This Privacy Policy explains how the Watermelon Backup iOS app ("Watermelon Backup", "we", "our", or "us") handles information when you use the app. Watermelon Backup is designed to back up photos and videos from your Apple Photos library to storage destinations that you choose or connect, including local or external storage, network storage, object storage, secure file transfer, and supported third-party cloud storage.
1. Information Watermelon Backup Accesses or Stores
Photo Library Content and Metadata
With your permission, Watermelon Backup can read photos, videos, Live Photo related resources, and related technical metadata from your Apple Photos library. This can include:
- photo and video files
- related resource files, such as paired video or adjustment resources
- creation date and modification date
- file size and resource type
- local asset identifiers used by Apple Photos
If you use restore features, Watermelon Backup can also write selected backup items back into your photo library as new assets.
If you grant limited Photos access, Watermelon Backup can only process the items that iOS makes available to the app.
iCloud-Hosted Originals
Watermelon Backup includes an optional setting that allows access to iCloud originals. If you enable that setting and some assets exist only in iCloud Photos, Apple may download original files from iCloud to your device so Watermelon Backup can hash, compare, or back them up.
Storage Connection Information
Watermelon Backup stores the storage connection information you enter so it can reconnect to storage destinations you configure. Depending on the storage type, this can include:
- profile name or display name
- local folder display paths, server addresses, endpoints, shares, folders, buckets, regions, or provider account metadata
- usernames, domains, authentication methods, host-key fingerprints, permission scopes, and other connection settings
- backup root paths and related identifiers needed to locate app-managed backup data
Credentials
Credentials for storage profiles are stored in the iOS Keychain where applicable. Depending on how you configure a storage profile, this can include passwords, private-key material, passphrases, access keys, account identity metadata, and token-related data. For third-party sign-in based storage, access and refresh tokens may be managed by the provider's authentication SDK or token cache. Watermelon Backup does not store third-party account passwords or client secrets. Watermelon Backup keeps active session credentials or access tokens in memory while a connection or backup task is active.
Backup Indexes and Manifest Metadata
To detect duplicates, support sync and restore, and improve performance, Watermelon Backup stores technical indexes and manifest data. This may include:
- content hashes
- asset fingerprints
- resource counts
- file sizes
- creation timestamps
- backup timestamps
- file names
- mappings between assets and resource hashes
On your device, Watermelon Backup stores local hash indexes in its app database. On your chosen backup destination, Watermelon Backup writes monthly manifest files together with your backed up media.
Logs and Settings
Watermelon Backup stores local app settings, such as:
- upload worker count preference
- iCloud originals access preference
- background backup preference
- Picture in Picture progress preference
- Pro entitlement cache state
Watermelon Backup also stores local execution logs for backup activity. Depending on what happened during a task, logs may include timestamps, profile names, storage type, month progress, file names, remote paths or endpoints, timing information, and error messages. In the current codebase, execution logs are stored locally in the app cache and are purged after about 14 days.
Purchase Status
If you buy Watermelon Backup Pro, purchase processing is handled by Apple through the App Store and StoreKit. Watermelon Backup checks your entitlement status and stores a local cached Pro state. We do not process payment card details ourselves.
Local Network Discovery
If you use SMB local discovery, Watermelon Backup browses _smb._tcp services on your local network to help you find SMB servers.
Support Requests
If you contact us by email, we receive the information you choose to send, such as your email address, message, screenshots, exported diagnostic logs, app version, iOS version, storage type, and error details. Please do not send passwords, private keys, access tokens, or other secrets in support messages.
2. How Watermelon Backup Uses Information
Watermelon Backup uses the information above to:
- connect to storage destinations that you configure
- back up, sync, deduplicate, and restore photos and videos
- create and update local hash indexes and remote manifest indexes
- support progress display, pause and resume, background backup, and recovery after interruption
- verify Pro purchase entitlements
- show local operational logs on your device
- understand app health, diagnose crashes, and improve reliability
- respond to support requests you send to us
3. Where Your Data Goes
On Your Device
Watermelon Backup stores different categories of data locally:
- app database files in the iOS Application Support area
- credentials in the iOS Keychain
- app settings in UserDefaults
- execution logs in the app cache
- temporary working files in the system temporary directory while backup, hashing, sync, manifest, or restore tasks run
To Your Chosen Storage Destination
Watermelon Backup uploads original media resources and monthly manifest files to the storage destination, service account, or app-specific folder that you choose. Those files remain under the control of that storage destination and its operator.
To Third-Party Services and Platforms
Depending on the features you use, third-party services and platforms may process data needed for those features, including:
- platform services for Photos permissions, iCloud originals, App Store purchases, and entitlement checks
- storage providers and authentication/API providers for cloud storage features you connect
- analytics and crash diagnostics services used to understand app health and reliability, without advertising identifier support
- email and support providers when you contact us
In the current app code, analytics and crash diagnostics are not used for targeted advertising or cross-app tracking, and we do not send your backed-up media files, storage credentials, or storage contents to analytics or crash diagnostics services. Third-party services handle data according to their own terms and privacy policies.
