Privacy Policy
Effective: August 9, 2026 · 日本語版
TAG Lens is a macOS app that tags, rates, and helps you review and delete photos in your Apple Photos library. It is built to work entirely on your Mac.
The short version
- 100% offline by default. No account or sign-in for tagging, no analytics, no tracking, no ads. The one exception: the optional one-time unlock purchase (and its restore) goes through the App Store with your Apple Account, like any Mac app purchase — Apple processes it, and TAG Lens never sees your account details.
- Your photos never leave your Mac on TAG Lens’s initiative. A photo file goes anywhere only by your own act: you drag, share, or export a copy — or you run Publish to Flickr, which uploads the photos you marked to your own Flickr account, only after a sheet you confirm per batch (it makes you choose who can see them and which license they carry; nothing is decided by your Flickr account’s defaults, and the names of your tagged people are withheld from the upload’s tags). The one optional feature that reads a photo’s pixels for analysis works only with a model running on your own Mac (see below) — pixels never go to a server for analysis, ever.
- All metadata you create (keywords, titles, captions) is written into your own Photos library. Ratings are stored locally on your Mac.
- The only network features are off by default and clearly labeled, and each one tells you exactly what it sends before you turn it on.
What TAG Lens stores, and where
- Keywords, titles, captions, favorites, albums, capture dates, locations — written directly into your Apple Photos library on your Mac, using the same fields Photos itself uses. They are yours, in your library, and remain there if you delete TAG Lens. If you use iCloud Photos, Photos syncs these edits to your other devices the same way it syncs any edit made in Photos itself — on iPhone and iPad, search finds your keywords, though iOS has no screen that displays them.
- Star ratings, progress, and app settings — stored in TAG Lens’s sandboxed app container on your Mac; TAG Lens never transmits them to a server. Two exceptions put ratings where you ask: on macOS 27 you can promote your stars into Photos’ own rating field (Library ▸ Promote Stars to Photos), after which Photos syncs them across your devices like any edit; and any JPEG you drag, share, or export carries its stars embedded as IPTC. Both are your action.
- Location data is never stored by the app itself. TAG Lens writes coordinates only into the photo’s own record in your Photos library, and only when you act: when you set or clear a location in the inspector, when you confirm a “place from photo text” suggestion (see below), when you approve photos in the reviewed bulk location-repair flow, or when you undo one of those changes and the prior location is restored. Every case is user-confirmed — never a third party, and never into TAG Lens’s own storage.
- People and faces (optional, off by default). If you turn on the People feature, TAG Lens detects faces and groups recurring people entirely on your Mac, storing the face groupings and any names you give them in the app’s own container. Nothing about a face or a name is ever sent anywhere — names you assign are also specifically blocked from every optional network lookup below. Turning the feature off deletes the face data from your Mac.
- Contacts you choose to link (optional). For a person you have already named, you can choose Link to Contact: TAG Lens then reads only that one contact — their name, nickname, and birthday, nothing else — and stores that copy (keeping only the month and day of the birthday, never the year) in the app’s own container to improve name suggestions. It never scans your address book, never reads any contact you didn’t pick, and never transmits any of it; contact nicknames are blocked from network lookups the same way people’s names are. Unlink severs the link, and the copied details never leave your Mac either way.
- API keys you supply for optional AI providers are stored in the macOS Keychain on this Mac only — never synced, never logged, never sent anywhere except to the provider you chose.
Optional network features (all off by default)
If you choose to enable them in Settings, each feature sends only what is listed here:
- Keyword suggestions (Wikidata / Grokipedia): sends the keyword term you typed (and only the term) to a public reference API — Wikidata, and/or Grokipedia (a keyless wiki lookup) — to find related terms. The term itself could contain personal information if you type it; nothing else is sent.
