Privacy

Your photos stay on your machine

Camera Shutter Count is a desktop app that reads photos. We do not want to know what is in your photos, and we engineered the app so we cannot.

Your photos stay on your disk. Your library lives in a local database on the same machine. We never see any of it, and we can't.

The short version

We collect as little as possible. Your photos and your library stay on your machine. The app does share a camera reading by default, with no name or email attached, so we can show you how your shutter count compares, and it switches off in Settings. We do not sell anything to anyone. This website carries no analytics scripts and no tracking cookies, only a session cookie that keeps you signed in.

What we collect when you buy

To sell you a licence we store your email address, your name, your country, and (if you fill them in for invoicing) your company name and VAT number. Stripe handles the payment; we never see your card. We do hold the Stripe customer ID and payment intent ID so we can reissue an invoice or process a refund.

When you sign in or check out from a new browser, we log the IP address and the browser user-agent of that attempt against the session. That is how we can show you a list of active sessions and let you sign out devices you do not recognise.

At signup we also record basic attribution: which page brought you in, which campaign, and your browser and OS. We use this to understand which channels send us customers. It is not shared with anyone else.

In the app, on your machine

Camera Shutter Count is a native app. Cameras, checks, parsed EXIF, lens history, settings and debug logs all live in a local SQLite database on your computer. We do not have access to any of it.

Your photos never leave the device. The EXIF parser runs locally in Rust; there is no cloud OCR and no third-party photo upload.

Your licence key, install UUID and install secret live in the app's own local database on your machine, not in the system keychain.

Licence activity

The app checks in with our API to revalidate the licence. The offline grace window is 365 days, so the call happens at least once a year and otherwise opportunistically whenever you are online. We see the install UUID, the app version, your operating system and the public IP of the call (from which we derive a country).

Each install also sends small lifecycle signals (launched, exited cleanly, dirty-exit detected, update observed) so we can spot crashes and watch update adoption. No photo data is ever attached.

Crash reports and product analytics

Crash reports are on by default. When the app hits a problem it sends a redacted report: stack frames, the OS, the app version, the last 20 in-app events. File paths, email addresses and your licence key are scrubbed before the report leaves your machine.

Product analytics are also on by default. These are usage counters (the tier you are on, your preferences, your display and locale, which features you have used) so we can see which parts of the app earn their keep.

Both are opt-out. Settings → Privacy turns either off independently.

Population stats (your camera make and model, its firmware, and its shutter count) travel on the same channel so we can show you how your body's wear compares against the rest. Your serial is sent only as a one-way hash, never the real number, and there's no name, email or location attached.

Cookies

This website sets a single session cookie to keep you signed in. That is it. No tracking cookies, no analytics scripts, no third-party tags. View source and there is nothing else there.

Third parties we use

Four external services touch your data in normal operation:

  • Stripe processes your payment. PCI-compliant; they see your card, we do not.
  • Postmark delivers transactional email: magic-link sign-ins, purchase confirmations, support replies.
  • Amazon S3 stores raw camera firmware dumps that people submit when their camera is not supported yet.
  • VIES is the EU's free public VAT-validation service, used at checkout if you provide an EU VAT number.

That is the complete list. No analytics SaaS, no error-tracking service, no ad networks, no remarketing pixels.

Your rights

Under UK and EU data protection law you can:

  • Export everything we hold about your account. Account → Privacy → Export streams a JSON file in your browser.
  • Request deletion. We delete what we can immediately. Invoice records are retained for six years (UK HMRC requirement); they are deleted at the end of that window.
  • Withdraw consent for any optional feature (crash reports, product analytics, population stats) at any time, in the app's Settings.

Questions?

Email us at support@camerashuttercount.com.

Last updated: May 2026