Privacy Policy
Effective date: August 9, 2026
Gallery is an Android photo and video organizer with local viewing, file-management, trash, location grouping, and a PIN-protected Vault. Your photos, videos, Vault media, media catalog, credentials, and preferences are stored on your device and are not uploaded to us or to Firebase. Eligible Google Play release bundles use Firebase Analytics for limited product events and Firebase Crashlytics for app stability. Gallery does not contain advertising SDKs and does not display ads.
1. Who We Are
This Privacy Policy applies to the Android app Gallery, package name com.ai.gallery.private.vault.hidepictures. Gallery is provided by Quovad Studio. In this policy, "we", "us", and "our" refer to Quovad Studio.
For privacy questions, contact us at support@quovadstudio.cc.
2. Scope and Accounts
This policy describes the current data practices of Gallery. The app does not require a Gallery account, and we do not operate an account database, photo-storage service, or cloud-sync service for Gallery.
3. Photos, Videos, Files, and Media Metadata
Gallery uses Android's MediaStore and the photo and video permissions you grant to find and manage media on your device. Depending on the action you choose, the app may read, display, play, search, copy, move, rename, share, hide, restore, or delete media files. On Android versions that support partial media access, Gallery can operate on only the photos and videos you select.
To organize and display your library, Gallery creates a local media catalog. It may process and store:
- File names, paths, media types, file extensions, sizes, and modification times.
- Photo and video dimensions, capture dates, video duration, and thumbnail information.
- Local MediaStore identifiers, storage-volume information, and content hashes used for file identity, change detection, recovery, and duplicate-safe operations.
- Location coordinates embedded in photo EXIF metadata or video metadata, when present, and the country, region, or city derived from those coordinates for location grouping.
Your media files, thumbnails, file names, file paths, content hashes, and media catalog are not uploaded to us or intentionally included in Firebase Analytics or Crashlytics reports.
Location Metadata and Geocoding
Gallery does not request your device's current location. It may read coordinates already embedded in media files and use Android's system Geocoder to convert those coordinates into place names. A geocoding request may be processed by the geocoding service provided by your device, Google, or your device manufacturer, and that service may receive the coordinates and related technical request data under its own privacy policy. Derived place names and coordinates are stored in Gallery's local database for media grouping.
4. Media Access and Other Permissions
- Photos and Videos: Used to browse, display, organize, play, and manage the public media you allow Gallery to access. On Android 14 and newer, you can grant access to selected media only. Gallery does not request All Files Access.
- Media Location: Optional and used to read unredacted location metadata already embedded in media files for location grouping. Gallery does not use this permission to obtain your device's current location.
- Media Management: Optional special access that can reduce repeated Android system confirmation prompts for supported media-management actions. If it is not granted, Gallery uses the system confirmation flow where required.
- Internet: Used for Firebase Analytics, Firebase Crashlytics, Android geocoding when the device's service requires a network connection, and pages you choose to open.
- Network State: Used to understand whether network-dependent services are available.
- Vibration: Used for brief feedback when supported media features, such as Live Photo playback, begin.
- Notifications: Used on supported Android versions to show progress or status for longer-running media-management work.
- Foreground Service: Used for eligible background data-sync work that scans, enriches, or maintains the local media catalog.
- Device Administrator: Optional and used only for uninstall protection after you explicitly enable it in Android's system screen. Gallery does not use device-administrator access to set or read your lock-screen password, lock the device, wipe data, or control other apps.
5. Vault and Recovery Information
Gallery's Vault copies media you select into the app's private internal storage and, after verification, asks Android to remove the public source where confirmation is required. Ordinary apps and public gallery scanners cannot access Gallery's private internal directory. Release versions block screenshots on Vault screens. Vault media remains on your device and is not uploaded to us.
Vault media content is protected by Android's app sandbox but is not separately encrypted at the file-content level. The Gallery PIN controls access through the app. A person who can bypass Android's device and app-storage protections may still be able to read the underlying files, so you should also protect access to your device.
The four-digit PIN is not stored in plain text. Gallery stores a PBKDF2-derived PIN hash and a random salt locally. You must also choose a local recovery method:
- If you choose email recovery, the email address you enter or select from Android's account chooser is stored locally. Gallery does not send a recovery email and does not upload the address.
- If you choose a security question, Gallery stores the question identifier or custom question and a salted PBKDF2-derived hash of the answer. The answer is not stored in plain text.
Gallery also keeps encrypted recovery-catalog metadata inside the app's private, non-backed-up storage to recover Vault folder and file relationships after an interrupted operation. This recovery metadata does not encrypt the media content itself and is deleted when Gallery is uninstalled.
6. Local App Data, Trash, and Backup
Gallery uses Room and MMKV to store its media catalog, Vault associations, trash state, operation state, language and display preferences, permission-prompt state, and other settings locally. Items moved to Gallery's public or Vault trash are normally eligible for permanent deletion after 30 days, or sooner if you choose to delete them permanently.
Android app-data backup and device-to-device transfer are disabled for Gallery, and the app's backup rules exclude its databases, preferences, and private files. Uninstalling Gallery deletes the app's internal Vault media, Vault trash, credentials, and recovery catalog. Move important items out of Vault before uninstalling the app.
