TRTriageRoll

Effective August 12, 2026

Privacy Policy

No developer collection

TriageRoll has no account, developer-operated server, cloud database, remote AI service, advertising, analytics, tracking, or third-party SDK. ToolBistro does not receive selected photos or routing data.

Photos access

You explicitly select a batch with Apple's photo picker. TriageRoll requests Photos read-and-write access only when you choose to apply a locked plan. It uses that access on-device to find selected items, create or reuse the two albums you named, add routed items, and ask Apple to confirm planned deletion.

Local app data

Selected Photos identifiers, source labels, destination names, route decisions, commit-stage results, purchase entitlement, and receipts are stored locally. Photos and thumbnails are not copied into TriageRoll storage.

Exports and sharing

Receipt CSV files are generated locally and leave TriageRoll only after you explicitly use Apple's share sheet and choose a destination.

Purchases

The optional lifetime unlock is processed by Apple. TriageRoll can read StoreKit entitlement status, but ToolBistro does not receive your payment card details.

Deletion boundary

Delete All Local Data removes TriageRoll drafts, commit records, receipts, and saved destinations; it never deletes Photos items. Photo deletion occurs only in the separate commit stage after Apple presents system confirmation.

No cleanup claims

TriageRoll does not detect duplicates, judge photo quality, recommend deletion, promise storage savings, move items out of Camera Roll, or guarantee an Apple Photos operation will succeed.

Contact

Questions about this policy can be sent to tianwenliuyu@gmail.com.