Privacy Policy

What Lighthouse for Mac and its companion Glassroom for iPhone and iPad send, when, and to whom. The short version: the apps browse, search and develop the photos that are already in your folders, on your own devices. They talk to the network only for the things listed here — your own iCloud, the galleries you choose to publish, optional usage statistics you can switch off, feedback and crash reports, and the update check of the direct-download copy. There is no account of ours, no advertising, no tracker. Your original photos are never uploaded unless you ask for it.

Effective 18 September 2026 · applies to Lighthouse for Mac version 26.0.25 and later, downloaded from this site or installed from the Mac App Store, and to Glassroom for iPhone and iPad from the same date.

Overview

In one table

Every network connection the apps can make, and what triggers it. Nothing else leaves your devices.

FeatureWhenWhat is sentTo whom
iCloud libraryWhile you are signed in to iCloud on the device, in the backgroundThumbnails and a reduced neutral preview of each photo, its edit settings (the XMP sidecar), ratings, labels, the names you give to people, search words. Full originals only when you explicitly request one from another deviceYour own iCloud account (Apple CloudKit, private database). We cannot read it
Share Gallery via iCloudOnly when you share a folderThe same previews and settings of that folder, to the people you inviteApple CloudKit, shared with the Apple IDs you choose
Publish Photos OnlineOnly when you publish a galleryA 2048 px preview of each selected photo, the gallery name and cover. Never the originalsApple CloudKit, public database: anyone with the link can view it, until you unpublish
Usage statisticsIn the background, while Share Usage Data is onWhich features are used and which screens are opened, with a random installation identifier, app and OS version. No file names, no paths, no search text, no people’s namesOur Pulse Lite collector, hosted on Google Cloud (USA)
Send FeedbackOnly when you press SendYour text, the screenshots you attach, a technical context (app version, macOS version, host name, the name of the open folder, the name and size of the selected image, the last lines of the app’s own log)Our feedback server, appsupport-gajv.onrender.com (hosted on Render)
Crash reportAt the launch after a crashThe crash text: exception, call stack, the same technical context and log lines. No photo contentThe same feedback server
Check for UpdatesHelp › Check for Updates…, and the background check (direct-download copy only)A plain GET of the update feed. No personal data, no identifierThis website, rainbowfactory.uk
Search, People, RAWNothing: the AI search index, face recognition and RAW development run entirely on your device
Your own iCloud

Your iCloud library

Lighthouse and Glassroom keep one library across your devices through your iCloud account, using Apple’s CloudKit. The data lives in the private database of your Apple ID, in the container iCloud.imageverewstapp.imagebrowser. It is protected by Apple, under Apple’s privacy policy; Rainbow Factory has no server in this path and cannot read what you store there.

What travels: for each photo, its pyramid of thumbnails, one reduced neutral preview (about 4096 px on the long side, undeveloped, so the other device can apply your edits itself), the edit settings written in the XMP sidecar, rating, colour label, the folder structure, the search words computed on the device, and the names you give to people in the People section. The face descriptors used to recognise people never leave the device; only the name and the position of a face in a photo do.

Original files are the exception, not the rule: an original travels through iCloud only when you ask for it from another device (“Request Original”), or, in a shared folder, when the owner approves the request. Such a copy is temporary: it is deleted once delivered, and in any case within 7 days.

Signing out of iCloud, or turning iCloud Drive off for the app in System Settings, stops the sync. Deleting the app’s data from iCloud (System Settings › Apple ID › iCloud › Manage Storage) removes the library from Apple’s servers.

File › Publish Photos Online… · Share Gallery via iCloud…

Published and shared galleries

Publish Photos Online (public web gallery)

When you publish a gallery, the app writes a 2048 px preview of each selected photo, the gallery name and its cover into the public database of the same CloudKit container, and gives you a link on this site (rainbowfactory.uk/gallery/). Anyone who has the link can open it, without an account, and the page reads the previews directly from Apple’s servers. Originals are not published. Metadata inside the preview is stripped down to what a JPEG viewer needs; captions are whatever you typed. Unpublish (the same command again) removes the previews from the public database; the link then shows an empty gallery. Search engines may keep a cached copy of a page they had indexed while it was public.

