Last updated: 2026-08-21

Privacy Policy

PixJey – a local documentation app by The SmallJennyCompany

In short: PixJey is a local app. Your photos, videos, PDFs, categories and notes are by default stored only on your device. There is no user account and no server operated by us. Data leaves your device only in these cases: when you create a backup into a folder you choose, when you share or export content yourself, when you open the map view for a photo (the app then passes the coordinates to the Maps app), when you send us feedback (we then receive your sender address and your message), when ads (Google AdMob) are served, when you have iCloud Backup switched on for your iPhone (PixJey's content is then part of that device backup at Apple, see “Device backup” under 2), and when you switch on iCloud Sync yourself in the app's settings — this is off by default and then stores your content in your own iCloud, not with us (see “iCloud Sync” under 2). The app itself retrieves no content from the internet.

1. Data Controller

Jennifer Kurfner Weich
Sole proprietorship, trading as “The SmallJennyCompany”
Mozartring 23A
85293 Reichertshausen
Germany

Phone: +49 15679 823566
Email: smalljennycompany@gmail.com
Full provider identification in the legal notice.

2. What we process and why

Your content (local): captured or imported photos, videos, PDFs, documents and arbitrary other file types, plus saved links. Along with the structure you create and the related metadata:

This is stored in your device's internal storage; we never access or transmit it. If you have switched on iCloud Sync (off by default, see “iCloud Sync” under 2), it is additionally stored in your own iCloud — that transfer is performed by Apple, not by us. Categories can additionally be locked with device biometrics.

Camera and file picker: the camera is used for in-app capture into a category, stored locally. To take over existing photos, videos or documents, the app opens the iOS photo and file pickers. You choose there what to import, and the app receives access to exactly those files only.

The app deliberately has no access to your media library as a whole. It requests no permission to read your images and videos, cannot search your library, and does not learn what other media are on your device. What you select is copied into the app's internal storage. From there it leaves your device only in the cases summarised above — in particular if you share or export it yourself, or if you have switched on iCloud Sync.

Location (optional): if you grant permission, the capture location may be saved as a geotag in the photo's metadata. We never receive it — there is no server it could go to. It stays on your device, but can leave it through your own actions: as part of a backup into your chosen folder, and when you share or export the photo. When exporting to the Photos app the geotag is deliberately written into the image file so the Photos app can show the capture location. You can revoke the permission anytime in system settings, and switch geotagging off in the app's capture settings.

Biometric lock (optional): categories can be protected via device biometrics (Face ID / Touch ID); verification is handled entirely by iOS and the app only receives a “recognised” or “not recognised” answer. We do not collect biometric data.

Cloud backup (optional): you may back up into a folder you choose (via the iOS Files app, e.g. a folder on the device or your own iCloud Drive or OneDrive). Files are written into that folder. There is no backup server operated by us; we never receive this data. Your chosen cloud provider's privacy policy applies.

The backup is not encrypted. The backup is written as an archive containing your files unencrypted. Anyone with access to the folder you back up into can read the photos, videos and documents it contains. Please therefore treat a backup like your original files and only place it somewhere whose access you control. The reason for this design: PixJey deliberately has no sign-in and no password from which an individual key could be derived, and a key built into the app would be the same on every device and would therefore only pretend to offer security.

No background execution: a backup runs only while you have the app open and only when you start it yourself. There is no automatic background backup and the app sends you no notifications.

Device backup (iCloud Backup / Finder): this is separate from the backup above. If you have iCloud Backup switched on in your iOS settings, iOS also backs up PixJey's content — your photos, videos, PDFs, categories and notes — to Apple as part of that device backup. The same applies to a Finder (or iTunes) backup on a computer. This is intentional: after switching or losing a device, your documentation is there again. The backup is performed by iOS, not by the app, and we never receive this data. Apple's privacy policy applies; transfer and storage are encrypted. You can turn it off per app at any time under Settings → [your name] → iCloud → iCloud Backup → Backup Options (or, for a Finder backup, by not creating a backup of your device).

iCloud Sync between your devices (optional, off by default): in the app's settings under iCloud Sync you can switch on keeping your categories and media in sync across your own devices (e.g. iPhone and iPad). This switch ships turned off; nothing is synced unless you enable it.

When you do, the app stores your content in the private database of your own iCloud account (Apple's CloudKit). This creates no PixJey account and involves no server operated by uswe never receive this data and cannot access it. Apple is responsible for the storage and transfer, Apple's privacy policy applies, and the data counts against your iCloud storage quota. Syncing requires that you are signed in to iCloud with an Apple Account on the device.

For technical reasons videos larger than 100 MB stay on the device they were captured on and are not synced. You can switch the setting off again at any time; from the next launch the app uses local storage only. Data already transferred to iCloud can be removed via the iOS settings (Settings → [your name] → iCloud → Manage Account Storage).

Location technology: the position is determined by iOS location services on your device. No third-party service is involved: the app asks the operating system directly, and the position is transmitted neither to us nor to anyone else.

Map view of a photo (triggered by you): if you open the map view for a photo that has a geotag, the app passes the exact coordinates of the capture location to Apple Maps. This only happens when you trigger it; the coordinates go to Apple, not to us, and Apple's privacy policy applies.

