Privacy Policy

Your library, and who can see it.

Literoom is a private library: nothing in it is published unless you post it to 2bit.pics, and only you can open it. There are no analytics, no ad trackers, and no third-party scripts. It’s also not end-to-end encrypted, and this page explains what that means along with everything else Literoom keeps.

Last updated October 8, 2026

This update: you can post a photo from your library to 2bit.pics. The post is public and covered by the 2bit.pics Privacy Policy; the photo stays private in your library.

Who this is

Literoom is run by Alex Akers, who also runs 2bit.pics. It’s a separate app with its own sign-in, and this policy covers it alone; 2bit.pics has its own.

Where your library lives

Your library is a private “space”: a set of records kept apart from your public repository on your AT Protocol provider (your PDS), and never published to the network. You are its only member, and Literoom only ever reads or changes it as you, after you sign in.

Today every library is kept by the indexing service behind Literoom (HappyView), which we run on Microsoft Azure — none are stored on a PDS yet, even one that supports private spaces. Moving libraries to PDSes that support them is planned; when that happens, this page will say so first.

A library holds:

  • your photos, as Game Boy Camera image data — four shades, the format itself, not the files you imported — with the title, description, tags, palette, and frame you give each one, and the date it was taken;
  • a fingerprint (a hash) of each imported file, so the same photo imported twice is spotted;
  • your albums, frames, and palettes;
  • if you use search, a description of each photo as a list of numbers, which is what search matches against. It says what a photo shows, so it’s kept exactly as private as the photo.

Who can read it

Only you, through Literoom. There’s no sharing yet, no public link, and no one else in your space.

It is not end-to-end encrypted. HappyView holds it as ordinary records in a database we run, so whoever runs that server — Alex Akers, and Microsoft as the host — could technically read it. We don’t look at libraries, except when you ask us to help with something in yours or the law requires it.

While Literoom is running, its server also keeps a copy of a library it has recently loaded in memory, so pages open quickly. That copy is never written anywhere, is dropped when you delete your library, and is gone when the server restarts.

Posting to 2bit.pics

Nothing leaves your library unless you post it. When you press Post on a photo, Literoom copies it into a public post on 2bit.pics, written to your account’s public repository like any other 2bit.pics post: the four shades, in the palette you picked, without its frame, and with the caption, alt text, content warnings, and challenge entry you chose for the post. Nothing else from your library goes with it — not the photo’s title, description, tags, or date. From then on the post is public, and the 2bit.pics Privacy Policy covers it.

Your library notes which post a photo became, so its page can link to it. Taking the post down there deletes it from your account and keeps the photo. Deleting the photo, or your whole library, doesn’t take its post down; do that first, or delete the post on 2bit.pics.

If your caption mentions someone by handle, Literoom’s server looks the handle up so the mention links to the right account: it asks the handle’s own domain, and if that doesn’t answer, Google’s public DNS. Only the handle is sent.

Importing

Imports happen in your browser. Literoom reads the files you pick — save files, printer captures, tile dumps, or ordinary images — converts them to the four-shade format there, and sends only the result, a title taken from the file name, and the date. The original files are never uploaded. For an ordinary image, that date comes from its EXIF data, which is read in your browser for that and nothing else; otherwise it’s the file’s modification date.

Exporting a photo as a PNG also happens entirely in your browser: nothing is sent anywhere.

Search

Search finds photos by what they show — “a cat”, “trees at dusk” — rather than by their titles or tags. It uses an AI model, MobileCLIP, that runs in your browser, not on our servers. It works in three steps.

  1. Getting the model. The model is published on Hugging Face (huggingface.co), and your browser downloads it from there the first time it’s needed: the part that looks at photos when you first index, and the part that reads text when you first search — about 66 MB together. Your browser keeps it, so each part is downloaded once. Hugging Face sees those downloads, with your IP address and browser as with any request, but nothing about your library or what you search for.
  2. Indexing. Nothing is indexed until you press Index. Your browser then fetches your photos from Literoom, shows each one to the model (in gray, so recoloring a photo doesn’t change it), and gets back a description: a list of 512 numbers that summarizes what the photo shows. It isn’t a caption anyone can read, but it can be matched against words, so it’s kept as private as the photo. The descriptions are saved to your library, so your other devices don’t have to repeat the work, and a copy stays in this browser.
  3. Searching. What you type is turned into the same kind of list by the model in your browser, compared there against your photos’ descriptions, and the closest matches are shown. What you type is never sent anywhere — not to us, and not to Hugging Face.

If you’d rather not use search, choose “No thanks” when Literoom offers to index, or turn it off on the Account page. Then there’s no search field, and nothing is indexed or downloaded for it in that browser. Turning it off there also removes that browser’s copy of your descriptions.

