Effective date: 3 September 2026
Picca is a local desktop application. In ordinary use we (the publisher) do not collect, receive, host, or sell your photographs, tags, captions, GPS coordinates, or face data. All processing happens on your computer. You control your files.
If we ever add an optional cloud account or telemetry, we will update this notice before any data leaves your device.
Your photo library. You (or your organisation) decide which folders Picca indexes. You are typically the controller of that personal data under UK GDPR / EU GDPR, because it stays on your equipment and we cannot access it.
The publisher. We supply the software. We are not given a copy of your catalogue. We are not a processor of your face embeddings unless you separately send us files (for example, a support email you choose to send).
Picca stores catalogue data in a local folder (typically .catalogue-data beside
your photo library), including:
| Data | Purpose |
|---|---|
| Paths, file names, sizes, thumbnails | Browse and search your library |
| Tags, captions, albums | Organisation you create |
| GPS coordinates (from photo metadata or map tools) | Map view and place tagging |
| Face boxes, suggested names, and face embeddings | Optional people grouping |
| Face "profiles" (sample embeddings per named person) | Matching new photos to names you confirmed |
| Downloaded AI model files | Face detection/recognition and optional local vision tagging |
| Cached map tiles | Offline map display |
Original photo files stay where you put them. Picca does not copy your library into a vendor cloud.
When you run face detection, Picca:
face: tag.This is biometric data when it can be used to distinguish people (UK GDPR / EU GDPR Article 9 "special category"; UK Data Protection Act 2018; and similar rules such as Illinois BIPA, which treats face geometry as biometric identifiers).
It is not identity verification. Embeddings are for sorting your pictures. They are not a government ID check and they can mis-identify people.
If GDPR applies to your use of Picca (for example, a business cataloguing staff or customer photos):
If you only catalogue your own family photos on a home PC, you may fall outside GDPR "household" limits in some situations — but you should still treat other people's faces with care.
Picca's publisher does not collect, capture, or store your biometrics on our servers, does not sell, lease, trade, or otherwise disclose biometric data to third parties, and does not profit from sharing face templates, because those templates never leave your machine in ordinary use.
If you use face features, you (the operator of the PC) are the party that possesses the embeddings on disk. You should:
Retention / destruction schedule: embeddings and face profiles are kept on
your computer until you delete them via Edit → Delete all face data…,
delete the catalogue database, or remove the .catalogue-data folder. There is no
automatic upload and no vendor-side retention.
These are not face embeddings or your photo library:
| Activity | What is sent | Destination |
|---|---|---|
| First-time model download | HTTP request for public model files (no photos) | GitHub, Hugging Face, or similar CDNs |
| Map tiles | Tile coordinates (z/x/y), not photos | OpenStreetMap tile servers |
| Place search on the map | The search text you type | OpenStreetMap Nominatim |
| Optional Ollama fallback | Cropped image for tagging (if you run Ollama locally) | Your local Ollama process (127.0.0.1) |
We do not sell this information. OpenStreetMap's own privacy terms apply to their services.
We do not sell personal data or biometric data. We do not use your catalogue for advertising. We do not train our own models on your photos (we never receive them).
Third-party model authors trained YuNet, SFace, Moondream2, and similar models on their own datasets before you downloaded the weights. That training is described by those projects, not by Picca, and does not use your library.
Under UK GDPR / EU GDPR, where they apply, people may have rights of access, rectification, erasure, restriction, objection, and complaint to the ICO (or another EU authority). Because we do not hold your catalogue, you exercise erasure on the device:
.catalogue-data folder..catalogue-data; delete that folder if you want local catalogue data gone.Picca is not directed at children. Do not use face detection on photos of children unless you have a lawful basis (parental responsibility, consent, or another ground the law allows).
Data protection is as strong as your PC, disk encryption, backups, and who can access the
catalogue folder. Treat .catalogue-data as sensitive: it can contain biometric
templates and a full index of your photos.
We do not transfer your catalogue. If you download models or map tiles, those connections go to wherever those public hosts are located (often outside the UK). That is ordinary HTTPS download / map use, not a transfer of your photo library.
We will update this policy if Picca's data practices change. The effective date at the top will be updated accordingly.
For the software: the seller named at purchase.
For UK data-protection complaints:
Information Commissioner's Office.
For Illinois BIPA questions about your local copy of embeddings: you hold that copy; we do not.