Share Gallery via iCloud (private share)

A shared folder is an Apple CloudKit share: the previews and settings of that folder become readable, and if you allow it editable, by the Apple IDs you invite, through the standard iCloud sharing sheet. Nothing is public and nothing goes through our servers. You can stop sharing at any time from the same sheet.

Settings › Privacy › Usage Data

Usage statistics (Pulse Lite)

From version 26.0.25 the apps can share limited information about how their features are used, so that we know what to improve. This is done with Pulse Lite, a small collector that Rainbow Factory runs on its own Google Cloud project (Cloud Run and BigQuery, United States). It is never used for advertising or for tracking you across apps or websites, and the data is not sold or shared with anyone.

What is sent. An event when the app starts, goes to the background or ends a session; which main screen is shown (grid, viewer, RAW editor, settings); and which of a short list of features is used (opening the RAW editor, saving a development, publishing a gallery, sharing via iCloud, exporting or converting, naming a person). Each event carries: a random installation identifier (a UUID created on first launch and stored on the device), a random user identifier (a UUID kept in the Keychain so that it survives a reinstall), a session identifier, the app version and build, the OS version, the device family (Mac, iPhone, iPad), and how the app was distributed (App Store, TestFlight, direct download). On iPhone and iPad, Apple’s identifier-for-vendor is included so that a deletion request can find every record of that installation.

What is never sent. No file names or paths, no photo content or thumbnails, no search text, no names of people, no folder names, no e-mail address, no device name, no precise location, no advertising identifier.

It is pseudonymous, not anonymous. The identifiers above let us count installations and let you ask for deletion; they are not linked to your Apple ID, to your iCloud library or to your feedback. We do not combine them with data from any other source.

Your controls. In Lighthouse: Settings › Privacy › Usage Data. In Glassroom: Settings › Usage Data.

  • Share Usage Data switches collection on or off. Switching it off also asks our collector to delete what it holds for your installation, and clears anything still queued on the device.
  • Remove My Usage Data sends that deletion request on its own. After the server confirms, the installation identifier is renewed. Your files, settings, edits, purchases and iCloud library are not affected.

Events are kept for 365 days and then deleted. If a deletion request fails because you are offline, collection stays off and you can retry.

Help › Send Feedback…

Send Feedback

Help › Send Feedback… (⇧⌘F) lets you write to us. Nothing is sent until you press Send. When you do, the app posts one report to our feedback server at https://appsupport-gajv.onrender.com, a service we run on Render (Render Services, Inc., United States). Glassroom uses a second instance of the same service, appsupport-ios.onrender.com. The report contains:

  • the text you wrote;
  • the screenshots you attached, if any. Nothing is attached unless you attach it;
  • a technical context: the app version and build, the macOS or iOS version, the computer’s host name, the display language, the kind of build (App Store, direct download, development), the name of the folder you are looking at, the name and pixel size of the selected image, and the last 2000 characters of the app’s own log. Not the photo, not its full path, not your library. Log lines can mention file names of what the app was processing at the time.

If you are offline the report is queued on your device (on the Mac, in ~/Library/Application Support/ImageBrowser/feedback-outbox/) and sent the next time the app starts with a connection. Delete that folder and the queued report is gone.

The host name is included so that several reports from the same machine can be read together. It is the only identifier in a feedback report; there is no account and no e-mail address unless you type one in the text.

Automatic, at the next launch

Crash reports

If the app crashes, it writes a plain-text file on your device with the type of failure and the call stack. At the next launch that file is packaged as a report — the same payload as a feedback message, with the stack and the last lines of the previous session’s log — and sent to the feedback server above through the same offline queue. It contains no photo content and no path to your library; it can contain file names that appear in the log. A crash is reported once: the file is consumed at the launch that reads it. If you would rather not send it, quit the app before it reconnects and delete the outbox folder.

