Privacy Policy
The short version
- Lensogram copies photos and videos you select into a private channel inside your own Telegram account. The account is yours and so is the storage.
- We run no server the app talks to, and the app has no endpoint of ours to contact (this website's own access log is section 10). We never receive your files, your phone number, your login code or your Telegram password. Telegram does receive them: that is where you chose to put them. Telegram is a separate company under its own privacy policy.
- In Google Play's vocabulary that is collecting and sharing your photos and videos, because they are transmitted off your device to a third party. Section 5 is the whole Data safety form.
- The app has no analytics, crash reporting, advertising or tracking library, reads no advertising ID and no device ID, and you can delete everything yourself (section 15).
Section 01What Lensogram is
Lensogram is a gallery app for Android. It shows the photos and videos already on your phone and copies the ones you choose into a private channel inside your own Telegram account, so you have a second copy somewhere other than the phone.
To do that you sign in to Telegram inside the app. Lensogram is an unofficial, third-party Telegram client, built on TDLib, the library Telegram publishes for the purpose; it is not made by, endorsed by or affiliated with Telegram. There is no account with us: nothing to register for, no profile, no password of ours. Signing in to Telegram is required before any part of the app, the gallery included, will open.
Backup is a choice you make: no album is selected until you tick one, and nothing is backed up automatically from an album you have not ticked. The first-run screens ask what you want, and one of them, automatic backup, is offered already switched on. Section 8 explains what that turns on.
Section 02Who is responsible, and how to reach us
Lensogram is made and published by Lenvio Software, established in Spain, which is the controller for the processing described in section 11 and can be reached at the address below. Section 3 sets out why that is a narrower role than it sounds, and who is responsible for the backup itself.
Controller: Lenvio Software, Av. de Jaume III, 3 Centre, Palma, Illes Balears 07012, Spain.
Privacy contact: privacy@lensogram.app. It is the right address for questions, complaints, requests to exercise your rights, security reports, or a report that something here does not match what the app does. Formal requests under data protection law are answered within one month. There is no data protection officer, and none is required: we are not a public authority, we monitor no one on a large scale, and we process no special categories of data on a large scale.
Representative in the EU: none needed. Article 27 GDPR requires a representative of controllers established outside the Union; we are established in Spain, so the GDPR applies to us directly and there is nobody to represent us to. Telegram, the party that actually receives your files, is established outside the EU and does have one; see section 9.
Section 03Who does what with your photos
You. They are your photos, in your Telegram account, and you decide which albums are backed up and when. While the channel stays private to your account this is personal use, which data protection law does not regulate. If you later let other people into that channel, photos of other people become a disclosure and you take on responsibilities of your own. That is worth knowing before you share the channel.
Telegram. Once a file leaves the phone it is on Telegram's servers, and Telegram is independently responsible for it under its own policy. Telegram is not our supplier or our processor and does nothing on our instructions.
Us, the developer. We wrote the software and operate no server it talks to. We cannot read, list, download or delete anything in your channel, or see that it exists. We supply software that runs on your device, on settings you chose and can change or pause, and sends data only where you pointed it; reading your library and sending the files you selected is done solely to deliver the backup you asked for, and for nothing else.
Having no server is not the same as there being no privacy questions here. Your photos do leave your device, travel over the internet and rest on a large company's infrastructure, and your phone number, login code and two-step password pass through this app on the way to Telegram. Not receiving data does not by itself put a developer outside data protection law, and we do not claim that it does.
Section 04What the app handles, and where each thing goes
Everything the app reads, and where each item ends up. None of it comes to us.
