MPOViewer doesn't have a server, an account system, or any analytics, so there's no data collection to describe. In full:
- No accounts. You never sign in, and MPOViewer doesn't know who you are.
- No analytics, no crash reporting, no ads. And no third-party SDKs of any kind.
- One download, on request. The app makes no network requests of its own, with one exception since version 1.11: Settings can fetch a larger colour model for stereo cards from a public GitHub release, and only when you tap Download. That request carries no identifier and nothing about you or your photos, and GitHub sees it the way any web server sees a file download. Verified in the source code, not just promised on this page.
- Your photos stay put. MPOViewer reads .mpo files only from a folder you explicitly choose, on your device or in your own iCloud Drive, via Apple's standard folder-access permission. Nothing is copied, uploaded, or shared, by the app or by BaseTrend.
- Settings and captions stay local. Anything you type into MPOViewer, captions and preferences alike, is kept in the app's own storage on your device, not in a file among your photos, and not sent anywhere. The one exception is Export Captions in Settings, which writes a caption file into your own folder when you ask it to, so another device can read it.
- No biometric data. The optional Face ID or Touch ID lock on the Hidden list is handled by iOS itself, which only answers yes or no. MPOViewer never receives or stores anything about your face, fingerprint or passcode.
- The camera stays on the phone. The live card view uses the camera to find a stereo card in your hand, and the colour model for a card runs on the phone itself. No frame and no card leaves the device.
If that ever changes (say a future version adds an optional feature that talks to a server), this page will be updated first, and the change will be opt-in.
Questions about this policy? Email support@basetrend.nl.
Last updated: 18 September 2026.