This page is maintained by the FotoFairy team to answer common security and privacy questions about the app. It describes our current practices — not an independent certification or audit result.
FotoFairy helps you curate camera-roll batches into a cleaner final collection. The app runs fast local checks in your browser, then may use server-side AI analysis to improve scene understanding, duplicate handling, ranking, captions, and final order.
FotoFairy currently requires an account for private saved collections. Email confirmation, magic links, and password reset links are handled by FotoFairy's secure sign-in flow.
For saved collections, FotoFairy stores project metadata, uploaded photo records, analysis metadata, duplicate/group decisions, removed/restored states, final ordering, pinned cover photo, captions, and selected preferences. This lets you leave and come back without losing a completed draft.
Photo files for saved collections are stored in private cloud storage. FotoFairy creates fresh, short-lived display links when you reopen a collection.
FotoFairy uses local/browser analysis first where possible. When deeper analysis is needed, optimized previews may be reviewed through secure server-side AI. Private keys stay on the server and are not exposed to the browser.
FotoFairy uses essential browser storage for sign-in state and short-lived workflow handoff state. Local browser storage is not treated as the permanent source of truth for saved collections.
Saved collection rows remain until you delete them. Deleting a collection should remove the associated collection records and request cleanup of associated private photo files. Older drafts with missing photo files may show a specific fallback message rather than silently restarting the flow.
To report a security or privacy concern, contact the FotoFairy maintainer through the project repository or support channel. We will respond as soon as we are able.