Last updated: October 2, 2026 · Effective date: when this revision is published.

1. Introduction

HUEO (the “App,” Chinese name “原画光年”) is an iOS, iPadOS, and macOS application developed by Robin (“we,” “us,” or “our”). It provides Log-video restoration and color processing, video-to-Live-Photo creation, and import of supported external-device media into Photos. This Privacy Policy explains how information is processed when you use the App.

Privacy summary: the App is local-first. We do not operate an account, media, analytics, or quota server. The App does not automatically send us your media, LUTs, editing recipes, or diagnostics. We do not receive payment credentials. You decide whether to share a diagnostic package or other information when contacting support.

2. Information processed on your device

The App may process the following information locally to provide features you request:

InformationPurposeStorage
Videos and audio you selectImport, compatibility inspection, preview, Log restoration, color processing, export, and video-to-Live-Photo creationManaged working copies, temporary render files, and user-chosen exports
Media metadataInterpret color, camera or Log identity, timing, orientation, and audio; read available capture time and embedded location for supported import and output workflowsLocal workspace and recovery records where needed
External-device photos, videos, Live Photo resources, and thumbnailsBrowse the directory you authorize, preview supported items, and import the items you choose into PhotosSource files remain on the device; thumbnails and preparation copies are cached locally
External-device access and import recordsRestore authorized access, identify previously imported items, and recover interrupted importsLocal access bookmarks, device/content fingerprints, and import-recovery records
App-album and saved-media identifiersFind or create the app album and add newly saved media to itFor album organization, one album identifier in local App settings and a bounded in-memory queue of saved-media identifiers
Local diagnosticsInvestigate interruptions and performance problemsRedacted stage records, session markers, and filtered Apple MetricKit reports; see section 4
User LUTs, presets, and editing recipesApply and restore your selected looks and processing configurationLocal application storage
Workspace and recovery stateResume the current task, recover interrupted exports, and keep local libraries consistentLocal SQLite database and Application Support files
Export allowance eventsMaintain the 30-successful-export free allowance and reconcile it across your Apple devices when the system permitsApple Keychain, with limited records described below
StoreKit purchase evidenceDisplay products, purchase or restore Pro, and determine subscription or Lifetime Pro accessVerified StoreKit state and minimal local purchase-recovery state

3. Photos and Files access

Photos

You choose videos through Apple's system photo picker. To preserve original media quality and metadata, the App may request Photo Library read/write permission and use the identifier of the item you selected to resolve its original video resource through Apple's Photos framework. The video-to-Live-Photo picker also uses Photos read access to display the videos, thumbnails, duration, dimensions, and capture dates available within your authorization. With limited access, only the items permitted by the system are available. Original video resources are imported for processing after you select them; the App does not upload your library to us.

When browsing or selecting media stored in iCloud Photos, Apple may download thumbnails or the selected original resource to your device. That transfer is provided by Apple and is governed by your Apple account, device settings, and Apple's privacy terms.

Saving an exported video, a generated Live Photo, or selected external-device media requests Photos add permission. External-device import does not request full-library read access for duplicate checking. Video-to-Live-Photo recovery may check a previously created item if full read access was already granted.

App Album

In App versions that include App Album, newly saved external-device imports, generated Live Photos, and color-processing exports to Photos are automatically added to an app album when Full Photos Access is already granted. The album is created when needed, using “HUEO” or “原画光年” according to the App language, or an existing editable app album is reused. Organization adds existing Photos items to an album; it does not create another media copy or change their capture metadata.

This feature needs full Photo Library read/write access, not permission limited to the app album. With add-only or limited access, organization is skipped. You can still save to Photos if adding permission remains allowed. This organization feature does not request full access during launch or media saving. You can request it through Settings > App Album > Allow Automatic Organization; if access is limited or denied, the page directs you to system Settings.

The organizer looks up the cached album or the two app-name album titles and the identifiers of the newly saved items. It does not scan other media files or automatically add past saves, editor source media, or files-only exports. Album names and album or saved-media identifiers are not sent to us or included in App diagnostic packages. Apple's own Photos and iCloud services remain subject to your system settings.

Files

You may select videos and LUTs through Apple's system Files picker. The App accesses the selected items within the access granted by the operating system.

External devices and capture metadata

For Import to Photos, you authorize a device or directory through the system directory picker. The App searches for supported photos, videos, and Live Photo resources within that directory and its permitted subdirectories. It does not search outside that scope or modify, move, rename, or delete the source files. Only the items you select and start importing are added to Photos.

