1. Introduction
HUEO (the “App,” Chinese name “原画光年”) is an iOS, iPadOS, and macOS application developed by Robin (“we,” “us,” or “our”). It provides Log-video restoration and color processing, video-to-Live-Photo creation, and import of supported external-device media into Photos. This Privacy Policy explains how information is processed when you use the App.
2. Information processed on your device
The App may process the following information locally to provide features you request:
| Information | Purpose | Storage |
|---|---|---|
| Videos and audio you select | Import, compatibility inspection, preview, Log restoration, color processing, export, and video-to-Live-Photo creation | Managed working copies, temporary render files, and user-chosen exports |
| Media metadata | Interpret color, camera or Log identity, timing, orientation, and audio; read available capture time and embedded location for supported import and output workflows | Local workspace and recovery records where needed |
| External-device photos, videos, Live Photo resources, and thumbnails | Browse the directory you authorize, preview supported items, and import the items you choose into Photos | Source files remain on the device; thumbnails and preparation copies are cached locally |
| External-device access and import records | Restore authorized access, identify previously imported items, and recover interrupted imports | Local access bookmarks, device/content fingerprints, and import-recovery records |
| App-album and saved-media identifiers | Find or create the app album and add newly saved media to it | For album organization, one album identifier in local App settings and a bounded in-memory queue of saved-media identifiers |
| Local diagnostics | Investigate interruptions and performance problems | Redacted stage records, session markers, and filtered Apple MetricKit reports; see section 4 |
| User LUTs, presets, and editing recipes | Apply and restore your selected looks and processing configuration | Local application storage |
| Workspace and recovery state | Resume the current task, recover interrupted exports, and keep local libraries consistent | Local SQLite database and Application Support files |
| Export allowance events | Maintain the 30-successful-export free allowance and reconcile it across your Apple devices when the system permits | Apple Keychain, with limited records described below |
| StoreKit purchase evidence | Display products, purchase or restore Pro, and determine subscription or Lifetime Pro access | Verified StoreKit state and minimal local purchase-recovery state |
3. Photos and Files access
Photos
You choose videos through Apple's system photo picker. To preserve original media quality and metadata, the App may request Photo Library read/write permission and use the identifier of the item you selected to resolve its original video resource through Apple's Photos framework. The video-to-Live-Photo picker also uses Photos read access to display the videos, thumbnails, duration, dimensions, and capture dates available within your authorization. With limited access, only the items permitted by the system are available. Original video resources are imported for processing after you select them; the App does not upload your library to us.
When browsing or selecting media stored in iCloud Photos, Apple may download thumbnails or the selected original resource to your device. That transfer is provided by Apple and is governed by your Apple account, device settings, and Apple's privacy terms.
Saving an exported video, a generated Live Photo, or selected external-device media requests Photos add permission. External-device import does not request full-library read access for duplicate checking. Video-to-Live-Photo recovery may check a previously created item if full read access was already granted.
App Album
In App versions that include App Album, newly saved external-device imports, generated Live Photos, and color-processing exports to Photos are automatically added to an app album when Full Photos Access is already granted. The album is created when needed, using “HUEO” or “原画光年” according to the App language, or an existing editable app album is reused. Organization adds existing Photos items to an album; it does not create another media copy or change their capture metadata.
This feature needs full Photo Library read/write access, not permission limited to the app album. With add-only or limited access, organization is skipped. You can still save to Photos if adding permission remains allowed. This organization feature does not request full access during launch or media saving. You can request it through Settings > App Album > Allow Automatic Organization; if access is limited or denied, the page directs you to system Settings.
The organizer looks up the cached album or the two app-name album titles and the identifiers of the newly saved items. It does not scan other media files or automatically add past saves, editor source media, or files-only exports. Album names and album or saved-media identifiers are not sent to us or included in App diagnostic packages. Apple's own Photos and iCloud services remain subject to your system settings.
Files
You may select videos and LUTs through Apple's system Files picker. The App accesses the selected items within the access granted by the operating system.
External devices and capture metadata
For Import to Photos, you authorize a device or directory through the system directory picker. The App searches for supported photos, videos, and Live Photo resources within that directory and its permitted subdirectories. It does not search outside that scope or modify, move, rename, or delete the source files. Only the items you select and start importing are added to Photos.
Available capture time, embedded location, and other media metadata may be read locally and retained in supported imported or generated media. This reads existing media metadata; the App does not request the device's current location or record GPS tracks. It cannot reconstruct information missing from the source. Review media metadata before sharing an output that may contain capture time or location.
4. Local storage and retention
- Working copies: imported media is copied into App-managed storage so the selected source can remain unchanged. Working copies may remain while the current task is active or recoverable.
- Temporary files: previews, candidate renders, and delivery files are stored temporarily and removed after success, failure, cancellation, or recovery cleanup, subject to normal operating-system behavior.
- Presets and LUTs: user-created presets and imported LUTs remain until you delete them or remove the App's local data.
- Workspace data: completing or replacing a session removes related managed work files when they are no longer needed. Uninstalling the App removes its local container, subject to Apple's platform behavior.
- External-device import: authorization bookmarks, local import fingerprints, and recovery records remain in App storage to support reconnection and interrupted imports. Thumbnail disk caching has a 200 MiB limit. Temporary import copies, extracted Live Photo resources, and preview clips are cleaned up after completion, failure, cancellation, or a later launch.
