Privacy Policy

Scope of this policy

This privacy policy applies to the Imora iOS application and its share extension, referred to collectively as the app. Imora is a client application for Immich, a self-hosted photo and video management platform. The developer of Imora operates no backend infrastructure: the app is not connected to any proprietary cloud service or account system, and it integrates no third-party analytics, advertising or crash reporting frameworks.

Accordingly, this policy describes the data that remains on your device and the data exchanged with the server you configure.

Data collection

Imora does not collect personal data. The app transmits no usage statistics, device identifiers or diagnostic information to the developer or to any third party.

Authentication and credentials

During sign-in, the server address you provide and your credentials - either your email address and password, or an OAuth authorization if your instance is configured for OAuth - are transmitted exclusively to your own Immich server. Upon successful authentication, the server issues a session token, which Imora stores in the iOS Keychain, the encrypted credential store provided by the operating system. Your password is not retained by the app.

Photo library access

Imora requests photo library authorization in order to back up your library to your Immich server. Library contents are read solely for backup and upload purposes. Local copies of photos are deleted only upon your explicit request, and never as a side effect of browsing or backup operations.

Notifications

Notifications are generated locally on your device from events delivered over your server's realtime connection, such as album invitations, album activity and server alerts. No push notification service is involved, as Immich does not provide a push transport. Disabling notifications does not affect any other functionality.

Data stored on the device

  • A thumbnail cache, limited to 1 GiB, used to accelerate browsing. Its contents can be retrieved again from your server at any time.
  • Files shared into Imora, staged in a private application container until their upload to your server completes.
  • Your session token, held in the iOS Keychain.

Uninstalling the app removes all of the above.

Network connections and third parties

Photos, videos, search queries, album operations and all other application data are exchanged exclusively between your device and the Immich server you configure. The only additional network party is Apple: map views are rendered by Apple Maps, which retrieves map data subject to Apple's privacy policy.

Data processed by your server

Data residing on your Immich instance - including stored media, logs, machine learning artifacts and shared content - is governed by the operator of that server and by the Immich software. Refer to the Immich documentation for authoritative guidance, including backing up the server itself.

Changes to this policy

Should the app's behavior change in a way that affects this policy, this page will be revised and the date below updated accordingly. As the source code is publicly available, every statement in this policy can be verified against the code.

This policy is effective as of August 8, 2026.