Legal
Privacy Policy
Last updated August 23, 2026
Your privacy is critically important to us. At Twist Labs, we have a few fundamental principles:
- We are thoughtful about the personal information we ask you to provide and the personal information that we collect about you through the operation of our services.
- We store personal information for only as long as we have a reason to keep it.
- We build so that the information stays with you. Fotometis has no account, no backend, and nowhere for us to put your photographs even if we wanted to.
- We help protect you from overreaching government demands for your personal information.
- We aim for full transparency on how we gather, use, and share your personal information.
Below is our Privacy Policy, which incorporates and clarifies these principles.
Who We Are and What This Policy Covers
Twist Labs LLC (“Twist Labs,” “we,” “us,” “our”) makes Fotometis, a raw photo editor for macOS that you can talk to. This Privacy Policy applies to information that we collect about you when you use:
- Our website at fotometis.app, including its documentation; and
- The Fotometis application for macOS, distributed through the App Store.
Throughout this Privacy Policy we’ll refer to the website and the application collectively as “Services.”
The most important thing to know is what the Services are not. Fotometis is a local application. There is no Fotometis account, no sign-in, and no server of ours that your work passes through. We do not operate a backend, a sync service, or a cloud library. Your photographs, your edits, your .fmx sidecars, and your conversations with the assistant are files in the folders you opened on your own Mac. We have no copy of them and no way to obtain one.
Fotometis does connect to other companies at your direction — a model provider you choose, a host that serves model weights, and Apple, who delivers the app. Those companies have their own privacy policies, and this one does not cover them. The section on Where Your Data Goes explains exactly what reaches whom.
Creative Commons Sharealike License
We’ve decided to make this Privacy Policy available under a Creative Commons Sharealike license. It is adapted from the policy published by Automattic, available on GitHub. You’re more than welcome to copy it, adapt it, and repurpose it for your own use. Just make sure to revise the language so that your policy reflects your actual practices.
Information We Collect
We only collect information about you if we have a reason to do so — for example, to provide our Services, to communicate with you, or to make our Services better. There is not much of it.
Information You Provide to Us
- Communications with us. If you email us with a support question, a bug report, or feedback, we store a copy of that correspondence and whatever you chose to include in it — your email address, and any logs, screenshots, or files you attach. Please send us only what you are comfortable sharing.
- Community participation. We run a Discord community for help and support, at fotometis.app/discord. Joining it is optional; nothing in Fotometis requires it. If you participate, we see what you choose to share there — your Discord username and avatar, and the messages and files you post. The community is a shared space, so post only what you are comfortable with other members reading. Discord itself collects information about you under its own privacy policy, which this one does not cover.
That is the complete list. We do not ask you to create an account, and we never ask for payment information: if you buy Fotometis, Apple processes that transaction and we never see your card, your billing address, or your Apple Account.
Information We Collect Automatically
- Website log information. Like most websites, fotometis.app is served by a hosting provider that processes the information web browsers make available with each request — browser type, IP address, language preference, referring site, and the date and time of access. This is used to serve the site and to protect it from abuse.
- App usage and diagnostic information. We may collect anonymous information about how the application is used and how well it runs: which features are opened, which connector tier is selected, which controls are used, the frequency and shape of errors and crashes, and the application version, macOS version, and Mac model. This information is not associated with your name, your email address, or any identifier that would let us pick you out. We use it to understand which parts of the editor people actually reach for, and to find the bugs that reports never make it to us for. You can turn it off — see Choices.
Information We Never Collect
Because the boundary matters more than the list, here is the other side of it. Fotometis never sends us, and we never receive:
- Your photographs, or any part of them — not the raw file, not an export, not a preview, not a thumbnail, not a histogram. No image data reaches us in any form.
- What you type to the assistant. Your prompts and the conversations they produce are not sent to us, in whole or in part.
