The long version
Balise Privacy Policy
Last updated 9 September 2026 · Publisher and controller: Balise, Inc
Publisher / controller: Balise, Inc. Product site: usebalise.com. Privacy contact: apps@usebalise.com (subject “Balise privacy”).
Balise is not an on-device-only product. Short-lived inference copies are uploaded for cloud vision processing, and structured knowledge is stored server-side for your workspace. Balise does not keep a general archive of Apple Photos images. If you explicitly import selected Instagram photos, Balise privately stores bounded display renditions so those imports remain viewable across your devices.
1. In short
- Your original photos stay in Apple Photos (or another library you connect later). Balise is not a photo backup service.
- If you connect Instagram and explicitly select photos to import, Balise keeps private, encrypted display renditions bounded to 1,504 px in your Workspace so the imported photos remain viewable across your devices. Instagram originals remain at Instagram. This is not a backup or continuous sync.
- For photos you include in processing, Balise uploads a temporary inference render (a bounded 1,504 px HEIC derivative today, not a full-resolution archive) to private Balise infrastructure on Google Cloud so vision models can extract structured knowledge. A private Balise service may derive a WebP rendition for models that require it.
- Balise requests deletion of encrypted inference renders after processing; a one-day storage lifecycle is a cleanup backstop if immediate cleanup is interrupted.
- Balise does not keep a general photo archive. Originals remain in Apple Photos. User-chosen exceptions are selected Instagram photos you explicitly import, a card or story you publish, and exact Connected AI photos you approve for one requesting connection. Connected AI access ends one hour after approval and does not include future imports (§4.4).
- Balise stores structured knowledge derived from your photos (observations, facts, domains, search indexes, preferences) in your workspace — that is the durable product asset, and it is yours to correct or delete.
- We do not use your content to train models, and we instruct our AI providers not to train on Balise inference content.
- Balise does not offer a face-identification service or persistent biometric people graph. Recurring-people grouping is opt-in and starts on your device; face templates, crops and embeddings stay there. After an import, a vision model may compare faces within the already-uploaded temporary processing copies once to reconcile obvious duplicate opaque groups. It cannot name people, split groups or create identities, and Balise stores only the resulting opaque alias links. A name you assign may accompany that reference as temporary model context when a future matched photo is processed (§4.6).
- You must be 16+ to use Balise (see §11). Parents photographing their own children for personal knowledge is an expected personal use.
- You can delete all Balise data from inside the app (Profile → “Delete all Balise data”), and ask us by email to close the sign-in account itself. See §10.
- We do not sell your photos or knowledge, and we do not show ads.
- The website (usebalise.com) stores a waitlist email if you give one and measures visits without analytics cookies, advertising, or cross-site tracking (see §4.8).
2. Who we are
Balise, Inc is the legal entity that publishes Balise and acts as data controller for personal data processed in connection with the Balise service and the usebalise.com website, unless a specific processing is described as performed by a third party as an independent controller (for example Apple operating system services on your device).
2093 Philadelphia Pike #3795
Claymont, DE 19703
United States
1 Chome-23-5 Higashiazabu
Minato City, Tokyo 106-0044
Japan
2-4 rue Jules Lefebvre
75009 Paris
France
Contact: apps@usebalise.com · usebalise.com
Privacy contact. One person at Balise is responsible for privacy questions, for your requests under §10, and for talking to data protection authorities — the role called a data protection officer in Europe and an encarregado in Brazil. Write to apps@usebalise.com with the subject “Balise privacy” and it reaches them. You can write in English, 日本語, français, español or português.
3. Scope
This policy covers:
- the Balise iOS app (iOS 17+), including TestFlight / beta builds;
- Balise backend APIs and storage used to provide the service;
- Balise’s connector for an AI service you choose: reading your memory and photos, and a small set of writes you ask for — saving a private List, saving or updating a private discovery, and preparing a private story proposal. The connector cannot publish anything;
- the usebalise.com website, including the waitlist form and site analytics;
- related support communications about Balise.
It does not cover third-party websites or apps that link to us, or Apple’s own processing as platform provider (Sign in with Apple, Photos, App Store, TestFlight), except to describe how Balise interacts with them.
