Balise Privacy Policy
Draft · Last updated 11 August 2026 · BRK · Groupe Tamara · Not yet reviewed by counsel — not legal advice
Publisher / controller: BRK (legal entity Groupe Tamara). Company-level policy: BRK privacy policy. Product site: usebalise.com. This Balise policy controls for Balise data practices.
Balise is not an on-device-only product. Temporary inference media is uploaded for cloud vision processing, and structured knowledge is stored server-side for your workspace. In the current Service, Balise does not retain image copies.
In short
- Your original photos stay in Apple Photos (or another library you connect later). Balise is not a photo backup service.
- For photos you include in processing, Balise may upload temporary inference renders (bounded derivatives, not full-resolution archives) to Balise / Google Cloud infrastructure so vision models can extract structured evidence.
- Temporary inference media is cleaned up on a short schedule (on the order of hours) with a lifecycle backstop of about one day for abandoned objects.
- In the current Service, Balise does not retain image copies. Inference renders are ephemeral only. Structured knowledge (text / facts) is what we keep in your workspace.
- A future optional preview-retention feature — keeping display-sized copies only if you explicitly ask — is not implemented today, would be off by default, and would require a policy update before shipping. It is not a current user-facing feature.
- We do not use your content to train models, and we instruct AI providers not to train on Balise inference content.
- Balise does not offer face recognition / a people identity graph as a product. Biometric face templates are not uploaded as persistent cloud embeddings.
- You must be 16+ to use Balise. Parents photographing their own children for personal knowledge is an expected personal use; seeing pictures means resolving back to Apple Photos.
- You can request deletion of your account and workspace data. In-app account deletion is a commitment for App Store readiness; if it is not yet available in your build, email us and we will delete.
- We do not sell your photos or knowledge to advertisers.
Who we are
Groupe Tamara (public brand BRK) publishes Balise and acts as data controller for personal data processed in connection with the Balise service, except where a third party (for example Apple) acts as an independent controller for its own platform services.
Contact: apps@groupe-tamara.com · groupe-tamara.com · BRK Support
Counsel to insert registered address, company number, and EU representative if required.
Scope
This policy covers the Balise iOS app (SwiftUI, iOS 17+), including TestFlight / beta builds; Balise backend APIs and storage; and related support communications about Balise. It does not cover unrelated third-party sites or Apple’s own platform processing except to describe how Balise interacts with them.
Personal data we process
Account and authentication
Clerk user id, Sign in with Apple identifiers, session tokens, and email if provided by the auth method; workspace id and provisioning state generated by Balise.
Photo library inputs
With your permission via Apple PhotoKit, Balise may read for authorized assets: image content (to create temporary inference renders for cloud vision — not to archive your Camera Roll); capture / modification timestamps; location metadata when present; album membership for inclusion / exclusion rules; technical flags (for example screenshot, favorite, dimensions); and PhotoKit local identifiers and, where available, cloud identifiers used for deduplication and evidence linking.
- You choose the sample or scope Balise should consider.
- Hidden albums and shared albums are excluded by default.
- Limited Photos access may apply: Balise can only see assets Apple makes available under that grant.
- Photo-library permission does not mean every asset is uploaded immediately or at all.
Temporary inference media
Bounded inference renders uploaded for cloud vision processing. These are short-lived processing copies, not an archive of your Camera Roll. They are deleted after processing on a hours-scale schedule, with a ~1 day lifecycle backstop for abandoned objects.
Image retention (current Service: none)
In the current Service, Balise does not retain image copies — neither originals nor display-sized “retained renditions.” Originals stay in Apple Photos (or another Connected library). Inference renders are ephemeral only.
We may later offer an optional feature that keeps display-sized previews only for images you explicitly ask us to keep. That feature is not available in the shipping product today, would be off by default, would require a separate explicit opt-in, and would be described in an updated version of this policy before it ships.
Structured knowledge (durable)
Observations and extracted facts (including structured descriptions of photos that may depict children or other people when you included them in a sample); provenance; domain / interest configurations; search indexes and embeddings of structured content; corrections and preferences; visual asset records used for deduplication and processing state (hashes, identifiers, status — not your original file).
Local processing
On device, Balise may use Apple frameworks for OCR, quality checks, embeddings / clustering, and face detection or grouping for local policy. Persistent face embeddings / biometric templates are intended to remain on-device. Cloud state may include opaque person references, user-assigned names, bounding boxes, or confidence where supported — not a cloud face-recognition identity service.
Operational, diagnostics, and support
API logs, IP address, device / app version, crash or performance signals if collected; Redis / Memorystore operational state (job progress, locks, manifests, short-lived tokens); and support email content if you contact us.
Purposes and legal bases
Counsel to confirm legal bases. Draft GDPR-style mapping:
- Account, library processing, knowledge features, ephemeral inference — contract performance.
- Security, reliability, abuse prevention — legitimate interests; legal obligation where applicable.
- Support — contract / legitimate interests.
- Compliance and deletion tombstones — legal obligation.
- Future optional preview retention (not offered today) — explicit opt-in (consent and/or contract) if/when shipped.
We do not sell personal data. We do not use your photos, inference renders, structured knowledge, or other customer content to train machine-learning models. We instruct AI subprocessors (including Vertesia, OpenAI, and Google Vertex AI / Gemini where used) not to use Balise inference content to train their models. Providers process content only to deliver inference for your workspace. Counsel to confirm DPAs match this promise.
How processing works
- You authorize Photos and select scope / exclusions.
- On-device policy decides whether an asset may be processed locally only, denied, or allowed for ephemeral cloud inference.
- If allowed, Balise creates an inference render and uploads it (typically via a short-lived signed URL) to a private Balise inference bucket on Google Cloud Storage.