- Your edits. Parameter values, curves, masks, presets, ratings, flags, and the contents of your
.fmxsidecars stay on your Mac. - Anything about your files. File names, folder names, paths, volume names, capture dates, EXIF, and the size or contents of your library.
- Your provider credentials. API keys you enter are stored in the macOS Keychain and are sent only to the provider they belong to. Fotometis never holds them and we never see them.
- Your location, your contacts, your calendars, or anything else the editor has no reason to touch.
Information We Collect from Other Sources
- Apple. As the distributor of Fotometis, Apple gives us aggregate reports about downloads, sales, and App Store performance, and aggregate App Store analytics about how the app behaves in the field. If you have chosen to share crash and usage data with developers in your macOS settings, Apple also passes us crash reports. Apple decides what we receive and in what form; we receive it already aggregated or anonymized and cannot tie any of it back to you. What Apple itself collects is governed by Apple’s privacy policy, not by ours.
Where Your Data Goes When You Use Fotometis
Fotometis talks to a small number of other companies, always at your direction and never through us. None of these paths gives us a copy of anything.
- A model running on your Mac. When you use the on-device connector, the model runs locally. Your prompt and your photograph never leave the machine, and no network request is made to answer your question.
- Model weights. To run a model on your Mac, the application first has to download its weights. Today it fetches them from Hugging Face; we may use additional hosts in the future. That download is an ordinary file transfer: the host sees your IP address, which repository and files you asked for, and when. It carries no photograph, no prompt, and no information about your edits. Hugging Face’s handling of that request is governed by its own privacy policy.
- A model provider you connect. If you connect your own key for Anthropic, OpenAI, or OpenRouter, or point Fotometis at any other server you name, then each time you ask the assistant a question your prompt, the conversation so far, and a downscaled JPEG preview of the frame you are working on are sent to that provider. This is billed to your account with them, not through us. We do not route, proxy, intercept, or receive a copy of that traffic, and we do not control what the provider does with it — including whether they retain it or use it to train models. Please read the terms and privacy policy of any provider before you connect it. The application marks which connectors send data off your Mac and which do not.
- A model provided by Apple. Where Fotometis uses a model that Apple supplies with the operating system, whether it runs on your device or on Apple’s Private Cloud Compute, that request is handled by Apple under Apple’s privacy policy. It does not pass through us.
- Other applications on your Mac. Fotometis can act as an MCP server, so that a client you already use can drive the same controls on the photographs in the folders you have opened. That connection is local to your machine. What the client on the other end of it does with what it reads is between you and whoever makes it.
How and Why We Use Information
Purposes for Using Information
- To provide our Services. For example, to serve the website and its documentation, and to deliver application updates.
- To fix problems with our Services. For example, by using crash reports and error information to find, reproduce, and repair defects.
- To ensure quality and improve our Services. For example, by understanding in aggregate which features are used, so we know what to refine and what to retire.
- To communicate with you. For example, by answering a support question you sent us.
- To protect our Services, our users, and the public. For example, by detecting and protecting against malicious, deceptive, fraudulent, or illegal activity, and by complying with our legal obligations.
We do not run an advertising program, we do not build profiles of you, and we do not use your information to train machine learning models.
Legal Bases for Collecting and Using Information
A note here for those in the European Union about our legal grounds for processing information about you under EU data protection laws, which is that our use of your information is based on the grounds that:
(1) The use is necessary in order to fulfill our commitments to you under the applicable terms of service or other agreements with you — for example, in order to deliver the website to your device; or
(2) The use is necessary for compliance with a legal obligation; or
(3) The use is necessary in order to protect your vital interests or those of another person; or
(4) We have a legitimate interest in using your information — for example, to provide and update our Services; to improve our Services so that we can offer you an even better user experience; to safeguard our Services; and to communicate with you; or
(5) You have given us your consent.
Sharing Information
We share information about you in limited circumstances, and with appropriate safeguards on your privacy:
- Third-party vendors. We may share information with vendors who need it in order to provide their services to us — our website host and content delivery network, our email provider, and the tools that process crash and diagnostic reports. We require vendors to agree to privacy commitments in order to share information with them.
