What Palomino stores
Palomino writes data only to your Mac, in three places:
- App preferences: settings like filmstrip position and auto-advance, stored in macOS UserDefaults. These never leave your device.
- Session files: a
.palomino-session.jsonfile written inside each folder you open, containing the ratings, picks, rejects, and color labels you assigned. This file stays with your photos and is never transmitted anywhere. - XMP sidecar files: standard
.xmpfiles written alongside each photo, containing ratings and labels in a format compatible with Lightroom, Capture One, and other editors. These stay on your disk.
Recent folder history is also stored locally in UserDefaults so the app can show you folders you opened before.
Network activity
Palomino has the macOS network entitlement (com.apple.security.network.client). The App Store requires it for in-app purchases, and that is the only thing Palomino uses it for. Apple's StoreKit framework uses it to load the Pro price, complete a purchase, and restore a purchase you already made. Those App Store transactions are handled by Apple using your Apple Account credentials, and Palomino does not see, store, or transmit your Apple Account information.
macOS grants that entitlement as all or nothing, so it covers any outbound connection rather than only the App Store. Palomino still contacts no servers other than Apple's, and it makes no network requests of its own. Your photos, ratings, folder names, and preferences are never sent anywhere.
Apple's privacy policy governs what Apple collects during those transactions: apple.com/legal/privacy
Analytics and tracking in the app
There are none. The Palomino app contains no analytics libraries, crash reporters, advertising SDKs, or telemetry of any kind. No behavioral data is collected.
This website
The palomino-app.com website uses Cloudflare Web Analytics. It is cookie-free, does not fingerprint visitors, and does not track you across other sites. It collects only aggregate page-view and performance metrics. Read more at cloudflare.com/web-analytics. The app itself sends nothing.
Third-party services
Palomino the app has no third-party dependencies. Every framework it uses is from Apple (AppKit, SwiftUI, ImageIO, StoreKit, Accelerate, CoreGraphics, OSLog). No data from the app passes through any third-party service.
Your privacy choices
Because Palomino collects no personal data and performs no tracking, there is nothing to opt out of. You can:
- Delete session files (
.palomino-session.json) from any folder to remove Palomino's records of your ratings for that shoot. - Delete XMP sidecar files to remove embedded ratings and labels.
- Use macOS privacy controls (System Settings › Privacy & Security) to review or revoke Palomino's folder access at any time.
California residents: Palomino does not sell or share personal information as defined by the California Consumer Privacy Act, because no personal information is collected.
European residents: No personal data is processed, so GDPR does not apply to Palomino's operation.
Children
Palomino does not knowingly collect any information from anyone, including children.
Changes to this policy
If this policy changes in a meaningful way, the updated version will be posted here and the effective date above will be updated.
Contact
Questions about privacy? Email nkodner@gmail.com.