Privacy Policy
This Privacy Policy describes how NO PLAN inc. ("we", "us") handles information in the macOS application Hakoly (released in Japanese as さすだけフォト; the "App").
1. Summary
The App analyzes and selects photos entirely on the user's Mac (on-device). The only destination the App sends photos to is the Google Photos account the user connects. We do not receive the user's photos and do not store them on any server we operate. The App contains no analytics and sends no crash reports or usage telemetry.
2. Google user data
2.1 Scope requested
The App requests exactly one Google OAuth scope:
| Scope | https://www.googleapis.com/auth/photoslibrary.appendonly |
|---|---|
| Purpose | To upload the selected photos and videos to the user's Google Photos library, and to create an album for each shooting date and add the uploaded photos to it. |
This scope is append-only and grants no read access to the user's Google Photos library. The App therefore cannot view, retrieve, modify, delete or share photos that already exist in the user's library.
2.2 Data accessed and stored
| Data | Where it is stored | Purpose and retention |
|---|---|---|
| OAuth access token and refresh token | macOS Keychain on the user's Mac | To upload to Google Photos. Never transmitted to any server we operate. Deleted when the user signs out in the App. |
| Upload results (Google Photos media item IDs, album IDs) | A local database on the user's Mac | To prevent uploading the same photo twice and to let the user review what was processed. Removed when the App's data is deleted. |
The App does not request or access Google profile information, email addresses, or contacts.
2.3 Limited Use disclosure
Hakoly's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
- use Google user data for any purpose other than providing the user-facing features of the App;
- sell or transfer Google user data to third parties;
- use Google user data for advertising purposes;
- use Google user data to develop, improve or train generalized AI or machine learning models;
- allow humans to read Google user data, except with the user's explicit consent, where necessary for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized.
3. Photos and local data
- Photos imported from the SD card are stored in a folder on the user's Mac (by default
~/Pictures/Hakoly). - Judgments about blur, exposure, face capture quality, eye openness and image similarity are computed on the Mac using Apple's Vision framework. No photo leaves the device for analysis.
- A processing ledger (file names, checksums, decisions) is kept in a local database on the Mac.
- A file is deleted from the SD card only after a copy on the Mac has been verified to match the original by SHA-256 checksum.
- All of this data stays under the user's control and can be deleted by the user at any time. We have no access to it.
4. Information handled when a license is purchased
- Email address — used to deliver and re-deliver the license key, stored in our license issuing system hosted on Cloudflare.
- Payment details — handled by our payment processor Stripe, Inc. We never receive card numbers.
License validation is performed offline on the user's Mac using public-key signature verification; the App does not contact our servers to check a license. If no purchase is made, we collect no information at all.
5. Third parties
We do not sell or transfer users' photos or personal information to third parties, except as required by law. The App communicates with:
| Google LLC | User authentication (OAuth) and uploading photos to the user's own Google Photos library. |
|---|---|
| Stripe, Inc. | Payment processing for license purchases. |
6. Revoking access and deleting data
- Revoke Google access — sign out in the App's settings, or remove Hakoly's access under your Google Account's third-party apps & services. After revocation the App can no longer upload to Google Photos.
- Delete uploaded photos — delete them from the Google Photos app or website.
- Delete local data — remove the destination folder and the App's Application Support folder, and move the App to the Trash.
- Delete purchase records — contact support@hakoly.com. Note that we can no longer re-send the license key afterwards.
7. Security
OAuth tokens are stored in the macOS Keychain and protected by the operating system. All network communication uses HTTPS (TLS). Authentication uses the OAuth 2.0 authorization code flow with PKCE.
8. Children's privacy
The App is not directed to children under 13, and we do not knowingly collect personal information from them.
9. Changes to this policy
If we change this policy we will post the updated version on this page and revise the "Last updated" date. Material changes will be communicated through appropriate means, such as an in-app notice.
10. Contact
NO PLAN inc.
support@hakoly.com