- Legal and regulatory requirements. We may disclose information about you in response to a subpoena, court order, or other governmental request. We will push back on demands that we consider overreaching, and we cannot hand over what we do not have — which, for your photographs, your prompts, and your edits, is all of it.
- To protect rights, property, and others. We may disclose information about you when we believe in good faith that disclosure is reasonably necessary to protect the property or rights of Twist Labs, third parties, or the public at large.
- Business transfers. In connection with any merger, sale of company assets, or acquisition of all or a portion of our business by another company, or in the unlikely event that Twist Labs goes out of business or enters bankruptcy, user information would likely be one of the assets that is transferred or acquired by a third party. If any of these events were to happen, this Privacy Policy would continue to apply to your information, and the party receiving your information may continue to use it, but only consistent with this Privacy Policy.
- With your consent. We may share and disclose information with your consent or at your direction.
- Aggregated or de-identified information. We may share information that has been aggregated or de-identified, so that it can no longer reasonably be used to identify you.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
How Long We Keep Information
We generally discard information about you when it’s no longer needed for the purposes for which we collect and use it, and we’re not legally required to keep it.
We keep web server logs for approximately 30 days, in order to analyze traffic to the site and to investigate issues if something goes wrong. Usage and diagnostic information from the application is retained in aggregate for no longer than we need it to understand trends and fix bugs. Support correspondence is kept for as long as we need it to help you, and for a reasonable period afterward as a record. Messages you post in the Discord community remain there until you delete them or ask us to remove them.
Security
While no online service is 100% secure, we work very hard to protect information about you against unauthorized access, use, alteration, or destruction, and take reasonable measures to do so.
The strongest protection here is structural rather than procedural: your photographs, edits, and conversations never leave your Mac, so there is no repository of them to breach. Provider credentials are held in the macOS Keychain rather than by the application. The website is served over HTTPS.
Choices
You have several choices available when it comes to information about you:
- Turn off usage and diagnostic reporting. You can disable the collection of anonymous usage and diagnostic information in the application’s settings, under Privacy. Crash reporting that reaches us through Apple is controlled separately, by the “Share with App Developers” setting in macOS under Privacy & Security › Analytics & Improvements.
- Keep everything on your Mac. If you use the on-device connector rather than a third-party provider, no photograph and no prompt leaves your machine at all. The application shows you which connectors send data off the Mac before you select one.
- Limit what the application can reach. macOS governs which folders and which parts of your photo library Fotometis can open. You can review and revoke that access at any time in System Settings › Privacy & Security.
- Browse without being tracked. fotometis.app sets no cookies, runs no third-party analytics, and carries no advertising or tracking pixels. The site remembers your light or dark theme preference in your browser’s local storage; that value never leaves your browser.
Your Rights
If you are located in certain parts of the world, including some US states and countries that fall under the scope of the European General Data Protection Regulation (aka the “GDPR”), you may have certain rights regarding your personal information, like the right to request access to or deletion of your data.
A practical note before the list: we hold very little, and what we do hold is either anonymous or, in the case of support email, filed under an address you gave us. We usually have no way to connect a request to records about you, because there are none to connect it to. That is the design, not an evasion — but it does mean a request may honestly come back empty.
European General Data Protection Regulation (GDPR)
If you are located in a country that falls under the scope of the GDPR, data protection laws give you certain rights with respect to your personal data, subject to any exemptions provided by the law, including the rights to:
- Request access to your personal data;
- Request correction or deletion of your personal data;
- Object to our use and processing of your personal data;
- Request that we limit our use and processing of your personal data; and
- Request portability of your personal data.
You also have the right to make a complaint to a government supervisory authority.
US Privacy Laws
Laws in some US states require us to provide residents with additional information about the categories of personal information we collect and share, where we get that personal information, and how and why we use it. You’ll find that information in this section (if you are a California resident, please note that this is the Notice at Collection we are required to provide you under California law).
