legal
privacy
lockbox is built around intimacy: your full camera roll stays on your phone. if you sign in, only the active nine and memories you like can leave the phone for the specific uses below. this page says what we collect, where it lives, and how to get it deleted.
the short version
- your photo library is read on your iphone so you can curate. we do not upload your full camera roll.
- signed-out cleanup, keeps, private notes, and stats stay on your device.
- if you joined our past early-access list, we stored your email so we could send product access information.
- if you create an account (Apple or email), we store that identity so you can publish and follow live nines.
- if you publish a live pack, only the nine you chose (posters, friend-facing notes, display name) leave your phone.
- when you are signed in and lockbox is active, only your active nine and liked memories are securely processed by polarity lab's vision models on cloudflare-operated infrastructure to build private memory understanding. the rest of your camera roll is not uploaded.
- the compressed image used for ai analysis is not stored as a vision asset. we retain the structured private insight and its lockbox-derived memory until you remove the selection or delete lockbox data.
- we do not sell data. we do not run ads. we do not add third-party trackers to this site.
who we are
lockbox is a product of polarity lab (rhode island, usa). contact: [email protected].
what we collect
on this website
-
past early-access list. before the public App Store release, the site accepted email signups.
we stored the email, a source tag (for example
lockbox-landing), and the time submitted in our account-access database. the public site no longer collects these signups. - operational logs. our service infrastructure may retain short-lived request metadata (ip, user-agent, path, status) for security and reliability. we do not use that for advertising.
- fonts. this site loads ibm plex mono from google fonts. that request is subject to google’s privacy policy.
in the ios app
- photo library access. lockbox asks permission to read (and, when needed, write) your photos so you can swipe, caption, keep, and delete. originals stay in the photos app on your device. you confirm every delete.
- on-device preferences. favorites, captions, session stats, cleanup filters, and similar settings are stored locally on your phone (for example in app storage / userdefaults).
- live pack (optional). if you publish or refresh a live nine, we store for that pack: display name, share token, visibility, slot metadata (caption, media type, optional place/time labels), and poster images (compressed stills, not your full camera roll). polarity lab stores those posters and the pack metadata.
- follows (when enabled). if you follow another person’s live nine, we store that follow relationship between accounts so your feed can load their packs.
- lockbox activity. while you are signed in and lockbox is active, we automatically store activity events from dump sessions, album changes, and nine / lockbox changes: keep/delete/skip, hesitation signals, coarse photo context (age, media type, home/away class — not exact gps), on-device vision features (scene labels, face counts, pseudonymous cluster ids), public captions you already chose to share, album titles you assign, and optional on-device themes derived from private notes. we do not upload unselected camera-roll pixels for this activity stream.
- private selected-photo understanding. after you allow this processing, while you are signed in and lockbox is active, we send polarity lab a bounded compressed jpeg for each photo in your active nine or liked memories. we may include your private note, public caption, and person tags for that selected photo. polarity lab runs its vision models on infrastructure operated by cloudflare, which processes the request for polarity lab under equivalent confidentiality and data-protection requirements. polarity lab uses the image for that request and does not retain it as a stored photo. we retain a structured private summary (such as scenes, activities, objects, broad relationship cues, themes, emotional tone, and summarized visible text) in your private polarity memory. this result is not placed into your caption or shown to friends.
what we do not collect
- your entire camera roll, or photos outside your active nine and liked memories.
- raw unselected dump photos or videos (unless you separately publish a pack poster).
- exact gps coordinates from training events (only coarse place class when location exists).
- advertising identifiers, fingerprinting scripts, or cross-site trackers on this site.
- likes or engagement scores on your nine. lockbox is not a scoreboard.
- payment card data. lockbox does not currently offer in-app purchases.
how we use it
- send product access information or updates you asked for.
- show your live nine to people who have your link (or who you let follow you).
- keep the product working, secure, and honest about bugs.
- while signed-in lockbox is active, build private memory understanding from the photos you explicitly keep in your nine or liked memories.
- study aggregated patterns (for example how many people publish a live nine), not to read private camera-roll contents.
we do not sell your data. we do not share it with advertisers.
where it lives
the website and live-pack services run on systems operated for polarity lab. private selected-photo processing uses polarity lab vision models on cloudflare-operated infrastructure. photo cleanup happens on your device. the app sends only the active nine and liked memories for private memory understanding after you allow it, plus pack posters you explicitly publish. no other library asset is eligible.
sharing and access
- you. through the app and any live pack link you create or rotate.
- people you invite. anyone with your current share link can see the published nine and public captions. rotate the link to cut off old recipients.
- polarity lab. polarity lab receives only eligible selected photos after you allow private processing. we do not browse private camera rolls. staff access to past access-list or pack records is limited to support, security, deletion, and legal requests.
- cloudflare. cloudflare operates the infrastructure that processes eligible selected photos for polarity lab's vision models. cloudflare is required to protect that data consistently with this policy. lockbox does not send the photo directly to a model developer.
export and deletion
- disable lockbox. in the app: settings → lockbox account → disable lockbox. this stops lockbox cloud sync, sharing, follows, activity uploads, selected-photo ai processing, and notifications while preserving lockbox data so you can re-enable later. on-device photo cleanup still works.
- delete lockbox data. in the app: settings → lockbox account → delete lockbox data. this permanently removes your lockbox pack and uploaded media, follows, comments, reports, notification devices, activity events, private selected-photo insights, lockbox-derived memory nodes, and local lockbox state. it deletes data from this specific lockbox connection, preserves your broader polarity account, and does not delete photos from apple photos.
- delete polarity account. in the app: settings → lockbox account → delete polarity account. this permanently removes the shared polarity account and its data across polarity lab apps, including all lockbox cloud data and uploaded media. it does not delete photos from apple photos.
- past early-access list. email [email protected] from the address you used and ask to be removed. we delete the row.
- on-device data. use delete lockbox data in settings or delete the app to clear local lockbox state on that device. photos you deleted from the library follow apple’s photos recovery rules.
- live pack. use delete lockbox data in settings to remove the pack and posters immediately, or email us from the account you used if you cannot access the app.
if you are in the eu or uk and want to exercise gdpr / uk-gdpr rights (access, rectification, erasure, portability, restriction, objection), email the same address. we will respond within 30 days.
children
lockbox is not directed at children under 13. if you believe a child submitted an email or published a pack, contact us and we will delete it.
security
traffic uses https. pack media keys are scoped per account. report a vulnerability privately to [email protected].
changes
if this policy changes in a material way, we will update the date on this page and, when practical, note it in the product or by email. the current version is always at lockbox.polarity-lab.com/privacy.
contact
privacy questions: [email protected].