Skip to main content
Vixlo 0.1

The guarantees

This page is the short list of promises Vixlo makes about your photographs, and where the app says each one on screen. Read it before you trust the app with a card, and before emptying the bin or rebuilding an index.

The list​

  1. Originals are never changed. Nothing in Vixlo opens a photograph for writing. A decision, a rating or a label is written to the library's index and, in a library you imported, to a small file beside the photograph. A crop, a spot clean or any other develop setting is written to that file, with a copy in the index; the three Earlier libraries have no folder to write it in and refuse it. None of it goes into the photograph. Your originals are never changed.
  2. The source is read at import and never written to. Nothing goes onto the card or folder you imported from — not an XMP file beside a photograph, not a mark that a file was copied, not a deletion. The review refuses a working library or backup folder on the card itself. Vixlo never formats a card, and it says one is safe to format only when every photograph on it, the ones the library already held included, has two verified copies on two different volumes, when no video, XMP file or other file the import does not copy is left on it, and when no part of it went unread. Every photograph an import adds is the library's own copy, checked against the original first; a file that did not verify is left out, never linked to the card. Your originals are never changed, When a card is safe to format and What counts as the card.
  3. No photograph is deleted except by Empty bin. Reject, Restore all, Undo, closing a library, quitting — none of them deletes, moves or renames a photograph. One action deletes photographs; it asks first with a count, and only for the library's own copies. The one action that deletes a photograph.
  4. A library is a folder, and the index is rebuildable. In a library you imported, every decision, rating, label and develop setting is also written into a small file beside its photograph, so the index can be lost and rebuilt from the folder. Only the undo history, your favourites and the pass you had open live in the index alone. (The three Earlier libraries keep decisions, ratings and labels in the index alone, because their photographs are bundled in the app, and cannot store develop settings at all.) A library is a folder and The index can be rebuilt.
  5. The pass never reorders under you. Once you start walking a pass, the list of frames is frozen; deciding on a frame never pulls it out from under you. Nothing decides for you.
  6. Nothing Vixlo measures becomes a decision. Every score, mark and suggestion is advisory; only a key you press, a button you click or an Accept you choose writes a Take, Hold or Reject. Nothing decides for you.
  7. Nothing leaves this Mac except the licence check — and what you turn on yourself. Your photographs, their names, your decisions and your edits never go through your account. Two features can send something small off the Mac; both stay off until you set them up, and neither ever sends a photograph. What leaves this Mac, and when.
In Vixlo 0.1

Two things fall short of these promises in this version, each set out on its own page:

Where the app says it​

The title bar of the cull page and the edit page carries Originals read-only at its right, on every library. Beside it, Saved says what you have done has reached the library's folder. If a write ever fails, the cull page's bar shows Not saved in the Reject colour in its place.

The cull page's title bar with Originals read-only and Saved at the right

The launch screen's HOW A LIBRARY WORKS card says Originals are never rewritten — Ratings, states, labels and adjustments are metadata. The photographs stay byte-for-byte as shot.

The Library rules sheet marks three rows ALWAYS, because they are not choices: Originals are read-only in every library — This cannot be turned off. Culling, rating and editing only ever write metadata.; Photographs render with metadata applied; and Holds stay as a revisit queue.

The three always rows on the Library rules sheet

Every step that writes files says what it will and will not touch. The Hand off folder picker: Nothing is copied, moved, or deleted — your originals stay exactly where they are. The Export folder picker: Nothing is written to your originals. The import sheets: Originals stay untouched on the source the whole time. The sign-in card says it of the account too; What leaves this Mac, and when quotes it.

What "metadata" means here​

A photograph is the file the camera wrote. What you decide about it — that you took it, that it is four stars, that it wears a look and a crop — is a small amount of text kept in the library's index and in an .xmp file beside the photograph. Vixlo draws the photograph through that text. The photograph itself is the same bytes it was the day it came off the card.

The deletions that stop and count​

The app can destroy things you cannot get back, and three of those actions stop and count before they run.

  • Empty bin… deletes the library's own copies of rejected frames. The one action that deletes a photograph.
  • Forget my taste…, in the Proposals and criteria pane, deletes what proposals have learned from you — never a photograph, never a decision. Learning from your decisions.
  • Remove, on the Models on this Mac sheet (Vixlo ▸ Models…), deletes a model's files from this Mac — never a photograph, never a decision. Removing a model.

Each opens a sheet that names what is about to go and how much of it: This deletes 3 items — 412 MB for a model. Cancel — or Keep them, for the bin, or Keep it, for a model — is the safe way out.

In Vixlo 0.1

The Remove sheet for a model ends Run the model's fetch script again to bring it back. The app cannot do that for you, so on a Mac with only the app a model you remove stays gone.

Smaller removals ask nothing — Delete on a saved search, which ⌘Z does not bring back, and Clear on a stored API key or on the Diagnostics log — and none touches a photograph or a decision. Recent and saved searches and Cloud providers and their keys say more.