In the last 12 months, we collected the following categories of personal information:
- Identifiers — your IP address when you visit our website, your email address if you write to us, and your Discord username if you join our community;
- Internet or other electronic network activity information — standard web request data, and anonymous information about how the application is used.
We do not collect commercial information, characteristics protected by law, precise geolocation data, biometric information, professional or employment information, education information, or the contents of your communications with others, and we do not draw inferences about you.
You can find more information about what we collect and where it comes from in the Information We Collect section above. We collect personal information for the business and commercial purposes described in How and Why We Use Information, share it with the categories of third parties described in Sharing Information, and retain it for the length of time described in How Long We Keep Information.
In some US states you have additional rights, subject to any exemptions provided by your state’s respective law, including the right to:
- Request a copy of the specific pieces of information we collect about you and, if you’re in California, to know the categories of personal information we collect, the categories of business or commercial purpose for collecting and using it, the categories of sources from which the information came, and the categories or list of third parties we share it with;
- Request deletion of personal information we collect or maintain;
- Request correction of personal information we collect or maintain;
- Opt out of the sale or sharing of personal information;
- Receive a copy of your information in a readily portable format; and
- Not receive discriminatory treatment for exercising your rights.
Right to opt out. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under US state privacy laws. There is accordingly nothing to opt out of. We also respect the Global Privacy Control browser signal. We do not knowingly collect or process sensitive personal information.
Contacting Us About These Rights
To exercise any of the rights above, see How to Reach Us below. When you contact us about one of your rights, we’ll need to verify that you are the right person before we disclose or delete anything — for example, by asking you to write from the email address the records are filed under. You can also designate an authorized agent to make a request on your behalf by giving us written authorization. We may still require you to verify your identity with us.
Appeals Process for Rights Requests Denials
In some circumstances we may deny your request to exercise one of these rights — for example, if we cannot verify your identity, or if we are legally required to maintain a copy of the information. In the event that we deny your request, we will communicate this to you in writing. You may appeal our decision by responding in writing to our denial and stating that you would like to appeal. In the event that your appeal is also denied, this will be communicated to you in writing.
If your appeal is denied, in some US states you may refer the denied appeal to the state attorney general if you believe the denial is in conflict with your legal rights. The process for how to do this will be communicated to you in writing at the same time we send you our decision about your appeal.
Controller
Twist Labs LLC, a United States company, is the controller responsible for processing the personal information described in this Privacy Policy, wherever in the world you use our Services.
How to Reach Us
If you have a question about this Privacy Policy, or you would like to contact us about any of the rights mentioned in the Your Rights section above, email us at privacy@fotometis.app.
Other Things You Should Know (Keep Reading!)
Transferring Information
Twist Labs is based in the United States, and the limited information described in this policy is processed there. If you use our Services from outside the United States, that information will be transferred to and processed in the United States. Where we transfer personal data out of the European Economic Area or the United Kingdom, we take appropriate measures to ensure it is protected in accordance with this Privacy Policy and applicable law, including entering into standard contractual clauses approved by the European Commission.
Third-Party Software and Services
Fotometis is designed to be pointed at services you choose — a model provider, a model host, an MCP client. Once you do, information you send through it is handled according to that third party’s privacy policy and practices, not ours. We don’t own or control these third parties, and they have their own rules about information collection, use, and sharing, which you should review before connecting them. See Where Your Data Goes for what is sent and when.
Children
Our Services are not directed to children under the age of 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will delete it.
Privacy Policy Changes
Although most changes are likely to be minor, Twist Labs may change this Privacy Policy from time to time. We encourage visitors to frequently check this page for any changes. If we make changes, we will revise the date at the top of this policy, and in some cases we may provide additional notice. Your further use of the Services after a change to this Privacy Policy will be subject to the updated policy.
That’s it! Thanks for reading.