In short: your memory library is stored on your device and synced through your private iCloud database when iCloud is available. Derived face thumbnails, feature prints and face-group IDs remain only on the device.
1. Information you provide
RecallNest may process text you enter, photos, documents, audio, video, names you assign to detected faces, API keys you provide, and questions you ask when recalling memories.
2. Information processed on your device
The app stores your memories, attachments, AI summaries, extracted text, tags, people, event times, recording locations, mood and weather snapshots in the app's local database. Apple Vision may perform OCR and image analysis locally. The bundled embedding model creates semantic vectors locally for search. Face data is described separately in Section 3.
Private iCloud sync. Memories, photos, videos, documents, audio, extracted text, metadata and summaries sync through Apple's CloudKit to the private iCloud database associated with your Apple Account. Only you can access that private database by default; its contents count against your iCloud quota and aren't visible to AiStudioWorks in the developer console. You control iCloud availability through system settings. Derived face thumbnails, feature prints and face-group IDs are kept in a separate local-only store and are not included in this sync.
3. Face Data: collection, use, sharing, storage, retention and deletion
Face data collected. When you add a photo or video containing a face and allow face organization, RecallNest uses Apple Vision on the device to detect faces and creates: (a) a small cropped face thumbnail; (b) a numeric image feature print derived from the crop and used to compare visual similarity; and (c) a random app-specific face-group identifier such as “FACE-0001.” If you choose, the app also stores the name you manually assign to that face group. A source photo or video may itself visually contain a face. RecallNest does not collect TrueDepth camera data, a depth map, a face mesh, facial landmark coordinates, or the Face ID biometric template managed by iOS.
Use. The face thumbnail, feature print and face-group identifier are used only to group visually similar faces within your personal memory library, show a representative thumbnail, let you filter memories by face, and carry a name you choose across matching memories. They are not used to authenticate you, identify you outside your own library, build an advertising or marketing profile, track you, or make eligibility or other consequential decisions. The app's optional Face ID lock is a separate iOS authentication feature; RecallNest receives only the success or failure result and never receives the system Face ID template.
Sharing and disclosure. Face thumbnails, image feature prints and face-group identifiers remain on the device and are not uploaded to iCloud or AiStudioWorks servers, and are not sold, shared or transferred to OpenAI, Alibaba Cloud, Google AdMob, analytics providers, advertisers or data brokers. Source photos and videos may sync only to your private iCloud database as described in Section 2; AiStudioWorks can't view them in the developer console. If you separately choose an external AI provider and give the explicit consent described in Section 6, a text description may include only the number of detected faces and relevant memory context may include a person name that you manually assigned. Face thumbnails, feature prints, face-group identifiers, facial measurements and original media are not included in that external AI request.
Storage and security. Derived face data is stored only in a local SwiftData store inside the app's sandbox on your device and is excluded from RecallNest's CloudKit sync. AiStudioWorks has no face-data server or cloud database. Apple backup settings may separately include local app data in a device or iCloud backup. Optional device authentication can restrict access to RecallNest.
Retention and deletion. A thumbnail, feature print, face-group identifier and optional assigned name remain until the earliest of: (a) you delete that face ID in RecallNest, which immediately deletes every local derived face record in that group; (b) you delete a memory, which deletes the derived face records associated with that memory; (c) you withdraw face-data consent in Settings, which immediately deletes all local derived face records and prevents further face processing; or (d) you uninstall RecallNest, which deletes the app's live local database. In the memory library, expand a memory's details, tap a face thumbnail, then choose Delete Face ID. Deleting a face ID does not delete the source photo, video or memory; delete the memory separately to delete its locally stored source media. Copies in a device or iCloud backup remain subject to Apple's backup lifecycle and can be removed through your Apple backup controls. AiStudioWorks retains no server copy and therefore has no additional server-side retention period.