| What | Why | Where it goes |
|---|---|---|
| Your photos and videos (the files) | The point of the app: a copy that is not on your phone | Read from the media library and sent by TDLib into the private channel in your own Telegram account, either byte for byte or re-encoded smaller, depending on the quality you chose. Automatically, only from albums you ticked. Any single item or selection you back up by hand goes there too. |
| A caption on each upload | Telegram keeps no filename on a photo message; without the caption a fresh install would upload everything a second time | Into your channel, as the message caption: the capture date, the exact capture timestamp, and the filename. |
| Information about your files | Filename and capture time match a file on the phone to a file in the channel; the dates order the gallery | The app's database on the phone. Filename and capture time also leave the device inside the caption above; the album or folder name does not. |
| Your phone number | Telegram identifies accounts by phone number | Typed on the app's own keypad and sent straight to Telegram. The app saves it in none of its own storage and never writes it to a log. But Telegram returns it with your account, the app shows it on the code and account screens, and TDLib keeps it on the device until you sign out. |
| Your login code, and your two-step password if you use one | To finish signing in | Straight to Telegram and nowhere else. Neither is stored by the app or written to a log; the only thing recorded is how the code was delivered and how long you have to enter it. |
| Your Telegram profile | To show which account you are signed in to | Fetched from Telegram and shown on screen. Your name, username and picture are held on the device by TDLib as in any Telegram client; the app keeps no copy of its own. |
| Device model, Android version, app version | Every Telegram client identifies itself; this is what makes Lensogram appear in your list of active sessions, so you can end that session whenever you want | To Telegram, when the connection is set up. |
| The titles of your chats | To find out whether a Lensogram storage channel already exists before creating a second one (after a reinstall, for example) | The app asks Telegram for your main chat list and compares each title with one fixed name; only the matching channel's ID number is kept. The list is cached on your device by TDLib, as in any Telegram client. Nothing about your other chats is sent anywhere or used for anything else, and their messages are not read. |
Two things are read on the device and go nowhere: the rotation tag inside a photo, so portrait pictures do not arrive on their side, and how much free space the phone has, for the bar on the account screen. One route out is not in the table because it is not backup: the photo viewer's share button hands the item you are looking at to another app through Android's own share sheet. It is one item at a time, always your choice, and what that app does with it is governed by that app.
The app has no code that strips or rewrites the technical tags inside a photo. In Original quality the file is uploaded byte for byte as it sits on your phone, so whatever tags it carries (camera model, exposure, timestamps) travel with it into your channel. HD and Compressed normally re-encode, which leaves those tags behind, but they pass the original through untouched when it is already small enough, and send it as a file when it cannot be re-encoded.
Location is the exception, and not because we remove it: the app holds no ACCESS_MEDIA_LOCATION permission, so Android redacts GPS coordinates from the media it hands the app. Removing them is the operating system's job rather than ours: the app neither reads, adds nor preserves location anywhere. That is the operating system withholding them; adding that one permission would change it, and if we ever do, this page changes first.
Section 05Google Play's Data safety form
Google Play asks whether data is collected, meaning transmitted off the device, and whether it is shared, meaning passed to a third party. By those definitions Lensogram collects and shares your photos and videos, because they leave your device for Telegram. That the developer never receives them is true, and is not what the form asks. Every answer, so the form and this page can be read side by side:
| Data type | In Lensogram | Collected / shared |
|---|---|---|
| Photos and videos | The files in the albums you select, and any item or selection you back up by hand, each with a caption carrying the filename and capture time | Yes / yes. To Telegram, into your own account. Purpose: app functionality. Optional: automatic backup uploads only from albums you select; anything else is uploaded only when you tap to back it up. |
| Personal info: phone number | Typed to sign in to Telegram | Yes / yes. To Telegram. Purpose: account management. Required: the app cannot be used without signing in. |
| Location | No location permission, no location service, no location column read from the media library | No / no |
| Device or other IDs | No advertising ID, no Android ID, no hardware or installation identifier | No / no |
| App activity, app info and performance | No analytics, no crash reporting, no diagnostics sent anywhere | No / no |
| Everything else on the form | Your login code and two-step password pass through the app to Telegram and are never stored, cached or logged, so they stay off the form under Play's rule for data processed only in transit (section 4 describes them in full). Files and documents beyond the media above, contacts, calendar, financial info, health and audio: not read. Message content in your other chats: not read either. The app reads chat titles, on the device, to find an existing storage channel, and reads the captions and file names in its own channel (section 4, section 7) | No / no |
Data is encrypted in transit, over TDLib's connection to Telegram. You can delete everything without asking anyone (section 15). No data is sold, shared for advertising or passed to data brokers, and none of it is used to build a profile of you.
