Effective 29 July 2026

Privacy Policy

This describes what Sanary AI Cleaner does with data, separating what never leaves your iPhone from what is collected by the services in the app. It is written to match the build, not to sound reassuring.

1. Who is responsible

The data controller for Sanary AI Cleaner is:

In this policy, “we” means MARQUER DIGITAL, MB and “the app” means Sanary AI Cleaner for iPhone. This policy covers the app and this website.

2. Summary table

The detail follows, but this is the whole picture on one screen.

What happens to each kind of data in Sanary AI Cleaner
DataWhere it is handledLeaves the device?
Photos and videos in your library, and the comparisons between themOn your iPhoneNo
Your contacts and the comparison of duplicate entriesOn your iPhoneNo
Items you move into the private vaultOn your iPhoneNo
Photos you edit with AI Photo presetsOn your iPhoneNo
An email address you type into Email CheckSent from the app to Have I Been PwnedYes, at your request
A password you type into Password CheckChecked against the Have I Been Pwned breach dataYes, at your request
Purchases, subscription status, receipt validationApple and AdaptyYes
In-app events, screens opened, session dataAmplitudeYes
Install identifier, IP address, device model, iOS and app versionAdapty and AmplitudeYes
Emails you send usOur mailboxYes, because you sent it

We do not sell data. The app contains no advertising or attribution SDKs, does not use the Advertising Identifier (IDFA), and does not track you across other companies' apps or websites.

3. What is processed on your device and stays there

The cleaning features are the reason the app exists, and they are local. When you grant access to your photo library, the app reads the items through Apple's Photos framework on the device and compares them there:

  • Duplicate photos and videos — matching is done on your iPhone. The images are not uploaded for analysis.
  • Similar shots and bursts — the grouping and the Top Pick suggestion are computed on the device.
  • Screenshots, Live Photos and largest videos — these lists are built from the metadata iOS already holds about your own library.
  • Duplicate contacts — comparison happens on the device. Your address book is not uploaded.
  • Private vault — items you move into the vault are stored in the app's own storage on your iPhone. They are not backed up to any server of ours, and we cannot see them.
  • AI Photo presets — the presets are applied to your photo on the device.

We do not operate servers that store your library, your contacts or your vault. Deleting the app removes its local storage, including the vault, so take anything you want to keep out of the vault before you delete the app.

Deletion. When you confirm a deletion, the app asks iOS to remove those items. iOS moves them to the Recently Deleted album and keeps them there for around 30 days before erasing them. During that window they can be recovered from the Photos app, and they still occupy storage. Emptying that album is something only you can do.

4. What is collected, and by whom

4.1 Online Safety checks (only when you use them)

The Online Safety tab answers whether an email address or password appears in publicly known data breaches. That answer cannot be produced on the device, because it requires a breach index.

  • Email Check. The email address you type is sent directly from the app to the Have I Been Pwned API at haveibeenpwned.com, and the response is shown to you. The address is not sent to any server operated by us — we have no backend of our own in this path.
  • Password Check. The password you enter is checked against the same Have I Been Pwned breach data.

These checks run only when you initiate them. If you do not open that tab, nothing is sent. Have I Been Pwned is an independent service with its own privacy policy and terms, which govern what it does with an incoming query. Everything else in the app works without ever using this tab.

4.2 Subscriptions — Apple and Adapty

Payment is handled entirely by Apple. We never see your card details, and Apple does not pass them to us. To know whether your subscription is active and to validate receipts, the app uses Adapty (adapty.io), a subscription infrastructure provider acting as our processor. Through Adapty we receive:

  • subscription and transaction data: product purchased, currency and price, purchase and renewal dates, trial status, whether a subscription is active, cancelled or refunded, and Apple's transaction identifiers;
  • the receipt data Apple issues for validation;
  • an installation identifier generated for your app install, so purchases can be matched to the right install;
  • technical context sent with those requests: IP address, device model, iOS version, app version and region.

None of this identifies you by name. We use it to unlock what you paid for, to restore purchases, and to understand how many active subscriptions exist.

4.3 Product analytics — Amplitude

The app uses Amplitude (amplitude.com), a product analytics provider acting as our processor, to see how the app is actually used — which screens people reach, where a flow is abandoned, whether a feature is found at all. Amplitude receives:

  • event data: which screens were opened, which actions were taken and when, session start and end, and app version;
  • an installation or device identifier generated for analytics, so events from one install can be grouped into a session;
  • device and environment data: device model, iOS version, language, and country or region;
  • IP address, which is used to derive an approximate country. We do not use it to determine a precise location.

We do not send the contents of your photos, videos, contacts, vault or Online Safety entries to Amplitude, and we do not attach your name or email to analytics events.

4.4 What Apple gives us

If you agree to share diagnostics and usage with developers in your iOS settings, Apple may pass us crash reports and aggregated App Store metrics such as downloads and subscription counts. This comes from Apple in aggregate or de-identified form, and is governed by Apple's own privacy terms.