4. Personal data we process
4.1 Account and authentication
| Category | Examples | Source |
|---|---|---|
| Identity / auth | Clerk user id, sign-in identifiers (for example Sign in with Apple), session tokens, and the email or name held by Clerk if your sign-in method provides one. Balise’s own servers store only the Clerk user id and use it as your workspace id. | You / Clerk / Apple |
| Workspace linkage | Workspace id, provisioning state, role | Generated by Balise |
| Push notifications | Device push token, if you allow notifications, so we can tell you when a round is done | You / Apple |
4.2 Photo library inputs
With your permission via Apple PhotoKit, Balise receives, for the assets you include:
- image content (to create a temporary inference render for cloud vision — not to archive your Camera Roll). The render is re-encoded on device with camera metadata (EXIF, GPS, maker notes, thumbnails) stripped from the file;
- capture / modification timestamps and the capture time-zone offset;
- location metadata when present on the asset (GPS coordinates, altitude, heading, accuracy from the photo — not live tracking of you) and a place name resolved on device from those coordinates;
- This is precise location. The coordinates are stored with the photo in your workspace and can be searched, for as long as that photo’s knowledge is kept (§9). They are how Balise places a photo on the map and answers where you were. No setting keeps location out of processing today: to keep a photo’s location from Balise, remove it in Apple Photos before importing, or leave that photo out;
- Place lookup at Google. To name the venue in a photo and to fill in geography the photo does not carry, Balise also sends the photo’s coordinates from our servers to Google Maps Platform (Places API and Geocoding API) and keeps the candidates it returns. Google receives the coordinates and nothing else — no image, no account identifier, no name. If a photo has no location, nothing is sent for it;
- an optional positive “near home” hint computed on the originating device, without copying the separately stored home-zone label, center, or radius onto the photo record;
- album membership, including album names (for inclusion / exclusion rules and as context);
- technical flags and camera settings (for example screenshot, favorite, edited, dimensions, camera model and lens, exposure, flash) and any caption you typed in Photos;
- on-device Vision results: number and position of faces and people, whether you appear (§4.6), animals, whether text is present, and quality scores — never the recognized text itself, and never face templates of other people;
- PhotoKit local identifiers and, where available, cloud identifiers, and a per-install device identifier, used for deduplication and to link facts back to the photo on your device.
These facts travel with the render as structured data (not inside the image file), are stored with the resulting knowledge, and are given to the vision model as context for describing the photo.
Instagram imports. If you connect a supported Instagram Creator account, browsing alone does not import anything. When you explicitly choose still photos to import, Balise receives their image content, stable account/post/media identifiers, carousel order, posting time, original permalink where available, and any available caption. Posting time is not treated as capture time, and captions remain text attributed to Instagram rather than verified visual fact. Videos are not imported as photos.
Defaults and limits
- You choose how many photos and which period Balise should consider; the app samples evenly across that period. Album-by-album selection is not offered in the current build.
- Hidden albums and shared albums are always excluded; this cannot be switched on. Screenshots are excluded unless you turn them on.
- Limited Photos access (iOS) is supported: Balise can only see the photos you picked in Apple’s sheet.
- Photo-library permission does not mean every asset is uploaded immediately or at all.
- Keep up as you shoot (new photos picked up automatically) is off unless you turn it on, and is offered on a running plan, free included. It is off once a plan has ended.
4.3 Temporary inference media
Bounded inference renders uploaded for cloud vision processing. These are short-lived processing copies, not an archive of your Camera Roll. Balise requests deletion of encrypted copies after processing, including any enabled post-import People comparison; a one-day storage lifecycle is a cleanup backstop if immediate cleanup is interrupted; failed, skipped, cancelled, reset, and explicitly deleted work is cleaned sooner where possible. The storage soft-delete window is set to zero so a deleted copy is gone.
4.4 Image copies (no photo archive)
Balise does not keep a general archive of Apple Photos images. Originals stay in Apple Photos. The choices below retain only what their screens describe: selected Instagram imports, published cards, story pages, and private Connected AI renditions.
Selected Instagram imports remain private in Balise. For each still photo you explicitly import, Balise stores an encrypted display rendition bounded to 1,504 px in your Workspace. It is not publicly accessible by default and remains available across your devices even if you disconnect Instagram. We keep it until you delete that imported photo, delete all Balise data, or close your account. The original remains at Instagram; Balise does not back up the original or continuously synchronize the account. Storing this rendition does not authorize blanket access by Connected AI: the exact-photo approval and one-hour access rule below still applies.
Shared cards are opt-in, one photo at a time. Balise can turn a photo and what it noticed there into a card. Rendering that card on your phone, or saving it to your own photo library, uploads nothing at all. Only if you separately choose to publish it at a link do we store anything: the card image your phone rendered, a preview image for when the link unfurls, and a display-sized copy of that one photo.
Those are kept until you delete them — there is no expiry, because a dead link in something you posted is a broken promise. The address is unguessable and carries noindex, so we ask search engines not to list it, but a link is a link: treat a published card as public. Take one down in the app (Profile → Shared) or from the page itself; deletion removes the images and then the record, the address answers “gone” afterwards, and it is never reused. Deleting your data or your account removes published cards too. Payment card digits are never part of a card: they are discarded when it is made, not hidden when it is shown.
Story pages are opt-in, one day at a time. Balise can write up a single day as a short story — a title, a few sections of prose, and the pictures the story is about — at a link you can send to people. Nothing happens until you tap “Tell its story” on that day. Then, and only then, we store small copies (about 640 pixels on the long side) of up to twelve photographs from that day’s grid — Balise’s pick ticked, yours to change, and the text written about them. Nothing else from that day, and nothing at all from the rest of your library.
A published story page shows a small map, and that map is an embedded frame from OpenStreetMap. It carries the story's coordinates, so anyone who opens the page contacts openstreetmap.org directly and OpenStreetMap sees their IP address and the place the story is about. That happens in the reader's browser, not on our servers, and only on a page you chose to publish.
This is the only Balise-authored storytelling feature where a model looks at your photographs in order to write. Connected AI is a separate, user-directed connector. To tell the story of your day, the story model is shown exactly the twelve pictures the story will publish — for the few minutes it takes to write — and nothing else. Our AI providers are instructed not to train on Balise content.