7. Firebase Analytics
Eligible production versions distributed as a Google Play Android App Bundle use Firebase Analytics to understand broad feature use and improve reliability. Debug builds and local release APK builds are configured not to upload analytics.
Analytics events may describe app and screen use, language changes, media-viewer and video-player actions, favorite or file-operation results, Vault setup and operation stages, bucketed item counts, and optional uninstall-protection state. Firebase and Android may also supply app version, device type, operating system, language, region, session, and installation information.
We do not intentionally send photos, videos, thumbnails, file names, file paths, content hashes, precise coordinates, place names, PINs, recovery email addresses, security questions, security answers, or user-entered text to Firebase Analytics. We do not use Analytics for advertising or personalized advertising.
8. Firebase Crashlytics
Eligible production versions use Firebase Crashlytics to diagnose crashes, application-not-responding events, and selected non-fatal errors. Crashlytics may process stack traces, relevant application state, app and build information, device manufacturer and model, operating-system information, language, network connection type, session data, Firebase installation identifiers, and privacy-reviewed custom keys.
Vault diagnostics use bounded categories and count ranges. The app is designed to sanitize these reports so they do not intentionally include media content, file names, file paths, Vault keys, coordinates, recovery information, or user-entered credentials. We do not set a Crashlytics user ID.
9. Firebase Identifiers and No Advertising
Firebase may create service-specific identifiers, such as a Firebase installation ID or Crashlytics installation UUID, to distinguish app installations and sessions and measure how many installations are affected by an issue. These identifiers are governed by Google's applicable documentation.
Gallery does not contain an advertising SDK, does not display ads, does not offer in-app purchases or subscriptions, and does not use Firebase data for behavioral advertising. Gallery does not intentionally read the Android Advertising ID, IMEI, IMSI, SIM serial number, hardware serial number, or MAC address.
10. Sharing Through Other Apps
When you choose to share media, Gallery grants the receiving app temporary access to the files you selected through Android's sharing system. The receiving app and service process those files under their own privacy policies. Gallery does not share media in the background or without an action you initiate.
11. How We Use Information
- Display, organize, search, play, and manage local photos and videos.
- Provide location grouping, local trash, Vault, recovery, and uninstall protection.
- Remember app settings and maintain the local media catalog.
- Diagnose crashes, compatibility problems, and reliability issues.
- Measure aggregate feature use and improve Gallery.
- Protect users, app security, our rights, and comply with legal obligations.
- Respond to support or privacy requests you choose to send.
12. Third-Party Services and International Processing
Gallery uses Google Firebase Analytics, Crashlytics, Installations, and supporting Firebase components. This Privacy Policy is published using Firebase Hosting. Android geocoding may use a service supplied by Google or your device manufacturer. These providers may process service data on servers outside your country or region under their applicable safeguards.
More information is available here:
- Google Privacy Policy
- Privacy and Security in Firebase
- Firebase Android Data Disclosure
- Google Play Terms and Policies
13. Sharing and Sale of Data
We do not sell personal information or share personal information with advertising companies. Limited information may be disclosed only:
- To Google and Firebase as service providers for Analytics, Crashlytics, Installations, supporting services, and Hosting.
- To the device's geocoding provider when coordinates are resolved into place names.
- When required by applicable law, legal process, or a valid government request.
- When reasonably necessary to protect users, app security, our rights, or public safety.
- At your direction, such as files you choose to share through another app.
14. Retention and Deletion
Local app data remains until you delete it, clear Gallery's app storage, or uninstall the app. Trashed media is handled as described in Section 6. Clearing app storage or uninstalling Gallery deletes the internal Vault, its trash, local credentials, and recovery metadata. Public media that has not been moved into Vault remains under Android's public media storage rules.
Firebase retains Analytics, Crashlytics, installation, and session data according to our Firebase settings and Google's applicable retention practices. Firebase identifiers may be recreated if the app continues to use Firebase services after an identifier is deleted.
Because Gallery has no user accounts and does not upload your media library to us, there is no Gallery cloud-media account to delete. To request deletion of support correspondence or ask about service data associated with your installation, contact support@quovadstudio.cc. We may need technical information from you to identify a relevant record, and some service data may not be reasonably linkable to you.
15. Security and Your Choices
We use reasonable technical and organizational safeguards, including Android private internal storage, local credential hashing, encrypted Vault recovery metadata, screenshot protection on Vault screens in production builds, and encrypted network connections for Firebase. As explained above, Vault media content is not separately encrypted, and no storage or transmission method can guarantee absolute security.
You can change or revoke photo and video access, media-location access, notifications, optional media management, or device-administrator access in Android settings, although disabling access may make related features unavailable. You can delete media and local app data or uninstall Gallery at any time. Depending on where you live, you may have rights to access, correct, delete, object to, or restrict certain personal data. Contact us to exercise an applicable right.
16. Children's Privacy
Gallery is a general-audience utility and is not specifically directed to children under 13. We do not knowingly ask children to provide personal information to us through the app. If you believe a child has provided personal information, contact us and we will take appropriate action.
17. Changes to This Policy
We may update this Privacy Policy as Gallery changes. The latest version will be posted on this page with a revised effective date.
18. Contact Us
For questions or requests about this Privacy Policy, contact support@quovadstudio.cc.
This page is provided for Google Play and in-app privacy policy access for Gallery.