klymov.dev
Back to OnlyKeep
🇬🇧EN🇺🇦UA
OnlyKeep app icon
LegalOnlyKeep

Privacy Policy

How OnlyKeep handles data and protects your privacy.

Documents

Privacy PolicyTerms of UseApp page↗
Have a question about this document?Contact support

The current version included with the app.

Last updated: August 31, 2026

1. Who we are

OnlyKeep is provided by Individual Entrepreneur Danylo Klymov (Ukrainian: Фізична особа-підприємець Климов Данило Віталійович) ("OnlyKeep", "we", "us", or "our"). We are the controller of personal data described in this policy.

2. Scope and privacy summary

This policy applies to the OnlyKeep iOS application and related support communications. OnlyKeep helps you review your Apple Photos library and submit deletion requests that you confirm through iOS.

Photo and video analysis, duplicate detection, cleanup decisions, and session progress are designed to run on your device. We do not upload your photos or videos to our servers, sell personal data, or use data for third-party advertising or cross-app tracking.

3. Photos, videos, and on-device data

With your permission, OnlyKeep reads items available through Apple PhotoKit, including thumbnails, photos, videos, creation dates, media types, file-size information, duration, and location metadata already attached to media. The app uses this information to display your library, create cleanup sessions, group likely duplicates or similar items, estimate storage, and organize media by time or place.

This media content and metadata are processed on your device. OnlyKeep does not send your photos, videos, filenames, PhotoKit asset identifiers, exact media dates, or photo location coordinates to our analytics, diagnostics, or purchase providers.

OnlyKeep stores local app state such as language, onboarding status, notification preference, cleanup decisions, session drafts, selected asset identifiers, cached library statistics, cached file sizes, and cached place titles. Free-use counters and consumed trial-session identifiers may also be stored in the iOS Keychain and can remain after reinstalling the app.

4. Permissions and Apple services

  • Photos. Required to show and organize the media you allow OnlyKeep to access and to submit a deletion request after your review. Limited Photos access restricts the app to items selected in iOS.
  • Deletion. A swipe does not delete media. Deletion occurs only after a review screen and a separate iOS confirmation. Items may remain in the Photos "Recently Deleted" album according to iOS behavior and your settings.
  • Notifications. Optional permission for local reminders about unfinished sessions or returning to cleanup. OnlyKeep does not use remote marketing notifications.
  • Location metadata. OnlyKeep does not request or track your live location. If you use location cleanup, coordinates already attached to media may be sent to Apple's geocoding service to obtain a readable place name. The result is cached locally.

Apple processes information under its own Privacy Policy.

5. Data processed off the device

Product analytics

Firebase Analytics and Mixpanel are enabled as minimized product-improvement services. They process separate random installation identifiers and a limited allowlist of OnlyKeep product-interaction events such as screens viewed, features or cleanup modes used, permission status, and bucketed counts, durations, storage estimates, and outcomes. Firebase also processes standard app lifecycle, session, engagement, device, and App Store purchase events. Basic properties include app version, build, device model, operating-system version, language, and approximate geography derived by Google from the Firebase request IP address. Mixpanel is configured to use its EU data-residency endpoint, disable automatic event collection and IP-based geolocation, and receive only the same allowlisted product schema. We use this information to measure feature use, funnels, reliability, and retention across sessions.

Each analytics identifier represents one installation. Neither is an advertising identifier; OnlyKeep does not join the Firebase and Mixpanel identifiers, link them to an account or purchase-provider identifier, or use them to track you across other companies' apps or websites. OnlyKeep uses FirebaseAnalyticsCore, does not collect IDFA, and disables IDFV collection. We do not send names, email addresses, precise or live location, photo coordinates or metadata, filenames, PhotoKit identifiers, notification text, or support text to either analytics provider. Google Signals and advertising personalization are disabled, and Analytics is not linked to advertising products.

Crash reports

Firebase Crashlytics is enabled as a service needed to monitor and improve app stability. It processes crash stack traces, relevant technical app state, timestamps, installation and session identifiers, bundle and app version, device model, operating-system information, processor architecture, available RAM or disk information, and other technical diagnostics needed to identify and fix crashes. OnlyKeep adds no crash custom value other than its bundle identifier. We do not deliberately add photos, videos, names, email addresses, precise locations, filenames, PhotoKit identifiers, or support-message content to crash reports.

App configuration and availability

Firebase Remote Config is used for required app-availability, rollout, and update checks. It may process a Firebase installation identifier, device country and language codes, time zone, operating-system version, app identifier, bundle identifier, Firebase SDK information, and limited Analytics app properties such as first-open time.

Purchases

Apple processes payments and payment credentials. We do not receive your card or bank details. RevenueCat processes an automatically generated anonymous app-user identifier, Apple receipt and transaction information, product identifiers, purchase and entitlement status, app and device technical information, locale or currency information, and a temporary IP address or IP-derived country where applicable. We use this information to show purchase options, validate purchases, prevent fraud, unlock OnlyKeep Pro, restore purchases, and understand subscription performance. We do not provide RevenueCat with your name, email address, advertising identifier, or photo-library data.

Support

If you contact support, we receive the email address, subject, message, and attachments that you choose to send. If you enable optional diagnostics in the support form, the prepared email also includes the OnlyKeep version and build, selected app language, iOS version, and device model. Do not attach sensitive media unless it is necessary for your request.