Section 06What stays on your device
All of this is in the app's private storage, which Android keeps other apps out of. The app adds nothing to your media library and modifies no file in it; the only change it can make there is removing items you selected, which Android confirms with its own dialog (§15). It writes nothing outside its private storage, and it sets allowBackup="false", so none of it is copied into Android's cloud backup or a device-to-device transfer.
- A database of your gallery: filenames, types, sizes, dates, album names, the phone's own reference to each file, the matching Telegram message IDs, the upload quality, and the progress or error of each transfer. It holds no image data, but filenames, capture times and folder names do describe your library. It is an ordinary SQLite database, protected by the Android sandbox and the device's own encryption. The app adds no encryption of its own.
- Your settings, in two small preference files plus one holding your chosen language: theme, gallery layout, Wi-Fi-only, roaming, automatic backup, upload quality, size and age limits, whether transfers are paused, which prompts you have seen, and your storage channel's ID number. No personal data beyond that ID.
- Your Telegram session: TDLib's own store, which holds the authorisation key that keeps you signed in, its chat and message database, and its file cache including your profile picture. The app gives TDLib no database key, so this store is protected by the sandbox and device encryption rather than by a password of yours. Secret chats are switched off.
- Files you restored from the cloud: full-size photos and videos you asked the app to fetch back out of your channel. These are the most sensitive thing the app writes to disk, and they stay until you delete that item in the app or uninstall. Thumbnails downloaded for items that exist only in the cloud are kept the same way.
- Temporary working files in the cache: resized photos, re-encoded videos, and occasionally a staged copy of a file that could not be read from its original location.
- Android's own log: the app writes diagnostic lines to the system log on the device. Your phone number, login code, two-step password and Telegram credentials are not among them.
The "clear cache" action empties the app's database and deletes the cache directory. Restored files and downloaded thumbnails are not in the cache, so they survive it. Because the database rows that pointed at them are gone, they stay on the phone taking up space with no way to reach them from the app. Uninstalling, or clearing the app's storage in Android's settings, removes them properly.
Section 07Permissions, one by one
What the app requests, and then what Android's own libraries add to it: the whole list in the shipped build, not just the ones written by hand.
| Permission | Status | What it is for |
|---|---|---|
| READ_MEDIA_IMAGES READ_MEDIA_VIDEO | Required | Read the photos and videos in your library, so the gallery can show them and selected albums can be backed up. Android treats the two as separate permissions. |
| READ_EXTERNAL_STORAGE | Required on Android 12L and older | The older single permission that did the job of the two above. It is capped so it is never requested on newer versions of Android. |
| INTERNET | Required | The connection to Telegram: signing in, uploading, fetching files and thumbnails back, and reading the history of your storage channel. |
| ACCESS_NETWORK_STATE | Required | To see whether you are on Wi-Fi, mobile data or roaming, so the "Wi-Fi only" and "not while roaming" settings work and the app can tell you when you are offline. |
| FOREGROUND_SERVICE FOREGROUND_SERVICE_DATA_SYNC | Required | So a transfer already running keeps running when you leave the app, instead of being cut off halfway through a large video. |
| POST_NOTIFICATIONS | Optional | The progress notification for a running transfer, with its pause button. Decline it and backups still work; you just will not see them in the notification shade. |
| VIBRATE | Granted automatically | The small haptic ticks when you drag the fast-scroller down a long gallery. This is a normal, install-time permission: Android grants it with the install and you are never asked about it, so unlike the notification permission above it is not one you can decline. |
| WAKE_LOCK RECEIVE_BOOT_COMPLETED | Added by WorkManager | Not asked for by us: they come with Android's own WorkManager library. The first keeps the device awake while a transfer you started runs; the second lets a scheduled backup you turned on be re-registered after you restart the phone (section 8). |
| DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION | Added by AndroidX | An internal, signature-level permission generated by the AndroidX core library and carried by every app that uses it. It grants nothing outside the app's own signature and is never shown to you. |
Not requested, and so not available to the app: location of any kind, media location, contacts, the phone's own number, the microphone and the camera.
