Skip to content
FFoverix
WorkflowFeaturesPricingFAQJoin the launch

Privacy

Privacy policy

How Foverix handles website visits, support messages, purchases, and the processing modes you choose in the app.

Last updated: 1 September 2026 · Effective: 1 September 2026

ControllerWebsiteProductProvidersYour rights

1. Controller and contact

The controller responsible for Foverix is Mohammadamin Ghalebi, a sole proprietor trading as Foverix; the full provider identification and serviceable address are published in the Impressum. Questions about this policy can be sent to support@foverix.com.

2. The Foverix website

Hostinger serves the static Foverix website. No non-essential analytics or cookies are used at version 1. The site has no advertising pixels, third-party fonts, contact forms, or marketing trackers.

Technical hosting data

Hostinger may process standard server and security logs when a page is requested, such as IP address, timestamp, requested URL, browser or device information, referrer, response status, and diagnostic data. These hosting logs are used to deliver, secure, and troubleshoot the website and are retained under the verified production settings disclosed before launch.

Email support and license delivery

If you contact support, Foverix processes the email address, message content, attachments, and related correspondence needed to answer the request, operate the service, or document a transaction. Resend sends license-fulfillment and recovery email from the verified Foverix sending domain. The service does not ask Resend to track opens or clicks: its send request carries only the sender, recipient, subject, and message body, and only the provider message id is stored. Open and click tracking are additionally switched off in the Resend account itself. Do not send passwords, API keys, or unnecessary sensitive information.

3. Processing inside the Foverix app

Foverix is local-first: original photos, the local catalog, local processing results, and Keychain credentials are not uploaded merely because you use the app. Beyond the four exceptions set out in this section — location lookup, model downloads, license checks, and manual update checks — the data flow changes only when you choose a cloud mode or an external destination.

Local processing

For supported local features, photo and metadata processing takes place on your Mac. Files can still be written to locations you select, and ordinary macOS backup or sync services may process them according to your own settings.

Location lookup (GPS)

Photos often carry GPS coordinates in their EXIF data. Foverix can look those coordinates up to fill in city, country, and nearby-landmark context for titles, descriptions, and keywords. Location lookup is switched off by default. While it is off, the coordinates are read on your Mac only, no location service is contacted, and the place and landmark fields stay empty.

When you switch location lookup on, the exact coordinates of each geotagged photo in the batch are sent to two OpenStreetMap services: nominatim.openstreetmap.org for reverse geocoding, operated by the OpenStreetMap Foundation, and overpass-api.de for nearby-landmark queries. The coordinates are transmitted at full precision; the copies Foverix stores and logs are rounded to four decimal places, roughly 11 metres. Those services receive coordinates only — never the photograph, the filename, or an account identifier. If you do not want any coordinate to leave your Mac, leave the setting off or remove GPS data from the files before importing them.

Model downloads and update checks

The installer deliberately does not ship the large image-recognition model. The first batch that needs it downloads roughly 2.8 GB once from huggingface.co into the app’s support folder, verified against a pinned size and checksum, and reuses it afterwards. This download is enabled by default. If an object-detection model is not already present on your Mac, further model weights are fetched from download.pytorch.org on first use.

If you accept the guided setup for a third-party local-model runner, Foverix downloads that vendor’s macOS installer from the vendor’s own site, installs it, and then asks the locally installed runner to fetch the caption model from its own registry. The runner is separate software under its own terms; Foverix does not redistribute it or its models.

Automatic update checks are off in version 1.0. A manual update check requests the signed update feed from Foverix.com. Separately, license and trial checks contact api.foverix.com with a device identifier derived from the Mac; see section 4.

Bring your own key

If you bring your own key for a supported AI provider, Foverix sends the inputs needed for the selected operation directly to that provider. Your relationship, account settings, retention choices, and the provider's own terms and privacy policy apply.

When location lookup has produced place context and you then use a cloud caption engine, a reduced form of that context travels in the prompt. Every cloud engine — a bring-your-own-key provider, a cloud caption service, the Claude subscription engine, and Managed AI — receives at most the city and the country. Coordinates, the resolved street address, the region, the country code, and the landmark records stay on your Mac. An engine that runs on your Mac receives the full local context, because nothing leaves the machine.