You read it first: the story is a private draft until you publish it, and you can retitle it, rewrite any section, move pictures between sections, drop a section, or have one written again. Published, it is kept until you delete it, at an unguessable address carrying noindex — but a link is a link, so treat a published story as public. Take one down in the app (Profile → Stories) or from the page itself; the pictures and the text go, then the record, and the address answers “gone” afterwards and is never reused. Deleting your data or your account removes published stories too. Card numbers are never written into a story at all.
Connected AI is facts-only by default. Your assistant may request up to 24 exact photos. Balise shows every selection in the app and sends nothing unless you approve it within 10 minutes. Approval lets only that requesting connection access those exact 1,504 px display copies for one hour from approval; fetching a photo again does not extend the hour, and future imports or later selections require another approval. Expiry blocks further access through Balise; it does not erase images already received by the assistant or remove them from your conversation. At most four selected images may be returned in one authenticated response. There is no public image URL. The iPhone encrypts its HEIC rendition before upload; originals stay in Apple Photos and Balise keeps no general photo archive.
Balise does not automatically receive or store your Claude or ChatGPT conversation. It receives the arguments sent in authenticated connector calls. If you ask or approve it, one separately scoped operation may save a new private text List or replace one existing private List in your Workspace. It stores the List text and verified private links to supporting photo records; it cannot publish, delete, change a published List, or alter your photographs or structured knowledge. Once your chosen service receives facts or images at your direction, its own terms, privacy policy, account controls, and retention choices apply. Our no-training promises for Balise subprocessors do not make a promise about an independently chosen Claude or ChatGPT account.
Public profiles are a separate, optional publishing surface. You can reserve an @handle and publish a display name, short bio, and links to cards, recaps, stories, or Lists you already published. Making the profile public does not make your indexed photo library, Apple Photos originals, or private Connected AI copies public; it exposes only the profile and links to material you had already published. Profiles are meant to be findable and may be indexed. If you ask Balise to prepare a draft, it uses only the public-safe titles and summaries of that already-published material; the draft stays private until you edit, curate, and publish it. You can unpublish it at any time. An old handle remains reserved to you so nobody else can take over an address you shared.
Saved Lists are text, not image copies. When Ask assembles things or places from your photo knowledge, nothing new is retained until you tap Save or Share. A Connected AI service may save or revise a private List only after you ask or approve the operation. Saving keeps the List text and private links back to the supporting photo records in your Workspace; it does not copy or publish those photos. Sharing publishes only the list title, summary, item names and descriptions at an unguessable noindex address. Anyone with that link can read it. It stays until you delete it in Collections → Lists (also available from Profile → Lists) or delete your Balise data; deletion removes the text and the address then answers “gone”.
4.5 Structured knowledge (durable)
- observations and extracted facts (objects, text cues, places, domain-specific fields) — including structured descriptions of photos that may depict children or other people when you included those photos;
- provenance linking facts to evidence identifiers;
- domain / interest configurations and insight definitions;
- search indexes and embeddings of structured content (not a photo backup);
- corrections and preferences you provide;
- your optional home-zone label, center and radius, stored as a private workspace setting rather than on any photo record;
- an import ledger used for deduplication and “already processed” state (photo identifiers, capture time and photo location, dimensions, status — not your original file);
- your preferred language, notification registration, and subscription entitlement state (from Apple’s StoreKit, no card details).
4.6 On-device processing, private home context, faces and the self reference
On device, Balise uses Apple frameworks (PhotoKit, ImageIO, MapKit, Vision) to select, sort and downsize photos before upload, to resolve a place name from the photo’s coordinates, and to detect faces, people, animals, text and foreground. Naming the venue itself happens on our servers, through Google Maps Platform, from the coordinates alone (§4.2). Counts, boxes, head angles, scores and optional random opaque person references may leave the phone; recognized text, face crops, landmarks and feature vectors do not.
Home area. If you choose a MapKit zone as home, Balise stores its broad label, center coordinate and small radius as a private workspace setting and mirrors it in protected storage on your signed-in device. Balise’s agents may use that selection as your explicit home context. It is not stored as a street address and is not copied onto photo records; a photo made inside it may carry only a positive home hint. You can replace or forget the zone in Profile at any time. Forgetting it deletes the server setting and the local mirror.
Self reference. A front-camera photo or Apple’s Selfies album does not identify who is pictured. Balise therefore treats every automatic candidate as untrusted. Only after you explicitly confirm a local self reference may the app compare faces on device and upload a yes/no self-presence result with confirmation provenance. The reference vector remains on your device and is never sent to Balise or a model provider. Older account vectors are deleted by the service.
Recurring people. Where supported and only if you turn the People feature on, the app uses Apple Vision face landmarks and a bundled on-device model to group recurring faces, then assigns random workspace-scoped identifiers so you can browse the same person across photos and optionally tell Balise who they are. Face crops are not stored; face-embedding templates are encrypted in the app’s local database with a device-only key and stay on the device. After a completed import, Balise may make one bounded vision-model comparison over faces already present in the private temporary processing copies, solely to merge two whole opaque groups that unmistakably depict the same person. The model cannot split a device group, name anyone, create a person id or describe sensitive traits; the server independently refuses a merge when the groups co-occur in one photo or conflict with labels you supplied. Medium- and low-confidence proposals are not applied. No cloud face crop, template or embedding is retained; the processing copies are deleted after processing, including this comparison, with a one-day cleanup backstop, and durable cloud state holds only opaque identifiers, photo membership, merge history, and labels or relationships you enter. If you give a People entry a name, Balise may include that user-authored name as temporary context when a cloud vision model processes a future photo your device matched to the same opaque identifier, so the description can use the name you supplied; the structured actor remains opaque, and a name does not establish a family, friendship or other relationship. Balise does not infer a person’s name or relationship from their face and does not run a general-purpose face-identification service.
4.7 Operational and diagnostics data
- API logs, IP address, device / app version, and crash or performance signals from Firebase Crashlytics, Firebase Performance Monitoring and Apple MetricKit;
- fixed product-interaction events (app open, import, first card, collection, search, Ask and plan actions), linked to your workspace so we can measure activation and retention; these events never contain search text, Ask prompts, photo or collection identifiers, notes, or arbitrary properties;
- Redis / Memorystore operational state (job progress, locks, manifests, short-lived tokens) — not a durable photo store;
- a control database (Cloud SQL) holding import batches, the import ledger, entitlement usage and an audit trail of account actions (for example that a data reset completed);
- security and abuse-prevention signals.
Shipping iOS builds use Firebase Crashlytics and Performance Monitoring for operational diagnostics. Google Analytics is not linked, and Balise does not use an advertising identifier or cross-app tracking. Full Apple MetricKit diagnostic payloads stay bounded on the phone; only numeric summaries go to Firebase Performance. Product interaction events go to Balise’s own authenticated API and are stored in PostgreSQL. When server forwarding is enabled, Balise may also send the same closed events to PostHog under a pseudonymous workspace identifier; no new analytics SDK is added to the app. Forwarding is disabled in development and preview environments and is enabled in production only after remote deletion is configured. Resetting the workspace or deleting the account requests queued deletion of the corresponding PostHog person and events; if that request cannot be submitted, the reset does not report success.
4.8 The website (usebalise.com)
- Waitlist. If you leave your email on the homepage we store the email address, the optional line about what you photograph, your browser’s user-agent string, a salted hash of your IP address (used only to rate-limit sign-ups) and the time of sign-up, in Cloudflare KV. A notification email with the same details is sent to the founder’s inbox so we can invite you. We use the address to send TestFlight invitations and Balise news, and for nothing else.
- Site analytics. Balise’s own browser code sends pseudonymous typed events to
/api/e; our Cloudflare Worker validates them and forwards them to PostHog’s US ingest service. We may record a random per-tab session id in session storage, a page path with shared-object ids removed, device/browser/operating-system categories, country, referrer domain only, short source andutm_source/utm_medium/utm_campaign/utm_contentcodes, page variant, and typed controls or events. We do not forward IP addresses, email, the waitlist interest line or other form text, photo content, full query strings,utm_term, or referral codes. There is no PostHog browser script, analytics cookie, replay, autocapture, advertising, or cross-site tracking. Do Not Track and Global Privacy Control disable collection. The per-tab id does not persist across visits, and website attribution is not automatically joined to an app workspace. The canonicalwaitlist_joinedconversion is created only after a new waitlist record is saved; repeat signups are excluded. A browser success event is only a UI diagnostic. - Cloudflare Web Analytics. Cloudflare may also measure aggregate traffic and site performance without cookies.
- Language cookie. If you pick a language path (for example /fr), the site sets a single functional cookie,
balise_lang, to remember it. Nothing else is stored in cookies. - Hosting. The website and its API run on Cloudflare (Workers, KV, Email Service). PostHog processes the limited pseudonymous analytics events in the United States.
4.9 Support communications
If you email us, we process your address and message content to respond.
4.10 Sensitive information in your photographs
A camera roll is not a neutral archive. Over a few years it will contain a hospital corridor, a prescription on a kitchen table, a place of worship, a demonstration, a partner, a child. Several countries treat information like that as a special category that needs more care than ordinary personal data — special category data under the GDPR, dados pessoais sensíveis under Brazil’s LGPD, 要配慮個人情報 under Japan’s APPI. Here is how Balise handles it.
Explicit photos are set aside before Balise looks closely. When a photo is flagged as explicit at the first glance, Balise stops there: the processing copy is deleted, no description is written, and nothing about the photo enters your knowledge. Balise keeps only the fact that the photo was set aside, so it is not picked up again on a later round. Your import summary shows you a count of the photos this happened to.
Health photos stay out of everything that narrates your life. When Balise notices that a photo concerns health or healthcare, it marks it, and that mark sticks. A marked photo is kept out of Stories, story highlights, the photos an editor can add, Memory prose, the material the Memory writer can see at all, episode covers and hero images, the photo strip on the map, share-card picture plans, and any description Balise writes about a person. The photo stays where it belongs in the day it happened; what it does not do is get written about or put on a cover.
Two honest limits. Photos processed before this labelling existed may not carry the mark — for Memory prose we leave out any witness that is not labelled rather than risk it, but the other surfaces rely on the mark being there. And if you deliberately send a photo to a connected assistant, Balise sends the photo you chose; the health mark does not overrule your choice.