4. Location and weather
With permission, the app may obtain your location while in use to associate a recording place with a memory. For weather retrieval, latitude and longitude are reduced to two decimal places and sent to Apple Weather through WeatherKit. Apple processes this location data to return current weather conditions. Weather information is cached for up to approximately 30 minutes. Photo metadata may also contain capture time and location and may be retained with the related memory.
5. Speech recognition
When supported, speech recognition is requested on device. If on-device recognition is unavailable, Apple's speech recognition service may process audio under Apple's terms and privacy practices.
6. AI processing and explicit consent
- Apple Intelligence: this is the default provider. When selected and available, compatible requests are processed using Apple's system model without RecallNest sending the request to OpenAI or Alibaba Cloud.
- OpenAI API, provided by OpenAI: only after you select OpenAI and explicitly consent, the app may send your entered memory text and questions; text or descriptions extracted on the device from photos, documents, audio and video; and relevant memory context such as names, locations, dates, mood, weather, attachment filenames and existing AI summaries. This data is used to organize memories, create daily summaries, plan local retrieval and answer your questions. See OpenAI Enterprise Privacy.
- Alibaba Cloud Model Studio (Qwen), provided by Alibaba Cloud: only after you select Qwen and explicitly consent, the app may send the same categories of data described above for the same AI features. See the Alibaba Cloud Model Studio Privacy Notice.
Original photos, documents, audio and video are not sent to these external AI providers by RecallNest; however, text, descriptions and metadata extracted from them may contain personal information. A provider also receives technical connection information such as the IP address needed to complete the request. Requests are sent directly from your device using the API key you provide. AiStudioWorks does not receive or store the external AI request content on an AiStudioWorks server. API keys are stored in the iOS Keychain.
Before the first transmission to each external AI provider, the app displays the recipient, the data categories and purposes and requires an affirmative consent action. Declining leaves Apple Intelligence and other on-device features available. Consent is stored separately for each provider and policy version.
We select and permit only external AI providers whose published, contractual and technical data protections we have determined provide the same or equivalent protection required by this policy and the App Review Guidelines. Provider processing, security, retention and deletion are also governed by the agreement associated with your API account and the provider's applicable terms. Do not submit passwords, identity documents, medical records or other highly sensitive material.
7. Advertising
The app uses Google AdMob. Google and its partners may process IP address, diagnostics, ad interactions, approximate location, and app- or developer-bounded identifiers for ad delivery, fraud prevention, frequency control and measurement. RecallNest does not request the IDFA or App Tracking Transparency permission, and disables AdMob's publisher first-party ID. See Google's Privacy Policy.
8. Storage, security and retention
Memories are stored locally and synchronized to your private iCloud database when available. Deleting a synced memory removes it from the active local and CloudKit stores, subject to synchronization delay, Apple recovery and backup lifecycles, and copies on offline devices until they reconnect. Optional Face ID or device authentication can restrict access to the app. Derived face data follows the local-only retention and deletion rules in Section 3. AiStudioWorks cannot directly delete data held under your Apple, OpenAI or Alibaba Cloud account; use the relevant account controls or privacy request process.
9. Your choices
You can deny or revoke microphone, speech, location and photo permissions in iOS Settings; choose the AI provider; edit or delete memories; delete face IDs; and remove external API keys. In RecallNest, open Settings → Privacy → External AI Data Sharing to review or withdraw consent separately for OpenAI or Qwen. Withdrawal immediately prevents new transmissions to that provider and switches the app to Apple Intelligence if necessary. It does not automatically delete data previously processed by the provider. Some features may stop working when their permission is disabled.
10. Children
RecallNest is not directed to children under 13, and we do not knowingly collect children's personal information through an AiStudioWorks account service.
11. Changes and contact
We may update this policy as the app changes. The effective date above will be revised when material changes are published. Questions or deletion requests concerning an AiStudioWorks-controlled service can be sent to drive.notes.app@gmail.com.