Why the app needs your whole library
Android offers a photo picker that returns only the files you point at, and for most apps that is the right tool. It cannot do this job. Lensogram is a gallery: its main screen is your whole library laid out by day, each item marked as being on the phone, in the cloud, or both. You back up albums rather than files, so the app has to notice photos that did not exist when you ticked the album; and to tell you that 340 of your 1,200 photos are not backed up, it has to be able to count all 1,200.
What it reads is a short fixed list of columns (an ID, the filename, the type, the size, three dates and the folder), with no location column among them. Access to everything is not the same as uploading everything: the automatic pass queues only the albums you ticked, and anything outside them leaves the phone only when you tap to back it up.
Section 08When the app runs on its own
Backups run as a scheduled job, and while a transfer is in progress the app runs a foreground service of the "data sync" type so Android keeps the work alive while you are elsewhere. That is the notification with the progress bar and the pause button.
- Automatic backup is offered switched on during first-run setup. Turning it on registers a pass that runs roughly every six hours when its conditions are met, uploading new files from your selected albums; once a day it also walks your channel's history to notice anything you deleted there by hand.
- Backing up a new photo immediately is off unless you turn it on in settings. With it on, Android wakes the app whenever a new photo or video is added to your library (by the camera or by any other app, a screenshot or a download included), even if you have not opened Lensogram. It then backs up only what is in your selected albums.
- After you restart the phone, if either of those is on, Android starts the app so it can re-register its jobs: a scheduled backup survives a reboot by design. Turn both off and, once the queues are empty, nothing starts the app at boot any more.
- Uploads respect Wi-Fi-only and the no-roaming setting, both on by default, and stop at the pause button. A file you tap to restore does not: it is fetched over whatever connection is available, including mobile data and roaming, and is not held back by the pause button, because you are watching a spinner waiting for it. That trade-off is deliberate and applies only to downloads you asked for.
Section 09Telegram
Telegram is the only outside party in the app, and it is there because the app is a Telegram client. That is the product. Telegram is not our supplier and not our processor: we have no contract with it covering your data and it does nothing on our instructions. For everything it receives from you it is independently responsible under its own policy at telegram.org/privacy. Telegram has appointed an EU representative (EDPO, Avenue Huart Hamoir 71, 1030 Brussels, Belgium), and requests about data held by Telegram should go to Telegram rather than to us.
- Your storage channel is an ordinary Telegram cloud chat, not a Secret Chat, and the app does not use Secret Chats at all. We are not going to tell you your photos are end-to-end encrypted, because that is not true of a channel. How Telegram protects what it stores is Telegram's to describe.
- The channel is created by your own account, which owns it. At creation the app sets joining to require approval, and it never creates or shows an invite link and never gives the channel a public username. Those settings are yours to change, and if you let other people in you are choosing to share those photos with them.
- We cannot reach anything in it: not to list, read, download or delete. Asking us to remove something from Telegram achieves nothing; section 15 is the route that works.
One technical detail, since the app's network behaviour is the whole argument here. The app makes no HTTP requests of its own (no analytics call, no update check, no endpoint of ours anywhere in the build), and the image loader that draws your gallery has no network fetcher at all. The single path out is TDLib's connection to Telegram. If that connection is blocked, TDLib falls back to Telegram's own datacenter-discovery endpoints, some of them hosted for Telegram by Google; those fallbacks are part of Telegram's library and belong to Telegram, not to us.
Section 10This website
lensogram.app is a small static site. Its pages and everything they use (scripts, stylesheets, fonts and images) are served from this same domain: no cookies, no analytics, no tracking, no fingerprinting, no embeds, and nothing at all (no fonts, no images, no scripts) fetched from anyone else. The home pages run a script for their animations and for opening their menus; this page runs no script at all. The script makes no network request of any kind and stores nothing in your browser: no cookie, no localStorage, no other storage. Open your browser's network panel and every request you see goes to lensogram.app, for a page and its own files, and nothing to any other domain.
