Section 1 A roll, start to finish
Four steps. The first three happen on the phone, over however many days the roll takes; the fourth happens once the scans are back, and it is the only one with a choice in it.
-
Step 1.1 Your gear, and your name
Creator and Copyright are copied into a roll when it is created, not added to it later. Set them before the first roll, not after.
- Bodies
- Gear → Cameras. Make and model get written into every scan.
- Lenses
- Gear → Lenses. Mount is optional. The aperture dial can be bounded to the stops the ring really clicks at, half-stops included.
- Creator & Copyright
- Settings.
The marked rows in Fig. 1 came from a bundled catalogue and still follow it, so an app update can correct one. Editing a row makes it your own copy and stops those corrections, which the editor says before you do it. What you added yourself survives the fork: a lens keeps its serial number, a film its notes and scanned barcodes, and Use the catalogue’s version is the way back without losing either. Films and lenses have a catalogue; cameras do not, on purpose.
Barcodes are learned rather than shipped. The first scan of a box asks which film it is and every scan after that is instant, which is slower on day one and right for the reason that matters: a wrong barcode in a bundled table would load Portra onto HP5 and be believed.
Fig. 1 Gear, before the first roll. -
Step 1.2 Create the roll, and load it into a body
Both halves are the same form: the film goes at the top, the body at the bottom.
- Rolls → + → New roll
- format, stock, the ISO you're rating it at.
- Scan the film box
- fills in the stock from the barcode.
- Name
- optional; a roll is labelled by its canister number either way.
- Load into a camera now
- on the same form, or later from the roll or Apple Watch.
- Swapping one out?
- the app asks what happened to the last roll: shot to the end, or pulled part-shot.
Fig. 2 New roll — film at the top, body at the bottom. -
Step 1.3 Log each frame as you shoot it
A frame logged without the dials in view records the time, place and gear and leaves the exposure blank on purpose. It is never guessed from the frame before it.
- Set the dials, tap Log frame N
- time and place are stamped automatically.
- No dials in view
- Live Activity, Action button, Siri, Apple Watch.
- Skipped a frame?
- Add blank frame holds its place: pairing is positional.
- Finished
- ✓ marks the roll Exposed.
The dials are for a phone already in your hand. Most of a roll is not like that, so there are paths that log a frame with nothing on screen at all, and one more that decides which camera they log onto. Each records the time, the place and the gear. What none of them ever does is guess an exposure. On these routes a frame's light was either set by a person, in a shortcut or on the wrist's own dials page, or it is not recorded at all. Nothing in the app derives one.
- The lock screen. A loaded roll puts a Live Activity there: the frame count, and a button that logs the next frame without unlocking. The mark shows in the Dynamic Island.
- The Log Frame control. One control, placed on the Action button, in Control Centre or on the Lock Screen, with no trip through Shortcuts to set it up.
- Siri and Shortcuts. Log Frame and Record Track run from a spoken phrase or a shortcut, with the phone locked and without bringing the app forward. The roll picker searches everything, archived rolls included, and the intent takes a Note. It takes the dials too, if the shortcut sets them.
- In hand. With several bodies loaded, none of these paths can see which camera you just used. The same left-edge swipe that archives a roll offers In hand on a roll that is in a camera, and so does holding that roll down; every blind path logs onto that body until you say otherwise.
Apple Watch is the one that is an app rather than a button. A page for each loaded body, dials on a page of their own, and a grid two across when there are several: tap the camera you just shot, hold it to open that camera's dials. It does not need the phone to be reachable. Every press is written to the watch's own disk before the radio is asked for anything, and a press that waited is placed on the roll by the time it was made rather than the time it arrived. The watch takes its own fix at the press, because the arm that pressed the shutter is a better answer than a phone in a bag two rooms away; the GPS runs for the press and goes off again, and a press that found no fix carries none. Lock page guards against a stray swipe, the frame count turns orange once the roll is full, and rolls can be loaded and finished from the wrist.
Every frame records which route made it, which is what answers the question why has this frame no exposure? when somebody asks it months later. It stays in the app: there is no EXIF tag for how a shutter release was pressed, and inventing one would put provenance about this app into somebody else's photographs. An imported log (§3) therefore cannot restore it, and correctly carries nothing.
Fig. 3 Frame 4 carries no exposure, left blank on purpose rather than guessed. Fig. 4 The roll on the lock screen. The count, the last frame's settings, and a button that logs the next one without unlocking. What it does not carry is a pair of dials, which is why a frame logged here records no exposure. -
Step 1.4 Write the log onto the scans
All three routes write from the same document, by the same positional pairing, into the same tags. What differs is which files they open and what they leave behind (§6).
- On the phone
-
- ⋯ → Write onto scans, then From Photos or From Files.
- Check the pairing, tap write. JPEG only: a TIFF is refused.
