MyGallery Privacy Policy
MyGallery ("the App") is a simple gallery app that lets you view and manage the photos and videos on your phone, organized by folder. When you set up a cloud storage connection, photos and videos stored in the cloud can be displayed in the same way as media on your device, and the connection can also be used as a backup destination. The App does not operate its own backend server; this processing takes place on your device, or directly between your device and the cloud storage you set up. This Privacy Policy ("this Policy") explains how the App handles information.
1. Information We Collect and Store
To provide its features, the App may store or use the following information on your device.
1.1 Information About On-Device Media
- The image and video files themselves
- Metadata such as file name, storage location, URI, size, modified date, and capture date
- Capture information available from EXIF and similar data
- Thumbnails, previews, and caches used for video playback
- The list of media in the trash and information needed to operate on it
This information is used for on-device gallery display, improved searchability, sorting, grouping, copying, moving, deleting, restoring, and cache display.
1.2 App Settings
- Language and theme settings
- Display settings, sort settings, grouping settings
- Folder pinning settings
- Cloud sync settings
- Setting for sending usage analytics data
- The list of cloud settings
- The state of in-app review requests
These settings are stored mainly in the App's on-device settings storage.
1.3 Location Information
To provide the map feature, the App may use the following location information.
- Capture locations attached to photos and videos (GPS location information contained in EXIF)
- The device's approximate or precise location when you use the current-location display on the map screen
The capture location of a photo or video is used to display media that contains location information on a map, so you can browse it by where it was taken.
The device's location (your current location) is used to show your current location on the map. When you tap the current-location button on the map screen and the device's location permission has not been granted, the App shows a separate consent prompt before requesting that permission. Only if you agree does the App go on to request the device's location permission, and only if that permission is granted does it obtain and display your current location. The current location thus obtained is not stored on the device. If you do not agree, your current location is not obtained or displayed, but the other map features (such as browsing media by capture location) remain available. You can stop the App from obtaining your current location at any time by disabling the device's location permission.
The App does not intentionally send location information as usage analytics data. Information sent to the Google Maps Platform for map display is described in "5. Transmission to Third-Party Services."
1.4 Cloud Connection Information
If you use Google Cloud Storage, the App may store or use the following information.
- Your Google account email address
- The Google Cloud Storage bucket name
- The access token required to access Google Cloud Storage
If you use S3-compatible storage, the App may store or use the following information.
- Endpoint
- Bucket name
- Access key ID
- Secret access key
If you use a shared folder (SMB), the App may store or use the following information.
- Host name or IP address
- Share name
- Folder within the share
- Workgroup
- User name
- Password
Secret access keys, shared folder passwords, and Google access tokens are stored in the device's secure storage.
The App can display cloud connection information as a QR code on screen so that another device can read it with its camera and import the settings. Both generating and reading the QR code take place on the device, and the information is not sent anywhere. The secret access key for S3-compatible storage and the password for a shared folder are included in the QR code. For Google Cloud Storage, only the bucket name is included; the account email address and access token are not.
1.5 Usage Analytics Data
To improve the App, the App may send usage analytics data using Google Analytics for Firebase. You can stop this from the settings screen.
Details of the information that may be sent are described in "5. Transmission to Third-Party Services." The App does not intentionally send image or video files themselves, file names, cloud credentials, access keys, or the contents of objects in a bucket as usage analytics data.
2. Purposes of Use
The App uses the information it collects or stores for the following purposes.
- To display images and videos stored on your device and in the cloud
- To display images and videos with location information on a map, so you can browse them by where they were taken
- To display your current location on the map screen
- To copy, move, delete, restore, and sync files
- To generate thumbnails, previews, and caches to speed up display
- To retain app settings, cloud settings, and display state
- To connect to Google Cloud Storage, S3-compatible storage, or a shared folder
- To display cloud connection information as a QR code, and to import settings by reading a QR code displayed on another device
- To request an in-app review at an appropriate time and, depending on your action, take you to the store page
- To investigate issues, improve quality, and understand usage
3. Data Controller
The data controller for personal data in the App is UH (mfactory.me; referred to as "we," "us," or "our" in this Policy). We make all decisions regarding the handling of personal data.
Because the App is developed and provided by a single individual, we also serve as the person responsible for handling personal information. Please direct inquiries to the contact listed in "16. Provider and Contact."
4. Legal Basis for Processing
Where the law of your country or region requires a legal basis for the handling of personal data, the App handles information primarily on one of the following bases.
- The processing is necessary to provide a feature you have chosen to use (such as cloud integration or the map display)
- Our legitimate interest in investigating issues, improving quality, and operating the App reliably
- Your consent, for features that are processed only after a separate consent prompt, such as showing your current location on the map screen
5. Transmission to Third-Party Services
The App works with the following third-party services. Information is sent to third-party services over the internet while you use the relevant feature, or while sending of usage analytics data is enabled. Communication uses HTTPS/TLS. The retention period and detailed handling of information at each third-party service follow that provider's own privacy policy and terms of service.
The region each service sends information to is described in the sections below. Where information is handled across national borders, each provider may implement the safeguards required by applicable law under its own policies. For cloud storage providers you choose to specify in the App, handling follows that provider's own privacy policy, terms of service, and settings.
5.1 Google Analytics for Firebase
When sending usage analytics data is enabled, the App sends usage analytics data to Google Analytics for Firebase (a service provided by Google).
Information that may be sent:
- Usage such as app launches and settings operations
- Application and device information such as the app identifier, device, OS, app version, language, and country or region
Service provider:
- Google LLC
Sent-to region:
- The United States and other countries where Google operates
Related policies:
- Google Privacy Policy: https://policies.google.com/privacy
- Firebase Privacy and Security: https://firebase.google.com/support/privacy/
5.2 Google Maps Platform
The App's map feature uses Google's Google Maps Platform (Maps SDK for Android) to display maps. In the course of displaying and operating the map, the following information may be sent to Google. Information sent is handled in accordance with Google's policies.
Information that may be sent:
- IP address, device information, app usage
- Map display position, zoom level, and operations performed on the map
- The device's approximate or precise location when you use the current-location display
Service provider:
- Google LLC
Sent-to region:
- The United States and other countries where Google operates
Related policies:
- Google Privacy Policy: https://policies.google.com/privacy
- Google Maps Platform Terms of Service: https://cloud.google.com/maps-platform/terms
5.3 Google Sign-In / Google Cloud Storage
If you set up Google Cloud Storage, the App authenticates you through Google Sign-In and performs operations such as listing, downloading, uploading, copying, moving, and deleting objects in the bucket you specify.
Information sent or used:
- Authentication results from Google Sign-In
- Your Google account email address
- The access token required to access Google Cloud Storage
- The name of the Google Cloud Storage bucket you specify and information about its objects
- Images, videos, and related metadata that you perform cloud operations on
Service provider:
- Google LLC
Sent-to region:
- The United States and other countries where Google operates
- Depends on the location setting of the Google Cloud Storage you specify
Related policies:
- Google Privacy Policy: https://policies.google.com/privacy
- Google Cloud Privacy Notice: https://cloud.google.com/terms/cloud-privacy-notice
- Google API Services User Data Policy: https://developers.google.com/terms/api-services-user-data-policy
The App does not obtain, store, or view your Google account password during Google Sign-In authentication.
5.3.1 Sharing, Transferring, and Disclosing Google User Data
The App uses your Google account email address, authentication information, access tokens, Google Cloud Storage bucket names, object information, images and videos, and related metadata obtained or used through Google Sign-In or the Google Cloud Storage API (collectively, "Google User Data") only to provide the cloud storage integration feature you set up.
The App does not sell Google User Data and does not use it for advertising, user tracking, or any purpose not described in this Policy. Except as set out in this Policy, the App does not share, transfer, or disclose Google User Data to third parties.
Google User Data may be shared, transferred, or disclosed only in the following cases:
- To Google Cloud Storage, in order to perform operations such as listing, downloading, uploading, copying, moving, and deleting on the Google Cloud Storage bucket you specify
- To Google Sign-In / Google OAuth-related services, in order to authenticate you with your Google account
- To a third-party app you explicitly choose, when you explicitly choose to open a file with that external app
- To the relevant cloud storage service, when you explicitly choose to do either of the following with a file downloaded from Google Cloud Storage to your device: uploading it to S3-compatible storage or another cloud storage service supported by the App, or setting up one-way upload sync for a folder to such a service
- When disclosure is required under applicable law, a court order, or a valid request from a government authority
Except as described above, the App does not share, transfer, or disclose Google User Data to third parties.
5.4 S3-Compatible Storage
If you set up S3-compatible storage, the App connects to the endpoint you specify and performs operations such as listing, downloading, uploading, copying, moving, and deleting objects in the bucket you specify.
Information obtained from S3-compatible storage and the connection information you set are used solely to provide the cloud storage integration feature you set up. The App does not use this information for advertising, user tracking, or any purpose not described in this Policy.
Information sent or used:
- The endpoint you specify
- Bucket name
- Access key ID
- Credentials required to sign requests
- Object information in the bucket you specify
- Images, videos, and related metadata that you perform cloud operations on
Service provider:
- The S3-compatible storage provider you specify
Sent-to region:
- The endpoint you specify and the service region of the relevant provider
Supported services may include AWS S3, Cloudflare R2, MinIO, Backblaze B2, DigitalOcean Spaces, Wasabi, Akamai Object Storage, and others. How each service handles information is governed by that provider's own privacy policy and terms of service.
5.5 Google Play (In-App Review and Store Page)
The App uses the Google Play In-App Review API for its in-app review feature. When certain conditions are met, the App may request that Google Play display a review dialog. You can also open the App's store page from "Rate & Review the App" in the settings screen.
When using these features, Google Play determines whether to show the review dialog and displays the store page, and in that process the following information may be sent to or processed by Google. Information sent is handled in accordance with Google's policies.
Information that may be sent or processed:
- The App's package name and app version
- Device information, Google Play usage, and information about the account signed in to Google Play
Service provider:
- Google LLC
Sent-to region:
- The United States and other countries where Google operates
The content and rating of a review are entered and submitted by you on Google Play, and are handled in accordance with Google's and Google Play's policies. The App does not obtain or store the content of your review or rating itself.
The App may send the fact that it requested a review, and the fact that you interacted with the store page link, as usage analytics data described in "5.1 Google Analytics for Firebase." This usage analytics data does not include the content of your review or rating.
Related policies:
- Google Privacy Policy: https://policies.google.com/privacy
- Google Play Terms of Service: https://play.google.com/intl/en/about/play-terms/
6. Handling of Images and Videos
Unless you set up cloud storage, the App does not send image or video files themselves to any external service. For local images and videos, the App performs on-device processing such as viewing, generating thumbnails, creating caches, copying, moving, deleting, and restoring.
If you use cloud storage, the App, according to the operations you specify, uploads files from your device to cloud storage, and lets you view, download, copy, move, delete, and save changes such as image rotation for images and videos stored in cloud storage.
If a video cannot be played with the internal player, depending on your device environment you may be able to choose to play it with an external player. In that case, the video file is passed to the external app you choose.
7. Device Permissions
The App uses the following Android permissions to provide its features.
- Permission to access images and videos
- Permission to access the location information (capture location) attached to images and videos
- Location permission (approximate or precise location), used when you show your current location on the map screen
- Permission to access nearby devices and the local network, used when connecting to a shared folder
- Camera permission, used when reading a QR code that contains cloud connection information
- Permission to read and write external storage on older Android versions
- Internet access permission
These permissions are used to display on-device media, perform file operations, display the map, show your current location, connect to the cloud, read QR codes, and send usage analytics data. Location permission is used only when you use the current-location display on the map screen; even if you do not grant it, the other map features remain available. Camera permission is used only when you read a QR code that contains cloud connection information. The camera image is processed on the device to read the QR code and is neither stored nor transmitted. Even if you do not grant it, you can still add cloud settings by entering them manually.
8. Retention Period
Settings, metadata, caches, and cloud connection information stored on your device may be retained until you delete the App's settings, delete your cloud settings, clear the cache, or uninstall the App.
Files and metadata stored in cloud storage are retained according to the retention period and settings of the cloud storage provider you use.
Usage analytics data sent to Google Analytics for Firebase is retained according to Google's and the Firebase project's settings.
9. Deleting or Stopping Information
You can delete or stop sending information in the following ways.
- Stop sending usage analytics data from the settings screen
- Delete cloud settings within the App
- Delete the App's data or cache from your device's app settings
- Disable the App's location permission from your device's app settings
- Uninstall the App
- Delete or change files or permissions in cloud storage from each cloud provider's management console
- Revoke the App's access to your Google account from your Google account settings
10. Sale of Personal Data
The App does not sell any information to third parties in exchange for money or other consideration. The App also does not share information with third parties for advertising or user-tracking purposes beyond what is described in this Policy.
11. Your Rights
Depending on where you live, you may have rights under applicable data protection law to access, correct, or delete your personal data.
You can exercise these rights in the following ways.
- Data stored only on your device can be deleted by deleting the App's data or uninstalling the App.
- Cloud-related data is managed by you or by the cloud provider you set up; you can delete or change it from that provider's management console.
- Usage analytics data (if you have enabled sending it) is processed by Google in a way that does not let us identify individual users. As a result, we cannot retrieve or delete a specific user's data. You can stop sending it from the settings screen.
