond 64 MB in total are removed. Today's log is never removed
Records of internal failures: time, version, thread, source location and messageLocal logs/panic.log, with one previous file kept as panic.log.1Started afresh once it passes 256 KB
Copies of the database made before a database format upgradeLocal backups folder in the archiveThe newest 3 are kept
Diagnostic report, written only when you press DiagnosticsA file at the location you chooseUntil you delete it

Archive locations:

  • Windows, installed: %APPDATA%\com.aftrimge.desktop
  • Windows, portable: AFTRIMGE Data beside the executable
  • Linux: ~/.local/share/com.aftrimge.desktop

The embedded web view also keeps its own browser cache in a local folder.

The diagnostic report contains the AFTRIMGE version, database format, operating system and architecture, whether the copy is portable, counts and sizes, a database check result, log file names and sizes, the number of failure records, and up to the last 400 log lines with every value except plain numbers redacted. It contains no file contents, no file names or paths, no project names or folder locations, no archive location, and no account or computer names. AFTRIMGE does not transmit it.

None of this data is encrypted by AFTRIMGE. None of it is transmitted by AFTRIMGE. On Linux the archive folder is readable only by your account.

Network communication

  • AFTRIMGE itself: none. No update checks, no telemetry, no crash reports, no licence checks, no analytics, no remote fonts or scripts. The failure record and the diagnostic report are local files and are never sent.
  • Windows installer: if the Microsoft Edge WebView2 Runtime is not already installed, the installer downloads and runs Microsoft's WebView2 bootstrapper. That connection is to Microsoft and is governed by Microsoft's terms.
  • Third-party runtimes: AFTRIMGE displays its interface through the operating system's web engine (Microsoft Edge WebView2 on Windows, WebKitGTK on Linux). Those components are not part of AFTRIMGE and have their own behaviour and policies.
  • Crash reporting by the operating system: Windows may record application crashes through Windows Error Reporting, under your Windows settings.

Your control

  • You choose which folders are watched, and can stop watching or delete a project at any time.
  • You can release stored content through retention and remove it with a sweep.
  • You can delete the whole archive by deleting its folder, or through the Windows uninstaller's Delete the application data option.
  • Nobody but you, and anyone with access to your device, can access the archive. The provider of AFTRIMGE receives none of it.

Children

AFTRIMGE does not collect personal data from anyone, and so collects none from children.

Changes

[TO BE DETERMINED: how changes to this policy will be published]

Contact

[TO BE DETERMINED: an official contact channel has not been established]

Source: docs/legal/PRIVACY.md