Faces. Grouping recurring people is biometric processing in most of these laws, which is why it is off unless you turn it on, why the templates and vectors never leave your iPhone, and why the cloud holds only random identifiers, the merge history, face boxes and head angles, and the names you type yourself (§4.6).
Religion, politics, sex life, ethnicity. Balise does not set out to infer any of these and does not build audiences or profiles from them. Facts of that kind can still end up in a description if they are plainly visible in a photograph you chose to include — a wedding, a march, a shrine. You can correct or delete any of it (§10), and the controls that matter most are the ones at the start: give Balise limited access and pick the photos yourself, or keep a period out of range.
Precise location. Several US states count a photo’s exact coordinates as sensitive data in their own right. Balise keeps them with the photo and uses them to place it (§4.2) — that is providing the service, not a use beyond it.
5. Why we process data (purposes and legal bases)
The purposes, stated plainly. We use your personal data to: create and secure your account; process the photos you choose and build the structured knowledge, collections and Memory that Balise is for; run the cloud inference that does that processing; tell you when a round of work is finished; keep the Service reliable, debug it and prevent abuse; answer your support messages; run the waitlist and send invitations; understand how the website is used; and meet our legal obligations. That is the whole list. We do not use your data for other purposes, and if we ever want to, we will tell you what the new purpose is before we start (§15). The table below adds the legal basis for each purpose for readers in the EEA and the UK.
| Purpose | Data (high level) | Legal basis |
|---|---|---|
| Create and secure your account | Auth identifiers, sessions | Contract (Art. 6(1)(b)); legitimate interests for security |
| Provide library processing and knowledge features you request | Ephemeral inference renders, structured knowledge, preferences | Contract |
| Ephemeral cloud inference | Inference renders, model input / output | Contract |
| Tell you when a round is done | Push token | Contract / consent (iOS notification permission) |
| Improve reliability, debug, prevent abuse | Logs, operational metadata, salted IP hashes | Legitimate interests; legal obligation where applicable |
| Waitlist and invitations | Email, interest line | Consent / steps prior to a contract |
| Understand how the website is used | Pseudonymous interaction events | Legitimate interests (no analytics cookies, advertising, or cross-site tracking) |
| Support | Email content | Contract / legitimate interests |
| Comply with law | Limited records, deletion audit entries | Legal obligation |
Publishing a card at a link is processed on the basis of your explicit, per-photo choice to publish it, and lasts only as long as you keep it published (§4.4).
5.1 No training, no selling
We do not sell personal data. We do not use your photos, inference renders, structured knowledge, or other customer content to train machine-learning models. We instruct our AI subprocessors (Vertesia, OpenAI, Google Vertex AI / Gemini, xAI, Anthropic, and Amazon Web Services as used through Vertesia) not to use Balise inference content to train their models. Providers process content only to deliver inference and related Service features for your workspace.
6. How processing works (pipeline)
- You authorize Photos (full or limited) and choose how many photos and which period.
- On-device rules decide which assets are eligible (screenshots only if enabled; hidden and shared albums always out; the sample spread evenly across the period).
- For each eligible asset, Balise creates one bounded 1,504 px HEIC processing copy, encrypts it on the iPhone, packs encrypted copies into an archive and uploads it over TLS, via a short-lived signed URL, to a private Balise inference bucket on Google Cloud Storage, together with the photo facts listed in §4.2 as structured data. A dedicated private Balise service decrypts copies for processing and derives an encrypted 1,504 px WebP version when needed.
- Vision models (orchestrated by Vertesia; currently OpenAI and Google Vertex AI / Gemini paths) analyse a temporary render and extract structured evidence. Google’s Vertex path receives a separate temporary private cloud input with expiring access, currently ten minutes. This input has cloud storage encryption rather than the phone’s per-image encryption. OpenAI-compatible paths receive short-lived access through Balise. Later text-only steps may use Gemini, OpenAI, xAI (Grok), or Anthropic (Claude, including through Amazon Bedrock) through Vertesia. Memory construction receives a bounded, filtered packet of extracted witness names, descriptions, domains, time and coarse place context; it does not receive photos, full Search text, exact home coordinates, healthcare content, or document bodies. Other text-only steps receive the bounded schema, account, event-story, or non-sensitive profile fields needed for that operation.
- Structured results are written to your workspace (Vertesia content objects and search index) and to the control database ledger.
- Balise requests deletion of encrypted inference objects after processing, including any enabled People comparison; a one-day lifecycle removes stragglers if immediate cleanup is interrupted.
- Balise keeps no general image archive. Explicitly selected Instagram imports keep the private bounded display rendition described in §4.4.
New photos after the first import. You can send more rounds by hand. “Keep up as you shoot” picks up new photos automatically when you turn it on, on a running plan. The app UI for your build is the source of truth for whether newly added photos are being picked up.