Help › Check for Updates…

Check for Updates

The copy downloaded from this site checks for updates with the open-source Sparkle framework: it fetches https://www.rainbowfactory.uk/lighthouse/downloads/appcast.xml with a plain HTTP GET and compares the version in it with the one you have. The request carries no identifier and no system profile — Sparkle’s profile reporting is off — and we do not log who asked. If you install an update, the app downloads the disk image from this site and verifies its signature against the key built into the copy you are running; anything that does not verify is refused. The Mac App Store copy has no update check at all: updates come from the App Store under Apple’s terms.

On your devices

What stays on your devices

  • Your photos and documents. Lighthouse works on the folders you open, where they are. Developing a RAW file writes an .xmp sidecar next to it and never modifies the original pixels; rotation, ratings and labels are sidecar entries too. Exports and conversions go where you save them.
  • The search index (~/Library/Application Support/ImageBrowser/search.sqlite): the words, tags and OCR text that the on-device Vision analysis extracts from your photos, and the People data — face positions, face descriptors, the groups and the names you give them. Face recognition runs entirely on the device with models bundled in the app; descriptors are never uploaded, and only names (which you typed) reach your iCloud library.
  • The thumbnail cache (~/Library/Caches/ImageBrowser/): the multi-resolution previews the grid and the viewer draw.
  • The local sync store (~/Library/Application Support/ImageBrowser/sync/): which of your photos correspond to which library records in your iCloud.
  • Preferences, the feedback outbox and the app log (lighthouse.log, overwritten at every launch, one previous session kept).

Uninstalling the app does not delete these folders; you can remove them yourself. The Mac App Store copy keeps the same data inside its sandbox container.

rainbowfactory.uk

This website

This site is static pages. It sets no cookies of its own, runs no analytics and embeds no advertising. Fonts are served from this site; no third party receives your requests. The gallery viewer at /gallery/ loads the previews of a published gallery directly from Apple’s CloudKit servers with Apple’s CloudKit JS, which is subject to Apple’s policy. Links to Discord, the App Store and GitHub lead to those services and their policies. Our hosting provider keeps ordinary server logs (IP address, requested page, time) for the operation of the service.

Retention, your rights, contact

Retention, your rights, contact

Data controller: Rainbowfactory Ltd, London, United Kingdom (the company also trades as Rainbow Factory). Registered office: 24 Fitzroy Square, London, England, W1T 6EP. Company number: 14629999. E-mail for privacy requests: support@rainbowfactory.uk. You can also reach us on Discord.

Why we process it. The iCloud library and shared galleries exist to give you the feature you switched on (they are processed by Apple, on your behalf). Published galleries are processed because you asked to publish them. Usage statistics are processed with your consent, given through the Share Usage Data switch, to improve the apps. Feedback and crash reports are processed to fix bugs and improve the apps (our legitimate interest, and your request when you press Send). Update checks are processed to deliver the version you asked for. Nothing is used for advertising or profiling, and nothing is sold.

How long we keep it. Usage events: 365 days, or until you press Remove My Usage Data. Feedback and crash reports: as long as the issue they describe is open, and at most 12 months. Published galleries: until you unpublish them. Your iCloud library: for as long as you keep it in your iCloud; we hold no copy. The update feed is a public file and records nothing.

Where. iCloud data is stored by Apple in its data centres under Apple’s terms. The usage-statistics collector runs on Google Cloud in the United States. The feedback server runs on Render in the United States.

Your rights. Under the UK GDPR and, where it applies, the EU GDPR you can ask us what we hold about you, ask for it to be corrected or deleted, withdraw consent, object to the processing, or complain to the Information Commissioner’s Office. For usage statistics the fastest way is the Remove My Usage Data button in the app, which deletes everything tied to your installation without you having to tell us who you are. For feedback, a request should mention the host name and approximate date of the report so that we can find it.

Children. The apps are not directed at children and collect no personal data from anyone as part of normal use.

Changes. When the apps gain or lose a network feature, this page changes with it, and the date at the top is updated. Version 26.0.25 added the optional usage statistics described above.