Privacy Policy

Nestra · Last updated 16 September 2026

Nestra is an offline vault for photos and videos on your iPhone. It is made by an independent developer, Snir Tam.

The short version: the app has no server, no account and no login, and it never sends your photos, videos or any other personal information anywhere. Everything you put in the vault stays on your iPhone. There is nothing for us to see, because nothing ever reaches us.

What we collect

Nothing. There is no analytics, no tracking, no advertising identifier, no crash reporting, and no third-party SDKs of any kind in the app. Its App Store privacy label is “Data Not Collected”, and that is accurate.

We have no database of users, because there are no user accounts. We cannot identify you, contact you, or look at your vault, because the app never transmits anything to us.

The app does derive something new from your photos, on your iPhone, so that you can search them — see Searching your vault. That is made on your device and stays on your device. “Collect” on the App Store means sending data off the device to us, and we still do not do that, because there is nowhere for it to go.

Where your photos and videos live

Items you import are copied into the app's own private storage area on your iPhone. They are not uploaded, synced to a service of ours, or shared with anyone.

Those files are protected by iOS Data Protection at the .completeFileProtection level. In plain terms: iOS encrypts them with hardware-backed keys tied to your device passcode, and they are unreadable while your iPhone is locked. This is the same protection iOS uses for its own most sensitive data.

The app can search what is inside your vault, and to do that it has to read it.

When you add a photo or a video, the app looks at it on your iPhone using Apple’s Vision framework — the same on-device technology the Photos app uses. Two things come out of it: a short list of words for what appears to be in the picture (“beach”, “document”, “dog”), and any text the picture itself contains. A receipt, a screenshot or a photo of a letter will have its words read out of it.

Those words are saved in the app’s own storage on your iPhone, next to the item they came from, so that later you can type “receipt” and find it. This is the same promise as the rest of the app rather than an exception to it: it happens on your device, offline, and none of it is sent anywhere. There is no server to send it to, and the app makes no network request of any kind other than the App Store purchase check.

Two things worth being straight about:

What was read out of an item is removed from the vault with that item. Delete the app and all of it goes.

Your vault passcode and Face ID

You unlock the vault with Face ID or Touch ID, or with a 4-digit passcode you choose.

There is no password recovery — please read this

Because there is no account and no server, there is no “forgot passcode” email, no reset link, and no support back door.

If you forget your passcode and you do not have Face ID or Touch ID enrolled for the vault, your vault cannot be opened by anyone — including the developer. Nobody holds a copy of your passcode or a master key. This is what makes the vault genuinely private, and it is also a real risk: choose a passcode you will remember, and keep biometric unlock turned on if you can.

Permissions the app may ask for

Every permission is optional. The app works with all of them denied, and it only asks at the moment the permission is actually needed — never up front just in case.

Purchases

The app offers a yearly subscription with a 3-day free trial, and a one-time lifetime purchase. Purchases are handled entirely by Apple through the App Store.

The developer never sees your payment details, card number, or billing address — Apple does not share them with us. Apple's handling of that information is governed by Apple's privacy policy. The app checks your purchase status locally through StoreKit, on your device.

Backups

Your vault contents are included in your own iPhone backups, whether you back up to iCloud or to a computer.

This is a deliberate choice. If the vault were excluded, people would lose everything in it the moment they upgraded to a new iPhone, which is far more likely to cause harm than the backup itself. Those backups are yours: they go to your own iCloud account or your own computer, never to us, and the developer has no access to them. iCloud backups are encrypted by Apple. A backup to a computer is encrypted only if you turn on “Encrypt local backup” in Finder or iTunes, so we recommend turning that on if you back up that way.

Deleting your data

Deleting the app from your iPhone permanently removes everything the vault stored on that device: the imported photos and videos, their thumbnails, the words read out of them for search, and your stored passcode hash. Because none of it was ever sent anywhere, there is nothing else to delete and no request you need to send us.

You can also remove individual items inside the app at any time.

Children

The app is not directed at children under 13, and we do not knowingly collect information from them. Since the app collects no information from anyone, there is nothing for a child or a parent to request the deletion of.

Changes to this policy

If this policy changes, the updated version will be posted on this page with a new “Last updated” date. If the app ever started collecting data — it does not today — that change would be described here and in the App Store privacy label before it shipped.

Contact

Questions about this policy, or about the app: tamsnir@gmail.com.