Privacy Policy
Last updated: August 2, 2026
Your privacy matters. Photo Date Rescue is built to keep your photos and videos in your hands: the desktop app processes your library locally on your own computer. We collect only what is necessary to sell, license and support the software, and we keep marketing strictly separate from the emails we send to complete a purchase.
1. What Data We Collect
- Email address and order details — plan, date, amount — collected through the Lemon Squeezy checkout when you buy a license.
- License activation data, such as a device identifier and operating-system type, used to activate and validate your license.
- Support correspondence you send to us (for example, emails to our support address).
We do not collect, upload or store your photo and video library. In the desktop app, your media is analyzed locally on your computer and is never uploaded to us.
2. Web Demo Uploads
If you use the optional web demo, only the files you explicitly choose are uploaded, and they are handled as temporary working copies used solely to produce your result. They are not added to any library, and your original files on your device are never altered by the demo. We do not build a media library from web-demo uploads or use them for marketing.
How long we keep them: until your result is delivered, and no longer. Each demo run works inside its own temporary folder, which is deleted the moment your download completes. It is deleted just the same if the run fails, or if the upload is rejected for being too large or the wrong file type. Nothing from a demo run is retained afterwards.
The web demo has no account and no sign-in, so a demo run is not linked to a named person. It accepts a ZIP file of up to 200 MB containing photos.
3. How We Measure Our Website
We need to know which pages help people and which channels bring them here. We do that without identifying anyone and without advertising trackers.
- Where a visit came from. When you arrive, your browser notes the campaign or search details in the link you followed, the page you landed on, and the website that referred you — reduced to its name only, never the full address. If you go on to buy, those few details are attached to the order so we can tell which channel produced the sale.
- The first link wins, and only for that tab. Only the way you first arrived is kept. If you follow a second campaign link later in the same tab, the original details stay and the new ones are ignored — nothing builds up a picture of where you have been. Because it is held only for that tab, a visit that starts after you have closed it begins with no memory of the earlier one, so somebody who reads about us one week and buys the next is recorded as having arrived directly. We would rather undercount a campaign than follow you around to give it credit.
- How far people get. On this site and in the web demo we count four things, and only these four: that a visit started, that one of our main buttons was clicked, that someone crossed from this site to the web demo, and that a checkout was opened. Each one is sent to our own server as a single count carrying the name of the event, which button it was, whether it happened on this site or in the web demo, the date it happened on, and the campaign details described above. The date travels with the count because a count that could not get through at the time is sent again later, and it has to be added to the day it happened on rather than the day it finally arrived. It is a date and nothing finer, which is the same date for everyone else awake at the time, and it is no more than the moment we would see anyway from the request itself. Sending it is a web request like any other, so it reaches our hosting provider, Cloudflare, carrying the ordinary things every web request carries: your IP address and which browser you use. We add nothing of our own to that, and we keep none of it. What is written down is the count together with the details just listed — the name of the event, which button it was, which of the two it happened on, the date, and the campaign details — along with the one-time tag described next, and nothing more: no IP address, no browser or device details, no cookie, no visitor number, and no time more precise than the date. Because the stored record holds no identifier of any kind, two visits by one person cannot be told apart from visits by two people — these are counts of events, not journeys, and that limit is deliberate.
- A one-time tag, so nothing is counted twice. Each count carries a random tag made fresh for that one message. It exists so that if the same message reaches us twice — a retry after a dropped connection, or a page your browser brings back from its history — it replaces itself instead of being counted again. The tag is created at the moment of sending and is never reused for a second count. Every count is written to your browser’s session storage — tag included — before it is sent, so that one which does not get through can be sent again. It is taken out again as soon as an answer settles it, and anything still there is discarded when you close the tab. There is nothing about it that can be matched to you or to any other count. We keep the tag for as long as the day's total can still change: through the nightly tally that adds the day up, and for two days after that tally, because until the day is closed for good the tag is the only thing that can tell a repeat from a new count. It is deleted when the day is closed. If the nightly tally does not run at all, the copy written when the count first arrived deletes itself after fourteen days.
- It lasts for the visit and no longer. Those details are held in your browser's session storage and are discarded when you close the tab. Each count is written down before it is sent and taken out again the moment an answer settles it, so what is there at any time is only what has not been answered. Two kinds of count are never answered. One is a count sent as you leave a page, because a browser tearing a page down does not wait to report back. The other is a count handed to the browser’s own background channel, which is what carries a count off a page that is going away: the browser will send it for us, but it never reports back what became of it, so we cannot tell one that arrived from one that did not. We used to treat those as delivered and keep nothing, which was a certainty we did not have; they are kept as well now. The next page you open on the same address sends whatever is left again under the same one-time tag and the same date, so it can only ever be counted once, and on the day it happened. This site and the web demo are separate addresses with separate session storage, so a count left over from one waits until you are back on that one; it is not carried across. Anything still unsent after a day is discarded rather than sent. Our server keeps the tag until the day it belongs to is closed for good, which is two days after that day is tallied, and we stop a full day before the earliest moment that can happen. That margin is the whole point: a count sent again always arrives while the tag is still there to recognise it, and one that has waited longer is thrown away rather than risk arriving after the day was closed, when nothing would be left to tell it from a new count and it could be counted twice — and all of it is discarded when you close the tab in any case. Nothing is added to it while it waits. Our own measurement creates no identifier and writes nothing to a cookie, and gives us no way to recognise you on a later visit or on any other website.
