Privacy Policy โ Alt Text Intelligence
Last updated: August 5, 2026
I develop Alt Text Intelligence through Bridge City Lab LLC. This policy covers the iPhone, iPad, Mac, and Android apps, plus the web tool at dr.eamer.dev/alt/.
Short version
You do not need an account. The native apps do not contain advertising or tracking SDKs. Local descriptions, preferences, and History stay on your device, along with the iPhone and iPad extensions and Shortcuts. The Mac app has no cloud description service and never uploads an image or description. The iPhone, iPad, and Android apps upload a selected photo for cloud description only after you confirm. In the web tool, choosing, dropping, or pasting an image sends it through the private server to an external description service. This site does not retain images or use them for training.
Web tool
The web tool at dr.eamer.dev/alt/ sends an image to api.dr.eamer.dev as soon as you choose, drop, or paste it. The request contains the image and its media type. The server forwards it to an external description service and returns the requested alt text. This site does not retain the image or use it for model training.
The web tool stores accessibility preferences and a random anonymous quota identifier in your browser. It uses the identifier only to limit the web tool to 10 image descriptions per UTC day. The identifier is not an account and has no connection to your name, email address, or social accounts. Clearing browser storage creates a new identifier, so this is a practical usage limit rather than identity verification.
If you connect Bluesky or Mastodon, the service session or access token stays in your browser until you disconnect or clear browser storage. Bluesky passwords go directly to Bluesky and are not stored by this site. Mastodon sign-in occurs on your chosen Mastodon server through OAuth, so this site never receives your Mastodon password. Posting sends the selected image, your edited alt text, and any post text to the social service only after you choose Post. Downloading a tagged image sends the image and edited alt text to api.dr.eamer.dev to create the download; the image is not retained.
Signing in to Mastodon sends you to your chosen server and back, which reloads this page. So the image you are posting is not lost on the way, the web tool holds that one image and your edited description in your browser's local database for the length of the round trip. It stays on your device; this step uploads nothing. It is deleted the moment you return, whether you approve or deny access, and a later visit clears anything left behind by a sign-in you walked away from. If your browser refuses to store it, the web tool says the image did not survive sign-in rather than failing quietly. Sign-in also stores the connection details for your chosen server until it completes or you cancel.
The web tool uses a self-hosted GoatCounter service for basic, aggregate page-visit measurement. It does not use advertising cookies or cross-site tracking. The alt-text request itself is not used for analytics.
On-device processing and storage (iPhone and iPad)
- On-device description uses Apple's Vision framework, a deterministic rule-based composer, and, when available, the system language model.
- The Share extension, Photos action extension, and Describe an Image shortcut use the local pipeline.
- The app stores History, thumbnails, preferences, accessibility options, and anonymous cloud consent state locally in its sandbox or App Group.
- Widgets read a small local snapshot from the App Group. They do not access a remote database.
On-device processing and storage (Mac)
The Mac app has no cloud description service and never falls back to one. It creates descriptions with Apple's Vision framework and a deterministic rule-based composer, plus a system language model, locally installed MLX vision model, or locally running Ollama vision model when you choose one.
- Ollama requests are restricted to its loopback service at
127.0.0.1:11434. The app excludes models Ollama reports as cloud-hosted or remotely routed and checks again before sending an image. - Downloading a listed MLX model requests revision-pinned model files from Hugging Face and stores them in the app's private local storage. Images, descriptions, and model-generated text are not included in those requests.
- History and preferences stay on the Mac. Opening and exporting files uses locations you choose.
- The Direct-download edition checks a signed release feed at
dr.eamer.devonly when you choose Check for Updates or enable periodic checks. Automatic checks are off by default. The request does not contain system profiling, a device identifier, images, descriptions, files, or model details. As with an ordinary web request, the server receives the IP address, time, and standard request metadata needed to deliver the feed. - The Mac App Store edition does not use the Direct update feed. Apple provides and manages its updates through the App Store.
Cloud description
The primary Alt Text screen may offer cloud description when daily quota remains. Before upload, the app asks you to confirm that it may send the selected photo to a server for analysis.
A cloud request contains:
- The selected image and its media type.
- Description options such as length, tone, text handling, and image type.
- An anonymous installation identifier used to enforce the daily quota.
The app sends cloud requests to api.dr.eamer.dev, which forwards uploaded images to an external description service. This site does not retain the images or use them for training. The app may save generated text locally to History. If you decline cloud description, lose access to it, or run out of quota, on-device description remains available.
Android app
The Android app follows the same rules as the iPhone and iPad app. It needs no account and contains no advertising, tracking SDKs, or automatic analytics.
- On-device description keeps the selected image on your phone or tablet. History, thumbnails, preferences, and cloud-consent state stay in the app's local storage, and you can clear History or remove the app's data at any time.
- Cloud Describe works as described above: it runs only after your consent and sends the selected image, its media type, description options, and a random installation identifier to
api.dr.eamer.devto enforce the daily quota. - The app requests camera permission only when you choose to take a photo. It reads gallery images and images shared from another app only after your action.
- Copying or sharing a description uses Android's system tools, and you choose the destination.
- The build distributed outside Google Play checks a version file at
dr.eamer.devto offer updates; that check sends no personal data. The Google Play build updates through Google Play instead.
Social publishing (iPhone and iPad)
The app publishes only after you tap Publish and choose a connected service. It then sends the selected image and your edited alt text to that service. The app keeps account credentials in local secure storage and uses them only for actions you request. Each service has its own privacy policy and data practices.
Diagnostics
Diagnostic logging is optional and off by default. When you enable it, the app stores error reports locally and sends nothing automatically. A report leaves the device only if you tap Send report by email and complete the email composer.
Exports and sharing
History export writes a JSON file locally after you accept an explicit notice. Sharing an image with a description writes a temporary local file and opens the system share sheet. After either action, you choose where to send the file and how to use it.
What the app does not collect
- No advertising identifiers.
- No location, contacts, microphone recordings, or address-book data.
- No third-party advertising or tracking SDKs.
- No automatic analytics or diagnostic uploads.
- No sale of personal information.
Children's privacy
Alt Text Intelligence is rated for all ages. The app does not collect personal information from children or adults.
Your choices
You can decline cloud description and continue on device. On Mac Direct, periodic update checks remain off unless you enable them; you can still check manually. You can leave diagnostics disabled. You can remove connected social accounts in Settings, clear History, or delete the app to remove its local data.
Changes to this policy
If the app's data practices change, I will update this policy and its date before the new behavior ships.
Contact
Luke Steuber, Bridge City Lab LLC
Email: luke@lukesteuber.com
Website: lukesteuber.com