7. Processors and subprocessors
We use service providers (“processors”) to operate Balise. They process data on our instructions. The list below reflects company-confirmed vendors and the deployed infrastructure for the Balise Google Cloud project (region us-central1 today).
| Provider | Role / purposes | Data typically involved |
|---|---|---|
| Clerk | App authentication and OAuth authorization for Connected AI | Account identifiers, auth metadata, email if provided, connector grants and scopes |
| Google Cloud / Firebase | Hosting and infrastructure: Cloud Run (API and import services), Cloud Storage (private inference media, selected Instagram display renditions, and request-approved Connected AI copies), Memorystore (Redis) (short-lived leases and disposable caches), Cloud SQL (control database, import ledger and fixed product events), Cloud KMS (encryption-key operations), Secret Manager, Artifact Registry, networking; Firebase Crashlytics and Performance Monitoring; Vertex AI / Gemini when Vertesia routes inference to Google’s Vertex environment | Temporary processing copies, selected Instagram display renditions, and request-approved Connected AI copies; ledger and operational data, fixed product events, crash/performance and installation diagnostics, model input / output for the Vertex path |
| Temporal Cloud | Durable import and task workflow execution, timing and retries | Opaque account and work identifiers, workflow state, timing and redacted failure metadata; no photo bytes or provider credentials |
| Vertesia | Durable workspace knowledge, search, agents / workflows, and inference orchestration using short-lived media access supplied by Balise (US region today) | Structured knowledge, workspace-scoped credentials, run metadata; temporary media access for inference |
| OpenAI | Vision / model inference via Vertesia using short-lived HTTPS media access supplied by Balise; text-only domain design steps | Temporary media references / model inputs and outputs |
| xAI | Text-only model inference via Vertesia for domain-screen design, a bounded non-sensitive person description, and committed Memory prose (Grok) | Domain schemas and templates; bounded non-sensitive aggregate counts, filtered domain examples and facets, committed accounts and event-story text — no photos |
| Anthropic | Text-only model inference via Vertesia, including year-level Memory prose and fallback processing (Claude) | Bounded structured text, committed accounts, event labels and event-story text — no photos for these Memory writing steps |
| Amazon Web Services | Amazon Bedrock inference infrastructure used by Vertesia for some Anthropic Claude paths | The bounded model input and output for the applicable Claude text-only step |
| Google Maps Platform | Naming the venue in a photo and filling in missing geography: Places API (New) and the Geocoding API, called from our servers | The photo’s coordinates only — no image, no account identifier, no name |
| Meta (Instagram) | Only if you connect Instagram: reading the media you chose to import | Your Instagram authorization, and the media, captions and permalinks Balise imports |
| X Corp. | Only if you connect X to publish an article | Your X authorization and the article you chose to publish |
| Cloudflare | Website hosting, first-party analytics endpoint, cookie-free aggregate Web Analytics, waitlist storage (KV), and email (Email Service): waitlist notifications, subscription confirmations, and the updates sent to people who follow a publisher | Waitlist email and interest line, subscriber and follower email addresses, IP data used at the edge for rate limiting, limited pseudonymous interaction events, aggregate traffic and site-performance measurements |
| PostHog (United States) | Website analytics; optional server-side closed product events and sanitized error reporting | Pseudonymous typed events and static error summaries; browser errors may include an allowlisted script filename and line number; no photo content, form text, or IP address forwarded by Balise |
Apple (platform, not a Balise AI subprocessor): OS, PhotoKit, Sign in with Apple, push notifications, App Store / TestFlight distribution and crash reports. Apple acts under its own terms for platform services.
We also hold accounts with OpenRouter and Baseten for evaluating models. They are not in the production route today, and we do not send customer content to a model vendor whose terms permit training on it — some vendors reachable through those accounts have exactly such terms, which is why they stay out of the route.
We require processors to protect data appropriately. We do not authorize processors to use Balise customer content to advertise to you or to train models on Balise inference content.
What deletion does not reach. Deleting your data removes it from Balise, our storage and our analytics. It cannot reach back into a model provider's own operational logs; those providers keep limited records under their own terms and retention periods, and we do not control them.
8. International transfers
Balise infrastructure and processors may process data in the European Union and other countries, including the United States (the Google Cloud project runs in us-central1 today; Vertesia runs in its US region today; OpenAI, Vertex, xAI, Anthropic and Amazon Bedrock paths may also process outside the EEA; PostHog processes limited analytics events in the United States; Cloudflare runs a global network), depending on provider regions and account configuration.
Which countries, in plain terms. Today, the substance of Balise — the servers, the temporary photo copies, your structured knowledge, and the models that process them — runs in the United States. Cloudflare serves the website from wherever you are. No other country holds your data as a matter of course.
What that means for the United States. The United States has no single comprehensive federal data protection law. Protection there comes from sectoral and state laws, from the contracts we hold with each provider in §7, and from the technical limits described in §13 — not from an equivalence with your own country's law. US public authorities may in some circumstances compel a provider to hand over data.
From the EEA/UK. Where required, we use appropriate safeguards — such as Standard Contractual Clauses — for transfers to countries without an adequacy decision.
From Brazil. Personal data of people in Brazil is processed in the United States by the providers named in §7, for the purposes in §5. We give you this information so your transfer decision is an informed one, and we hold each provider to the protections described here.
From Japan. Personal data of people in Japan is processed in the United States by the providers named in §7. We are telling you the destination country, the fact that it has no comprehensive national data protection law, and the measures each recipient takes, so that you can decide with that in front of you.