4.5 If you email us

When you write to support@sanaryapp.com or privacy@sanaryapp.com we receive your email address, whatever you put in the message, and any screenshot you attach. We use it to answer you and, where relevant, to fix the problem you reported.

5. Device permissions and why they are asked for

  • Photos. Required to find duplicates, similar shots, screenshots and large videos, to move items into the vault, and to delete what you select. Full Access is needed for detection to be meaningful: with Limited Access the app can only see the specific items you picked.
  • Contacts. Required only for the duplicate contacts feature, and only to compare entries on the device. If you decline it, everything else still works.
  • Notifications (optional). Used only for app-related messages if you allow them. Declining changes nothing else.

Every permission can be withdrawn at any time in iOS Settings → Privacy & Security. When a permission is withdrawn, the feature that depended on it stops working; nothing is deleted as a result.

6. Legal bases under the GDPR

  • Performance of a contract (Art. 6(1)(b)) — providing the app's features to you, and managing your subscription, purchases and restores through Apple and Adapty.
  • Your consent (Art. 6(1)(a)) — access to your photos and contacts, which you grant through the iOS permission prompts; and each Online Safety lookup, which happens only because you asked for it. You may withdraw consent at any time by revoking the permission or by not using the feature.
  • Our legitimate interests (Art. 6(1)(f)) — product analytics to understand and improve how the app is used, keeping the app secure, and preventing abuse of subscriptions. We keep this to what is necessary and do not use analytics to profile you.
  • Legal obligation (Art. 6(1)(c)) — keeping records of transactions where accounting and tax law in Lithuania requires it.

7. Service providers

We do not sell or rent personal data and we do not share it for advertising. Data is shared only with the following, for the purposes above:

  • Apple — App Store distribution, payment processing, subscription management.
  • Adapty (adapty.io) — subscription management and receipt validation, as our processor.
  • Amplitude (amplitude.com) — product analytics, as our processor.
  • Have I Been Pwned (haveibeenpwned.com) — receives the query you make in the Online Safety tab, as an independent service.
  • Cloudflare — hosting and delivery of this website. Server logs of website visits, including IP addresses, are processed for security and availability.
  • Our email provider, for correspondence you send us.

We may also disclose data where the law requires it, or to establish or defend legal claims.

8. International transfers

Adapty, Amplitude, Have I Been Pwned, Cloudflare and Apple process data outside Lithuania, including in the United States. Where personal data is transferred out of the European Economic Area, we rely on the safeguards permitted by Chapter V of the GDPR — in practice the European Commission's Standard Contractual Clauses, or, where the recipient is certified, the EU–US Data Privacy Framework. You can ask us which mechanism applies to a specific provider at privacy@sanaryapp.com.

9. How long data is kept

  • Library content, contacts, vault items. Held on your device only, for as long as you keep them there. Deleting the app removes the app's local storage.
  • Online Safety queries. Sent for the check and shown to you. We do not build a history of your checks. What Have I Been Pwned logs is governed by its own policy.
  • Subscription and transaction records. Kept for as long as the subscription is active and afterwards for as long as accounting and tax law in Lithuania requires — generally ten years for accounting records.
  • Analytics events. Retained in our Amplitude account for as long as needed to analyse product usage, and deleted or anonymised when no longer needed for that purpose.
  • Support email. Kept for as long as needed to resolve your request and to have a record of it, then deleted.

10. Your rights

If the GDPR applies to you, you have the right to request access to the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to processing, to receive it in a portable form, and to withdraw consent where processing is based on consent.

Write to privacy@sanaryapp.com from the address concerned, or tell us enough for us to identify the relevant records. We answer within one month, and we will tell you if we need longer, as the GDPR allows. There is a practical limit worth knowing in advance: because your library, contacts and vault never reach us, a request in practice concerns your subscription records and analytics data, and we may need the installation identifier or the purchase date to locate them.

If you believe we have handled your data improperly, you can complain to the State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija), or to the supervisory authority in your own country of residence. We would rather you told us first, at the address above.

11. Children

Sanary AI Cleaner is not directed to children. We do not knowingly collect personal data from children under 16, or under the lower age set by the law of your country where that applies. If you believe a child has used the app in a way that provided us with personal data, write to privacy@sanaryapp.com and we will delete what we hold.

12. Security

Data sent between the app and the services listed above travels over encrypted HTTPS connections. Access to our provider dashboards is limited to the people who need it and protected by two-factor authentication. The strongest measure here is structural rather than technical: the app is built so that your photos, videos, contacts and vault stay on your device, which means there is no server of ours holding them to be breached. No method of transmission or storage is completely secure, and we do not claim otherwise.

13. Changes to this policy

If the app changes — a new feature, a different provider — this policy is updated before or at the same time as the release, and the effective date at the top changes with it. Material changes will also be noted in the app's App Store release notes. The current version always lives at sanaryapp.com/privacy.

14. Contact