Choose language

Security and data handling

Your guests hand you their photos. This page says plainly where those photos live, who can reach them, how long we keep them, and what to do if you find a security problem.

Last reviewed: 24 September 2026

Where the photos are stored

Photos and videos are stored with Cloudflare R2. Events of EU users are served from EU servers. Event data such as titles, albums and permissions is stored with Google Firestore in a European region. Everything travels over HTTPS, and both providers encrypt the stored files.

Who can see an event

An event is reachable only with its link or QR code. There is no public directory and no way to browse other people's events.

How long we keep things

Payments

We never see your card details. Subscriptions are handled by Paddle or by the app stores, and printed products are paid for at our print partner's checkout.

Who processes data for us

The processors we use, what they do and where they sit are listed in our data processing agreement. Business customers can conclude it with us electronically.

Data processing agreement · Privacy policy · Terms

Reporting a security problem

If you find a vulnerability, please tell us before you tell anyone else. Write to [email protected] with the steps to reproduce it. We read every report, we answer, and we will tell you when it is fixed.

Please stay within these lines while you look: use only your own events and test data, do not run load or denial of service tests, do not access, change or delete other people's content, and give us a reasonable chance to fix the issue before you publish it. If you do that, we will treat your report as a favour and not as an attack.

This page is also referenced from /.well-known/security.txt.