To Us When You Contact Support
If you email us, your message and any attachments are processed so we can respond to your request. Exported logs and screenshots may contain personal information such as file names, storage endpoint details, profile names, or error messages, depending on what you choose to send.
4. What Watermelon Backup Does Not Do
Based on the current codebase, Watermelon Backup does not:
- operate a developer-run cloud backup server for your media
- include code-level advertising SDKs
- use the advertising identifier or request App Tracking Transparency permission
- request access to your camera, microphone, contacts, calendar, precise location, or Health data
- use third-party analytics or crash diagnostics services for targeted advertising or cross-app tracking
- request broad cloud-storage access beyond the scope needed by the feature you enable
We do not sell your personal data.
5. Sharing and Third Parties
Watermelon Backup sends data only to destinations, platforms, and providers needed to provide the features you use:
- storage services, devices, accounts, or app folders that you configure or connect
- platform providers used for Photos access, iCloud originals, App Store purchases, and entitlement checks
- cloud storage authentication/API providers when you connect supported cloud storage
- analytics and crash diagnostics providers used to understand app health and reliability, without advertising identifier support
- email and support providers when you contact us
Your chosen storage destination is selected, operated, and secured by you or by the provider you use. We do not control the availability, security settings, retention rules, access permissions, quota limits, throttling, or terms of your external drives, NAS devices, network servers, object-storage providers, cloud storage accounts, app folders, or Files providers. Their own terms and privacy practices may apply.
6. Permissions
Watermelon Backup currently requests the following system permissions:
- Photos read access, to back up original photo and video resources
- Photos add access, to restore selected backups into your photo library
- Local Network access, when you use SMB local discovery on your LAN
- iOS Files / security-scoped access, when you choose an external storage folder
Watermelon Backup also supports background processing and an optional Picture in Picture progress feature, but it does not record audio and does not request microphone access.
7. Background Backup
If you enable Background Backup and have Pro access, Watermelon Backup may schedule background backup work when iOS allows it. In the current codebase, background backup is limited to eligible remote profiles, requires network connectivity, and is scheduled only when the device is on external power.
8. Security
Watermelon Backup uses platform protections such as iOS Photos permissions, iOS Keychain storage for credentials, iOS security-scoped access for external storage, SFTP host-key fingerprint pinning where applicable, and third-party authentication token handling where applicable. Where supported by a connected provider, cloud storage access is limited by provider permission scopes or app-specific folders. No app, device, network, or third-party storage service can be guaranteed to be secure in every circumstance. You are responsible for protecting your device, storage destination, storage accounts, credentials, private keys, and access permissions.
9. Your Choices, Controls, and Rights
You can:
- grant, limit, or revoke Photos access in iOS Settings
- choose whether to allow access to iCloud originals
- choose whether to enable background backup
- choose whether to use SMB local discovery
- delete a storage profile inside Watermelon Backup, which removes the saved profile and its stored credential from Watermelon Backup
- remove a saved third-party cloud storage profile inside Watermelon Backup, which removes the related saved profile data and lets the app remove unused cached account tokens where possible
- delete exported or historical diagnostic logs shown inside Watermelon Backup
- delete remote backup files and manifest files directly from your chosen storage destination
Deleting a storage profile from Watermelon Backup does not automatically delete files that were already written to your chosen storage destination.
Depending on where you live, you may have privacy rights such as access, correction, deletion, objection, or portability. To exercise rights for information we control, contact us at the email address below. We may need enough information to verify and process your request. For data stored only on your device, in platform services, third-party services, or storage destinations you choose, the relevant device controls, platform-provider controls, third-party-provider processes, or storage-provider controls may also apply.
10. Data Retention
Watermelon Backup retains data in different places for different durations:
- local indexes, settings, and storage profiles remain until they are updated, reset, deleted by you, or removed by the system
- saved credentials remain until the related storage profile is deleted or replaced, or until they are otherwise removed from the iOS Keychain
- third-party cloud account tokens may remain in a local authentication SDK or token cache while saved profiles reference that account
- execution logs are currently retained locally for about 14 days, unless you delete them sooner
- temporary working files are intended to be deleted after tasks finish, although some temporary files may remain until the system or a later cleanup removes them
- remote backups and manifest files remain on your chosen storage destination until you delete them there
- support emails and attachments are retained only as long as reasonably needed to respond, maintain business records, resolve disputes, or comply with legal obligations
- platform providers, analytics and crash diagnostics providers, support providers, and your chosen storage providers retain data according to their own policies
11. International Processing
Platform providers, cloud storage providers, analytics and crash diagnostics providers, support email providers, and other third-party services you choose or use through the app may process information in countries or regions other than where you live. Your chosen storage destination may also be located in a region you select or that your provider controls.
12. Children
Watermelon Backup is not directed to children. If you believe a child has sent personal information to us through support email, contact us and we will handle the request as required by applicable law.
13. Changes to This Policy
We may update this Privacy Policy as Watermelon Backup changes. When we do, we will update the "Last updated" date above.
14. Contact
If you have questions about this Privacy Policy, you can contact:
- Email: [email protected]
- Publisher: ZIZICICI LIMITED