Available capture time, embedded location, and other media metadata may be read locally and retained in supported imported or generated media. This reads existing media metadata; the App does not request the device's current location or record GPS tracks. It cannot reconstruct information missing from the source. Review media metadata before sharing an output that may contain capture time or location.

4. Local storage and retention

Local diagnostics and optional sharing

The App keeps a bounded local record of processing stages, session and incident times, random session identifiers, hashed item tokens, resource pressure, counts, and error codes. Apple MetricKit reports are filtered before storage to retain numeric performance and crash information plus App/build, operating-system, architecture, and binary details needed for troubleshooting. Other free text is removed.

Diagnostic records and packages exclude media, thumbnails, user media filenames and paths, capture times, locations, camera/lens strings, Photos identifiers, and access bookmarks. Import-recovery information included in a package is reduced to batch phases, state/error counts, and recovery-status information.

Incident cleanup applies limits of 20 records, 30 days, and 50 MiB. Diagnostic storage is excluded from system backup. Diagnostics are not automatically uploaded. In Settings > Diagnostics, you can prepare a ZIP and then choose whether to share or save it using the system share sheet. Temporary diagnostic ZIPs older than 24 hours are cleaned up when the App starts or you prepare another package; the system may remove temporary files earlier.

Delete Local Diagnostics removes the App's local diagnostic records and temporary packages without deleting media or import history/recovery records. Copies you have already saved or sent outside the App must be managed separately. If you contact support, we receive the contact details, message, and attachments you choose to send and use them to respond and investigate the issue.

5. Free-export allowance and iCloud Keychain

Free users currently receive 30 successful full-quality exports. To record delivered exports, the App stores a minimal, append-only event in the system Keychain. Each event contains a random export-job identifier, policy/schema information, an App-family identifier, and commit time. It does not contain the filename, file path, Photos asset identifier, video metadata, camera profile, LUT, editing recipe, or media content.

If iCloud Keychain is enabled, Apple may eventually synchronize these Keychain items among your eligible iPhone, iPad, and Mac devices signed in to the same Apple account. The App does not actively contact an account or quota server, cannot read your Apple ID, and cannot force or guarantee when Apple completes synchronization. Devices can therefore show temporarily different remaining counts while offline or before Keychain convergence. Reinstalling the App does not guarantee that the allowance resets.

6. Purchases and subscriptions

Purchases are provided by Apple StoreKit. Apple processes payment credentials, billing, storefront pricing, taxes, subscription management, refunds, and purchase history under Apple's terms and privacy policy. The App receives verified product and entitlement information needed to display products and grant Pro access. We do not receive your card number or Apple account password.

7. Information we do not collect

8. Apple services and third parties

The App relies on operating-system services including App Store/StoreKit, Photos, Files, iCloud Photos when applicable, and iCloud Keychain when enabled. Apple may process information necessary to provide those services under Apple's own policies. We do not operate an independent backend that receives that information.

More Imaging Tools in Settings displays a bundled list of apps by the same developer. It does not detect installed apps, record views or clicks, or use your media or location to choose recommendations. An App Store link opens only when you tap it and contains no user, device, media, location, or attribution identifier. Downloads and purchases for those apps are separate.

Opening support, legal, or App Store links uses your browser or Apple's services. Contacting support or sharing a diagnostic package uses the mail or sharing service you choose; that service handles the information you send under its own policies.

The support and legal pages are hosted on GitHub Pages. Visiting them sends ordinary web requests to GitHub, which may process connection information such as your IP address and browser details under the GitHub Privacy Statement. These pages contain no developer-added analytics or advertising scripts. Their language selector uses the browser language or the language choice in the page URL; visiting them does not upload your App media or album records.

9. Your controls

10. Security

The App uses Apple's sandbox, system permission controls, StoreKit verification, and Keychain protection. No method of storage is completely secure, so you should keep important source media backed up and protect access to your devices and Apple account.

11. Children's privacy

The App is not directed to children under 13 and does not require a developer-operated account. We do not knowingly collect children's personal information through a developer-operated service.

12. Changes to this policy

We may update this policy when the App's features, data practices, or legal requirements change. Revisions are posted here with a last-updated date and take effect when published, unless a later effective date is stated. Descriptions of a feature apply to App versions that include it. Where applicable law requires notice or consent for a change, we will provide it.

13. Contact

For questions about this Privacy Policy, contact: