Photos access and local analysis
Unfill asks for access to your Photos library so it can analyze storage, identify cleanup opportunities, prepare compression, and show media for your review. That analysis happens locally on your device. Unfill does not upload your photos or videos to this service.
Assistant context
The assistant is optional and runs only when you send it a message. Unfill may send your message, a short recent conversation, and aggregate app facts such as:
- counts of library items, compressible items, duplicates, clutter, and large media;
- estimated media savings and reclaimable-space totals;
- aggregate queue progress and pending-work totals;
- the Unfill screen you are on, including whether the library is scoped to photos or videos, and your current sort order; and
- your device language tag, so the reply comes back in your language.
These facts describe the library as a whole. They do not identify an individual asset. The assistant can open a local screen or change your sort order; it cannot delete, commit, compress, or start work.
Your device storage is never sent. Total, used, and free space are read on device to draw Unfill's own screens and are deliberately excluded from everything the assistant receives.
Cloud processing
Assistant requests are received by a Cloudflare Worker at the edge and then forwarded to OpenRouter, which routes the request to a model provider that generates the reply. Only your message, a short recent conversation, and the aggregate facts described above are sent. Cloudflare, OpenRouter, and the model provider each process the request under their own terms. A network address is hashed into a key only for a short-window abuse limit; the raw address is not logged, stored by Unfill, or included in the model prompt. This Worker does not cache assistant replies and does not write conversations to a database.
Replies stream back as they are generated, so partial text arrives over the connection before the answer is complete. The assistant runs only in the cloud: if a request fails, Unfill shows a retryable error rather than answering from the device.
Diagnostics, purchases, and service providers
Unfill may collect limited app diagnostics and product analytics—such as app version, device class, feature use, and error events—to keep the app reliable. This does not include photo-library content. Purchases are handled by Apple and may be supported by a subscription-management provider; those providers process transaction and entitlement data under their own privacy terms.
Retention and sharing
This Worker does not store assistant conversations in a database. We do not sell personal information. We share limited data only with service providers needed to operate Unfill, to comply with law, or to protect the service and its users.
Your choices
You can use Unfill without the assistant, change Photos access in system Settings, and stop future assistant processing by not sending another message. Removing the app removes its local app data subject to iOS and iCloud behavior.
Contact and changes
Questions or privacy requests can be sent to support@unfill.app. We may update this policy as Unfill changes; the effective date above will show the latest revision.