Ingest

Ingest / Privacy

Your photos. Your control.

Last updated October 5, 2026. Applies to Ingest 0.9.5 (41).

Ingest has no account, no analytics, and no server of mine that receives your photographs. Optional Apple Photos, address and map services, Claude Second Opinion, and software updates use the network as described below.

Your photographs and what Ingest stores

Ingest reads the cards and folders you open. It reads metadata and previews for browsing, and reads image data for rendering, analysis, exports, and verified copies. File workflows write to the destinations you choose. Sending files to Apple Photos is described below.

What Ingest stores locally:

When you ask it to, Ingest writes keywords, captions, titles, ratings, color labels, and GPS into your photograph files. These changes go into supported writable image files or XMP sidecars. Memory-card originals do not receive metadata edits; changes made while reviewing a card are applied to the copies during import. Card cleanup runs only when explicitly requested after verified copying. With RAW-only import, Delete copied files also removes deliberately excluded JPEG/HEIF twins after their RAW copy verifies at every destination. Keep Leave the card alone to preserve all originals.

Local photo analysis. Apple’s Vision framework finds faces and other subjects for close-ups, similarity grouping, and culling suggestions. Ingest caches feature prints, face and subject regions, and assessment results on your Mac. User corrections persist locally. No names or identities are assigned, and no analysis or photograph is sent to a server for these features. Suggestions change no decisions until you apply them.

Apple Photos and iCloud

Apple Photos integration has a global switch in Settings → General and a switch for each workspace. Both must be enabled. Enabling the feature does not itself request library access. Connecting or sending photos requests native Photos read/write permission for your System Photo Library. You can revoke it in macOS System Settings → Privacy & Security → Photos.

Ingest uses Apple’s PhotoKit framework to read your photos and albums and apply the changes you request. Cloud-only images, video, or Live Photos may be downloaded by Apple Photos. Imports, favorite and metadata changes, album organization, and library deletions follow your Photos and iCloud settings and may sync to your other devices. Ingest does not upload your library to a server operated by me.

Ingest stores Photos object references, local tags, rejection, protection, color labels, review marks, grouping recipes, and import receipts on your Mac. On systems before macOS 27, Photos star ratings are stored locally as well. Social Export keeps durable local copies of the rendered Photos images you import into a project; clearing thumbnails does not remove those project inputs. Sending files to Photos stages local copies and retains import receipts so confirmed imports can be reused.

Turning integration off hides its controls and stops library observation. It preserves your saved Ingest state, does not revoke the macOS permission, and does not remove photos or undo changes already made in Photos.

Photo suggestions

When you request a caption or keywords with Apple Intelligence, the on-device model processes a preview of your selected photo on your Mac. Suggestions remain editable drafts until you approve them. Ingest does not send the photograph to a cloud AI service.

Optional Claude Second Opinion

Choosing Ask Claude for a Second Opinion… or Ask Claude About This Folder or Album… opens an optional conversation. Clicking Ask sends your question and requested photo previews, detail crops, and measurements to Anthropic through your own Claude account and installed Claude Code. Each question can retrieve up to 12 previews and four detail crops. Your Claude account’s terms and usage limits apply.

This is separate from Ingest’s built-in on-device analysis and Apple Intelligence suggestions. Claude can inspect and navigate the fixed photo scope, including opening comparisons; its Ingest tools cannot change ratings, tags, metadata, or originals. Opening the conversation alone does not send a question. Ingest disables Claude session persistence for this integration; this does not describe Anthropic’s server-side retention.

Software updates

Checking for updates fetches a small file from brianrenshaw.app, which is hosted by GitHub Pages, and downloads come from GitHub Releases. Those hosts see ordinary connection information such as your IP address, as they would for any web page.

Automatic checking is off until you turn it on. Ingest disables the part of the update system that would report details about your Mac, so nothing about your hardware, your photographs, or your settings is included in a check. Every update must carry a signature made with my key, or it is refused.

No analytics, no account

There is no analytics library, no crash reporting service, no advertising, and no account. Apple Photos uses Apple’s PhotoKit and iCloud services according to your settings. Address search and location maps use Apple’s MapKit services; update checks use the website and download hosts described above.

Actions you build yourself

Post-ingest actions can open your photographs in another app, import them into Apple Photos, copy them somewhere, run a Shortcut, or run a shell script you wrote. When an action runs, your files and the information about them are handed to software you chose, and what happens next is up to that software.

A shell script runs as you, with your permissions, and Ingest does not restrict what it can do. Only add scripts you wrote or understand. Actions can be set to ask before they run. Choose a supplied action or create your own; they run only when invoked or selected for a workflow. See actions for the detail.

The settings file you can export

Settings, Advanced can export everything you have configured as one file, to move to another Mac or to keep as a backup. That file can include destination folder paths, addresses you have used, your keyword history, and the text of any scripts in your actions. It contains no photographs. Share it deliberately.

Questions and changes

If you email me, I see what you chose to put in the message. I will update this page if what the app does ever changes. Questions: contact@brianrenshaw.app.

Metadata Assist history

Successfully applied or staged field values and map locations are remembered in your local Ingest application data. They are used for recent-value menus, Tab completion, and Use Last Details; this history is not sent to a server. Address search still uses Apple’s services when you choose to search for a place. Typing a descriptive location name does not perform an address search.