What we store in your browser

Three cookies:

  • hv_s — your session, encrypted before it’s set so it’s unreadable outside the server. Expires after 30 days; clearing it simply signs you out.
  • hv_p — a sign-in in progress, sent only to the sign-in callback and gone ten minutes later.
  • literoom-sidebar — the sidebar’s width and whether it’s collapsed, so it opens the way you left it. Kept for a year.

And in your browser’s storage:

  • grid zoom, whether frames are shown, whether search is turned off, and whether this browser keeps your library, under literoom:grid-zoom, literoom:album-zoom, literoom:show-frames, literoom:search, and literoom:offline;
  • if you choose Make Available Offline on the Account page, a copy of your library — every photo, album, frame, and palette (the literoom-library database) — so Literoom opens it without a connection, and your handle (literoom:handle), so the Account page can show it offline. It’s kept up to date while you use Literoom in that browser, and it’s never sent anywhere: it’s a copy of what our servers already hold. Literoom also asks the browser not to clear it when the device runs low on space;
  • if you use search, a copy of your photos’ search descriptions (the literoom-search database), so search doesn’t fetch them every visit, and the downloaded model, so it’s fetched once;
  • Literoom’s own code — its scripts, styles, and icons, and an empty page that starts the app without a connection — cached by a service worker so it loads quickly. It never caches your photos or any page with your library on it.

Signing out clears the session cookie, the copy of your search descriptions, and the copy of your library, and turns keeping a copy off, so whoever signs in next in that browser decides for themselves. It keeps the view settings, the model, and Literoom’s code, none of which says anything about your library, so the next sign-in doesn’t download the model again. To remove those too, clear this site’s data in your browser.

What our servers see

Ordinary web request data reaches our host (Microsoft Azure) and HappyView: your IP address, your browser’s user agent, the pages you requested, and when. It’s used to serve the app, keep it up, and fend off abuse — not to profile you. Literoom has no analytics at all, and loads no fonts or scripts from anywhere else.

Signing in

You sign in with your AT Protocol account through OAuth, so we never see your password. Your provider asks you to let Literoom manage your library, and to post photos to 2bit.pics for you — including entering one in a challenge you’ve joined. Literoom only posts when you press Post.

Other services in the path

  • Microsoft Azure, our host, and HappyView, which holds your library. Both are described above.
  • Your PDS provider, which you sign in with. Their privacy policy covers that.
  • Hugging Face, only if you use search, for the model download described above.
  • 2bit.pics, only for photos you post, as described above. To show the challenges you can enter, Literoom also reads which 2bit.pics challenges you’ve joined.
  • Google Public DNS (dns.google), only when a caption you post mentions a handle whose own domain doesn’t answer for it.
  • The PLC directory (plc.directory), or your own domain if your account has a did:web identity. When you open the Account page, our server reads your public identity document from there to show your handle. That request comes from our server, not your browser, and carries only your account’s ID, which is public.

Deleting things

Deleting a photo removes it, its search description, and its place in any album. Deleting an album removes the album but keeps its photos; deleting a frame takes it off any photo using it first. Deleted records are gone from HappyView’s database, and so are earlier versions of edited ones. Its log of changes to your library keeps an entry for each change: what kind of record it was (a photo, say), its ID, when it was added, edited, or deleted, and a fingerprint (hash) of each version, which can’t be turned back into it. None of what a record held stays. Copies can also survive in the database’s backups until those expire.

To delete your whole library, use Delete Library on the Account page and type the confirmation it asks for. That deletes the space your library is kept in, and with it every photo, album, frame, palette, and search description, the log of changes, and your membership. It can’t be undone. You’re signed out, and this browser’s copies of your search descriptions and of your library are cleared; another browser’s copies go when you sign out there, and one that kept your library notices the deletion the next time it syncs. Your Atmosphere account isn’t touched, and signing in again starts an empty library. As with single deletions, copies can survive in the database’s backups until those expire.

If you can’t sign in, or want help, email privacy@2bit.pics and we’ll delete your library for you.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete personal data held about you, and to object to its processing. Write to privacy@2bit.pics and we’ll help. Alex Akers is the data controller for what Literoom keeps.

Children

Literoom isn’t for anyone under 13, and we don’t knowingly collect data from them. If you believe a child under 13 is using it, email privacy@2bit.pics.

Changes to this policy

If what Literoom does with data changes, this page changes and the date at the top moves with it, with a note of what changed.

Getting in touch

Privacy questions and data requests: privacy@2bit.pics. Anything else: hi@2bit.pics.