LegalGraycard

Privacy Policy.

Updated September 29, 2026Version 1.0Questions

The short version

Your photos never leave your Mac.

Graycard culls and grades them on the Mac in front of you, with on-device Core Image and Vision. Photo bytes are never uploaded, and there is no account.

Network
Used only for Mac App Store purchases and, if you turn it on, anonymized analytics.
Analytics
Off until Settings › Privacy. When enabled, usage events and an anonymous install ID go to PostHog in the EU. Photos, recipes, proofs, folder paths, and client names are never included. Turning analytics off deletes the install ID and stops sending.
No tracking
No advertising identifier, and the data is not used to track you across other companies’ apps.
App Store answers
Product Interaction, Other Usage Data, Other Diagnostic Data, and a User ID (the anonymous install ID), each for Analytics and not linked to your identity. If analytics stays off, nothing is sent.

01What stays on your Mac

Graycard reads your photos where they are, on the card or drive you open. It does not copy them into a library and never changes the original files. What it keeps is small and lives in its own container in Application Support:

  • Bookmarks to the folders you open, so they reopen next time
  • Grade recipes for each photo, and any styles you save
  • A thumbnail cache, capped at 2 GB
  • Auto-cull measurements for each shoot (see Face detection)
  • Job journals and history, so an interrupted export can resume
  • Your settings, including the creator and copyright credit you enter for exports
  • The studio logo image, if you add one to stamp on proofs

Settings → Privacy lists everything Graycard keeps, how large it is, and where it lives.

02Face detection

Auto-cull uses Apple’s Vision framework on your Mac to find faces and check whether eyes are open, focus is sharp, and exposure holds. It saves those measurements for that shoot so it does not have to measure again. They are numbers about each frame, not a face database, and they are never uploaded or used to identify anyone. Remove from Sidebar deletes a shoot’s measurements, and Clear Cache in Settings → Privacy removes all of them.

03What an exported proof contains

Proofs are written only to folders you choose. A proof keeps the shot date, camera, lens, GPS when the photo has it, IPTC fields (including the creator and copyright you set), and a body serial number when the file has one. MakerNote is dropped. GPS in a proof is the camera’s metadata in the file. Graycard does not collect your location. If location matters, check a proof’s metadata before you publish it. An XMP sidecar next to each proof holds ratings, labels, and white balance. JSON sidecars are not written.

04Network

Graycard runs in Apple’s App Sandbox and can read only the folders you open. Photo bytes are never uploaded. The network is used for Mac App Store purchases through StoreKit, and for PostHog in the EU only after you enable analytics in Settings › Privacy.

05Apple frameworks we use

  • Core Image and ImageIO: to decode RAW, JPEG, and HEIF files, grade them, and write proofs. All on your Mac.
  • Vision: for Auto-cull’s face, eye, and quality checks. Nothing is sent off-device.
  • UserNotifications: to tell you when an export finishes while the window is in the background. Notifications are local; you can turn them off in Settings → General.
  • App Intents: so Shortcuts can open a folder, grade or apply a look to the selection, and export it. Runs on your Mac.
  • StoreKit: Mac App Store purchases and restore. Apple processes the payment. Graycard does not receive your card number or Apple Account password.
  • PostHog: optional analytics, off until Settings › Privacy. Events and an anonymous install ID go to the EU. Photos are not included.

06What we never do

  • Upload your photos, previews, thumbnails, recipes, folder paths, client names, or face measurements
  • Send analytics unless you turn it on. It is off by default, and turning it off deletes the install ID
  • Ask for a Graycard account, or use an advertising identifier
  • Use analytics to track you across other companies’ apps
  • Sell personal information

If you have turned on Share with app developers in macOS Privacy & Security → Analytics, Apple may pass us anonymous crash logs. That is an Apple setting, off unless you choose it.

07Purchases

Graycard is sold through the Mac App Store. Apple processes any purchase in full. We do not see your payment details, billing address, or Apple Account.

08Children

Graycard is a tool for photographers. It does not knowingly collect a name or a photo from a child. There is no account. Analytics stays off unless you turn it on, and photos are never uploaded.

09Deleting your data

Everything Graycard keeps is on your Mac, so you can remove it yourself:

  • One shoot: right-click it in the sidebar and choose Remove from Sidebar. Its auto-cull measurements, marks, and job journals are deleted. Your photos are not touched.
  • Caches and history: Settings → Privacy → Clear Cache, and Clear next to job history.
  • Settings: Settings → General → Reset Graycard puts every setting back to its default.
  • Everything: delete Graycard from Applications, then its container at ~/Library/Containers/com.sideswipelabs.graycard.

Proofs you exported live in folders you chose, and stay until you delete them.

10Your rights (GDPR & CCPA)

If analytics stays off, Graycard sends us nothing from the app. If you turn analytics on, PostHog in the EU holds anonymized events and an anonymous install ID. Turning analytics off deletes that ID and stops sending. Email us if you want to ask about an install ID. Photos, recipes, and proofs are not part of that data. Everything else Graycard keeps is on your Mac, as described in Deleting your data.

If you email us, we use your address and message only to reply, and delete the thread on request. EU/EEA users may lodge a complaint with their local data protection authority. California users: we do not sell or share personal information.

11This website

graycard.io sets no cookies and loads nothing from other domains: no analytics, no advertising, and no third-party scripts or fonts. Your browser keeps two small notes for this site, on your device only: that the opening animation has played this session, and when you last dismissed the offer to download Graycard, so it stays away for 14 days. Neither is sent anywhere.

Like any website, graycard.io is delivered by a host, Netlify, which receives the technical details every request carries, such as your IP address and browser, to serve the page and protect it. Links to the Mac App Store take you to Apple, under Apple’s privacy policy.

12Changes to this policy

We will update this page and its version number when the policy changes. A summary also ships inside the app under Help → Privacy.

13Contact

Questions about this policy? Email hello@sideswipelabs.com.

This policy covers Graycard. See also the Graycard Terms of Use and the SideSwipe Labs umbrella privacy policy.

Mac App StoreFree download

Graycard for Mac.

Cull the day, match the color, and write JPEG proofs. The folder stays where it is, and photos are not uploaded.

Price
Free, 80 proofs
Requires
macOS 26 or later
Runs on
Apple silicon or Intel
Account
None

After you download

  1. 01Get it, free
  2. 02Open a card⌘O
  3. 03Auto-cull⇧⌘K
  4. 04Export proofs⇧⌘E

Pro lifts the 80-proof limit when a wedding needs it: $29.99 a year, $9.99 a month, or $59.99 once. Family Sharing on every plan.