- Downloads and update checks. Our update service counts how many downloads and update checks it handles so we know how many people are using the app. These are counted in aggregate. We do not store IP addresses or any personal identifier alongside them.
We do not use Google Analytics, advertising pixels or session recording, and our own measurement does not follow you between visits or across other websites. One exception applies if you arrive through an affiliate link — it is described in full below.
4. Affiliate Links
We run an affiliate programme through Lemon Squeezy, so that people who recommend Photo Date Rescue can be paid when a recommendation leads to a sale. Making that work needs the referral to be remembered from the moment you arrive until the moment you buy, which can be days apart. Lemon Squeezy provides the script that does it, and it is on every page of this site, including this one. It is also on the web demo at webapp.photodaterescue.com, which is a separate address but the same programme: a reader who is referred here, tries the demo and then buys would otherwise lose the referral at the moment they crossed over, and the person who recommended us would not be paid. What this section describes applies to both.
If you did not arrive through an affiliate link, that script does nothing. It checks for an affiliate reference in the address you followed and for one it may have stored earlier, finds neither, and stops there — no cookie is written, nothing is sent to Lemon Squeezy about you, and nothing about your device is examined. Loading the script is itself a request to their servers, in the same way as the checkout script described below, and carries the same ordinary details; what it does not do is add anything about you to it. For most visitors that is the whole story.
If you did arrive through an affiliate link, or you are still carrying a reference from an earlier affiliate visit, that script does the following, and we would rather set it out plainly than describe it as ordinary analytics:
- It stores a cookie named
ls_aff_ref, holding a reference number that identifies the referral. Lemon Squeezy sets it forphotodaterescue.comand its subdomains, so the same cookie is readable on this site and on the web demo — that shared cookie is how the referral survives the crossing between them. It is not deleted when you close the tab; how long it lasts is set in our Lemon Squeezy affiliate settings. This is the part that can recognise you on a later visit, and it is there so the person who referred you is still credited if you come back and buy. - It builds a fingerprint of your browser — details such as your screen size, time zone, language, installed fonts and graphics hardware — and combines them into a single value. This is used to recognise the same visitor if the cookie is unavailable.
- It sends that value, along with the address of the page you are on and the website that referred you, to Lemon Squeezy.
We do not receive the fingerprint and we do not use it for anything else. It exists to attribute a commission, not to profile you, and it is not used for advertising, for building an audience, or for any purpose beyond paying the referrer.
Because this is a third-party script, what it does is determined by Lemon Squeezy and can change. Lemon Squeezy's own privacy and cookie policy is published at lemonsqueezy.com/privacy, though it describes their own website rather than this script. The description above is based on our reading of the script as published, and is accurate to the best of our knowledge at the date of this policy.
The Lemon Squeezy checkout script, which is on the pages that show prices, is a separate thing. Loading it is itself a request to Lemon Squeezy's servers, as fetching any file from another company is, and that request carries the ordinary things any web request carries: your IP address, which browser you use, and which page you are on. After it has loaded it makes no further request until you open the checkout, writes no cookie and examines nothing about your device. Once you open the checkout, Lemon Squeezy is handling the payment and their own privacy policy applies to it.
5. Why We Collect Data
We use the information above to:
- deliver and activate your license,
- verify purchases and prevent misuse,
- provide customer support,
- send essential transactional messages, such as order confirmations, receipts and important service notices.
Sending these transactional messages is necessary to complete and support your purchase. They are not marketing and are governed by Section 6 below.
6. Email Marketing and Consent
We treat purchase emails and marketing emails as two separate things:
- Purchase and service emails (order confirmations, receipts, license delivery and essential service notices) are sent because they are necessary to complete and support your order. They do not depend on marketing consent.
- Marketing emails are only sent to customers whose current Customer marketing status in Lemon Squeezy is “subscribed.”
Buying from us is not, by itself, consent to marketing. We never treat the Orders email list — the record that someone made a purchase — as marketing consent. Customers with any other marketing status, including unsubscribed, unconfirmed or no recorded consent, are excluded from marketing sends.
You can change your marketing preference or unsubscribe at any time; doing so stops marketing emails but does not stop the essential transactional messages needed to support your license.
7. Data Storage & Security
Data is stored securely through:
- Lemon Squeezy (payments, receipts and the customer/marketing-status record)
- Secure email services (support requests and transactional email)
- Internal license-management systems
You may request access to, correction of, or deletion of your data at any time by contacting us.
8. Data Protection
We handle customer data in line with applicable data-protection requirements, and where registration with a supervisory authority is required for our processing activities, we maintain it accordingly.
9. Contact
For any privacy request — including access, correction, deletion, or withdrawing marketing consent — contact admin@photodaterescue.com.