- Files replace in place; a photo written back onto itself keeps Revert.
- On the Mac
-
- Film → Receive…, then tap this Mac on the phone, or AirDrop the exported
.json. - Drop in the scans, check the pairing, press Write metadata.
- Every scan keeps an
*_originalbackup. Full detail: §3.
- Film → Receive…, then tap this Mac on the phone, or AirDrop the exported
- In a browser
-
- Export shot log, then drop the
.jsonand the scan folder into metalign web. - Check the pairing, then Write into the files (Chrome, Edge, Opera) or download a ZIP.
- Nothing is ever uploaded; see §6.
- Export shot log, then drop the
Section 2 Three hand-offs
The roll above is one of three things that cross between the apps. The other two are about a digital body rather than a roll of film, and they take the same two routes.
| What travels | From | To | How |
|---|---|---|---|
A roll's shot log, one .json |
Rolls, on the phone | Film | Over the local network, or as a file you AirDrop |
| A recorded GPX track | Digital → Track | Geotag | The same two routes, carrying the same bytes |
| The true time | Digital → Sync Clock | Timestamp Correction | Through a photograph |
The third is the odd one. The Sync Clock draws a QR carrying metalign: and
the exact instant; you photograph it with the camera whose clock is wrong, and metalign
desktop reads the true time back out of that shot. The photograph is the carrier, so it needs no
network and no clock on either machine being right. It is for digital bodies: a film
frame's time is stamped at the shutter.
Section 3 Handing over a roll
On the phone
The ✓ in the toolbar — Finish roll — marks the roll Exposed; Mark as in the ⋯ menu carries all five states, Unused through Scanned. Export for metalign is in that menu while the roll is still loaded and in the toolbar once it isn't. It opens a screen showing what the document will contain, any warnings, and the JSON itself.
On the Mac
In Film, click Receive…. The panel says Listening and names this Mac; that name appears on the phone under Send to metalign. One tap sends it. The Mac answers with the roll and frame count it decoded, not what the phone said it sent, so you know it arrived while you are still standing there. The listener runs only while that panel is open.
Or as a file
Export shot log writes the same bytes to
<roll> — shot log.json. AirDrop it and drop it on the Film section
together with the scans; one drop zone takes both. No network, no listener, no Mac in the
room. It is also the only route to the browser — see §6 —
since nothing served to a tab can answer a push.
And back again
The same file comes in. Rolls → Send or import a shot log → Import a shot log takes one or several, and shows what each would add before anything is written: the roll, its frame count, the film and body it names. Gear it would create is called out separately and in orange, because finding a camera in your list that you never added is worse than being told about it first.
It is a reconstruction rather than a restore, and the screen says so plainly: “A shot log carries the roll and its frames. Where the roll was kept, its expiry, whether it was archived and which frames were flagged are not in the file, and the roll gets the next free number for its canister. Gear it names is matched against what you already have, and added when there is no match.” Nor does it carry which route logged each frame (§1.3), so an imported frame correctly says nothing about that.
A roll that is already in the library is refused by its own name rather than merged, and the refusal says what to do: delete the one you have if you meant to replace it. A file that could not be read is named by its filename instead, because a file nothing could be decoded from has no roll to name itself after, and being told “this isn’t a shot log” about one of three files you picked is a message you cannot act on.
Read before you walk to the Mac
Two warnings are properties of the document, so they apply whichever route you take: “This roll has no camera set, so the scans get no Make/Model, and metalign groups by model”, and “No frame has a capture time, so no dates will be written.”
Section 4 Pairing is positional
The rule
A scan is written with the frame it is level with in the table. Nothing else binds them: not the number in the lab's filename, not the frame number in the log.
Scans go down the left in filename order, the log's frames down the right, and only the left column moves. It works this way because the alternative fails silently: labs number files however they like, frame numbers skip, and a delivery missing one frame would mis-assign the whole rest of the roll with nothing to say it happened. The frame number is the label you check the pairing against, never the key it is made with. So check it. A row shows the frame the way the roll's own frame list draws it, with the scan under it: the exposure, time and title on the first line, the thumbnail and filename on the second. An off-by-one across a roll is obvious in pictures and invisible in filenames.
Only the scan column is re-ordered: re-arranging frames would be editing the roll from the wrong end. The frame column can gain one, and only that, a blank frame inserted from the row it belongs on, because the pairing table is the one place the missing negative's position is actually known.
- A frame the lab never returned is an empty row marked No scan. Drag it up to that frame and everything below moves down one, or right-click it and pick Move to frame. ⌘Z undoes any of it, and nothing on disk is touched either way.
- The same frame twice — a re-scan, or one job number repeating another — wears an orange !. It is read off filenames, so metalign desktop never acts on it: click the mark to see both frames, then Not a duplicate or Remove. Until you answer, the roll below sits one row out of step with the log. Check the pictures compares the images themselves and says which way the evidence went.
