As of 14 September 2026 · Applies to the Android app Yesta from version 1.32.0; anything marked from 1.35.0, from 1.38.0 or from 1.39.0 applies from that version · Deutsch · Español
In short: Yesta sends nothing. The app does not even
request the INTERNET permission — it is technically unable to
open a network connection. There is no account, no sign-in, no server and no
advertising.
All photos, all notes and all analysis stay on the device — unless you send something out yourself (section 5).
Yesta reads the device's photo library and builds its own index from it, in a database that exists only on the device. It contains:
| Kind of data | Source |
|---|---|
| Reference to the photo or video, capture time, folder name, file name | the device's photo library |
| Image dimensions, camera model, orientation | the shot's EXIF data |
| The shot's coordinates, where the camera recorded them | the shot's EXIF data — they stay on the device, see section 3 |
| Rating by sharpness, exposure, colourfulness | computed by Yesta on the device |
| Face prints and person groups | only after explicit consent — see section 2.1 |
| Labels for what a picture shows (“beach”, “Christmas”) with a confidence value | computed by Yesta on the device |
| Scaled-down copies of individual shots, so lists appear quickly | created by Yesta on the device, in the private app directory, clearable under Settings |
| Place name (“Hamburg, Germany”) | see section 3 |
| Notes you write about days and about individual shots | your input |
| Special days you enter yourself | your input |
| Which periods or shots you have hidden | your input |
| Names you give to groups of people, and which people you have hidden | your input — only with face grouping, see section 2.1 |
| Hearts on shots | your input, or taken over from your gallery |
| Capture dates you assigned yourself | your input |
| Letters to later: the text, the day it was written, the day it is to open, and when it was opened (from 1.35.0) | your input |
| On how many days the app was opened, how often via the widget or a notification, how often a slideshow ran and how often something was shared — numbers only | counted by Yesta on the device |
The photos themselves are not copied. Yesta remembers references to the shots and reads them in order to display them. No second collection is created. The one exception is Send as a day (section 5): it creates scaled-down copies, and photos you receive that way are placed in your gallery.
None of this is transmitted. The database sits in the
private app directory and cannot be read by other apps. Android's system backup
is explicitly switched off (allowBackup="false") — nothing goes to
Google Drive automatically either.
Yesta can recognise faces in your photos and put pictures of the same person together. To do so it computes a number for each face it finds: a face print.
That is biometric data within the meaning of Article 9(1) GDPR. Processing it is prohibited in principle, and here it rests solely on your explicit consent under Article 9(2)(a).
On first launch — and, on a device where Yesta is already installed, on the first launch after updating to 1.32.0 — the app asks: “May Yesta group faces?” The question cannot be swiped away; it has two buttons, and one of them has to be pressed. While it is unanswered, no face print is created. If you dismiss it without answering, it returns on the next launch.
| Where they are created | on this device, with a bundled model |
| Where they stay | in the database in the private app directory |
| Where they go | nowhere. Yesta does not hold the INTERNET permission |
| Who sees them | only you, on this device |
| What for | to group pictures of the same person. Nothing else |
No identification against any outside database takes place. Yesta does not know who is in a photo; it only establishes that two faces resemble each other. A group gets a name only when you type one in — and that name is your input, not a recognition.
You can withdraw your consent at any time under Settings → Group faces. Withdrawal does not merely stop the recognition: it deletes every face print, all groups and the names you gave them. If a note backup is set up, Yesta rewrites it at the same time — without names and without where faces were (from 1.39.0, section 5). This is final; if you switch the feature on again later, Yesta starts over, unless you read in an older backup file you kept yourself. The app tells you so before switching off. Withdrawal does not affect the lawfulness of processing before it (Article 7(3) GDPR).
Yesta works fully without face recognition: the look back, the calendar, notes, search by text, date and labels. Only the row of people in search is missing. Nothing in the app is tied to your consent other than the feature itself.
Shots often contain coordinates. So that “Hamburg” appears instead of
“53.55, 9.99”, Yesta passes the coordinate to Android's location
service (android.location.Geocoder). That service is part
of the operating system and usually resolves the request over the network —
depending on the device, via Google.
Important to understand: this request is made by the system, not by Yesta. That is why the app needs no internet permission. Only the coordinate is transmitted, never the photo and never any identifier of the user.
Since version 1.25.1 this is switched off. Unless someone turns it on, nothing leaves the device — not even a coordinate. Turn it on under Settings → Show places; turn it off again in the same place. Names already resolved remain on the device afterwards. Which data Google is responsible for during a lookup is governed by Google's privacy policy.
Yesta works with the coordinates themselves only on the device — for example for Your chapters (from 1.35.0), which reads off from the date and place of your photos which stretches you spent away from home. No place name is needed for that, and nothing is looked up.
Notes can be dictated instead of typed. For this, Yesta asks for permission to use the microphone the first time you tap the microphone icon.
Recognition runs on the device. Yesta uses only Android's own on-device recogniser. Where it is missing — on devices before Android 12 or without a downloaded language pack — the microphone button does not appear at all. There is deliberately no fallback to recognition over the network.
