DadShot 是一款在设备端运行的宝宝照片整理应用。我们的隐私原则只有一条:我们没有服务器,也看不到你的数据。你的照片始终留在你自己的相册里;如果你主动打开 iCloud 同步,档案与记录会存进你自己的 iCloud,我们同样接触不到。
不收集任何数据。DadShot 没有服务器、没有账号系统、没有广告、没有任何第三方 SDK。我们不收集、不存储你的任何个人信息或使用数据,也没有任何途径可以读取它们。
唯一会离开你设备的数据,是你主动打开 iCloud 同步后存入你自己 iCloud 的那部分——见下一节。它归属于你的 Apple ID,不经过我们,我们看不到。
在你授权后,DadShot 读取你的系统相册,用 Apple 提供的端侧框架(Vision、Photos、AVFoundation 等)在本机完成清晰度评分、人脸检测、去重和拼图渲染。「宝宝识别」功能的参考脸特征在本机生成,可随时在设置中清除。生成的高光、手账、壁纸保存回你的系统相册。你的原始照片不会被上传到任何地方,开启同步之后也是如此。
需要说明的是:如果你打开了 iCloud 同步,参考脸特征、宝宝头像、以及高光成片的缩略图会随档案一起存进你自己的 iCloud(详见下一节)。它们不会进入我们或任何第三方的服务器。
收集什么。「宝宝识别」是可选功能。你在设置里挑几张参考照之后,DadShot 用 Apple 的 Vision 框架在你的设备上为每张照片生成一个人脸特征向量(VNFeaturePrintObservation)。存下来的只有这些向量,不存参考照本身,也不存任何身份信息——向量无法还原成照片,也无法用来识别现实中的某个人。
用途。仅用于一件事:生成高光时在你自己的相册里比对,把更像这个宝宝的照片排在前面。全过程在你的设备上完成。
共享。不与任何第三方共享。DadShot 没有服务器,我们也没有任何途径读取这些数据。不做人脸识别以外的用途,不用于广告、分析或训练。
存储位置。默认只存在你设备上的应用沙盒内。若你主动开启 iCloud 同步,它会随宝宝档案存进你自己的 iCloud(CloudKit 私有数据库,归属你的 Apple ID,开发者无法访问、读取或导出)。
保留多久。保留到你删除为止,没有其它期限。我们不保留副本。
怎么删除。设置 → 宝宝识别 → 清除,立即从设备上删除;开启过同步的,删除也会同步到你的 iCloud。删除 App 会一并删除设备上的这些数据(iCloud 里的副本按下一节的路径单独删除)。
DadShot 自 1.4.0 版起提供 iCloud 同步,用于在你换手机或重装 App 后取回记录(更早的版本没有此功能,设置中也不会出现这个开关)。它默认关闭,需要你在设置中主动开启。开启后使用的是 Apple 的 CloudKit 私有数据库:数据存放在你自己的 iCloud 账户下,由 Apple 保管,开发者无法访问、无法读取、也无法导出。
会同步的内容:宝宝档案(乳名、出生日期、性别、头像、用于「宝宝识别」的人脸特征)、高光记录(标题、生成时间、所选照片在你相册中的标识符、成片缩略图)、照片说明,以及 App 设置。
不会同步的内容:你的原始照片。DadShot 只保存照片在你系统相册中的标识符,照片本身始终只在你的相册里(若你另行开启了系统的「iCloud 照片」,那是 Apple 的功能,与 DadShot 无关)。
关闭与删除:在 DadShot 的设置中关闭同步后,此后的改动不再上传。已经存入 iCloud 的数据需要单独删除,路径是:iOS「设置」→ 顶部你的姓名 → iCloud → 管理账户存储 → DadShot → 删除数据。
中国大陆 Apple ID 的 iCloud 服务由云上贵州大数据产业发展有限公司运营,数据存储在中国境内,受 Apple 隐私政策 与其 iCloud 条款约束。
照片详情中的地名,是通过 Apple 系统的地理编码服务(CLGeocoder)将照片中已有的坐标转换为地名。此过程仅向 Apple 发送坐标,不涉及照片内容,受 Apple 隐私政策 约束。你可以通过在系统相机中关闭位置记录来避免。
解锁功能为一次性买断,交易完全由 Apple 的 App Store 处理。我们不会接触、也不会存储你的任何付款信息。购买状态由 Apple 的 StoreKit 在本机校验。
未开启同步时,所有数据(高光记录、宝宝档案、设置)仅存储在你设备上的应用沙盒内,删除 App 即删除全部数据。
开启过 iCloud 同步的话,删除 App 只会删除本机的那一份,iCloud 里的副本仍在你的账户中,需要按上一节的路径单独删除。
DadShot 面向家长使用,不面向儿童,不向任何一方收集儿童个人信息。
如有疑问,请联系:liming.job112@gmail.com
本政策如有更新,将在此页面发布。
DadShot is an on-device baby-photo app. Our privacy principle is simple: we have no server and cannot see your data. Your photos stay in your own library. If you choose to turn on iCloud sync, your profile and records are stored in your own iCloud — still out of our reach.
