Privacy Policy
EXIF Viewer by Fluntro — web tool, Chrome extension & Google Drive · Last updated 4 August 2026
This Privacy Policy explains how Fluntro (“we”, “us”, “our”) handles information across three products: the online EXIF metadata viewer at exifviewerapp.com/online-exif-metadata-viewer (the “Tool”), the EXIF Viewer by Fluntro extension for Google Chrome (the “Extension”), and the EXIF Viewer for Google Drive integration at exifviewerapp.com/drive (the “Drive Integration”) — together, the “Web Products.” Our iOS app has its own listing and terms on the App Store.
Information we do not collect
This applies across the Tool, the Extension, and the Drive Integration alike:
- We do not receive or store your photos or videos.
- We do not receive or store the EXIF or other metadata (including GPS coordinates) contained in your files.
- We do not require an account, name, email address, or payment to use any Web Product.
- We do not use advertising cookies, and we do not run third-party analytics or tracking in any Web Product.
The web Tool: what's stored on your device
To remember your appearance preference (light or dark theme), the Tool saves a single value in your browser's local storage, on your device. This preference stays on your device, is never transmitted to us or anyone else, and is not used to identify or track you. You can remove it at any time by clearing your browser's site data. Because it exists only to honour a preference you set yourself and involves no tracking, it does not require consent under applicable e-privacy rules; we mention it here purely for transparency. The Tool sets no cookies of its own.
The Chrome extension
The Extension works two ways: drop a local photo into its side panel, or right-click any image on a web page and choose “View EXIF data.” Either way, the image is fetched and parsed by your own browser and is never uploaded.
Site access
The Extension asks for permission to read an image from a website only when you right-click an image there — never broadly, and never on install. You can review or revoke this access at any time from the extension's details page in Chrome.
What's stored locally
The only thing the Extension ever stores is a small interface preference: which metadata sections you left open or closed. This is kept in Chrome's local extension storage, on your own device, and is never transmitted anywhere. No photo, filename, or metadata is stored — each photo is read and discarded as soon as you close it or open another.
The Google Drive integration
When you open a photo from Google Drive — either by choosing “Open with → EXIF Viewer” on a file in Drive, or by picking one through the in-app file picker — your browser requests that file's bytes directly from Google's Drive API, using a short-lived access token. The bytes travel from Google to your browser only; they do not pass through any server of ours, because the Drive Integration has none.
What permission we ask for
The Drive Integration requests exactly one Google API scope, drive.file — Google's narrowest per-file permission. It lets the Integration read only the specific files you open or select with it. It cannot list, browse, or search your Drive, cannot see your folder structure, and cannot see any file you have not explicitly opened. It also does not request your name, email address, or Google profile.
What's stored
Nothing. The Drive Integration uses no local storage, no cookies, and no offline database. The access token used to fetch a file's bytes is held only in your browser's memory for the current tab; reloading the page discards it, and you'll be asked to grant access again next time. There is nothing left behind to secure, export, or delete.
Google's role
Three Google services are involved in making the Drive Integration work: Google Identity Services issues the access token when you grant permission; the Google Picker API provides the file-selection dialog; and the Google Drive API serves the file's bytes. Your use of these is also governed by Google's own Privacy Policy.
Revoking access
You can remove the Drive Integration's access to your Google account at any time from your Google Account's permissions page. Because nothing is stored, revoking access leaves nothing behind.
Links to third-party services
The Tool may show links to services you can choose to use, such as the Apple App Store and the mapping providers Google Maps, Apple Maps, and OpenStreetMap (for viewing coordinates). If you follow such a link you leave our Tool, and that provider's own privacy policy then governs your interaction with them. A link only opens when you click it, and we share no information with these services. On Apple devices, Safari may also display Apple's own “Smart App Banner” suggesting our iOS app; that banner is provided by Apple and governed by Apple's privacy policy.
Website hosting and server logs
The page itself (its HTML, styling, and code) is delivered to your browser by our web host so that it can load. Like virtually all web servers, our host may process standard technical connection data — such as your IP address, browser type, and the time of the request — in server logs, for the limited purposes of delivering the page securely and reliably and preventing abuse. This is entirely separate from your photos, which never reach any server.
Your rights under the GDPR and similar laws
If you are in the European Economic Area, the United Kingdom, or another region with comparable data-protection laws, you have rights over your personal data — including rights of access, rectification, erasure, restriction, objection, and portability. Because the Tool, the Extension, and the Drive Integration do not collect, receive, or store personal data about you — your photos and their metadata never reach a server of ours — we hold no such data to provide, correct, or delete. Any standard technical log data described above is processed by our host on our behalf; if you have a request, contact us and we will help direct it appropriately.
To the limited extent that technical connection data is processed to deliver the page, the legal basis is our legitimate interest in operating a secure and functioning website (Article 6(1)(f) GDPR).
Children
The Tool, the Extension, and the Drive Integration are general-purpose utilities and are not directed at children. Because we collect no personal data through any of them, we do not knowingly process any information from children.
Changes to this Policy
We may update this Policy from time to time. The “last updated” date above always reflects the current version.
Contact
Questions about privacy? Contact us at [email protected]