9. Retention
| Data | Retention |
|---|---|
| Inference renders (temporary) | Deletion requested after processing, including any enabled People comparison; a one-day lifecycle removes stragglers if immediate cleanup is interrupted; failed/cancelled/reset work cleaned sooner where possible; zero soft-delete window |
| Connected AI request copies | Exact photos only after in-app approval; available only to the requesting connection for one hour from approval, without extension on repeated fetches; cleanup follows expiry |
| Selected Instagram display renditions | Private and Workspace-scoped until you delete the imported photo, delete all Balise data, or close your account; disconnecting Instagram alone does not remove them |
| Optional home-zone setting | Until you replace or forget it, delete all Balise data, or delete the account |
| Structured knowledge, import ledger, opaque person metadata | Until you delete it or delete all Balise data / your account |
| Auth / account records (Clerk) | For the life of the account; then deleted or anonymized on request |
| Redis / Memorystore operational state | Short-lived / cache-oriented; loss must not recreate a photo archive |
| Product interaction events | Until you delete all Balise data or close your account; workspace-scoped and not used for advertising or cross-app tracking |
| Waitlist record (website) | Until you ask us to remove it, or once invitations for the beta are no longer sent |
| Site analytics events | Pseudonymous; retained according to the configured PostHog project retention policy |
| Provider input copies (the Vertex path) | Access expires in ten minutes; the bytes follow the same one-day storage rule |
| Data exports you asked for | 30 days, then removed by the bucket |
| Inference run records (which model ran, when, what it cost) | 120 days, then swept |
| Searches that found nothing | 90 days, then swept |
| Import batches, domain suggestions, import archives | 30 days, then swept |
| Workflow history (Temporal Cloud) | 30 days after a workflow closes |
| Database backups and server logs | Backups 30 days, transaction logs 7 days, platform logs 30 days |
| Support emails | As long as needed to handle the request and ordinary business / legal records |
| Deletion audit entry | Minimal non-content record that deletion completed (counts, timestamp) |
If an original photo is deleted from Apple Photos, related structured records may remain marked as evidence-unavailable until you delete them; Balise does not silently invent displayable originals.
10. Your rights and controls
10.1 In-product controls
- choose Photos access level (full or limited, picking photos in Apple’s sheet), how many photos and which period; screenshots on or off; “Keep up as you shoot” on or off;
- rely on the fixed exclusion of hidden and shared albums;
- correct or delete structured knowledge;
- Delete all Balise data (Profile → Balise data → “Delete all Balise data”): permanently deletes your searchable photos, notes, collections, import history, opaque person metadata, the local self reference, and any copies stored by Balise, across the phone, knowledge storage, both media buckets, the control database, push registration and operational state; running jobs are aborted first. Your Apple Photos and your sign-in account do not change;
- manage sign-in methods and sign out (Profile → Account & sign-in).
10.2 Access, export, correction, deletion
Depending on where you live (including GDPR if you are in the EEA/UK, and similar laws elsewhere), you may have rights to access, rectify, erase, restrict, port, and object to certain processing, and to withdraw consent where processing is consent-based.
The laws differ, so here is what you can ask for where you live. Write to apps@usebalise.com with the subject “Balise privacy” — from the email address on your account, or with enough detail for us to be sure the account is yours. We answer within one month — sooner where the law where you live sets a shorter deadline — and we do not charge for it. If a request is unusually repetitive or excessive we may say so and explain why, rather than charging you.
- EEA and the United Kingdom (GDPR). Access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right to complain to a supervisory authority (§10.3).
- Brazil (LGPD). Confirmation that we process your data at all; access; correction of incomplete, inaccurate or out-of-date data; anonymisation, blocking or deletion of data that is unnecessary, excessive or processed contrary to the law; portability; deletion of data processed with your consent; information about the public and private bodies we share data with; information about what happens if you refuse consent, and the right to refuse it; revocation of consent; and review of decisions made only by automated means (§14).
- Japan (APPI). Disclosure of the retained personal data we hold about you, including records of third-party provision; correction, addition or deletion where it is wrong; and suspension of use, erasure, or suspension of provision to third parties in the cases the Act allows.
- United States. Where your state's law provides them: to know, access, correct, delete, and obtain a portable copy; to opt out of sale, sharing for cross-context behavioural advertising, and targeted advertising — none of which we do (§10.4); to limit the use of sensitive personal information; and to appeal a refusal. We will not treat you differently for exercising a right.
- Latin America. Mexico's LFPDPPP gives you the ARCO rights — acceso, rectificación, cancelación, oposición — and Argentina, Chile, Colombia and others each have their own catalogue and their own deadlines. Write to us the same way; we follow the law where you live.
Export. You can request an export of workspace-held data such as profile properties, observations / facts / provenance, and domain configuration, by email. Exports do not include Apple Photos originals, which Balise never stored.
Account deletion. Deleting all Balise data from the app removes your workspace content. To close the sign-in account itself (the Clerk identity), email apps@usebalise.com with subject “Balise delete my account” from your account email (or include enough detail to identify the Sign in with Apple account). We will delete your workspace data if you have not already, and delete or anonymize the Clerk identity in the weekly prune of closed sign-in accounts, retaining only a minimal non-content audit entry if needed to prove completion. We are committed to offering in-app account deletion meeting App Store Guideline 5.1.1(v) before App Store release.
