Somewhere

Privacy

Last updated 29 August 2026

Somewhere has no accounts, no logins, and no profile of you. It is an app that sends chosen photographs to a cloud editing service. This page says where they go when it does that.

The short version. When you open a chosen photo in the editor, Somewhere immediately starts uploading that one full-size original to our private cloud storage so later edits can start faster. Once it arrives, cloud workers can finish Clean, Crop and Proof operations if the app is suspended, using Google's Gemini API where generative processing is needed. Your photo library is never uploaded, indexed or scanned in the background. Your copy of the app registers a random installation identifier so the cloud will accept its requests, and it sends us its own diagnostic log alongside your sessions. We do not sell data, and there is no advertising in the app.

Your photographs

When you open a chosen photograph in the editor, Somewhere immediately sends it over an encrypted connection to a private Amazon Web Services bucket. The full-size original is uploaded once. Our AWS Lambda workers read it and the generated assets needed for later operations, and store the results so work can finish if the app is suspended or disconnected.

For generative work, the worker sends the relevant image and instruction to Google's paid Gemini API. Google's handling of API inputs and outputs is governed by its Gemini API terms and abuse-monitoring policy. AWS describes its role in its privacy notice. If a photograph is private enough that you would not want AWS and Google to process it, do not open it in Somewhere's editor.

The cloud original, operation records and generated assets remain available for that session until you delete the session in Somewhere. Deleting a session requests deletion of its cloud objects, jobs and local files. AWS retains a deletion marker containing the anonymous session identifier and a one-way credential digest solely to reject delayed requests that could otherwise recreate deleted data. That marker is set to expire after one hour, although AWS may complete its removal later. Deleting the app itself cannot send that request; contact us if you deleted the app first and need help, although without the session identifier we may be unable to locate an anonymous session.

What stays on your phone

The installation identifier

The first time your copy of the app needs the cloud, it registers with our service and is issued a random installation identifier and a matching secret token. Both are stored in your device's Keychain and sent with every request the app makes to us, so the service can tell that a request came from a real installation rather than from someone else. This is a device identifier under Apple's definitions, and we declare it as one.

It is generated by us at random. It is not your Apple ID, your name, your email, your phone's advertising identifier or any hardware serial, and it is not shared with anyone or used to track you across other apps or websites. It does identify your installation to us, and the sessions and diagnostic logs described below are associated with it. Deleting the app removes the copy in your Keychain; a reinstall registers a new one.

Diagnostic logs

The app keeps a running technical log on your device — which operation ran, how long it took, whether it failed and why, and the random session and job identifiers involved. It sends the recent part of that log to us when you close a photo, when the app goes to the background, and after each Clean, Crop or Proof finishes or fails. This happens routinely, not only after a problem, and there is currently no setting to turn it off.

The log is text about the app's own behaviour. It carries no photograph, no image data and no contents of your library, and nothing you typed into the app. It is associated with your installation identifier and with the session it belongs to, and we use it to find out why a step was slow or came back wrong. It is not sold or shared.

What we count

Separately from the above, Somewhere sends one kind of message to a counting server we run: which step was used and which artist's proof was chosen. A message looks like this, in full:

{ "event": "proof_saved", "artist": "Saul Leiter" }

This particular message carries no identifier at all — no installation identifier, no account, nothing that ties one message to another or to you. It exists so we know which artists people actually pick, so we know which ones to keep. It is never joined to your sessions or your logs, and it is never sold or shared.

Permissions the app asks for

Somewhere does not use the camera, microphone, location, contacts, calendar, or health data, and does not request them.

Children

Somewhere is not directed to, and must not be used by, anyone under 18. If you believe a minor's photograph was submitted, write to us.

Your rights

Somewhere has no account tied to your identity. Each cloud session is controlled by a random credential stored on your device, and your installation is known to us only by the random identifier described above. You can delete a Developed session in the app to remove its local and cloud data. For access, deletion or privacy questions, write to us; include the session identifier, or your installation identifier, if you have it — without one of them we may be unable to locate a record that carries no name on it.

Changes

If this policy changes in a way that affects where your photographs go, the date at the top changes and the app will say so before the next time it sends one.

Contact

Write to support@somewherecamera.com.