Private screenshot search

How private on-device screenshot search works

Understand on-device screenshot recognition, local indexing, Photos permissions, and the privacy questions to ask before indexing a library.

Published
Reading time
7 minute read
By
Doxa Creative LLC

Direct answer

What makes screenshot search private?

Private screenshot search keeps recognition and the searchable index on the device, limits access to the Photos permission a person approves, avoids advertising and tracking, and makes external handoffs explicit. The privacy policy should say exactly what is stored and whether anything leaves the phone.

Recognition and search are separate stages

Text recognition converts visible screenshot text into machine-readable words. Indexing organizes those words so a later query can return matches. Search compares a query against that local index while the original image remains in Photos. Each stage can run locally, but the app's privacy policy should confirm its actual architecture.

Stillsift uses on-device recognition and a local index. It stores extracted text, category, confidence, and search records on the iPhone. Original images remain in Photos. Doxa does not receive those images or index records through the Stillsift app.

Photos permission defines the visible library

iPhone lets people control app access to personal information, including Photos. Full access can expose the approved library to the app's stated function. Limited access restricts the app to selected images. Permission can be changed later in Privacy and Security settings.

A full-library screenshot index needs full Photos access to be complete. A limited selection creates a deliberately partial index. The app should explain that difference before indexing so the person can choose privacy scope with an accurate expectation of search coverage.

Local does not mean invisible

A private design should still show what it is doing. Indexing status, recognized categories, confidence, and permission state help a person understand why a result appears or is missing. Deleting the app should remove its local index, while original screenshots remain governed by Photos and iCloud Photos.

System handoffs matter too. Calendar and Contacts changes should appear in Apple's editor for confirmation. Maps should open only after a deliberate tap. Keeping these transitions visible prevents private local analysis from becoming an unexpected external action.

Questions to ask any screenshot search app

Read the privacy policy before granting a full library. Ask where images are processed, whether text or embeddings are uploaded, how long index data persists, whether analytics are included, and what happens when access is reduced or the app is deleted.

Stillsift's planned 1.0 boundary is specific: no Doxa account, remote screenshot processing, advertising, analytics, or tracking. Apple processes purchases. The website remains a separate surface and should not be confused with the mobile app's local data path.

  • Does recognition run on the device or a server?
  • What extracted data is stored?
  • Can I choose limited Photos access?
  • Does the app include analytics, ads, or tracking?
  • What is removed when the app is deleted?

Sources and further reading

Related questions

Questions, answered

Does on-device mean no internet is ever used?

It means the screenshot recognition and index described here run locally. App Store purchases and the separate marketing website involve Apple or web services.

What happens if I delete Stillsift?

The local Stillsift text and search index is removed with the app. Original images remain in Photos.

Can I use limited Photos access?

Yes. Stillsift can index selected screenshots, but search results will cover only that approved subset.