Waitlist. Email us and we remove your address from the waitlist.
10.3 Complaints
You may contact us first so we can help. You may also lodge a complaint with the data protection authority where you live. In the EEA, that is your national authority; our European office is in France, where it is the CNIL (cnil.fr). In the UK, the ICO (ico.org.uk). In Japan, the Personal Information Protection Commission (ppc.go.jp). In Brazil, the ANPD (gov.br/anpd). In the United States, your state attorney general.
10.4 California / other US state laws
We do not sell personal information for money, and we do not share it for cross-context behavioral advertising.
11. Children and age eligibility
You must be at least 16 years old to create a Balise account (or the higher age of digital consent where you live). Where local law allows a lower age with verifiable parental consent (for example 13+), we may permit that only after implementing an appropriate parental-consent flow; until then, 16+ is the default. Balise is not directed at children under these thresholds. If you are between 16 and the age of majority where you live (18 in Brazil and Japan, among others), the law there may require a parent or guardian to agree to a paid subscription for it to hold; get their agreement before you buy. We do not knowingly create accounts for children or solicit personal data from them. If you believe a child has used Balise in a way that provided us personal data, contact apps@usebalise.com and we will take appropriate steps, including deletion.
12. People who appear in your photos (including children)
Your library may contain images of other people (including children). When the account holder includes such photos, Balise may process those images for inference and may store structured knowledge about them (descriptions, events, places, and related facts) in the workspace. Ordinary image renditions are scheduled for deletion after processing, with a one-day cleanup backstop. Exact photos approved for a connected assistant may also include other people and follow the same one-hour access rule. You remain responsible for having the right to share them.
Expected personal use. Parents photographing their own children for personal knowledge (for example watching a child grow up) is an expected personal use of Balise. The way to “see the pictures” is Apple Photos on your device — not Balise becoming a photo archive.
We do not have a direct relationship with third parties who appear in your photos and do not run a general-purpose face-identification network or retain cloud biometric templates. If People is enabled, the bounded post-import duplicate-group comparison described in §4.6 may process their faces inside temporary photo copies. You (the account holder) remain responsible for having the right to process photos that include other people. Use limited Photos access, the period and count controls, and deletion if photos should not be processed. Shared albums are always excluded, and face templates, crops and embeddings remain on your device (§4.6).
13. Security
The iPhone encrypts each processing copy before upload with a fresh AES-256-GCM key, wrapped using RSA-OAEP-SHA256. Private image copies are encrypted in storage. The master private key remains in Google Cloud KMS; decryption permission is restricted to the dedicated private media service. Staff are not granted access to open private photos. Authorized automated processing decrypts copies for preparation, AI processing and approved delivery. This is not device-only end-to-end encryption: the processing service and relevant AI providers can analyse the inputs they need, and searchable knowledge is stored separately on our servers. Production access controls enforce staff restrictions; encryption alone is not a guarantee against every possible system compromise.
AI providers receive time-limited access to decrypted inputs. Vertex processing can use a temporary private cloud input outside the phone’s per-image encryption, protected by cloud storage encryption and an expiring provider access permission. The current input access window is ten minutes. Expiry closes access independently of physical deletion; scheduled cleanup follows expiry and a one-day storage lifecycle backs up interrupted cleanup. Other image providers fetch through short-lived access links. These controls do not promise that a provider retains no inputs or traces.
We also use private storage, encrypted connections (TLS), access checks for each account, and logged decryption attempts. Read the plain-language photo protection explanation. Report suspected vulnerabilities to apps@usebalise.com.
14. Automated decision-making
Balise uses machine learning to extract and organize information from photos. These outputs are assistive knowledge tools for your account. They are not intended to produce legal effects or similarly significantly affect you as solely automated decisions under GDPR Art. 22. You can correct or delete extracted knowledge.
Automated processing is nonetheless how Balise works, so wherever you live: you can ask a person at Balise to look at anything it decided about you, and you can correct or delete it yourself in the app. In Brazil, the LGPD gives you that review right expressly, on a lower threshold than the GDPR, and we honour it on request without asking whether the threshold is met.
15. Changes
We may update this policy by publishing a new version at this URL with a revised date. We will tell you about material changes at least thirty (30) days before they take effect, in-app or by email, and say what changed — including any new purpose we want to use your data for. For significant changes that require consent under applicable law (including any future optional image-retention feature), we will request consent / opt-in before proceeding.
16. Contact
Balise, Inc
2093 Philadelphia Pike #3795
Claymont, DE 19703
United States
1 Chome-23-5 Higashiazabu
Minato City, Tokyo 106-0044
Japan
2-4 rue Jules Lefebvre
75009 Paris
France
apps@usebalise.com (subject “Balise privacy”)
usebalise.com
Contact and requests
Delete everything we learned: in the app, Profile → Balise data → Delete all Balise data. It runs right away. Your Apple Photos and your sign-in stay as they are.
Close the account itself, export your data, or anything else: email apps@usebalise.com from your account email. Subjects that help us route it: “Balise delete my account”, “Balise export”, “Balise security”, “Balise privacy”. A person answers.
Off the waitlist: same address, one line, done.