privacy · milkglass
privacy policy
milkglass does not collect, transmit, or share any personal data.
description
milkglass is a film simulation darkroom for macOS, published by miraisoft. this policy describes what data the app reads, writes, and transmits.
data collection
there are no analytics SDKs, no advertising SDKs, no crash reporting upload, no account system, no telemetry of any kind.
network use
at every launch milkglass asks the App Store, through Apple's StoreKit, whether your Apple ID owns the app. that request goes from your device to Apple. milkglass asks again when you use Restore Purchase.
those are the only outbound calls the app makes, and it has no other network permission. no data about you or your usage reaches miraisoft, and miraisoft runs no server the app could talk to.
file access
milkglass runs inside Apple's App Sandbox. it reads only files you explicitly open through the standard open dialog or by dragging a photo onto the app, and writes to locations you pick through the standard save dialog and to its own container.
the original RAW or image file is never modified. edits are written to a small record inside milkglass's own container under Application Support. nothing is written next to your photos.
if you move or rename a photo, milkglass finds its edits again when you reopen it, using a bookmark it keeps for each edited photo inside its container. if an older version of milkglass left a .milkglass file beside a photo, the app reads it once when you open that photo, moves the edits into its container, and removes the file.
on device storage
the following lives on your mac and never leaves it:
- edit records: a small file per photo recording your edits, plus a bookmark so the edits follow the photo when it is moved or renamed. both live inside milkglass's own container. the original file is never modified.
- app preferences: HUD window positions, recent documents, view options (stored in macOS UserDefaults).
- document recall: file references stored locally so the app can reopen recent documents.
- license state: the date of the last successful App Store check, and a random key kept in your mac's Keychain that signs that date so it cannot be forged. no Apple ID, receipt, or purchase detail is stored.
removing the app and its data removes all of the above except the Keychain key, which you can delete yourself in Keychain Access. milkglass does not request the camera, microphone, or location services.
tracking
none. milkglass does not track you across other apps or websites. Apple's NSPrivacyTracking manifest key is set to false.
required reason api declarations
under Apple's privacy manifest rules, milkglass declares these API categories with the following reason codes:
- UserDefaults, reason CA92.1 (internal preferences and window state)
- File timestamp, reason C617.1 (files inside the app's own container)
- File timestamp, reason 3B52.1 (files you granted access to: imported .icc and .cube profiles, and any .milkglass file an older version left beside a photo)
- File timestamp, reason DDA9.1 (showing a file's date on the launch screen, on device only)
these declarations describe internal use of system APIs. nothing is transmitted off the device.
third party services
none beyond Apple's own App Store, which handles licensing and purchases. no cloud sync, no third party APIs, no SDKs that phone home.
purchases
your purchase of milkglass is processed by Apple through the Mac App Store. miraisoft does not see, process, or store payment information.
children's privacy
milkglass is not directed at children under 13 and collects no information from any user.
changes
updates to this policy will be posted at this URL with a revised date.
contact
questions? reach me at hello@miraisoft.io.