Last updated 28 August 2026
The short version. Cherry runs on your computer. Your photographs, the reasons written under them and the taste profile it learns are processed on your machine and are never uploaded to us. This policy covers the limited personal data we do handle: your account, your billing, this website, and anything you send us directly.
1. Who we are
Cherry is operated by ARCAS Systems - F.Z.E., a free zone establishment registered under licence number 48375 at Office C1-1F-SF14863, Ajman Free Zone C1 Building, Ajman, United Arab Emirates ("Cherry", "we", "us"). For the purposes of the UK GDPR and the EU General Data Protection Regulation we are the data controller for the personal data described in this policy.
You can reach us about anything in this policy at info@getcherry.io.
2. What this policy covers
This policy applies to getcherry.io, to the Cherry desktop application, and to any email or support correspondence between us. It does not apply to third-party websites we link to, which have their own policies.
3. What we collect, and what we do not
Your photographs and photo data: not collected. Cherry reads your files where they sit on your disk. Decoding, scoring, scene grouping and every model pass happen locally on your CPU. No photo, thumbnail, embedding, histogram or derived score is transmitted to us or to any third party. You can verify this yourself by running a full cull under packet capture with the bundled network audit.
Your taste profile: not collected. The profile Cherry builds from your keeps, passes and swaps is stored in your user library on your own machine. We do not receive it and we do not train any model on it.
Account data. If you create an account we store your name, email address, a hashed password, your licence status and the timestamps of account events. You can use the free desktop application without an account.
Billing data. Paid plans are processed by our payment provider. We receive your billing name, country, the last four digits of the card, and the transaction record. We never see or store your full card number.
Website data. Our servers log the IP address, user agent, referring page and timestamp of requests, for security and to keep the site running. We use privacy-preserving analytics that does not set advertising cookies or build cross-site profiles.
Support correspondence. If you write to us we keep the message and our reply so we can follow up.
Diagnostics. Crash reports and performance diagnostics are off by default. If you switch them on, we receive a stack trace, your operating system version and the application build number. Diagnostic reports never include photo data, filenames or folder paths.
4. Why we process it, and our lawful basis
To provide the service (account data, licence status, billing): performance of our contract with you.
To keep the service secure and working (server logs, abuse prevention): our legitimate interest in operating a safe and reliable product.
To answer you (support correspondence): our legitimate interest in responding to people who contact us.
To improve stability (diagnostics): your consent, which you can withdraw at any time in the application settings.
To meet legal obligations (tax and accounting records for transactions): compliance with a legal obligation.
5. Cookies and similar technologies
The website uses strictly necessary cookies to keep you signed in and to remember your consent choices. We do not use advertising cookies, tracking pixels or cross-site trackers, and we do not sell or share personal information for behavioural advertising. Where required, you will be asked before any non-essential cookie is set, and you can withdraw that choice at any time.
6. Who we share data with
We do not sell personal data. We share the limited data above with service providers who process it only on our instructions and under a written agreement: our payment provider, our email provider, our hosting and error-reporting providers, and our accountants. A current list of sub-processors is available on request from info@getcherry.io.
We may also disclose data if we are legally required to, or where it is necessary to establish, exercise or defend legal claims. If we are ever involved in a merger or acquisition, we will tell you before your data moves and what it means for this policy.
7. International transfers
Some of our providers operate outside the United Kingdom and the European Economic Area. Where personal data is transferred outside those areas, we rely on adequacy decisions where they exist, and otherwise on the Standard Contractual Clauses or the UK International Data Transfer Addendum, together with the technical safeguards described here. You may request a copy of the relevant safeguards.
8. How long we keep it
Account data is kept while your account is open and for up to ninety days after you delete it, so the deletion can be reversed if it was a mistake. Billing and tax records are kept for the period required by law, normally six to seven years. Server logs are kept for thirty days. Support correspondence is kept for two years. Diagnostic reports are kept for ninety days.
9. Security
Data in transit is encrypted with TLS. Passwords are stored using a modern password hashing function and are never recoverable in plain text. Access to production systems is limited to the people who need it and is protected by multi-factor authentication. No system is perfect, and if a breach ever affects your rights we will notify you and the relevant supervisory authority within the statutory deadline.
10. Your rights
If you are in the UK or the EEA you have the right to access your personal data, to have it corrected or erased, to restrict or object to how we process it, to receive a portable copy, and to withdraw consent where processing is based on consent. You can exercise any of these by writing to info@getcherry.io, and we will respond within one month.
You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner's Office. In the EEA it is the authority in the country where you live or work.
If you are a California resident you have the right to know what personal information we collect and why, to request deletion or correction, and to be free from discrimination for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, and we do not process sensitive personal information for the purpose of inferring characteristics.
11. Automated decision-making
Cherry makes automated judgements about photographs, but it makes them on your device, about your files, under your control, and you can overrule every one of them. We do not carry out automated decision-making that produces legal or similarly significant effects about you.
12. Children
Cherry is a professional tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.
13. Changes to this policy
If we change this policy we will update the date at the top and, where the change is material, tell account holders by email before it takes effect. Previous versions are available on request.
14. Contact
Questions, requests or complaints: info@getcherry.io, or by post to ARCAS Systems - F.Z.E., Office C1-1F-SF14863, Ajman Free Zone C1 Building, Ajman, United Arab Emirates.