Managed AI (Zero Data Retention)

When you explicitly choose Managed AI, the image and prompt required for that request travel transiently through the Foverix service on Cloudflare, then OpenRouter, then the selected Zero Data Retention AI provider. That provider is Anthropic, whose Claude model the service is configured to use, served through a Zero Data Retention host (currently Amazon Bedrock); an emergency switch that only the operator can set routes to Google’s Gemini model instead. You cannot choose the model or the provider, and the service never fails over from one to the other by itself. The route requests zero-data-retention processing and does not log prompt, image, or response content. Technical request identifiers, usage counts, safe error codes, and credit-ledger records may be retained to operate and secure the service. This path consumes managed-AI credits.

Foverix does not claim that photos always remain on your Mac: that statement applies only to operations completed entirely through a supported local path.

4. Purchases and service providers

Cloudflare and D1

Cloudflare hosts the licensing and Managed AI service. Its D1 database stores the minimum customer, license, device-activation, trial, transaction, delivery-outbox, checkout-binding, credit-ledger, rate-limit, and privacy-operation records needed to run those services. The email address is held in one place only, the license record. Trial records are keyed by the device identifier the app sends when it asks for or renews a trial. Photos and the local catalog are not stored in D1.

Paddle

Paddle acts as Merchant of Record. Paddle collects and processes purchase, payment, tax, fraud-prevention, billing, and transaction data under its own notices. Foverix receives transaction and license information needed to provide access, support purchases, and reconcile refunds; Foverix does not receive full card details.

Encrypted backups

Validated D1 exports are encrypted before upload to a separate AWS account in the Frankfurt region. Backups are access-restricted and retained under the launch schedule: at least 35 successful daily and 12 successful monthly copies, with monthly deletion protection up to 367 days. An erased email address can therefore remain in restricted encrypted backups until every containing backup expires; deletion tombstones are reapplied before a restored database may serve customers.

International transfers

Relevant international transfers may occur because Cloudflare, Paddle, Resend, Hostinger, OpenRouter, the selected AI provider (Anthropic and its host Amazon, or Google if the operator switch is set), and AWS may process data in or make it accessible from countries outside Germany or the European Economic Area. Where a provider processes data outside the European Economic Area, the transfer rests on that provider’s EU Standard Contractual Clauses or on an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified), as set out in the provider’s data-processing terms; each provider’s role is described in the sections above.

5. Retention and security

Operational defaults are 90 days for completed delivery-outbox records, seven days after use or expiry for checkout sessions with URLs cleared immediately, 24 hours for rate-limit buckets, 400 days for webhook and reconciliation records, and 30 days for bounded local app logs, which are written only to your own Mac.

Two of those rate-limit counters — the one that limits how many new trials an address may start, and the one that limits new trial credit accounts — keep the raw IP address of the request inside the counter key for up to 24 hours. The license-recovery counters keep a keyed hash of the address and of the email instead of the values themselves. No other request log in the licensing service stores an IP address.

Some records are deliberately outside that cleanup schedule and are kept for as long as the service runs: license records, device activations, trial records, managed-AI credit-ledger balances, and Paddle transaction records. They are what proves an entitlement, keeps a purchased balance payable, prevents a second trial per device, and supports accounting and refund reconciliation. Transaction and tax records are kept for the period confirmed by the German accountant or counsel; purchased balances and lifetime entitlements remain while the service obligation continues. Foverix uses technical and organizational safeguards appropriate to the service, but no networked system can promise absolute security.

6. Your rights

Depending on applicable law, you may have rights to access, correct, erase, restrict, object to, or obtain a copy of personal data, and to withdraw consent where processing relies on consent. You may also complain to a competent data-protection authority. Requests can be sent to support@foverix.com; identity verification may be required.

What an erasure actually removes

An erasure request replaces the email address in your license record with a non-routing pseudonym derived from a keyed hash of the address, cancels any license email still waiting to be sent, and records a deletion marker so the same address is re-erased if a database is ever restored from backup.

It does not delete the records listed as outside the cleanup schedule in section 5. The license record itself, the device identifiers activated against it, the trial record for a device, the managed-AI credit ledger, and the Paddle transaction rows remain, because they carry the entitlement, the statutory accounting trail, and the per-device trial limit. After the erasure those rows no longer contain your email address. Where the law requires deletion rather than retention, tell support so in the request.

7. Changes

This policy may be updated when the service, providers, or legal requirements change. The current version and its update date will be posted on this page.

FFoverix

Native Mac workflow for stock photographers — from RAW batch to agency-ready package.

FeaturesPricingHelpRelease notesPrivacyTermsRefundsImpressum
© 2026 FoverixLaunching soonsupport@foverix.com