Privacy policy
- Operator
- Deng Yuezhou (邓岳州), an individual.
- Privacy and support
- tengle.deng@memoopen.ai. We provide an initial response within 15 working days; resolution depends on the request. This site has no upload form.
1. Scope and basic operation
The standalone edition works without a MO Photos desktop server or device pairing and does not run MO Photos device-to-device synchronization. This does not disable all networking: system Photos, location, weather, speech recognition, and casting, export or sharing you initiate may use networks.
Switching from an internal connected edition retains existing device identity, history and unconfirmed sync tasks locally; it does not delete them or mark them as sent. Old remote entries without usable local media are hidden from ordinary browsing, not deleted. Future connected editions require separate explanations.
2. Content processed on your device
- Photos and videos: media, existing capture times and locations within the Photos access you grant, local catalogues, previews and source links. Some media remains in system Photos rather than being copied into the app.
- Your records: favorites, comments, notes, recordings and transcripts, profile details, people and photo selections, reminders, private and trash states are stored locally.
- Independent people memories: names, nicknames, relationship notes, text, recordings and record times are stored in the local database and managed audio directory. A record can link multiple people without a photo. People recordings are not automatically sent for online transcription. Clearing derived face indexes preserves your records. Complete export includes committed people records and audio; unfinished recordings remain recoverable drafts rather than completed records.
- On-device people search: when you mark a person or explicitly enable automatic organization, bundled face models analyze authorized, non-private, non-trash photos. Scanning does not automatically download iCloud originals or upload photos or face vectors. Unnamed face indexes find similar photos, not real-world identities, and do not automatically create people. You confirm candidates. Pause or clear the derived index in Settings → People and Recognition; names and manual confirmations remain. Indexes use file protection and are excluded from device backup; manual decisions remain in the formal database.
- Review history: exposure, active review, effective dwell and playback support local ranking and statistics. Historical facts are retained; new records are not synchronized in this edition.
- Diagnostics: restricted event categories, times, versions, counts and durations help troubleshoot. Logging does not automatically send data to us.
You may deny or change Photos, camera, microphone, speech, location, notification and local-network permissions in system Settings. Related capabilities may be unavailable, without deleting saved facts. Revoking Photos or location access does not erase previously saved history.
3. Data that may leave your device
- Apple location and weather services
- Existing photo GPS or permitted current location supports place display. Uncached photo coordinates can be sent automatically to Apple geocoding during indexing, not only on a manual lookup. Reminder place searches send your entered place text to Apple MapKit. Camera and historical weather may send a location and requested date to WeatherKit.
- Apple speech recognition
- After you request recording and authorize recognition, on-device transcription is preferred when supported. Otherwise Apple online recognition may receive audio. Failed or denied speech recognition should not prevent saving the recording. Microphone and speech permissions are separate.
- System Photos and backup
- PhotoKit may retrieve iCloud resources according to your system settings. Device backup may include the local database and managed originals. This is not MO Photos cloud synchronization or a guarantee of a complete backup. See Apple's privacy information.
- Casting you initiate
- AirPlay uses system external display. DLNA supplies temporary previews to the receiver you select on your local network, possibly with time or location captions you enable, not comment text. DLNA's temporary HTTP delivery is not end-to-end encrypted; use trusted receivers and networks.
- Export or sharing you initiate
- Content goes to the file, mail or other service you choose. Complete recovery packages may contain private media and text and are not redacted diagnostics. External copies are outside local app cleanup; recipients apply their own rules.
- Support materials
- When you contact support, we receive the text, contact information and attachments you choose to provide. See support retention rules. Neither the site nor app uploads diagnostics automatically.
4. Retention, deletion and recovery
Local links and context remain during use and are handled through your editing, trash and confirmed deletion actions. App trash, system Recently Deleted, private storage and external backups are different locations; disappearance from one screen does not delete every copy. Read confirmation prompts before original-media operations.
Offloading and deleting the app are different. Deleting can lose app-only originals, recordings and context; do not use it to troubleshoot. Check storage and backups before removal. We cannot access or erase your local library through an email request.
App logs follow a 7-day / 20 MiB retention and size policy; cleanup is not promised while the app is stopped. Temporary diagnostic packages are cleaned during maintenance or manually. External copies require separate management. Complete recovery packages include only declared managed files and facts, not all system Photos, iCloud-only or desktop originals or system Keychain. We do not promise public one-tap overwrite recovery.
5. Security and received support data
The app uses sandboxing, file protection, private-entry authentication and diagnostic export restrictions. This is not a claim that every database is additionally encrypted or all delivery methods have equal security. Exported private copies may no longer have the app's private-entry protection.
Deng Yuezhou handles support manually through the existing Tencent business mailbox. Its provider processes support mail and attachments, and controlled support computers may hold downloaded copies. Access is limited to people needed for troubleshooting, not advertising, profiling or model training. Raw diagnostics are retained no longer than 30 days from receipt and deleted earlier when unnecessary. Cleanup covers the mail, attachments, downloads and trash. Provider backups that cannot be erased immediately are isolated, protected and no longer used, then cleared on the provider's cycle; legally required retention is limited to the relevant purpose and period. The app cannot guarantee the mailbox provider's physical backup deletion time. Do not provide passwords, verification codes, pairing keys or your private library.
6. Your choices and rights
You can adjust permissions, stop optional services, edit local content, export supported data and clear device logs. Refusing diagnostics does not affect local use. Contact the email above to access, correct, withdraw or delete previously sent support materials, specifying the original request, materials and action. We verify only the minimum necessary information and initially respond within 15 working days, explaining reasons and next steps if immediate completion is impossible. We do not ask for unrelated identity documents or your entire database. For inaccessible device-local content, we can provide instructions rather than remotely erase it.
7. Minors, regions and this website
The product serves general individual users in mainland China and overseas, not a children's app. Minors should use it with guardian guidance; users under 14 need guardian consent before sending support materials. Obtain appropriate permissions for information about other people or children; do not send their sensitive information as routine diagnostics. If children's information arrives without appropriate consent, we will investigate, restrict processing and delete as required.
These static pages contain no analytics scripts, advertisements, tracking, cookies or upload forms. The China site mophotos.memoxai.cn is hosted on Tencent Cloud in Shanghai; mophotos.memoopen.ai is hosted on Tencent Cloud in Singapore, with Cloudflare used only for its DNS. Website security logs process IP, time, paths without query parameters, response status and browser information. Access logs are retained up to 180 days, restricted and rotated for deletion; separate request error logs are not stored for this site. Infrastructure security records follow the hosting provider's rules and applicable law. Visiting either site involves its hosting region; neither site receives photos or diagnostics, and the app does not synchronize your library or people data across borders because of these pages.
8. Updates
We update the date and explanation when processing purposes, scope or sharing change, with notice and necessary authorization under applicable requirements. This policy does not mean future synchronization is enabled or the app has passed store review.