- App album: one device-local album identifier is cached in App settings to support reuse, including after you rename the album. This cache is not stored in Keychain, a shared App group, or an App-managed iCloud settings store. Pending organization uses only a bounded in-memory queue; it is not kept as a durable list for automatic backfilling after the App quits. Existing import/export recovery records keep their own identifiers where needed. Reinstalling the App or losing this cache can make a renamed album unrecognizable, so another app album may be created. Album creation on multiple devices and Apple's synchronization may also result in more than one app album; the App does not merge or delete albums.
- Saved results: delivered videos, photos, and Live Photos remain in Photos or your chosen destination until you delete them. If iCloud Photos is enabled, Apple may synchronize items saved to Photos under your system settings.
Local diagnostics and optional sharing
The App keeps a bounded local record of processing stages, session and incident times, random session identifiers, hashed item tokens, resource pressure, counts, and error codes. Apple MetricKit reports are filtered before storage to retain numeric performance and crash information plus App/build, operating-system, architecture, and binary details needed for troubleshooting. Other free text is removed.
Diagnostic records and packages exclude media, thumbnails, user media filenames and paths, capture times, locations, camera/lens strings, Photos identifiers, and access bookmarks. Import-recovery information included in a package is reduced to batch phases, state/error counts, and recovery-status information.
Incident cleanup applies limits of 20 records, 30 days, and 50 MiB. Diagnostic storage is excluded from system backup. Diagnostics are not automatically uploaded. In Settings > Diagnostics, you can prepare a ZIP and then choose whether to share or save it using the system share sheet. Temporary diagnostic ZIPs older than 24 hours are cleaned up when the App starts or you prepare another package; the system may remove temporary files earlier.
Delete Local Diagnostics removes the App's local diagnostic records and temporary packages without deleting media or import history/recovery records. Copies you have already saved or sent outside the App must be managed separately. If you contact support, we receive the contact details, message, and attachments you choose to send and use them to respond and investigate the issue.
5. Free-export allowance and iCloud Keychain
Free users currently receive 30 successful full-quality exports. To record delivered exports, the App stores a minimal, append-only event in the system Keychain. Each event contains a random export-job identifier, policy/schema information, an App-family identifier, and commit time. It does not contain the filename, file path, Photos asset identifier, video metadata, camera profile, LUT, editing recipe, or media content.
If iCloud Keychain is enabled, Apple may eventually synchronize these Keychain items among your eligible iPhone, iPad, and Mac devices signed in to the same Apple account. The App does not actively contact an account or quota server, cannot read your Apple ID, and cannot force or guarantee when Apple completes synchronization. Devices can therefore show temporarily different remaining counts while offline or before Keychain convergence. Reinstalling the App does not guarantee that the allowance resets.
6. Purchases and subscriptions
Purchases are provided by Apple StoreKit. Apple processes payment credentials, billing, storefront pricing, taxes, subscription management, refunds, and purchase history under Apple's terms and privacy policy. The App receives verified product and entitlement information needed to display products and grant Pro access. We do not receive your card number or Apple account password.
7. Information we do not collect
- No developer-operated user account or registration.
- No advertising SDK, advertising identifier, or cross-app tracking.
- No developer-operated analytics or crash-reporting service.
- No automatic upload of media, LUTs, presets, editing recipes, or diagnostics to us; support sharing is your choice.
- No sale, rental, or trade of personal information.
8. Apple services and third parties
The App relies on operating-system services including App Store/StoreKit, Photos, Files, iCloud Photos when applicable, and iCloud Keychain when enabled. Apple may process information necessary to provide those services under Apple's own policies. We do not operate an independent backend that receives that information.
More Imaging Tools in Settings displays a bundled list of apps by the same developer. It does not detect installed apps, record views or clicks, or use your media or location to choose recommendations. An App Store link opens only when you tap it and contains no user, device, media, location, or attribution identifier. Downloads and purchases for those apps are separate.
Opening support, legal, or App Store links uses your browser or Apple's services. Contacting support or sharing a diagnostic package uses the mail or sharing service you choose; that service handles the information you send under its own policies.
The support and legal pages are hosted on GitHub Pages. Visiting them sends ordinary web requests to GitHub, which may process connection information such as your IP address and browser details under the GitHub Privacy Statement. These pages contain no developer-added analytics or advertising scripts. Their language selector uses the browser language or the language choice in the page URL; visiting them does not upload your App media or album records.
9. Your controls
- You choose which videos, files, LUTs, and external-device directories the App may access, and control the Photos access available to its video picker.
- You can change Photos permission in system Settings, although original-quality import may stop working without the required access.
- You can review album-organization permission and the recent status in Settings > App Album. You can rename or remove albums and manage their items in Photos. Removing an app album does not disable organization: a later eligible save may create it again. Removing the App does not remove albums or media already saved to Photos.
- You can remove current tasks, presets, LUTs, and exported files using available App or system controls.
- You can uninstall the App to remove its local container. Keychain records and files already exported outside the container may remain under Apple's platform behavior and your own storage choices.
- You can prepare, share, or delete local diagnostics in Settings > Diagnostics. Preparing a package does not send it to us.
- You can manage subscriptions and purchases through your Apple account and the App Store.
10. Security
The App uses Apple's sandbox, system permission controls, StoreKit verification, and Keychain protection. No method of storage is completely secure, so you should keep important source media backed up and protect access to your devices and Apple account.
11. Children's privacy
The App is not directed to children under 13 and does not require a developer-operated account. We do not knowingly collect children's personal information through a developer-operated service.
12. Changes to this policy
We may update this policy when the App's features, data practices, or legal requirements change. Revisions are posted here with a last-updated date and take effect when published, unless a later effective date is stated. Descriptions of a feature apply to App versions that include it. Where applicable law requires notice or consent for a change, we will provide it.
13. Contact
For questions about this Privacy Policy, contact: