What Lighthouse for Mac and its companion Glassroom for iPhone and iPad send, when, and to whom. The short version: the apps browse, search and develop the photos that are already in your folders, on your own devices. They talk to the network only for the things listed here — your own iCloud, the galleries you choose to publish, optional usage statistics you can switch off, feedback and crash reports, and the update check of the direct-download copy. There is no account of ours, no advertising, no tracker. Your original photos are never uploaded unless you ask for it.
Effective 18 September 2026 · applies to Lighthouse for Mac version 26.0.25 and later, downloaded from this site or installed from the Mac App Store, and to Glassroom for iPhone and iPad from the same date.
Every network connection the apps can make, and what triggers it. Nothing else leaves your devices.
| Feature | When | What is sent | To whom |
|---|---|---|---|
| iCloud library | While you are signed in to iCloud on the device, in the background | Thumbnails and a reduced neutral preview of each photo, its edit settings (the XMP sidecar), ratings, labels, the names you give to people, search words. Full originals only when you explicitly request one from another device | Your own iCloud account (Apple CloudKit, private database). We cannot read it |
| Share Gallery via iCloud | Only when you share a folder | The same previews and settings of that folder, to the people you invite | Apple CloudKit, shared with the Apple IDs you choose |
| Publish Photos Online | Only when you publish a gallery | A 2048 px preview of each selected photo, the gallery name and cover. Never the originals | Apple CloudKit, public database: anyone with the link can view it, until you unpublish |
| Usage statistics | In the background, while Share Usage Data is on | Which features are used and which screens are opened, with a random installation identifier, app and OS version. No file names, no paths, no search text, no people’s names | Our Pulse Lite collector, hosted on Google Cloud (USA) |
| Send Feedback | Only when you press Send | Your text, the screenshots you attach, a technical context (app version, macOS version, host name, the name of the open folder, the name and size of the selected image, the last lines of the app’s own log) | Our feedback server, appsupport-gajv.onrender.com (hosted on Render) |
| Crash report | At the launch after a crash | The crash text: exception, call stack, the same technical context and log lines. No photo content | The same feedback server |
| Check for Updates | Help › Check for Updates…, and the background check (direct-download copy only) | A plain GET of the update feed. No personal data, no identifier | This website, rainbowfactory.uk |
| Search, People, RAW | — | Nothing: the AI search index, face recognition and RAW development run entirely on your device | — |
Lighthouse and Glassroom keep one library across your devices through your iCloud account, using Apple’s CloudKit. The data lives in the private database of your Apple ID, in the container iCloud.imageverewstapp.imagebrowser. It is protected by Apple, under Apple’s privacy policy; Rainbow Factory has no server in this path and cannot read what you store there.
What travels: for each photo, its pyramid of thumbnails, one reduced neutral preview (about 4096 px on the long side, undeveloped, so the other device can apply your edits itself), the edit settings written in the XMP sidecar, rating, colour label, the folder structure, the search words computed on the device, and the names you give to people in the People section. The face descriptors used to recognise people never leave the device; only the name and the position of a face in a photo do.
Original files are the exception, not the rule: an original travels through iCloud only when you ask for it from another device (“Request Original”), or, in a shared folder, when the owner approves the request. Such a copy is temporary: it is deleted once delivered, and in any case within 7 days.
Signing out of iCloud, or turning iCloud Drive off for the app in System Settings, stops the sync. Deleting the app’s data from iCloud (System Settings › Apple ID › iCloud › Manage Storage) removes the library from Apple’s servers.
When you publish a gallery, the app writes a 2048 px preview of each selected photo, the gallery name and its cover into the public database of the same CloudKit container, and gives you a link on this site (rainbowfactory.uk/gallery/). Anyone who has the link can open it, without an account, and the page reads the previews directly from Apple’s servers. Originals are not published. Metadata inside the preview is stripped down to what a JPEG viewer needs; captions are whatever you typed. Unpublish (the same command again) removes the previews from the public database; the link then shows an empty gallery. Search engines may keep a cached copy of a page they had indexed while it was public.
A shared folder is an Apple CloudKit share: the previews and settings of that folder become readable, and if you allow it editable, by the Apple IDs you invite, through the standard iCloud sharing sheet. Nothing is public and nothing goes through our servers. You can stop sharing at any time from the same sheet.
From version 26.0.25 the apps can share limited information about how their features are used, so that we know what to improve. This is done with Pulse Lite, a small collector that Rainbow Factory runs on its own Google Cloud project (Cloud Run and BigQuery, United States). It is never used for advertising or for tracking you across apps or websites, and the data is not sold or shared with anyone.
What is sent. An event when the app starts, goes to the background or ends a session; which main screen is shown (grid, viewer, RAW editor, settings); and which of a short list of features is used (opening the RAW editor, saving a development, publishing a gallery, sharing via iCloud, exporting or converting, naming a person). Each event carries: a random installation identifier (a UUID created on first launch and stored on the device), a random user identifier (a UUID kept in the Keychain so that it survives a reinstall), a session identifier, the app version and build, the OS version, the device family (Mac, iPhone, iPad), and how the app was distributed (App Store, TestFlight, direct download). On iPhone and iPad, Apple’s identifier-for-vendor is included so that a deletion request can find every record of that installation.
What is never sent. No file names or paths, no photo content or thumbnails, no search text, no names of people, no folder names, no e-mail address, no device name, no precise location, no advertising identifier.
It is pseudonymous, not anonymous. The identifiers above let us count installations and let you ask for deletion; they are not linked to your Apple ID, to your iCloud library or to your feedback. We do not combine them with data from any other source.
Your controls. In Lighthouse: Settings › Privacy › Usage Data. In Glassroom: Settings › Usage Data.
Events are kept for 365 days and then deleted. If a deletion request fails because you are offline, collection stays off and you can retry.
Help › Send Feedback… (⇧⌘F) lets you write to us. Nothing is sent until you press Send. When you do, the app posts one report to our feedback server at https://appsupport-gajv.onrender.com, a service we run on Render (Render Services, Inc., United States). Glassroom uses a second instance of the same service, appsupport-ios.onrender.com. The report contains:
If you are offline the report is queued on your device (on the Mac, in ~/Library/Application Support/ImageBrowser/feedback-outbox/) and sent the next time the app starts with a connection. Delete that folder and the queued report is gone.
The host name is included so that several reports from the same machine can be read together. It is the only identifier in a feedback report; there is no account and no e-mail address unless you type one in the text.
If the app crashes, it writes a plain-text file on your device with the type of failure and the call stack. At the next launch that file is packaged as a report — the same payload as a feedback message, with the stack and the last lines of the previous session’s log — and sent to the feedback server above through the same offline queue. It contains no photo content and no path to your library; it can contain file names that appear in the log. A crash is reported once: the file is consumed at the launch that reads it. If you would rather not send it, quit the app before it reconnects and delete the outbox folder.
The copy downloaded from this site checks for updates with the open-source Sparkle framework: it fetches https://www.rainbowfactory.uk/lighthouse/downloads/appcast.xml with a plain HTTP GET and compares the version in it with the one you have. The request carries no identifier and no system profile — Sparkle’s profile reporting is off — and we do not log who asked. If you install an update, the app downloads the disk image from this site and verifies its signature against the key built into the copy you are running; anything that does not verify is refused. The Mac App Store copy has no update check at all: updates come from the App Store under Apple’s terms.
Uninstalling the app does not delete these folders; you can remove them yourself. The Mac App Store copy keeps the same data inside its sandbox container.
This site is static pages. It sets no cookies of its own, runs no analytics and embeds no advertising. Fonts are served from this site; no third party receives your requests. The gallery viewer at /gallery/ loads the previews of a published gallery directly from Apple’s CloudKit servers with Apple’s CloudKit JS, which is subject to Apple’s policy. Links to Discord, the App Store and GitHub lead to those services and their policies. Our hosting provider keeps ordinary server logs (IP address, requested page, time) for the operation of the service.
Data controller: Rainbowfactory Ltd, London, United Kingdom (the company also trades as Rainbow Factory). Registered office: 24 Fitzroy Square, London, England, W1T 6EP. Company number: 14629999. E-mail for privacy requests: support@rainbowfactory.uk. You can also reach us on Discord.
Why we process it. The iCloud library and shared galleries exist to give you the feature you switched on (they are processed by Apple, on your behalf). Published galleries are processed because you asked to publish them. Usage statistics are processed with your consent, given through the Share Usage Data switch, to improve the apps. Feedback and crash reports are processed to fix bugs and improve the apps (our legitimate interest, and your request when you press Send). Update checks are processed to deliver the version you asked for. Nothing is used for advertising or profiling, and nothing is sold.
How long we keep it. Usage events: 365 days, or until you press Remove My Usage Data. Feedback and crash reports: as long as the issue they describe is open, and at most 12 months. Published galleries: until you unpublish them. Your iCloud library: for as long as you keep it in your iCloud; we hold no copy. The update feed is a public file and records nothing.
Where. iCloud data is stored by Apple in its data centres under Apple’s terms. The usage-statistics collector runs on Google Cloud in the United States. The feedback server runs on Render in the United States.
Your rights. Under the UK GDPR and, where it applies, the EU GDPR you can ask us what we hold about you, ask for it to be corrected or deleted, withdraw consent, object to the processing, or complain to the Information Commissioner’s Office. For usage statistics the fastest way is the Remove My Usage Data button in the app, which deletes everything tied to your installation without you having to tell us who you are. For feedback, a request should mention the host name and approximate date of the report so that we can find it.
Children. The apps are not directed at children and collect no personal data from anyone as part of normal use.
Changes. When the apps gain or lose a network feature, this page changes with it, and the date at the top is updated. Version 26.0.25 added the optional usage statistics described above.