Immount

Privacy policy

Last updated

Immount connects your Mac to the Immich server you choose. The app does not send your photos, API key or library data to me. It stores data on your Mac to make your library available in Finder. The website uses self-hosted analytics to understand how it is used.

About this policy

This policy covers immount.app and the official Immount macOS app. I am dan5py, the project's maintainer and the person responsible for the website and the information you choose to send me. In this policy, “I” and “me” refer to that role.

Your Immich server is operated by you or the provider you choose. Its handling of your account, photos and server logs is separate from this policy. You do not need an account with Immount to use the website or app.

Data on your Mac

Immount processes the information needed to browse and open your library:

  • Connection details. Your server addresses, Immich user ID and preferences are saved locally. Your API key is stored in the macOS Keychain and sent to your configured Immich server to authenticate requests.
  • Library information and files. The app caches folder listings and metadata, such as filenames, albums, people, tags, dates and file sizes. Finder requests thumbnails and downloads originals as needed. Downloaded originals are stored on your Mac through macOS File Provider.
  • Local statistics and diagnostics. The Statistics feature records download counts, transferred bytes and speeds on your Mac. You can turn it off in Settings; doing so keeps previously saved totals. The app also writes diagnostic messages to macOS logs. It does not include a service that sends usage analytics or crash reports to me.
  • Optional Wi-Fi detection. If you set up a local server address, the app can use your Wi-Fi network name to choose between local and remote connections. macOS requires Location Services permission to read this name. Immount does not request geographic coordinates; your selected network names are stored on your Mac.

In Settings, Clear Cache requests removal of downloaded originals. Files in use or kept downloaded may remain; this control does not clear library metadata or thumbnails. Forget Server removes the saved connection, its Keychain entry and its saved library listings and statistics. These actions do not delete photos from Immich or revoke the key on your server. Copies you save elsewhere and macOS-managed logs or caches may remain separately.

Connections and app updates

Library requests go to the Immich server addresses you configure. That server receives your API key and the connection information needed to answer those requests. Use an HTTPS address when you need the connection to be encrypted.

The app uses Sparkle to check for updates and download them from GitHub. GitHub and its download infrastructure receive your IP address and ordinary request information, including the app version. You can turn off automatic update checks in Settings under About. A manual check or download still contacts GitHub.

Website analytics

I use Umami, hosted on a Hetzner server in the EU, to measure visits, see which pages people use and improve the website. This analytics setup does not set analytics cookies or use advertising trackers.

Page-view records include:

  • the page URL and title, referring URL, and time of the visit
  • URL parameters and fragments, when present
  • browser, operating system, device type, screen size and language
  • approximate location, such as country, region or city, derived from the connection
  • generated identifiers used to group page views and estimate visits

Umami processes your IP address to derive location information and generate statistical identifiers using the website, browser information and a rotating salt. It does not store the raw IP address in its analytics records. I use the page-view and session records to produce usage reports. Hosting and security logs are separate and may contain IP addresses.

You can prevent these analytics requests with a browser content blocker that blocks umami.dan5py.com. The website remains usable without the analytics script.

Hosting and service providers

The website and analytics service run on servers I manage at Hetzner, with Cloudflare providing delivery and protection against abuse. Serving and protecting requests involves processing IP addresses, requested URLs, timestamps, browser information and security events. This information may appear in access or security logs.

Depending on the security checks applied, Cloudflare may use security cookies. The absence of Umami cookies does not mean that every service involved in delivering the website is cookie-free.

Source code, downloads and issue discussions are hosted on GitHub. Visiting those pages, downloading the app or checking for updates involves GitHub's services, covered by its privacy statement.

Cloudflare and GitHub operate internationally and may process information outside the European Economic Area. EU hosting of the analytics database does not mean all request data stays in the EU. Cloudflare describes its transfer safeguards in its data processing terms; GitHub describes its safeguards in its privacy statement.

I do not sell your personal information or use it for targeted advertising. Providers process information as needed to supply their services, as described above.

Information you choose to share

If you email me, open a GitHub issue or otherwise contact me, I receive the information you provide, such as your email address, username, message and attachments. I use it to answer your request and investigate problems. Public issues and comments can be read by anyone. Do not post API keys, private server addresses, personal photos or unredacted logs.

Purposes and legal basis

Where I process personal data to operate and secure the website, understand its use through basic audience statistics, or respond to requests, I rely on legitimate interests under Article 6(1)(f) GDPR. Those interests are maintaining a reliable website, preventing abuse and supporting and improving the project. You may object to processing based on legitimate interests.

I do not use this information for automated decisions that have legal or similarly significant effects on you.

How long information is kept

There is currently no fixed retention period for the self-hosted analytics records or the access and security logs I control. They may remain stored until deleted. This applies to the underlying records, not only to summary statistics. Service providers may retain their own operational records under their respective terms and policies.

Information on your Mac remains subject to the app's storage controls and macOS cache management described above. GitHub issues and comments may remain part of the public project history after an issue is closed.

Your rights and contact

Where the GDPR applies, you may request access, correction, deletion or restriction of your personal data, object to processing, and request data portability where applicable. I may be unable to associate analytics records with you. If so, I will explain that limitation; it does not automatically rule out a request.

For questions about this policy or to exercise your privacy rights, email [email protected]. Please include only the information needed to handle your request. Requests are normally answered within one month; if an extension is permitted and needed, I will explain why.

You may also complain to your local data protection authority, including the Garante per la protezione dei dati personali in Italy.

Changes

I will update this page and its date when this policy changes. You can inspect the app's source code and the policy's committed repository history.