Like almost any web server, ours writes an access log: the IP address that asked for a page, the time, the page, the response, and the browser string and referring page your browser sends. We use it to keep the site working and to spot abuse, we do not combine it with anything or profile anyone with it, and we keep it no longer than 30 days. The site's log is written to its own file and rotated daily, thirty days deep, so that limit is set in the server's configuration rather than left to habit.
Section 11Legal bases, recipients and transfers
A controller needs a legal basis for each thing it does with personal data. We are not going to invent one for the backup itself: we neither hold your photos nor decide what happens to them, so claiming a basis over them would contradict the rest of this page. These are the operations we actually carry out.
| What | Why | Legal basis |
|---|---|---|
| Email you send to our privacy address, and our reply | To answer your question or fix your problem | Legitimate interests, Art 6(1)(f): answering a message you chose to send; the data is only what you put in it |
| A request to exercise your rights, and our record that we handled it | To do what the law requires and be able to show it | Legal obligation, Art 6(1)(c) |
| This website's access log | To keep the site up and deal with abuse | Legitimate interests, Art 6(1)(f) |
There is no advertising basis, no analytics basis and no profiling basis, because there is none of those things. Two suppliers can technically reach that small amount of data: the company we rent the web server from, and the provider that runs the privacy mailbox. Each acts as a processor for us and receives nothing else; nobody else receives any of it. We send nothing onward, and if you want to know where those two are established, ask and we will tell you. Your own use of the app does involve your files crossing borders, because Telegram operates internationally: that is a transfer between you and Telegram, under Telegram's own policy and safeguards, not one we carry out or could describe accurately on Telegram's behalf.
Do you have to provide any of this?
- Your phone number is required, by Telegram, to sign in. Signing in is required before any part of Lensogram, including the gallery, will open. Declining means the app cannot be used. That is Telegram's requirement, not ours, but the consequence is ours to state plainly.
- The photo and video permission is what lets the app see your library. Decline it and there is no gallery and nothing to back up.
- Writing to us is entirely optional, and you decide what is in the email.
Section 12How long things are kept
- Your photos, videos and everything about them: we never receive them, so there is no period to state on our side.
- In your Telegram channel: for as long as you leave them there. Nothing expires on its own. That clock is yours to run.
- On your device: the database, settings, restored files, thumbnails and the Telegram session stay until you uninstall or clear the app's storage. Signing out ends the session and clears the app's record of what is in the cloud, but leaves restored files, thumbnails and your settings on the phone. Clearing the cache leaves restored files and thumbnails behind too (section 6). Uninstalling removes all of it.
- Email you send us: deleted within 12 months of the matter being closed, unless we need it longer for a legal claim. Website access log: 30 days at most, enforced by daily rotation on the server.
Section 13Security
In transit. The app's only network connection is TDLib's encrypted connection to Telegram, using Telegram's own client library and transport. There is no second channel to secure.
On the device. Everything the app stores is in its private storage, which Android keeps other apps out of and which the device's own encryption covers. The sandbox and device encryption are what protect the gallery database and the TDLib session store; the app adds no encryption key of its own, and we would rather say so than describe a safeguard that is not there. The app's data is excluded from Android's cloud backup, and your phone number, login code, two-step password and Telegram credentials are not written to the device log. What we hold is an email inbox and a web server's access log, both behind strong authentication, with access limited to the developer.
What is on you. Anyone who can unlock your phone can open the apps on it, including this one. Use a screen lock, and if you are passing the phone on, sign out inside the app before you uninstall (section 15). No system is perfect; if you find a security problem in Lensogram, write to privacy@lensogram.app. We would much rather hear it from you.
Section 14Your rights
If the GDPR or the UK GDPR applies to you, you have the right to ask for a copy of your data, to have it corrected or erased, to restrict how it is used, and to receive it in a portable form where that applies. Where we ever rely on your consent you can withdraw it at any time, which does not make what happened before unlawful. Write to privacy@lensogram.app; it is free and we answer within one month.