- A blank frame is a frame number with nothing logged on it, a negative you know exists and know nothing about. The counter read 18 while the app held 17, or a press went unlogged. It holds its place in the numbering, and it usually has a scan, because the negative is on the film for the lab to find. So a scan level with a blank frame is most often correct; it just can't be checked, because the log has nothing on that row to check it against. That is what the phone says about it, and why it asks you to look rather than telling you to repair.
- A placeholder is the other half of that pair, and they are opposite things. A blank frame is a negative that exists and carries nothing; a placeholder is a row no file lands on, a gap you open in the scan column when the lab skipped a frame. The phone draws them as a pair to keep them apart: a solid mark beside Blank frame, a dashed one for the placeholder. Each column repairs its own side. More frames than scans wants a placeholder; more scans than frames wants a blank frame.
- Deleting a logged frame is the same physics from the other end. Take a row out of a roll and every scan below it pairs one negative high: positionally, on another machine, weeks later, with nothing going visibly wrong. So the swipe settles that as two claims made one at a time, rather than one question arriving under a thumb already moving. A frame carrying anything offers Blank first, which says only I have nothing to record about this negative. Nothing moves, no number is re-dealt, and the row that now reads Blank frame carries an Undo beside those two words. Only a frame that already claims nothing offers Delete, and that is the claim that shortens the roll: “This frame is already empty. Deleting it takes its number off the roll, so the frames after it move up one.” The one-step route is kept on the long press with its question intact, because a frame logged by a double press stands for a negative that never existed, and blanking that one first would assert something false.
- A roll whose log has already gone out is told what a re-deal makes stale. One sentence in the dialog, and never a refusal: “Its log has already gone out, so moving the rest up leaves old numbers in the scans until you send it again.” Nothing is broken by it — metalign pairs positionally, not by the frame number written into a scan — and sending the roll again puts the two back in step. The marks a roll carries for having been sent and written are recorded, never enforced.
- The roll's first frames may have no logged frame at all. A body loaded fresh sits below 1 — an M6 at −2 — and those wind-on presses are blind, so they are real negatives nobody logged. A lab that scans them delivers those files first, and the scan column sorts by filename, so they take the top rows while the surplus shows up at the bottom. The two ends are not the same row: the blank frame to add belongs at the top, and adding it at the bottom instead pairs every scan on the roll two negatives high, with nothing on screen saying so. Fig. 9 is that case on the phone.
- An empty exposure is not a fault. A frame logged from the Action button, a control, the Live Activity or Apple Watch had no dials on screen, so it records the time, place and gear and leaves the exposure blank rather than copying the last frame's.
Section 6 Mac, phone, or browser
All three write out of one document, by one pairing rule, into the same tags. What they do not share is which files they will open, where the finished file ends up, and what they leave behind. One of the three is worth a paragraph first.
No app on either device can introduce metalign web, because it runs on neither: it puts the Film section in a browser, entirely on the machine it is open on. Nothing is uploaded and there is no account. That is not a promise about our conduct but a property of the page: it is served under a policy that permits it no connections of its own, so there is nowhere for a scan to go.
| Property | metalign, on the Mac | metalign companion, on the phone | metalign web, in a browser |
|---|---|---|---|
| Scans it will write | What the bundled ExifTool writes, TIFF included | JPEG only — ImageIO will not put a capture date into a TIFF's EXIF | JPEG and TIFF, written natively; ExifTool only for the files it will not vouch for |
| Where the file ends up | In place, beside the lab's delivery | From Files, replaced where it sits; from Photos, edited in place and filed in an album | In place, in the folder it came from, on Chromium; everywhere else a ZIP of the roll |
| Backups | An untouched *_original of every scan |
None of its own — Photos keeps the original, and Revert undoes the write | An *_original, written before the new bytes; the ZIP route reads the scans and touches nothing |
| Flash | Writes EXIF:Flash |
Never writes it, in either direction | Writes EXIF:Flash |
| A position nobody measured | Writes GPSProcessingMethod into the EXIF GPS block |
Writes the same value, into the XMP packet rather than the EXIF block, where a reader of EXIF alone will not find it | Writes it into the EXIF GPS block |
| Caption, title, keywords | MWG composites — EXIF, IPTC and XMP together | XMP, mirrored into ImageDescription, Artist and Copyright; no IPTC block |
MWG composites as well — EXIF, IPTC and XMP, in JPEG and TIFF alike |
Section 7 Worth knowing
- A roll is a source folder, which is how a lab delivers a job. Drop the whole download and each roll gets a tab; Write metadata writes every roll that has a log chosen, not just the one on screen.
- Lab scans are big. A 36-exposure roll of TIFFs runs to about 2 GB, so Film can write a JPEG beside each scan and tag only that one, leaving the lab's file byte-for-byte as it arrived.
