Security and data safety
Your photo library is not an upload.
Takeout Rescue is designed around local files, separate output, cryptographic verification, and explicit failure reports.
Media stays local
ZIP archives, photos, videos, JSON sidecars, GPS coordinates, and repair reports are processed on your computer. Network access is used for license status, downloads, and update checks.
The license service receives a device identifier and entitlement state. It does not receive filenames, media, metadata, coordinates, or repair reports.
Originals remain unchanged
The source ZIP or extracted folder is opened for reading. Repaired files are created under a different output directory, existing destination files are not overwritten, and an output location inside an extracted source is rejected.
Verified dependencies and releases
The Windows repair engine is an embedded ExifTool package pinned by SHA-256.
Windows releases require Authenticode signing and signed update manifests.
Known boundaries
Takeout Rescue does not invent missing Apple MakerNote identifiers, transcode damaged video streams, or promise recovery of information absent from both the media and Google sidecar. Ambiguous matches are reported instead of silently forced.