Privacy Policy
Last updated: September 1, 2026
Who we are
Dedupo is a phone app (bundle id: com.offjar.dedupoapp) made by Offjar. The website is https://dedupo.com. Help is at https://dedupo.com/site/help. For questions about this policy or the app, email dedupoapp@gmail.com or use Feedback.
What stays on your device
Features such as Similar Photos, Clean Up, Bulk Compress, Albumizer, and Edit run on your phone. They process photos and videos on the device. Dedupo does not upload your camera roll to Dedupo servers for those features. Grouping, cleanup suggestions, compression, albums, and editing happen on the device.
Archive: what it does and does not do
Archive (in the app menu) is a one-way copy of photos and videos you choose. It is not a camera-roll sync and not automatic backup like iCloud or Google Photos.
You pick items, pick a destination folder, and upload. After a successful upload you may delete the local copies. Nothing is deleted until you choose. After local delete, those items stay only in the folder you chose. They will not reappear on this phone or a new phone unless you download them again.
Destinations: Google Drive, OneDrive, Dropbox, and your own FTP or FTPS server. Dedupo does not provide SFTP. Dedupo does not run a file-hosting backend. Files go to the account you connect. Dedupo does not sell the contents of your photos or videos; your files stay in your device or the destinations you explicitly choose.
Cloud and FTP access
Archive can connect to Google Drive, OneDrive, or Dropbox if you tap Connect. The sign-in screen is from that company, not from Dedupo. After you agree, Dedupo can see folders (and files as needed) in that account so you can pick a destination, create a folder, upload only the photos and videos you selected, and preview an item you tap in Archive. Dedupo does not copy your cloud library to Dedupo servers.
Dedupo may show the email or name from that account on the Archive Accounts list so you can tell connections apart.
For FTP or FTPS you type the host, username, and password yourself. Those details and the files you upload go to your server, not to Dedupo.
Tokens and credentials
Sign-in tokens and FTP passwords stay on your iPhone in the system keychain. They are not stored on Dedupo servers. Disconnecting an account in the app removes those local tokens and passwords.
Data protection for sensitive data
Archive may handle sensitive data such as cloud OAuth tokens, FTP passwords, account email or display name for a connected provider, and the photos or videos you choose to upload. Dedupo protects that data as follows.
- On-device storage. Cloud OAuth tokens and FTP credentials are stored only on your iPhone in the iOS Keychain, with access limited to when the device is unlocked. They are not written to Dedupo servers and are not backed up to a Dedupo database.
- No Dedupo file hosting. Dedupo does not operate a cloud storage backend for your media. When you archive, the phone uploads directly to Google Drive, OneDrive, Dropbox, or your FTP or FTPS server over that provider's connection. Dedupo does not keep copies of those file bytes on Dedupo servers.
- User-initiated access. Cloud and FTP access runs only after you tap Connect and only for actions you start in Archive (browse a destination, create a folder, upload selected items, or preview an item you tap). Dedupo does not scan your entire cloud library in the background.
- Least data on Dedupo systems. Dedupo does not create a Dedupo account for Archive. We do not receive or store your Google, Microsoft, or Dropbox passwords. Sign-in happens on that company's screens. FTP passwords you type stay on the device Keychain until you disconnect.
- Local access control. The Archive Accounts list can require Face ID or your device passcode before showing connected accounts.
- Revocation. Disconnecting an account in Dedupo deletes the local tokens or FTP credentials from the Keychain. You can also revoke Dedupo's access in your Google, Microsoft, or Dropbox account settings. After disconnect or revoke, Dedupo can no longer use that connection until you Connect again.
- Transmission. Uploads to Google Drive, OneDrive, and Dropbox use HTTPS. FTPS uses TLS when you enable it. Plain FTP is unencrypted; use it only on networks you trust.
Feedback emails and crash or analytics events described below are separate from Archive file contents. We do not use Archive media to advertise to you or sell your photos or videos.
What connected accounts can access
When you connect Google Drive, OneDrive, or Dropbox in Archive, Dedupo accesses account and file information only to provide Archive features you request. This may include your account email or display name (to label the connection), folder and file metadata (to browse destinations and show file names), and the photo or video files you select (to upload, preview, download back to Photos, or delete on Drive when you choose Delete).
Dedupo uses this information only to operate Archive: browse folders, create folders, upload files you select, list and preview files in a folder, download media to your Photos library, and delete files you select on the connected service. Dedupo does not use it for advertising, selling data, training AI or machine learning models, credit decisions, or any purpose outside Archive.
Sharing, transfer, and disclosure
Dedupo does not sell, rent, or license data from your connected cloud accounts to third parties. Dedupo does not share it with data brokers, advertisers, information resellers, or other third parties for their own purposes.
Dedupo does not transfer your cloud file contents or sign-in tokens to Dedupo servers. When you archive, browse, preview, download, or delete on a connected service, those operations go directly between your iPhone and that provider. Your file bytes and OAuth tokens are not stored on Dedupo infrastructure.
The only third parties that may receive data related to your use of Archive are:
- The cloud provider you connect (for example Google Drive, Microsoft OneDrive, or Dropbox). Files you upload and folders you create or browse are stored in and served from your own account at that provider, under that provider's terms and privacy policy. Dedupo sends data to the provider only so it can provide storage to you on Dedupo's behalf as the connected app.
- Firebase (Analytics and Crashlytics). The iOS app may send anonymous or pseudonymous app usage and crash diagnostics to help keep the app reliable. Firebase does not receive your cloud file contents, folder listings, or OAuth access tokens.
Dedupo does not disclose data from your connected accounts to any other third party except as required by law or with your explicit direction (for example, when you choose to upload files to your own cloud account).
Retention and deletion
Sign-in tokens for connected cloud accounts stay on your iPhone in the Keychain until you disconnect the account in Dedupo or revoke the app's access in that provider's account settings. Dedupo does not retain copies of your cloud files on Dedupo servers.
Files you upload remain in your connected account until you delete them in Dedupo, in that provider's app or website, or through other tools from that provider. Deleting a file in Archive's Remote tab removes it from that remote account.
To stop Dedupo from accessing a connected Google account, disconnect it in Archive Accounts or revoke the app's access at https://myaccount.google.com/permissions.
Where uploaded files live
Files you upload with Archive live in your Google Drive, OneDrive, Dropbox, or FTP account under that provider's own terms and privacy policy. Dedupo does not store Drive, OneDrive, Dropbox, or FTP file bytes on Dedupo servers.
App health analytics
The iOS app uses Firebase Analytics and Firebase Crashlytics to understand app health and crashes. Those tools are for reliability, not for uploading your camera roll to Dedupo.
The website may use Google Analytics to understand how the site is used.
Who Dedupo is for
Dedupo is for a general audience: anyone who wants to manage photos and videos on their phone. It has no kid-specific content, no chat, and no social feed. You do not create a Dedupo account or a public profile. Dedupo does not run a server that stores your camera roll or keeps a directory of who uses the app.
On-device tools (Similar Photos, Clean Up, Bulk Compress, Albumizer, and Edit) work without signing in. Anyone in the household can use those tools. Archive only runs if you connect Google Drive, OneDrive, Dropbox, or your own FTP server. That uses an account you already have at that provider, not a Dedupo login. Your connection information stays on your device, not on Dedupo servers.
If you contact us through Feedback or email, we only see what you send. Ask us to delete that message and we will.
Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Continued use of Dedupo after an update means you accept the revised policy.
Contact us
Email: dedupoapp@gmail.com
Feedback: https://dedupo.com/site/contact
Website: https://dedupo.com