The core of it: Nirro analyses your photos, videos and contacts entirely on your iPhone. That content is never uploaded to us and we never see it. We do collect a small amount of technical and subscription data, described below.
1. Data controller
The controller for personal data processed in connection with the Nirro app is:
Kasar Software OÜ
Saare tee 10-2
Põvvatu küla, Tartumaa 62212, Estonia
privacy@nirro-app.com
2. Short version
| Data | Leaves your device? |
|---|---|
| Photos and videos in your library | No. Compared on-device. |
| Contacts | No. Read on-device to find duplicates. |
| Anything you place in the private vault | No. Stored in the app’s protected local storage. |
| Crash reports and device diagnostics | Yes, in pseudonymised form. |
| Subscription status and receipts | Yes, via Apple and our subscription provider. |
3. Your photos, videos and contacts
To find duplicates and similar shots, Nirro reads your photo library through Apple’s Photos framework and compares images using calculations performed on the device processor. The same applies to contacts.
We do not upload, copy, transmit, store or view your photos, videos or contacts. There is no server that receives them, no account, and no sync. If you turn off the internet entirely, scanning still works.
Any technical artefacts of the scan — thumbnails, comparison fingerprints, grouping indexes — are held on your device and are removed when you delete the App.
4. What we do collect
Technical and diagnostic data
- Device model, iOS version, app version, language and region
- Crash logs and error reports
- Anonymous or pseudonymous identifiers used to distinguish one installation from another
This is used to fix bugs and keep the App stable. It is not linked to your name and we do not attempt to identify you from it. We do not track what you do inside the App, and we do not build a profile of you.
Subscription data
- Purchase receipts, subscription status, renewal and cancellation events, trial status
- Country of the App Store account, for tax and pricing purposes
Payments are processed by Apple. We never receive your card number or full payment details.
Support correspondence
If you email us, we process your address and whatever you choose to tell us, for as long as needed to resolve the issue and to keep a record of it.
5. Device permissions
| Permission | Why it is asked for |
|---|---|
| Photos (full library) | Duplicate and similarity detection requires comparing images against each other, which is not possible with single-image selection. |
| Contacts | Only if you use contact cleanup or the contacts vault. Read on-device. |
Every permission can be withdrawn in iOS Settings at any time. Withdrawing photo access disables scanning but does not affect anything already on your device.
6. Legal bases (GDPR)
- Performance of a contract (Art. 6(1)(b)) — providing the App and managing your subscription.
- Legitimate interests (Art. 6(1)(f)) — keeping the App stable and secure, and preventing abuse.
- Consent (Art. 6(1)(a)) — optional analytics and any marketing communications, where consent is required. You may withdraw it at any time.
- Legal obligation (Art. 6(1)(c)) — tax and accounting records.
7. Service providers
We use a small number of providers who process data on our behalf, under written data processing agreements and only for the purposes set out in this policy:
- Apple Inc. — distribution of the App, payment processing, subscription management and crash reporting.
- Subscription management — validating App Store receipts and keeping track of whether a subscription is active.
- Crash and stability reporting — diagnosing errors so they can be fixed.
- Email and support tooling — handling the correspondence you send us.
These providers receive only the technical and subscription data described in section 4. None of them receives your photos, videos or contacts, because that content never leaves your device.
We do not sell personal data, and we do not share it with data brokers or advertising networks.
8. International transfers
Some providers are established outside the European Economic Area. Where data is transferred outside the EEA, we rely on the European Commission’s Standard Contractual Clauses or an adequacy decision. You can request a copy of the safeguards in place by writing to us.
9. Retention
- On-device data — kept until you delete the App or clear its data.
- Diagnostic and usage data — up to 14 months, then deleted or aggregated.
- Subscription and billing records — for as long as required by tax law, seven years under the Estonian Accounting Act.
- Support correspondence — 24 months after the issue is closed.
10. Your rights
If you are in the EEA or the UK, you have the right to access your data, correct it, have it erased, restrict or object to processing, receive it in a portable format, and withdraw consent at any time.
Write to privacy@nirro-app.com. We respond within one month. Because most of what the App handles never reaches us, we may need identifying details — such as your App Store order ID — to locate any record relating to you.
You also have the right to lodge a complaint with your national supervisory authority. In Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).
California residents
If you are a California resident, you have the right to know what personal information is collected, to request deletion, and to opt out of “sale” or “sharing”. We do not sell or share personal information as those terms are defined by the CCPA/CPRA. You will not be discriminated against for exercising these rights.
11. Children
The App is rated for general audiences but is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.
12. Security
Data in transit between the App and our providers is encrypted with TLS. Vault content is held in the App’s protected storage on the device and, where enabled, behind Face ID, Touch ID or a passcode.
No system is perfectly secure. Keeping your device passcode-protected and up to date is the single largest factor in the security of anything stored on it.
13. Changes
We will post any updated version on this page with a new “last updated” date, and will notify you in the App where the change is material.
14. Contact
Kasar Software OÜ
Saare tee 10-2
Põvvatu küla, Tartumaa 62212, Estonia
Privacy: privacy@nirro-app.com
Support: support@nirro-app.com