No audio recording is stored. What is recognised is the text, and it goes into the note field, where it can still be edited before saving.
The day card can read itself aloud: the date, how many memories there are
for each year, the names you have given to people, and your own note.
The speaking is done by the device's text-to-speech service
(Android TextToSpeech) — a separate app on the device, usually
from Google or the device maker. Yesta passes it only this text.
Yesta uses only voices that speak without the network and sets the voice itself rather than leaving the choice to the text-to-speech service. If there is no such voice for the language, Yesta does not read aloud — there is no fallback to a network voice. Reading aloud needs no new permission; Yesta may only check whether a text-to-speech service is installed. Nothing is recorded and nothing is stored.
Five paths lead out of the app. You start all five, and in all five you see beforehand what goes out.
Yesta opens only files created with Send as a day, and shows what is in one before anything is kept — through Open with, or under Yours → Open a shared day. Only when you tap Add does Yesta place the photos in the album “Yesta” in your gallery (Android 10 and later) and add them on the day they were taken; the album is added to your folder selection for that. A note that came along is kept only with Keep the note ticked, and goes below a note of your own, never over it. The copy of the file in the app's cache is deleted afterwards.
Whoever receives a day gets another person's photos, and perhaps their words, onto their own device. Yesta treats them like your own and passes them on nowhere.
In Settings, below the privacy note, there is a button Buy a
coffee. It opens the page ko-fi.com/yesta in the device's
browser — that is all it does. Yesta itself transmits nothing.
The app has no internet permission; it only hands the address to the browser,
which is a separate app.
From there on, the usual rules of the web apply: the operator of the page (Ko-fi) sees your IP address and sets its own cookies, and a payment is handled by PayPal or Stripe, depending on what you choose. Yesta does not learn who gives anything — there is no channel back into the app, and a contribution unlocks nothing in it. If you never tap the button, nothing changes for you.
| Permission | What for |
|---|---|
READ_MEDIA_IMAGES, READ_MEDIA_VIDEO | Reading the photo library. That is the purpose of the app |
READ_MEDIA_VISUAL_USER_SELECTED | So that sharing individual photos from Android 14 onwards does not count as a refusal |
READ_EXTERNAL_STORAGE | The same on Android 12 and earlier, where the two permissions above do not exist yet |
ACCESS_MEDIA_LOCATION | Without it, Android 10 and later strips the coordinates from every photo the app opens |
RECORD_AUDIO | Only for the spoken note. Requested when you first tap the microphone |
POST_NOTIFICATIONS | For the memory of the day and — from 1.35.0 — for a letter to later that opens today. That notification only says when the letter was written, never what it says. Off until you agree |
RECEIVE_BOOT_COMPLETED | So the widget shows the right day again after a restart |
ACCESS_NETWORK_STATE, WAKE_LOCK, FOREGROUND_SERVICE | Brought along by the WorkManager system library, which drives background passes. None of them allows a network connection |
…DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION | Created by the AndroidX system library. It makes sure that only Yesta itself receives its internal messages. No data, no dialog |
Not requested: INTERNET. Without this
permission an Android app cannot open a network connection.
Yesta contains no advertising networks, no analytics services, no third-party crash services and no user-tracking tools. No data is passed on to third parties, sold or analysed.
The counter under How is it going? counts on the device only and transmits nothing by itself.
Independently of this, Google Play collects its own data when the app is downloaded and updated (such as install counts and, where you have agreed, crash reports). Yesta has no influence over that; Google's privacy policy applies.
All data stays on the device for as long as the app is installed.
Uninstalling deletes everything Yesta has created in the app — database, notes, letters, settings and counters. The photos themselves are untouched; they belong to the photo library.
Yesta never changes or deletes a photo on its own. Two paths do so when you ask, both from Android 11, and in both Android asks in a dialog of its own before anything happens:
Individual notes and letters can be deleted in the app. If you only want to rebuild the index, you will find that under Settings.
Photos received through Send as a day (section 5) are in the album “Yesta” in your gallery. They stay there after uninstalling, like any other photo, and can be deleted in the gallery.
Face prints can be deleted on their own, without uninstalling: switching off Settings → Group faces deletes them along with the groups and names (section 2.1) — from 1.39.0 also the names in the note backup. The same goes for the scaled-down copies, which can also be cleared there.
A backup file in a folder you chose yourself remains after uninstalling — it belongs to you and lies outside the app.
Since no personal data is transmitted to the controller, none is held there that could be disclosed. The rights to access, rectification, erasure, restriction, objection and data portability (Art. 15–21 GDPR) exist nonetheless; for enquiries, the address in section 1 applies.
Anyone who has sent feedback or a problem report can request its deletion — that is the only situation in which anything can be held at all.
You have the right to lodge a complaint with a data protection supervisory authority.
Yesta is not directed at children under 13 and does not knowingly collect data from them. Since the app transmits no data, no processing outside their device arises even when children use it.
If anything about the processing changes, this policy will be adjusted and the date above updated. Substantial changes — in particular any transmission of data, which does not exist today — will additionally be announced in the app.
The German version is the authoritative one — this translation is provided for convenience. Zur deutschen Fassung