Sharing and export (triggered by you): you can pass individual media or whole categories to other apps via the iOS share sheet, export them to the Photos app, or write them out as files. The file then leaves the app including the metadata it contains — capture date and, if set, the geotag. What the receiving app or service does with it is governed by their terms; we have no influence over that and never receive this data ourselves.

Saved links: when you save a link, only the address itself is stored. The app does not request the linked page and loads no preview — the operator of the linked website learns nothing about you saving it. Only when you open the link is it handed to your browser and the page loaded as with any visit.

Advertising – Google AdMob: the app is ad-funded via Google AdMob (Google Ireland Ltd.). According to Google, the following are processed in particular: your IP address (from which an approximate location can be derived), device and advertising identifiers (on iOS the advertising identifier “IDFA”, if you allowed tracking — see below), device information such as model, OS and app version, and ad interactions (impressions, clicks) along with app usage and diagnostic data. Purposes are ad delivery and billing, frequency capping, reach measurement and fraud prevention. Personalized ads are shown only with your explicit consent (consent dialog at first start, Google User Messaging Platform). Without your consent you will not be shown personalized ads. You can change or withdraw your choice at any time via the “Ad Privacy Options” entry in the app's settings, with effect for the future. App Tracking Transparency (iOS): in addition to GDPR consent, iOS asks you in its own system dialog whether the app may track you across other companies' apps and websites. If you decline, the advertising identifier (IDFA) is unavailable and cannot be used by Google. You can change this at any time in iOS Settings under “Privacy & Security → Tracking”. The two prompts are independent: ads are personalized only if you allow both. See Google Privacy and AdMob.

Scope: the consent dialog is shown where it is required — in the European Economic Area, the United Kingdom and Switzerland. If you use the app from a region where local law does not require consent, no dialog appears and ads are served under the rules applicable there. This policy addresses users in the German-speaking area; the commitments above apply to you unchanged.

Advertising partners: besides Google, other companies take part in ad delivery (advertising partners under the IAB Transparency and Consent Framework). Which ones they are at any given time is shown in the consent dialog under the vendor/partner options, where you can also change your choices individually. The list is maintained by Google and can change, which is why we cannot reproduce it exhaustively here — the dialog always shows the current state.

App Store and reviews (Apple): the app is distributed and updated through the App Store; the provider is Apple. For the review prompt the app uses the iOS review function (StoreKit): iOS itself decides whether the dialog appears, and the review is submitted to Apple. We do not learn whether or how you rated the app — we only see the public reviews and their summary in the App Store. Google Play services are not used on iOS.

Diagnostic/log data: we use no crash or analytics tool of our own and receive no error reports directly from your device. The released app also writes no content, file paths, file names or addresses into the device log. Technical diagnostic data (device type, OS version, time, error info) may however be collected by iOS and the App Store if you have agreed in iOS Settings to share analytics with app developers (“Privacy & Security → Analytics & Improvements”). In that case App Store Connect lets us see not only aggregated stability figures but also individual crash reports, containing technical details about the device and the program flow at the time of the error. They contain none of your content, categories or file names.

Feedback by email (triggered by you): the “Feedback” menu entry prepares a message and hands it to your email app; you send it. If you do, we receive your sender address and the content of your message in our mailbox. Purpose is answering your enquiry, legal basis Art. 6(1)(b) or (f) GDPR. Retention: we delete enquiries and the related correspondence once the matter is settled and no statutory retention applies, at the latest after twelve months.

3. Legal bases

You can withdraw consent at any time with effect for the future — for advertising via “Ad Privacy Options” in the app's settings, for tracking via iOS Settings, for location via system settings or the app's capture settings.

4. Recipients & international transfers

Recipients may be:

This may involve transfers to third countries, in particular the USA. For transfers to Google, Google relies on two instruments: the European Commission's adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR), where the receiving company — Google LLC — is certified under it, and additionally the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). The certification can be checked in the public Data Privacy Framework list; the clauses Google uses are available via Google's ads data processing terms. You may also request a copy of the safeguards from us informally (contact in section 9).

For transfers you trigger yourself — sharing, export, backing up into a folder you choose, opening a saved link — the level of protection depends on the respective recipient; we have no influence over it.

5. Retention

As we operate no server, there is no copy of this data on our side and therefore no retention period controlled by us.

6. Your rights

You have the rights of access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it. As we do not store personal data on a server, requests to us are generally handled by email; local data is deleted directly in the app or by uninstalling.

Voluntary nature

Providing optional data is voluntary. If you refuse location access the app works fully, just without a geotag. If you refuse camera access, in-app capture is unavailable but media can still be imported. If you refuse advertising consent, you will not be shown personalized ads. None of these put you at a disadvantage for the remaining functions — every feature of the app is available to you regardless of your advertising choice.

Automated decisions

Automated decision-making within the meaning of Art. 22 GDPR producing legal effects for you does not take place. With personalized ads, however, Google performs profiling to select the ads shown; you can end this at any time by withdrawing your consent (“Privacy settings” menu entry).

Right to complain

You have the right to lodge a complaint with a data protection supervisory authority. The one responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de

You may equally contact the supervisory authority of your habitual residence.

7. Children

The app is not directed to children. Users should be at least 16 (or the minimum age for data protection consent in your country).

8. Changes

We may update this policy; the current version is available in the app. Last updated: 2026-08-21.

9. Contact

smalljennycompany@gmail.com