Privacy

Private by default.

Last updated · July 2026

This is the short, honest version of how we treat your event and your photos. The principle behind all of it: a roll belongs to the people at the event, and no one else.

What we collect

To run an event we need the basics: the host's account details (name, email), the event settings, and the photos taken on the roll. Guests joining with an invite code can participate without creating an account; we hold only a device identifier so their shot count works.

We don't scan your photos for advertising, train models on them, or sell any of this to anyone.

Your photos are yours

Photos belong to the people who took them and the host of the event. We store them so the roll can develop and be shared with the guest list — that's it. Deleting a photo removes it for everyone on the roll.

Rolls are private by default

Only people on the guest list can see a roll — before or after it develops. Rolls are never public, never indexed, and never appear anywhere except your event page.

The invite code is the key: anyone the host shares it with can join until the host locks the guest list.

Retention and deletion

Rolls stay available to the guest list until the host deletes the event. Deleting an event permanently removes its photos from our storage within 30 days, including backups.

You can request deletion of your account and everything attached to it at any time.

Contact

Questions about privacy? Reach out through the contact page and we'll get back within a couple of days.

    privacy | photo