-
Afterwards they are ordinary photos. They carry a real
Make,Modeland capture date, so they group by camera in every other section like any digital file. - Three bodies are verified end to end: Leica M10-P, Leica Q-P and Sony A7 III. Everything else is expected to work and has not been checked here.
- Both devices need the same network for either push. The file route needs none.
- Two devices, one library, if you switch it on. Sync with iCloud is off until you touch it, and the same switch is the way out: leaving keeps the local library. Where two devices logged into one roll, capture time is the physical frame order; a later edit wins whole rather than being stitched together field by field; tracks travel once they have been stopped; and a roll deleted on one device stays deleted on the others. Two rows report it rather than one — Status and Last synced — because a launch that has not reached iCloud in a week sits at Syncing…, which reads exactly like a device that synced a second ago. This is the nuance behind no account on the front page: metalign has no account of its own and uploads nothing to anyone, and sync, when you turn it on, is your own iCloud.
- A body whose counter starts below 1 can say so. Counter starts below 1 on the camera puts a fresh M6 at −2, and the app then relabels to match the dial you are actually reading while the log's own ordinals stand. That is the other half of the wind-on story in §4.
- Filters are recorded, never applied. Pick one and the capture bar says what it costs: “Yellow #8 costs 1: give 1 stop more than the meter.” Any exposure compensation you dialled is already added into that number, because both push the same way and you would otherwise be adding them up yourself between metering and setting the ring. What it never does is move the dials. They record what the camera was set to, not what it should have been.
- A frame with both a time and a place knows its light. Daylight, golden hour, blue hour, twilight or night, with the sun's altitude and its direction, worked out on the device from the two facts already logged and following a corrected time. A frame missing either one reports nothing rather than borrowing from the frame before it. None of this is written into a scan: it is the app's reading of the log, not a claim the log makes, so it is absent from §5 on purpose.
- A frame that got no place can still be given one. A fix more than two minutes old is not used, and a press from the watch may find nothing, so a roll can come back with gaps in it. The roll's ⋯ menu opens a Frame map: the frames that recorded no place, and under them the ones already on the map. Tap one of the first and it can take its place from the nearest located frame before or after it in time. It names the frames it is offering, how long before or after they were shot and how far apart they are, so the tolerance is seen rather than asserted; where only one side of a frame recorded a place it says that instead, because then nothing bounds the guess at all. Or you can put the pin down yourself. Two rules hold either way. An estimate is never the source for another estimate, which is what stops one guess walking down a roll. And it carries no accuracy figure, because the accuracy belonged to the measurement. Unlike the light above, this one does reach the scan: §5 has the tag.
Provenance
Read out of the three apps on and checked against them again on — the on-screen wording from the sources rather than from their documentation — and copied here by hand. Nothing keeps it in step automatically. Where the apps disagree with this page, the apps are right. The screenshots are of metalign companion running in a simulator on the first of those dates, on made-up film: there is no such roll and the coordinates are a mountain. The second check was every quoted control on both pages — 36 of them — grepped against the three repositories, plus §4's claims against metalign companion's own FRAMES.md and SCANS.md, and the three version numbers above against each project.yml. All of it held. It was run because this page was about to be published, and the seam it sits on is the one with no test on either side: a reworded string in an app breaks a transcription here without changing anything a build could notice. The material added later the same day is the exception to the row above, and says so here rather than quietly joining it. §1.1's two paragraphs on the catalogue, §1.3's account of the five ways to log a frame, §3's And back again, §4's two bullets on deleting a frame and the last four bullets of this section were read out of metalign companion's source and its own documents, not off a running screen. Every control they name and every sentence they quote was matched against a string literal in that repository, which catches a wrong quotation and would not catch a screen that no longer shows it. Only one of them touches a published plate: §1.1 explains the catalogue mark Fig. 1 has always drawn and this page had never named. One claim here was checked from the other side rather than only from this one, and it is the exception worth naming because it had been wrong. §1.3 and the landing page both said the screenless routes put no dials in front of you; the watch has a dials page, and a press there records a real exposure. Corrected 26.08.2026 and then verified against the app's source by a session working in that repository, which also established the boundary this wording now respects: a dial can be carried from an earlier frame rather than set for this one, so what holds is that nothing is ever derived, not that every value was chosen afresh. Added , and belonging to the same exception: §5's paragraph on a position nobody measured, the rows §5 and §6 gained for it, and this section's last bullet. All of it was read out of the three repositories' source rather than off a running screen: the phone's frame map and the picker it opens, the location a frame edit mints on the Mac and in a browser, and, for the question of where the tag lands, each writer's own tests and the measurements recorded beside them. The one screen seen running that day is the one in Fig. 6, whose menu had gained a row.