Please try the methods above first. If you still need further assistance, please contact us at the address listed in "16. Provider and Contact." We will provide assistance to the extent reasonably possible.
If a public supervisory authority or complaint channel for personal data matters exists in your country or region, you may also raise your concerns directly with that authority.
We will make reasonable efforts to respond to inquiries within a reasonable time. Where the law of your country or region sets a response deadline, we will follow that deadline.
12. Security Measures
To protect Google User Data and sensitive information required for cloud connections (access tokens, secret access keys, etc.), the App takes the following concrete security measures.
Specifically, the App:
- Stores secrets such as Google access tokens, S3 secret access keys, and shared folder passwords in the device's secure storage.
- Uses HTTPS/TLS encrypted communication for communication with Google APIs such as Google Cloud Storage and Google Sign-In.
- For endpoints you can specify yourself, such as S3-compatible storage, allows only endpoints using `https://` and uses HTTPS/TLS for communication with external services.
- Does not intentionally send Google access tokens, S3 secret access keys, shared folder passwords, image or video files themselves, file names, or the contents of objects in a bucket as usage analytics data to Google Analytics for Firebase.
- Blocks screenshots and screen recording while a QR code containing cloud connection information is displayed, and closes the display automatically after a period of time.
- Limits access to Google User Data, for the purpose of providing the cloud storage integration feature you set up, to the following scope:
- Processing operations you explicitly choose — such as listing, viewing, uploading, downloading, deleting, renaming, moving, and copying — on objects, object names, metadata, and bucket information stored in the Google Cloud Storage you connected within the App
- Processing the operation when you explicitly choose to upload, or set up one-way upload sync for, a file downloaded from Google Cloud Storage to your device, to S3-compatible storage or another cloud storage service supported by the App
- Lets you delete cloud connection information by deleting your cloud settings within the App, deleting the App's data on your device, or uninstalling the App.
- Lets you revoke access you granted to the App from your Google account's security settings.
That said, risks such as device loss, unauthorized access, vulnerabilities in the OS or external services, and misconfiguration by you cannot be completely eliminated. You are responsible for your own security measures, such as locking your device, enabling multi-factor authentication on your cloud accounts, setting appropriate permissions on access keys, and removing keys you no longer need.
13. Minors
The App is not directed to children under the age of 13 (or, where the law of your country or region sets a higher age, people under that age). The App is not designed primarily for minors, and does not intentionally collect personal information from minors.
Even when a minor uses the App, the scope of information collected and sent is the same as described elsewhere in this Policy. In particular, if you set up a cloud connection such as Google Cloud Storage or S3-compatible storage, images and videos are sent directly from the App to the cloud storage you specify. The App itself does not collect or store this data; its storage and management are governed by the privacy policy and terms of service of the cloud service provider you use.
Setting up a cloud connection requires creating a cloud account and managing access keys, so it should be done under a parent or guardian's management and supervision. Minors should use the App with the consent of, and under the management and supervision of, a parent or guardian. If you have any questions or concerns about the personal information of a minor, please contact us at the address listed in "16. Provider and Contact."
14. Language
The Japanese version of this Policy is the authoritative text. We may provide translations into English and other languages for reference, but if there is any discrepancy between a translated version and the Japanese version, the Japanese version prevails.
15. Changes to This Policy
This Policy may change in response to changes in law, changes to the App's features, or changes to the services it uses. A revised Policy takes effect once it is posted within the App, on the distribution page, or in related documentation.
16. Provider and Contact
Provider: UH (mfactory.me)
Official page: https://mygallery.mfactory.me/
Contact: uh@mfactory.me
Revision History
- Effective: May 1, 2026
- Amended: May 15, 2026 (Article 3.2 and Article 8)
- Amended: July 13, 2026 (Articles 1, 2, 3, 5, and 7 regarding location information and the Google Maps Platform, in connection with the map feature)
- Amended: July 19, 2026 (Articles 1, 2, and 3 regarding the state of in-app review requests and Google Play, in connection with the in-app review feature)
- Amended: August 3, 2026 (Article 9)
- Amended: August 30, 2026 (Added descriptions of cloud connection information, purposes of use, device permissions, and security measures in connection with shared folders and the transfer of cloud connection information by QR code; added new articles on the Data Controller, Legal Basis for Processing, Sale of Personal Data, Your Rights, and Language; added the service provider for each service, the sent-to region, and cross-border handling to Transmission to Third-Party Services; stated explicitly in Article 1 that the current location obtained for current-location display is not stored on the device; renamed the article on children's use to Minors; and renumbered all articles accordingly)