Your right to object. Two things we do rest on legitimate interests: the privacy mailbox and this website's access log. You have the right to object to either at any time, on grounds relating to your situation, by writing to the same address. If you object we stop, unless we can show compelling legitimate grounds that override your interests.
One honest limit. If you ask us for a copy of your photos, or to delete them, we cannot do it, not because we refuse, but because we have neither a copy nor any way to reach yours. We do not know your phone number or your Telegram account and cannot see your channel; there is nothing here to search. Section 15 is what you can do instead, and it is more complete than anything we could do for you. For anything you have sent us directly you are plainly identifiable, and we act on your rights normally. Nothing here profiles you, scores you or sorts you into groups: the little we hold is never used to make decisions about you.
If you think we have handled something badly, tell us, but you do not have to. You can complain to the supervisory authority where you live, where you work, or where you think the problem happened. Because we are established in Spain, our lead authority is the Agencia Española de Protección de Datos (AEPD, C/ Jorge Juan 6, 28001 Madrid, aepd.es), and you may go to it directly whichever country you are in. Anything about your Telegram account can go to Telegram or its EU representative (section 9).
Section 15Deleting your data
Account and data deletion
Lensogram creates no account with the developer, so there is no account of ours to delete and no request form to fill in. Everything the app produces is in two places you control (your phone and your Telegram account), and three routes remove it:
- Sign out in the app. Ends the Telegram session, which makes TDLib destroy its store, and clears the app's record of what is in the cloud. Files you had restored, and downloaded thumbnails, stay on the phone until you uninstall. Your channel and its contents stay in your Telegram account, because they are yours.
- Delete the Lensogram storage channel in any Telegram client. That removes every file the app ever uploaded, in one action. Deleting your Telegram account does the same and more.
- Uninstall Lensogram, or clear its storage in Android's settings. Removes the session, the database, the settings, the restored copies, the thumbnails and the cache. Because the app is excluded from Android's cloud backup, there is no copy of any of it in your Google account either.
None of this needs our involvement, and none of it can be undone or prevented by us. The one thing only we can delete is correspondence you sent us: ask at privacy@lensogram.app and we will delete it.
Item by item, inside the app
- Delete from the phone. Select items in the gallery and delete them from the device; Android shows its own confirmation dialog for files it manages, and that dialog is the real decision. Copies restored out of your channel sit in the app's own folder and go immediately.
- Delete from Telegram, or from both at once when the selection exists in both places. The app deletes the underlying messages for everyone (a channel has no "delete only for me"), and the dialog tells you how many of the selected items exist in only one place, so you can see which choice ends a file for good. This is the only way a file leaves your backup.
- Clear the app's database and cache, in settings. You lose nothing permanent (the gallery rebuilds from your phone and your channel), but read the caveat in section 6 first.
Uninstalling deletes the session data from the phone but does not tell Telegram the session has ended. Sign out inside the app first, or open any Telegram client and end the Lensogram session from your list of active sessions. This matters most if you are selling, returning or giving away the phone.
Section 16Children
Lensogram is not designed for or directed at children and is not part of any families programme. Using it requires a Telegram account, and Telegram sets its own minimum age and its own rules for younger users. We hold no photos and no account records; the only data we ever hold about anyone is an email they chose to send us and this site's access log.
If you are a parent or guardian with a question about a child's use of the app, write to privacy@lensogram.app. For anything already in a Telegram account you will need Telegram, or the routes in section 15.
Section 17Changes to this policy
If the app changes in a way that changes this document (a feature that handles data differently, a new library, a new permission), we update this page first and move the effective date at the top, so you can see that it moved. We will not quietly rewrite it and leave the date alone. For anything material we will also post a note in the Lensogram updates channel, @LensogramChannel, at or before the time the change takes effect. That is a public channel of ours, not the storage channel in your own account described in §9. If you want to know what a previous version said, ask and we will send it to you.
This policy is published at https://lensogram.app/privacy/ and this is the only version we maintain. If you have found a copy somewhere else, this page is the current one.
Questions, requests, or something on this page that does not match what the app does: privacy@lensogram.app
Privacy Policy for Lensogram · Effective 27 September 2026 · lensogram.app