Legal

Privacy Policy

Pixora is built so there is nothing to collect. This page explains exactly what the app does — and doesn't — do with your data.

Effective date: 14 August 2026

The short version

  • No accounts with Pixora. You don't sign up to use the app.
  • No Pixora servers. The app has no backend. Your photos are never uploaded to us.
  • No ads, no tracking, no analytics. The app does not phone home.
  • No AI training. Your photos are never used to train models — by us or anyone else.
  • Your backups live in your own Telegram account. Pixora never stores, sees, or holds a copy of them.

What we collect

Nothing is collected by Pixora. There are no Pixora servers, no user database, and no analytics SDK in the app. We have no way to receive data from you because there is nowhere for it to go.

Everything the app needs is stored locally on your device:

  • Your Telegram login session (stored by Telegram's official client library on your device, encrypted with a device-generated key)
  • Your preferences (theme, backup settings) and a local cache of thumbnails and recently viewed files
  • Backup configuration (bot tokens used for the optional backup channel), encrypted in your device's secure keychain

How photo backup works

When Pixora backs up a photo, the file travels directly from your device to your own Telegram account using Telegram's official API. The transfer does not pass through Pixora and Pixora cannot read it.

Your backup is not encrypted by Pixora — it lives in your Telegram account under whatever protections Telegram provides to your account. We never claim otherwise.

In addition to your Saved Messages copy, the app can post a secondary backup copy to a Telegram channel configured by the developer, using Telegram's official Bot API. As the channel owner, the developer can read the contents of that channel. If you do not want this secondary copy, disable the backup channel in the app's settings before uploading.

Our guarantee: Pixora itself never stores, sees, or holds a copy of your backups. What we cannot guarantee is what third parties (such as Telegram) do with data you choose to store with them — that is governed by their policies.

Permissions we ask for — and why

  • Media access ("All files access" / read media) — used only to scan your DCIM, Pictures, and Movies folders for the auto-backup feature you can turn off.
  • Notifications & foreground service — used only while files are uploading in the background, to show a progress notification.
  • Biometrics (fingerprint / face) — used only for the optional app lock, entirely on your device.
  • Internet — required to upload and download files to and from Telegram.

All permissions are optional and can be revoked any time in your system settings; features that depend on them simply stop.

Deletion

  • Delete a photo in the app — it moves to the app's Trash and is permanently removed from the app and (if you empty the Trash) from your Telegram Saved Messages after 30 days.
  • Delete everything — uninstall the app and delete the messages from your Telegram account; Telegram provides tools to clear a chat completely.
  • Our data about you — there is none to delete. Uninstalling Pixora removes all local app data.

Security measures

  • Your Telegram session is encrypted on-device with a device-generated key stored in your platform keychain.
  • Backup configuration is encrypted and bound to the app's signing certificate; if the app is tampered with, the stored configuration is destroyed automatically.
  • Optional app lock (PIN or biometrics) protects the app on your device.
  • The app never transmits anything to Pixora — there is no telemetry to intercept.

Third parties

The only third party involved in the product is Telegram (Telegram Messenger LLP), which operates the accounts and channels where you choose to store your backups. Your use of Telegram is governed by Telegram's own Terms of Service and Privacy Policy. Pixora has no agreement with Telegram beyond using its public API as a normal client.

Children's privacy

Pixora is not directed at children under 13 and does not knowingly collect any personal information from anyone — including children. Because we collect nothing, there is no data about children to protect or disclose.

Changes to this policy

If this policy changes, the effective date above is updated. We will never add data collection, advertising, or AI training without rewriting this document to say so — plainly.

Contact

Questions about this policy or your privacy? Write to pixoraapp@proton.me. We answer.