PhotoShelf
Privacy Policy
Last updated: August 10, 2026
PhotoShelf is a local-first iOS gallery and bridge for your Apple Photos library and private remote shelves. This policy describes what the app accesses, where it keeps information, and what it does not send to Cognerva.
Photos access
PhotoShelf requests Photos access only when you choose to use the native library or a Photos import/export action. It uses PhotoKit to enumerate, preview, import, and export the assets you authorize. A remote file remains remote until PhotoKit confirms that an asset was created.
Remote sources and network access
When you configure a supported local-folder or WebDAV/HTTPS source, PhotoShelf connects directly to the host and path you provide. For FTP, FTPS, SFTP, SMB, or NFS, you configure the server in Files (or a compatible provider app) and select its mounted folder; the provider owns protocol credentials, discovery, TLS/SSH negotiation, and reconnect behavior. iOS may ask for Local Network access for a private-network source. Remote originals are not uploaded to a Cognerva service.
PhotoShelf can store source names, paths, file fingerprints, transfer state, and selected metadata locally so it can show cached catalogs and resume or explain work. You choose whether a source is read-only or permits an explicit write operation.
Credentials and local data
Source usernames and passwords for direct WebDAV connections are stored in the iOS Keychain. Files providers retain credentials for provider-backed protocols. PhotoShelf stores the selected security-scoped folder bookmark, source catalog, hashes, transfer state, and selected metadata locally. The app’s cache and sync journal stay on the device. PhotoShelf does not require a PhotoShelf account, advertising SDK, analytics SDK, or third-party tracking system.
Purchases
PhotoShelf Pro is an optional non-consumable purchase processed by Apple through StoreKit. Cognerva does not receive your payment card details. The app stores only the local entitlement state needed to provide the purchased feature.
Background work and deletion
Background sync is opt-in per source and is subject to iOS scheduling. The app records progress and failures in its local journal. Deleting the app removes its local cache, credentials, and journal; files on a remote source or in Apple Photos are not deleted by uninstalling PhotoShelf.
Your choices
- Grant, limit, or revoke Photos and Local Network access in iOS Settings.
- Remove a configured source and its stored credentials from PhotoShelf.
- Review or cancel transfer operations before an explicit write or import.
- Contact Cognerva about privacy questions or support.
Contact
Privacy questions can be sent to [email protected]. Support requests can be sent to [email protected].