Legal
Privacy Policy
Status: draft for legal review. This page describes what the AFTRIMGE software does with data. It has not been reviewed by a lawyer. Items shown as [TO BE DETERMINED: ...] have not been established and must be completed before this policy is relied on.
Applies to: AFTRIMGE 0.2.0 for Windows and Linux.
Provided by: [TO BE DETERMINED: legal name of the entity that distributes AFTRIMGE]
Summary
AFTRIMGE runs entirely on your computer. It has no account, no server, no telemetry and no analytics. AFTRIMGE's own code makes no network requests. The data it records stays on the device where it recorded it.
What AFTRIMGE records, and where
AFTRIMGE records data only about folders you choose to watch, and only on your device.
| Data | Where it is kept | How long |
|---|---|---|
| Full paths of the folders you watch | The local archive database | Until you delete the project |
| File names and paths inside them, past and present | The local archive database | Until you delete the project |
| File contents, for each version kept | The local object store | Until released by retention and removed by a sweep, or the project is deleted and a sweep runs |
| Sizes, times and the history of changes | The local archive database | Until you delete the project |
| Image metadata read from images you investigate, such as EXIF fields | The local archive database | Until the archive is deleted. There is no command to remove one investigated image's record |
| Measurements and relationships AFTRIMGE computes | The local archive database | Measurements of watched files go with their project; those of investigated images remain until the archive is deleted |
| Bytes of images you choose to archive | The local object store | Until you release custody and a sweep runs |
| Preservation decisions you record | The local archive database | Until you withdraw them |
| Thumbnails and rendered comparisons | Local cache folders | Until the cache is cleared |
| Engine log files, which include file paths and project folder paths | Local logs folder, one file per day | The newest 14 days are kept; older days' logs beyond 64 MB in total are removed. Today's log is never removed |
| Records of internal failures: time, version, thread, source location and message | Local logs/panic.log, with one previous file kept as panic.log.1 | Started afresh once it passes 256 KB |
| Copies of the database made before a database format upgrade | Local backups folder in the archive | The newest 3 are kept |
| Diagnostic report, written only when you press Diagnostics | A file at the location you choose | Until you delete it |
Archive locations:
- Windows, installed:
%APPDATA%\com.aftrimge.desktop - Windows, portable:
AFTRIMGE Databeside the executable - Linux:
~/.local/share/com.aftrimge.desktop
The embedded web view also keeps its own browser cache in a local folder.
The diagnostic report contains the AFTRIMGE version, database format, operating system and architecture, whether the copy is portable, counts and sizes, a database check result, log file names and sizes, the number of failure records, and up to the last 400 log lines with every value except plain numbers redacted. It contains no file contents, no file names or paths, no project names or folder locations, no archive location, and no account or computer names. AFTRIMGE does not transmit it.
None of this data is encrypted by AFTRIMGE. None of it is transmitted by AFTRIMGE. On Linux the archive folder is readable only by your account.
Network communication
- AFTRIMGE itself: none. No update checks, no telemetry, no crash reports, no licence checks, no analytics, no remote fonts or scripts. The failure record and the diagnostic report are local files and are never sent.
- Windows installer: if the Microsoft Edge WebView2 Runtime is not already installed, the installer downloads and runs Microsoft's WebView2 bootstrapper. That connection is to Microsoft and is governed by Microsoft's terms.
- Third-party runtimes: AFTRIMGE displays its interface through the operating system's web engine (Microsoft Edge WebView2 on Windows, WebKitGTK on Linux). Those components are not part of AFTRIMGE and have their own behaviour and policies.
- Crash reporting by the operating system: Windows may record application crashes through Windows Error Reporting, under your Windows settings.
Your control
- You choose which folders are watched, and can stop watching or delete a project at any time.
- You can release stored content through retention and remove it with a sweep.
- You can delete the whole archive by deleting its folder, or through the Windows uninstaller's Delete the application data option.
- Nobody but you, and anyone with access to your device, can access the archive. The provider of AFTRIMGE receives none of it.
Children
AFTRIMGE does not collect personal data from anyone, and so collects none from children.
Changes
[TO BE DETERMINED: how changes to this policy will be published]
Contact
[TO BE DETERMINED: an official contact channel has not been established]
Source: docs/legal/PRIVACY.md