Time To Swipe Get the app

Privacy

Giving an app your entire photo library

It is the most sensitive permission on the phone, and the app asking for it is a utility you found in a store listing. Here is how to check the claims rather than take them.

What you are actually handing over

Photo library access is not one permission, it is several, and the extra ones are easy to forget about because no dialog mentions them.

This is why “it works on the device” is not a marketing line. It is the difference between an app that can leak all of that and an app that cannot.

Four checks you can do yourself

You do not have to trust anyone’s privacy page, including ours. All four of these are things you can verify.

  1. Airplane mode. Turn it on and use the app. If reviewing, filtering and queueing deletions all still work, the analysis is genuinely local. If it stalls or shows a spinner, something was going to a server.
  2. Read the store privacy label. Apple’s App Privacy card and Google Play’s Data safety section are declarations the developer makes under the store’s rules. Look specifically for “Photos or videos” under data collected. An on-device cleaner should not list it.
  3. Check whether it wants an account. There is no technical reason a photo cleaner needs to know who you are. If it insists on a sign-up before it will let you delete your own photos, the reason is commercial.
  4. Check what the free version is funded by. Free is fine — ads, a paid tier, both. What matters is whether the ad network gets a device advertising identifier and whether personalised advertising is on by default. That should be findable in the privacy policy in under a minute, and if it is not, that is itself the answer.

What Time To Swipe does, in full

Your photos never leave the phone. Not as a policy — as a property of the app. It reads your library through the operating system’s own photo APIs and contains no upload path for an image, a thumbnail, an EXIF field or a location tag. There is nothing in it that could send one.

There is no account, no sign-up, no email address and no password. Your counters — swipes, deletions, space queued — are computed and stored on the device and are never transmitted. We run no analytics SDK, no crash reporter and no event pipeline, so we do not know how many photos you deleted or whether you have ever opened the app.

What does leave, stated plainly and completely:

The paid tiers remove ads by not starting the ad SDKs at all, so they collect nothing rather than collecting less.

The honest qualification, which the privacy policy also makes: before ads, “nothing is transmitted” was true of the whole app. It is now true of us, and the ad networks keep their own diagnostics. We would rather write that sentence than quietly stop making the claim.

And this website

The pages you are reading hold to a narrower version of the same standard. This site is a set of static files: no fonts, frames or images from any other domain, no account, no form, and nothing that could reach a photo. It does run two third-party tags — Meta’s advertising pixel and Google’s ads tag — so we can tell which of our ads actually brought somebody here, and whether they run depends on where you are.

In the EU, the UK and Switzerland the tags load only if you accept them in a bar on your first visit; ignoring the bar means no. Everywhere else they run by default, and the control in the footer — “Do Not Sell or Share My Personal Information” in the United States — switches them off with one tap, as does a Global Privacy Control signal from your browser. When they run they set Meta’s and Google’s cookies and tell them that you viewed a page and whether you tapped a store link, and nothing else; the privacy policy’s “This website” section lists exactly what that carries.

The site’s Content-Security-Policy still starts from allowing no external origin and then names Meta’s and Google’s hosts, and only those, so the browser itself refuses anything else. The sentence in the footer is generated from what the site actually contains rather than maintained by hand: a page that loads a tracker and says it does not is not a state this site can be in.

What we cannot promise

Two limits, because a privacy page that lists only strengths is not a privacy page.

The host of this website and the settings file keeps standard access logs — IP address, timestamp, path, user agent — as every web server does. We do not read, aggregate or analyse them, but they exist.

And the free tier’s ad networks collect their own diagnostics and their own record of how you interacted with an ad. That is theirs, not ours; we never receive it. The way to have none of it is a paid tier, which stops the SDKs from running at all — not because paying should be required for privacy, but because that is the honest description of what the money changes.

Common questions

Do photo cleaner apps upload your photos?

Some do and some cannot. Apps offering similarity or duplicate detection sometimes upload photos or derived features because that analysis is hard to do on a phone; that should be stated plainly in the privacy policy and the store privacy label. The quickest test is airplane mode — if the app still works fully offline, the processing is local.

Does Time To Swipe upload my photos?

No. There is no upload path in the app for an image, thumbnail, EXIF field or location tag, so it is not a setting that could be switched on by accident or a promise that depends on our conduct. Put the phone in airplane mode and everything except ads behaves identically.

Does it need an account?

No. There is no sign-up, no email address and no password. You open it and it works. Nothing you do in the app is attached to an identity, because there is no identity to attach it to.

Can Time To Swipe see which photos I deleted?

No. Your counters are computed and stored on the device and there is no pipeline that could send them. We do not know how many photos you have, how many you deleted, which ones, or whether you have opened the app at all.

How is it free?

The free tier shows ads from three networks — Start.io, Google AdMob and Unity Ads — and has a swipe allowance: 100 swipes on install, 100 more every day, and an optional rewarded video worth 100 more whenever you run out, as often as you like. Ads are non-personalised for everyone, and where the law requires it the app shows Google’s consent prompt. The paid tiers remove ads entirely and stop the ad SDKs from running at all; they do not unlock any feature.

Get the app

Free on iPhone and Android. No account, no sign-up, and your photos stay where they are.

Available now on the App Store and Google Play.

Free to download. No account, no sign-up.

Last updated 2026-09-03