- AI keyword suggestions (a provider you choose): sends the keyword term — and only the term — to an AI service you select and, for the hosted ones, supply your own API key for: xAI, OpenAI, Anthropic, Mistral, Groq, or DeepSeek. You can instead point it at a model running locally on your Mac (e.g. Ollama on
localhost) or a custom endpoint URL you configure. TAG Lens has no key of its own and no server of its own; it never sends your photos to these services — only the typed term. Each hosted provider runs in its own operator’s region (DeepSeek’s endpoint, for example, is in China); the term you send is governed by that provider’s policy, and you choose the destination. - On-device photo analysis with a local model (loopback only): if — and only if — you configure the AI endpoint as a model running on your own Mac (a
localhost/127.0.0.1address), TAG Lens can send a small copy of the photo to that local model to suggest a caption. A strict check rejects any address that isn’t your own machine, so your photo’s pixels never reach an internet endpoint — they stay on your Mac. Hosted providers (above) never receive pixels, only text. - Place names: resolves a photo’s existing GPS coordinates to a place name (“Kyoto”) using Apple’s geocoding service. Off by default; when off, coordinates are never sent anywhere and are shown as raw numbers instead.
- Place from photo text: for a photo with no location, reads any place name on a sign in the photo (on your Mac) and sends only that recognized text — e.g. “Pine Ridge, South Dakota” — to Apple’s location search to find a coordinate to suggest. Off by default. Only the recognized place text is sent, only for the photo you’re viewing (never a library-wide sweep), and never the photo itself; text that looks like a street address, phone number, or email is filtered out and never sent. You confirm each suggestion before any location is written.
- Landmark guess: for a photo with no location, a model running on your own Mac can guess the place the photo shows; only that guessed name (never the photo) goes to Apple’s location search, and nothing is written until you press Use.
- Place search by name: when you type a place into Set Location (or a person’s residence), the words you type go to Apple’s location search — the same as typing in Maps. Only that text is sent.
- Recognized famous photographs: fetches one public catalog file listing famous works and their documented tags. Nothing about you or your library is in the request.
- Control photos (beta, opt-in): downloads the benchmark album’s public-domain images from the public archives the catalog lists — a download to your Mac; nothing about you is sent.
Disable any of these at any time; TAG Lens returns to fully offline operation. The complete network inventory, feature by feature, is kept current at What TAG Lens writes & sends.
Exports and publishes you create
These copy data out of the app only when you invoke them, to a destination you choose — this is your action, not collection by the app:
- Export Metadata as CSV writes a file you pick that by default includes each photo’s precise latitude/longitude. Turn on Strip location when sharing or exporting to blank those columns.
- Share / drag / export produces copies carrying your metadata; GPS is stripped when that same setting is on.
- Publish to Flickr uploads the photos you marked, as JPEGs with their titles, captions, and tags, to your own Flickr account over your own API key — only when you run the command and confirm its sheet, which requires an explicit visibility and license choice every batch. Your named people’s tags are withheld from the upload, and location goes only if you check its box. TAG Lens stores the resulting Flickr photo ids on your Mac so it can offer to match them up later; disconnecting your account deletes that map.
What TAG Lens never does
- Never uploads or shares your photos on its own — a photo leaves your Mac only by a drag, share, or export you perform, or a Publish to Flickr you confirm.
- Never collects analytics, telemetry, or crash reports of its own.
- Never sells your data, and never shares anything beyond what the optional lookups above send when you enable them — TAG Lens has no servers of its own to retain anything on.
- Never modifies your photo pixels. TAG Lens writes only metadata — the labels and descriptions attached to a photo, never the image itself.
Permissions
TAG Lens asks macOS for access to your Photos library (to read and write metadata) and for automation access to the Photos app (to write keywords, titles, and captions). If you use Link to Contact, it also asks for Contacts access — used only to read the single contact you pick, as described above. All of these are revocable at any time in System Settings ▸ Privacy & Security.
Contact
Questions: email wells01440@gmail.com.
Changes to this policy will be posted at this URL with an updated effective date.