Privacy
A default Basic film talks only to your Immich server. Hugging Face Hub telemetry is disabled before imports in the app and inference service; there are no app analytics or update checks. Fetch model files during setup. Explicit download switches and some optional music backends can also fetch weights on first use, including during a run.
Optional features can contact other services. You choose which ones, and whether they run on your own hardware or outside your network.
Before adding a service
| Feature | What it receives |
|---|---|
| Text reader | Candidate annotations, dates, places, people/relationship and album names, plus your memory brief |
| Caption server | Small picture tiles and video-frame strips |
| LLM captions | Pictures, only with explicit caption_provider: llm |
| Inference service | Previews and sampled frames for classification; generated WAV music for stem separation |
| Render worker | Cut/timing metadata, primary and selected partner API keys, names, titles, home coordinates and network settings |
| Geocoding/maps | Rounded coordinates or map tile requests |
| Generated music | Mood/genre/tempo text; stem separation can send audio |
| Notifications | Run outcome/details, optionally a thumbnail |
| OIDC | The usual login flow to your provider |
The reader is disabled by default. Enable it with llm.enabled: true, blank base_url and openai-compatible or ollama for an owned local reader;
a remote URL or hosted provider preset sends text to that endpoint. Configuring a reader does
not enable image captions. Check the full request inventory for exact
hosts, switches and defaults. preflight names enabled geocoding/map destinations; that list
does not cover every outside endpoint. Its service checks also send authenticated probes.
What Immich sees
The app reads metadata, previews and source media. It never changes your originals. With upload off (the default), it does not write to the library. With delivery enabled:
- Upload the finished film as a new asset.
- Tag it
immich-memories/generated, so it is not selected as source footage later. - Add it to the configured album (create the album if needed).
- Move a recognised previous render of the same recipe to trash, if the API key permits it.
immich-memories config test only checks authentication/API compatibility.
Geocoding and maps
Both are off by default:
network:
geocoding: false
geocoding_url: ""
map_tiles: false
Geocoding gets city, village and trip names and names in the film's language. It sends
coordinates rounded to two decimals (about a kilometre) to Nominatim, once per place. That can
include home. Answers stay in the store. Set geocoding_url for your own Nominatim.
Place names are requested in the film's language; a place without a name in that language keeps its local name instead of an English fallback.
Map tiles come from ArcGIS World Imagery for trip maps and location-card backgrounds. Requests reveal the area, including home base. With tiles off, ordinary title/location cards still work. Maps and titles explains the result.
Fonts
Docker includes script fonts. Python installs include the core fonts; other alphabets use one explicit download:
immich-memories titles fonts --install
Font files are pinned and digest-checked. A render never fetches a font. Detector downloads are
off unless allowed; the Compose inference overlay allows them, and the GPU overlay's one-shot
immich-memories-caption-models container fetches the caption model's weights at compose up,
before the captioner starts. models fetch and the web UI's Fetch models button run the same
download on demand. ACE-Step and local Demucs can fetch their own weights on first use.
Those downloads contain no library data. Local ACE-Step uses app-pinned immutable Hugging Face
snapshots and refuses incomplete downloads; checkpoint revisions
list the pins. API mode uses the remote music server's checkpoints.
Thumbnails in the web UI
Your browser asks this app for pictures/video, behind the same login. The app fetches or serves cached media from Immich. The API key stays on the server. It only serves a picture one of the configured accounts can read: any other ID gets a 404, even when it sits in the cache.
Privacy mode
For sharing a demonstration without showing the actual film:
immich-memories generate --privacy-mode --year 2024
The encoded film blurs pictures, scrambles speech, substitutes names and moves places to a fake city. This changes the film, not network requests. Trip geocoding can happen before names are substituted. The output filename can still contain real information: rename it before sharing.
For a screen share, enable server.enable_demo_mode and turn on the UI's Demo mode eye button.
Each browser has its own choice. This only blurs what the UI displays.
Diagnostic reports
immich-memories report creates a local report, with configured credentials, known personal
names/places, coordinates, addresses, URLs and absolute paths removed. Asset IDs become report-local
hashes. It contains no pictures and sends nothing automatically.
Read it before sharing; automatic redaction is not a substitute for checking the file.
Documents never ship
A photographed ID card, passport, bank card, letter or form with readable personal text is held back on every tier, on purpose, including its OCR check against your own configured Immich server, never an outside service; see picking a shot for how it's caught.
Everything that can leave, and when
The network request inventory keeps the complete egress table and image-provider details together for operators.
The one picture seat
The ordinary reader receives text. Picture tiles go to the caption server, or to the configured LLM only after an explicit image-caption opt-in. See the inventory.
Files on disk, and cancellation
Technical privacy details cover local file permissions and cancellation. Keep the store backed up.
Fetch once, then block outbound
The offline Basic recipe seeds a model volume before restricting the app to Immich. It includes Docker's same-host internal bridge and a destination-scoped Kubernetes policy, with their routing limits.
Before using the Basic offline recipe
Basic omits the extra GPU/Full detectors and Laya sharing pre-screen. Choosing Family instead of Just us does not add that missing coverage. Review the film before sharing; the audience guide explains the limits.
For an additional text service, see Basic with a local text model.