immich-smart-tools-extension

Privacy Policy — Immich Smart Tools

Last updated: August 2026

Immich Smart Tools is a browser extension that enhances a user’s own self-hosted Immich photo server. This policy explains exactly what data the extension touches, where it goes, and where it doesn’t.

What this extension does NOT do

What data the extension handles, and where it goes

Your Immich server credentials

API keys (or your logged-in browser session, if you choose that mode) for any Immich server you add are stored locally in your browser (chrome.storage.local) and are only ever sent to that specific server, to authenticate your own requests to your own photo library.

Your photos and their metadata

Photos, thumbnails, and metadata (including GPS location and any captions you’ve written) are read directly from the Immich server(s) you’ve added, in response to actions you take (copying, downloading, cropping, building a journey map, etc.). This data is never sent anywhere except back to that same Immich server, unless you explicitly use the optional Location Stories feature described below.

Location Stories (optional AI feature)

If you choose to configure an AI provider (OpenRouter or Google Gemini) with your own API key, some of your photo data — location names, photo captions, and small photo thumbnails — is sent to that provider when you explicitly click a “Generate” action, so it can write background text, suggest names, or generate images. This only happens when you take that action; nothing is sent automatically or in the background. You are billed directly by your chosen provider; the extension’s developer never sees this data and has no access to your provider account.

Local storage

Your settings, added servers, shortcuts, and — for Location Stories — previously generated text, images, and custom location names are stored locally in your browser so they persist between sessions. None of this is transmitted to the developer or to any analytics service.

Third parties

The only third parties this extension ever communicates with are:

  1. The Immich server(s) you explicitly add.
  2. The AI provider (OpenRouter or Google Gemini) you explicitly configure, if you choose to use the optional Location Stories feature — using your own API key, which you provide and control.

No other third party, including the developer’s own infrastructure, ever receives your data. There is no developer-run backend at all — this extension has no server component of its own.

Your control over this data

You can remove any server, clear your AI provider key, or delete any locally stored settings/generated content at any time from the extension’s settings page. Uninstalling the extension removes all locally stored data with it.

Changes to this policy

If this policy changes, the “Last updated” date above will change accordingly. Material changes will be reflected here before being submitted with any updated version of the extension.

Contact

byphil.eu