None. DadShot has no server, no account system, no ads, and no third-party SDKs. We do not collect or store any personal information or usage data, and we have no way to read it.
The only data that leaves your device is what you store in your own iCloud after you turn on iCloud sync — see the section below. It belongs to your Apple ID, never passes through us, and we cannot see it.
With your permission, DadShot reads your photo library and performs sharpness scoring, face detection, de-duplication and collage rendering locally, using Apple's on-device frameworks (Vision, Photos, AVFoundation). Reference face features for "Baby Recognition" are generated on device and can be cleared in Settings at any time. Generated highlights, journals and wallpapers are saved back to your photo library. Your original photos are never uploaded anywhere, including after sync is enabled.
To be clear: if you turn on iCloud sync, the reference face features, the baby's avatar and the highlight thumbnails are stored in your own iCloud along with the profile (see below). They never reach our servers or any third party's.
What is collected. “Baby Recognition” is optional. After you pick a few reference photos in Settings, DadShot uses Apple’s Vision framework to generate a face feature vector (VNFeaturePrintObservation) for each one, on your device. Only those vectors are stored — not the reference photos, and no identity information. A vector cannot be turned back into a photo, and cannot be used to identify a person in the real world.
How it is used. For one purpose only: comparing against photos in your own library when generating a highlight, so pictures that look more like this baby rank higher. This happens entirely on your device.
Sharing. Never shared with any third party. DadShot has no server and we have no way to read this data. It is not used for anything other than the recognition described above — no advertising, no analytics, no training.
Where it is stored. By default, only in the app’s sandbox on your device. If you turn on iCloud sync, it is stored alongside the baby profile in your own iCloud (CloudKit private database, owned by your Apple ID; the developer cannot access, read or export it).
Retention. Kept until you delete it. There is no other retention period, and we keep no copy.
Deletion. Settings → Baby Recognition → Clear removes it from the device immediately; if sync is on, the deletion propagates to your iCloud. Deleting the app removes this data from the device as well (the iCloud copy is deleted separately, as described in the next section).
Starting with version 1.4.0, DadShot offers iCloud sync so your records come back after you switch phones or reinstall (earlier versions do not have this feature, and the switch does not appear in their Settings). It is off by default and must be turned on by you in Settings. It uses Apple's CloudKit private database: the data sits in your own iCloud account, held by Apple, and the developer cannot access, read or export it.
What syncs: the baby profile (name, birth date, gender, avatar, and the face features used for "Baby Recognition"), highlight records (title, creation time, the identifiers of the chosen photos in your library, and a thumbnail of the result), photo captions, and app settings.
What does not sync: your original photos. DadShot only stores each photo's identifier within your own library; the photos themselves stay there (if you separately enable Apple's iCloud Photos, that is Apple's feature and unrelated to DadShot).
Turning it off and deleting: switching sync off in DadShot stops further uploads. Data already in iCloud must be removed separately: iOS Settings → your name → iCloud → Manage Account Storage → DadShot → Delete Data.
Place names shown in photo details are resolved from the photo's existing coordinates via Apple's geocoding service (CLGeocoder). Only coordinates are sent to Apple — never photo content — subject to Apple's Privacy Policy. You can avoid this by disabling location in the system Camera.
The unlock is a one-time purchase handled entirely by Apple's App Store. We never see or store your payment information. Purchase status is verified on-device by Apple's StoreKit.
With sync off, all data (highlight records, baby profile, settings) is stored only in the app's sandbox on your device, and deleting the app deletes all of it.
If you have used iCloud sync, deleting the app only removes the copy on that device. The copy in iCloud remains in your account and must be deleted separately, as described above.
DadShot is intended for parents, not children, and collects no personal information from anyone, including children.
Questions? Email liming.job112@gmail.com.
Updates to this policy will be posted on this page.