Privacy Policy
Last updated: September 30, 2026
The short version
Sortido analyzes your photos on your iPhone. Your photos are never uploaded to us or to any server for analysis. Sortido has no accounts and no sign-in, and never asks for your name or email. It does record usage statistics — which screens are opened, how long an analysis takes, how many groups it found — plus a crash report if it crashes, to see what works and what doesn't. Those are grouped under a random code generated on your iPhone, so we can tell whether people come back without ever learning who they are. These statistics never include your photos or anything from inside them — only counts, like how many groups were found. Nothing is deleted until you review the list and iOS asks you to confirm.
Photo library access
Sortido asks for access to your photo library so it can do its job: finding similar photos, duplicates, and screenshots, and recommending which one to keep. You can grant full access or limited access to selected photos — Sortido works within whatever you allow, and you can change this at any time in iOS Settings.
Sortido also requests permission to add photos to your library. This is used only when you ask it to save something back — for example a still frame extracted from a Live Photo, a compressed video, or a PDF copy.
On-device processing
All photo analysis — comparing images, scoring quality, and grouping similar shots — runs locally on your device using Apple's on-device frameworks. The results are cached on your device so the app stays fast. Your image data is not sent to Sortido or to any external service for this analysis.
One feature reaches outside the device. Places groups your photos by where they were taken, and to turn a photo's stored coordinates into a place name it uses Apple's geocoding service — so those coordinates go to Apple, under Apple's privacy policy, not to Sortido. No photos are sent, and this uses location data already saved in your photos by the camera; Sortido never asks for location permission and never reads your device's current position.
Deletion is always your choice
Sortido never deletes photos automatically. When you choose to clean up, Sortido shows you the exact list of photos proposed for removal so you can review it. Deletion happens only after you confirm and iOS presents its own system confirmation. Removed photos go to your Recently Deleted album, where iOS keeps them recoverable for a period before permanent deletion.
Information we collect
Sortido has no account system, asks for no personal details, and sells nothing to anyone. Specifically:
- No account, email, or sign-in is required to use the app.
- Your photos and the analysis results stay on your device.
- App preferences and settings are stored locally on your device (via iOS), not on our servers.
- There are no third-party advertising SDKs in the app, and Sortido does not track you across apps or websites.
- Sortido does record usage statistics and crash reports about how the app itself is used, grouped under a random per-install code — described in full below.
Usage statistics
To understand which parts of Sortido are useful and where it is slow, the app sends a small set of events to PostHog, an analytics service. These are stored on PostHog's European servers. Sortido gives PostHog no name, email, or account — events are grouped only by a random identifier generated on your device, which points to nothing outside the app.
What is recorded: the names of screens you open and which features you use — for example opening a comparison, using zoom, compressing a video, or saving a PDF; when an analysis starts and finishes, and how long it took; how many similar groups, duplicates, and screenshots the analysis found; how many photos you selected for cleanup and how many you confirmed for deletion; a rough size band for your library (for example "2,000–10,000 photos" — never the exact number); whether you granted full access, limited access, or no access to your photos; the device model, iOS version, and app version your phone reports; and an approximate, city-level location worked out from your network connection (see below).
About your IP address and approximate location: as with any internet connection, making the request reveals your IP address to PostHog's servers. Sortido's project shortens it before it is stored — the last part is replaced with zero, so 12.214.31.144 becomes 12.214.31.0 — and the shortened address is used to work out an approximate location, roughly at city level, which is stored alongside your events. That tells us which regions Sortido is used in. It is an estimate from your network connection, not a position: Sortido never reads your device's GPS or Location Services, and never asks for location permission.
Crash reports: if Sortido crashes, it sends a report so the bug can be found and fixed. The report contains the type of crash and the technical trace of which parts of Sortido's own code were running — no photos, and no file names. Crash reports often carry a free-text error message; Sortido deletes that message on your device before the report is sent, because a message about a file could otherwise repeat text read from one of your documents.
What is never recorded: your photos or any part of them. No image data, no thumbnails, no filenames, no photo identifiers, and nothing computed from the contents of your pictures. The events are numbers and screen names only.
This is not advertising and not cross-app tracking: Sortido does not use the iOS advertising identifier, and does not share this data with advertisers or data brokers.
Your usage profile
So we can tell whether people come back to Sortido after the first week — and not just how many times the app was opened in total — the events described above are grouped into a profile. Because of that, Apple's privacy labels for Sortido mark this data as “linked to you”.
What the profile is keyed on: a random code generated on your iPhone the first time you open the app, for example 018f3c2a-…. It is not your Apple Account, your device's serial number, or the iOS advertising identifier. It is stored inside Sortido's own app container, which means deleting the app resets it — a reinstall looks like a brand-new person to us.
What Sortido puts on the profile — three facts:
- whether you granted full, limited, or no access to your photos;
- the rough size band of your library (for example “2,000–10,000 photos” — never the exact number);
- the app version you were on when the profile was created — for anyone who installed Sortido before this change, that is the version this change shipped in, not the one they first installed.
What PostHog adds to it: PostHog attaches some of what it already receives with your events to the profile as well — the approximate, city-level location worked out from your shortened IP address (described above), and the device model, iOS version and app version your phone reports, as first seen and as last seen. Sortido does not choose these individually; they come with keeping a profile at all.
It holds nothing from your photos, and no name, email, or account, because Sortido never asks for any.
It includes usage recorded since you installed the app. Events from before this policy was updated were collected under the earlier wording, which called them anonymous. They carry the same random code, so they now appear under the same profile. We are saying so here rather than leaving it implied.
About deletion requests: we cannot act on one, and it is worth being plain about why. Sortido holds nothing that identifies you — no name, no email, no account — so there is no way for us to match a request to a profile, and no way to verify that a profile is yours. What you can do is delete the app, which resets the code and ends the profile's connection to your phone for good.
Beta distribution (TestFlight)
During the beta, Sortido is distributed through Apple's TestFlight. If you install the app this way, Apple may collect standard installation and crash diagnostics as described in Apple's own privacy policy. This is handled by Apple, not by Sortido. If you send feedback through TestFlight, that feedback is shared with us so we can improve the app.
This website
sortido.app is served by Cloudflare, which processes your IP address and basic request details (such as the page requested and your browser type) to deliver the site and protect it from abuse. We rely on our legitimate interest in running a working, secure website (Art. 6(1)(f) GDPR). Cloudflare may process this data in the United States and other countries, under the EU–U.S. Data Privacy Framework and the EU's Standard Contractual Clauses; it keeps it only as long as its own privacy policy describes. We do not log or store your visit ourselves.
The site sets no cookies of its own and uses no analytics, advertising or tracking. Cloudflare may set a strictly necessary security cookie if it needs to check that a visitor is not an automated bot. The site's fonts are served from sortido.app itself, not from a third party.
Children
Sortido is not directed at children under 13 and does not knowingly collect information from them.
Changes to this policy
If this policy changes, we will update this page and revise the date above. Material changes will be reflected here before they take effect.
Contact
Sortido is run by Felix Muller, Australia, who is responsible for the processing described in this policy.
Questions about privacy? Email support@sortido.app.