- Vision models (orchestrated by Vertesia; currently including OpenAI and Google Vertex AI / Gemini paths) extract structured evidence.
- Structured results are written to your workspace.
- Temporary inference objects are deleted after acknowledged persistence of structured results, with object-lifecycle rules as a backstop (about one day).
- Image copies are not retained in the current Service. A future explicit opt-in preview-retention path is reserved in infrastructure but is not enabled as a user-facing feature today.
Continuous processing of new photos may be offered and may be incomplete or unavailable in a given build. The app UI for your build is the source of truth for whether newly added photos are being ingested.
Processors and subprocessors
Company-confirmed vendors (aligned with Terraform / engineering for the Balise GCP project):
- Clerk — authentication and sessions.
- Google Cloud — Cloud Run (API); Cloud Storage (private inference bucket; a retained-media bucket exists in Terraform for a future opt-in path and is not used for shipping retention today); Memorystore Redis (operational state); Secret Manager; Artifact Registry; Vertex AI / Gemini when Vertesia routes inference there.
- Vertesia — durable workspace knowledge, search, agents / workflows; inference orchestration; GCS reader and GCS URL-signer identities for authorized read of temporary inference objects.
- OpenAI — vision / model inference via Vertesia’s OpenAI batch adapter (signed HTTPS URLs derived from temporary inference objects).
Apple provides platform services (OS, PhotoKit, Sign in with Apple, App Store / TestFlight) and is not a Balise AI subprocessor.
Transfer mechanisms (SCCs, adequacy decisions, etc.) remain for counsel to attach. The named list is confirmed by the company.
International transfers
Balise infrastructure and processors may process data in the European Union and other countries, including the United States (current GCP region includes us-central1; Vertesia / OpenAI / Vertex paths may also process outside the EEA). Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for transfers from the EEA/UK to countries without an adequacy decision. Counsel to document exact mechanisms; do not claim EU-only residency unless confirmed.
Retention
- Inference renders — hours-scale cleanup after processing acknowledgement; lifecycle backstop about one day for abandoned objects.
- Image copies / retained renditions — not retained in the current Service. Future optional opt-in (if shipped): only images you explicitly ask us to keep, until you delete them or delete the workspace.
- Structured knowledge — until you delete it or delete the workspace / account.
- Auth / account records — for the life of the account; then deleted or anonymized.
- Redis / Memorystore operational state — short-lived / cache-oriented.
- Support emails — as needed to handle the request and ordinary business / legal records.
- Deletion audit tombstone — minimal non-content record that deletion completed.
If an original photo is deleted from Apple Photos, related structured records may remain marked as evidence-unavailable until you delete them.
Your rights and controls
Depending on build, you may choose Photos access and sample / album scope; rely on default exclusion of hidden and shared albums; correct or delete structured knowledge; and sign out. Optional image retention controls are not offered in the current Service.
Depending on where you live (including under the GDPR if you are in the EEA/UK), you may have rights to access, rectify, erase, restrict, port, and object to certain processing, and to withdraw consent where processing is consent-based.
Export. You can request an export of workspace-held data such as profile properties, observations / facts / provenance, and domain configuration. Exports do not claim to include Apple Photos originals Balise never stored, and do not include retained image derivatives that the current Service does not keep.
Account / workspace deletion. We are committed to providing in-app account deletion meeting App Store requirements before App Store release. Current beta builds may still be catching up. If in-app deletion is not yet available or fails, email apps@groupe-tamara.com with subject “Balise delete my account”. We will delete your workspace data — including structured knowledge, temporary objects we still hold, and associated operational state — and will delete or anonymize the Clerk identity as requested, retaining only a minimal non-content audit tombstone if needed to prove completion.
You may lodge a complaint with a supervisory authority. In France, that is the CNIL.
Counsel to add CCPA/CPRA and other US state disclosures if US users are in scope. Draft position: we do not sell personal information for money and do not share it for cross-context behavioral advertising.
Children and age eligibility
You must be at least 16 years old to create a Balise account (or the higher age of digital consent where you live). Until a parental-consent flow exists, 16+ is the default. Balise is not directed at children under these thresholds. If you believe a child has provided us personal data through Balise, contact us and we will take appropriate steps, including deletion.
People who appear in your photos
Your library may contain images of other people (including children). When you include such photos in a sample, Balise may temporarily process those images for ephemeral inference and may store structured knowledge about them (descriptions, events, places) in your workspace. In the current Service, Balise does not keep the image files themselves. Parents photographing their own children for personal knowledge is an expected personal use; seeing the pictures means resolving back to Apple Photos. We do not run a face-recognition identity network. You (the account holder) remain responsible for having the right to process photos that include other people.
Security
We use private buckets for inference media, short-lived upload URLs, workspace-scoped credentials, encryption in transit (TLS), and access controls intended to isolate workspaces. No method of transmission or storage is perfectly secure. Report suspected issues to apps@groupe-tamara.com (subject: “Balise security”).
Automated assistance
Balise uses machine learning to extract and organize information from photos. Outputs are assistive knowledge tools for your account. You can correct or delete extracted knowledge. Counsel to confirm GDPR Art. 22 framing.
Changes
We may update this policy by publishing a new version at this URL with a revised date. Material changes will also be called out in App Store / TestFlight release notes or in-app notice when practicable. Where the law requires consent for a significant change (including any future optional image-retention feature), we will request it before proceeding.
Contact
BRK · Groupe Tamara · apps@groupe-tamara.com (subject “Balise privacy”) · BRK Support
This draft must be reviewed by counsel before public launch. Align App Store nutrition labels with the final text and the shipping binary.