6. Purposes and legal bases

Where the EU/EEA or UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract: providing cleanup features, processing purchase and entitlement information, restoring purchases, and responding to support necessary to provide the service.
  • Legitimate interests: protecting the app against fraud and misuse, maintaining required configuration and security, measuring product funnels and feature outcomes using minimized pseudonymous analytics, diagnosing crashes, improving reliability, and establishing or defending legal claims. We balance these interests against your rights. You may contact us to object to processing based on legitimate interests.
  • Legal obligations: tax, accounting, consumer-protection, regulatory, and lawful disclosure obligations that apply to us.

On-device processing of your photo library occurs at your direction after you grant iOS permission.

7. Service providers and disclosures

We disclose only the information needed for the purposes above to:

  • Apple, for App Store distribution, purchases, PhotoKit, and geocoding;
  • Google, for Firebase Analytics, Crashlytics, Installations, and Remote Config;
  • Mixpanel, for minimized product analytics processed through its EU data-residency endpoint;
  • RevenueCat, for purchase validation, entitlement management, and purchase analytics;
  • email and infrastructure providers involved when you send a support request;
  • professional advisers, authorities, or other recipients when reasonably necessary to comply with law, protect rights and safety, resolve disputes, or complete a lawful business reorganization.

Our providers are required by contract or applicable law to protect personal data. Their own policies are available at Apple Privacy, Google Privacy, Firebase Privacy and Security, and RevenueCat Privacy.

8. International transfers

We are established in Ukraine, and our providers may process data in the United States, the European Economic Area, and other countries where they operate. Where required, transfers rely on an adequacy decision, the EU-U.S. Data Privacy Framework for participating recipients, Standard Contractual Clauses, the UK Addendum, or another lawful safeguard. You may request information about applicable safeguards at support@klymov.dev.

9. Retention

  • On-device app state remains until you remove it in the app where a control is available, delete the related session or cache, or delete the app. Keychain-based free-use and trial records may remain after reinstall and are retained to administer limits and prevent repeated trial abuse.
  • Firebase Analytics user-level and event-level data and Mixpanel event data are retained for no longer than 14 months. Standard aggregated Firebase reports may remain available for longer because Google's retention control does not apply to them.
  • Firebase Crashlytics generally keeps crash reports and associated identifiers for 90 days before deletion begins.
  • Firebase installation identifiers used for Remote Config remain until deletion is requested; Firebase states that removal from live and backup systems may take up to 180 days after the request.
  • RevenueCat purchase and entitlement records are retained while needed to provide and restore purchases, prevent fraud, meet accounting or legal obligations, and resolve disputes. They are deleted or anonymized when no longer necessary and legally permitted. Apple independently retains App Store purchase records under its terms.
  • Support correspondence is normally retained for up to 24 months after the last interaction, or longer when needed for an unresolved issue, fraud prevention, legal compliance, or a legal claim.

Backup copies may persist for a limited period before secure deletion. We may retain de-identified information that can no longer reasonably identify an individual.

10. Your choices and deletion

You can revoke Photos or Notifications permission in iOS Settings. Firebase Analytics, Mixpanel, and Crashlytics have no in-app switches because we use them as minimized product-improvement and stability services. You can object to this processing or request deletion by contacting support@klymov.dev.

Deleting the app removes most local app data. iOS Keychain items may survive reinstall. Because OnlyKeep has no user account and uses random provider identifiers, we may need information from your device to locate a provider record. Email support@klymov.dev for access or deletion. We will explain any verification step and send requests to the relevant provider where technically possible. Some information may be retained where required by law or necessary to protect legal rights or prevent fraud.

To delete Firebase Analytics, Mixpanel, installation, or RevenueCat customer data, contact us before deleting the app if possible so we can help identify the applicable random app-instance, installation, or customer identifier.

11. Your privacy rights

Depending on where you live, you may have rights to be informed, access personal data, correct it, request deletion, restrict or object to processing, receive portable data, and withdraw consent. You may also complain to a competent supervisory authority, including the authority in your country of residence in the EEA/UK or the Ukrainian Parliament Commissioner for Human Rights.

OnlyKeep does not sell personal data, share it for cross-context behavioral advertising, or use it for targeted advertising. Where applicable US state law provides rights to opt out of those activities, there is nothing to opt out of under our current practices. We will not discriminate against you for exercising a privacy right.

Submit requests to support@klymov.dev. We may request proportionate information to verify the request. If we cannot associate a random identifier with you, we will explain why and may ask you to provide the identifier from your device.

12. Children

OnlyKeep is a general-audience utility and is not directed to children under 13. We do not knowingly collect personal data directly from a child under 13. A minor who is old enough to use the app but is not legally able to agree to these terms should use it only with a parent or legal guardian's permission, particularly for purchases and analytics.

If you believe a child provided personal data to us without required authorization, contact support@klymov.dev and we will take appropriate steps.

13. Security

We minimize transmitted data, use platform permissions, use encrypted HTTPS connections provided by our service SDKs, and restrict access to service dashboards. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

14. Changes to this policy

We may update this policy when the app, providers, or law changes. We will update the date above and, when a change is material, provide an appropriate notice in the app or through the App Store. The current version will remain available in OnlyKeep Settings and at the public Privacy Policy URL listed in the App Store.

15. Contact

Privacy and data-rights contact: support@klymov.dev

klymov.dev

Independent iOS apps, designed and built with care.

Explore

My AppsAboutContact

Legal

Privacy PolicyTerms of UseWebsite PrivacySupport

Contact

support@klymov.devLinkedIn

© 2026 Danylo Klymov. All rights reserved.

Apple, App Store, iOS, Swift, and SwiftUI are trademarks of Apple Inc.