English · 한국어 PhotoShare

Privacy Policy

Effective 28 August 2026 · Version 1.4

What changed: crash reporting (Firebase Crashlytics) is now described explicitly — what a report contains, what we strip before sending it, and how long it is kept (sections 2, 4 and 5). Nothing else about how we handle your data has changed.

PhotoShare is an app for sharing photos taken together on a trip. Photos are automatically sorted by the people in them, so each person can collect the photos they appear in. This policy explains exactly what the app collects, where it is stored, how long it is kept, and how to delete it.

The three things that matter most.

1. Who is responsible

PhotoShare is developed and operated by an individual developer. For any privacy question, request or complaint, contact: ehwogns1@gmail.com. We reply to data requests within 30 days.

2. What we collect and why

Account information

You can browse the app without an account. Signing in is required only when you create a trip or join one, because a trip needs a stable owner and member list.

When you sign in with Google, Firebase Authentication (a Google service) stores your Google account's email address, display name, profile photo URL and a unique user ID. Of these, only the unique user ID is used by the app itself — it identifies you as a member of a trip. We do not copy your email address or name into the trip database, and other members never see them.

Before you sign in, the app uses an anonymous Firebase identity so it can start up without asking anything of you. That anonymous identity holds no personal information.

Nickname

When you create or join a trip you choose a nickname (1–20 characters) which is shown to the other members of that trip. It is entirely your choice and does not have to be your real name.

Photos you upload

For each photo you upload, three files are stored:

The original keeps its embedded EXIF metadata. Depending on the camera and settings used, this can include the capture date and time, the camera or phone model, orientation, and — if location tagging was enabled when the photo was taken — GPS coordinates. We do not read, index or use these coordinates, but they travel with the file and are therefore stored on our storage provider and available to anyone you share the trip with, exactly as they would be if you sent the file by email or messenger. If you do not want that, remove location data from the photo before uploading, or turn off location tagging in your camera app.

We also store, in the trip database, the photo's capture time (read from EXIF), its file size, a content hash used to detect duplicates, and which member uploaded it.

Face data

This is the app's core feature and we describe it in full.

Depending on where you live, a face embedding may be classified as biometric or otherwise sensitive personal data. For that reason this processing happens only with your separate, explicit in-app consent: before your first upload the app asks for your choice, and faces are analyzed only in photos uploaded by people who agreed. If you decline, you can still share photos — the automatic people sorting is simply skipped. You can withdraw consent any time under Settings → People sorting (face analysis); withdrawal applies to subsequent uploads, and vectors already stored are deleted with the trip on the schedule in section 4. We keep a record of your choice, the policy version you consented to, and when.

Photos of other people. When you upload a photo containing other people, you are responsible for having their agreement to do so. Anyone who appears in a photo in a trip you belong to can ask us to remove it at ehwogns1@gmail.com, and we will act on that request.

Usage statistics

The app uses Google Analytics for Firebase to understand which features are used. We deliberately send only aggregate values: counts (for example, how many photos an upload contained) and speed ranges (for example, "under 1 second"). We do not send your user ID, trip ID, nickname, file names or invite codes.

Google Analytics itself automatically records the country, device model, operating system version and app version associated with each event, and assigns a randomly generated app instance identifier. You can reset that identifier by clearing the app's data or reinstalling the app.

Crash reports

When the app crashes or hits an internal error, it sends a crash report through Firebase Crashlytics. A report contains the type of error, the stack trace showing where the code stopped, the device model, the operating system and app version, and a randomly generated installation identifier.

Before a report is sent we strip file paths, photo URLs and raw server messages. Your photos, face vectors, trip names, trip IDs, invite codes, nickname and sign-in identity are never included in a crash report.

What we do not collect

3. Device permissions

PermissionWhy
Photos / media To let you pick photos to upload, and to save downloaded photos back to your gallery. Only the photos you select are read.
Notifications To show upload progress while an upload continues in the background. Optional — uploads still work if you decline, but Android may pause them when the app is not in the foreground.
Internet / network To upload and download photos.

4. How long we keep it

DataRetention
Trip, membership, photo records, face vectors 4 days from the trip's creation by default, or up to 7 days if extended with a rewarded ad — never more than 7 days, in any case. A scheduled backstop removes anything a failed cleanup left behind, at the latest 21 days after creation.
Photo files (original, viewing copy, thumbnail) Deleted with the trip. An independent storage lifecycle rule removes any remaining object at the latest 10 days after it was uploaded.
Account (sign-in identity) Kept until you delete it. See section 8.
Usage statistics Retained by Google Analytics under its own retention setting, currently 2 months for event-level data.
Crash reports Retained by Firebase Crashlytics under its own retention policy, currently 90 days.

Deleting a photo, leaving a trip or deleting your account removes the data ahead of these deadlines. Deletion is permanent — we keep no backup from which a deleted trip could be restored.

5. Who else processes your data

We use two infrastructure providers. Neither is given your data for their own purposes; both act on our instructions.

ProviderPurposeRegion
Google (Firebase Authentication, Cloud Firestore, Cloud Functions, Google Analytics for Firebase, Firebase Crashlytics) Sign-in, trip database, server logic, usage statistics, crash reports United States
Cloudflare (R2 object storage) Storage of photo files Asia-Pacific

This means your data is transferred outside your country and, if you are in the European Economic Area or the United Kingdom, outside it as well. Both providers offer Standard Contractual Clauses for such transfers, and we rely on those. See Firebase privacy and Cloudflare's privacy policy.

Photo files are transferred directly between your device and Cloudflare R2 using short-lived signed links. They do not pass through any server of ours. Those links expire after 7 days at most; anyone who obtains one before it expires can open that photo, so treat an invite link as you would the photos themselves.

6. Advertising

This app shows ads from Google AdMob. Ads cover our server costs so the app can stay free.

We do not place ads in the screens you use to download photos.

What is processed for ads

To show and measure ads and to prevent fraud, Google processes your advertising ID (an identifier you can reset in your device settings), your IP address and the approximate region inferred from it, device and app information, and records of ad views and clicks. For this purpose Google acts as an independent controller under its own policy — see how Google uses data in advertising.

Photos, face vectors, invite codes, nicknames and trip names are never sent to the ad network. Only when you finish watching a rewarded ad, a trip identifier and a user identifier (both random strings) travel back to our server through Google, so that we know which trip to raise the limit for.

Your choices

7. Security

No system is perfectly secure. If a breach affects your personal data, we will notify affected users and the competent authority where the law requires it.

8. Your rights and how to exercise them

You can, at any time:

Depending on your jurisdiction you may also have the right to access a copy of your data, correct it, restrict or object to its processing, withdraw consent, receive it in a portable format, and lodge a complaint with your data protection authority. To exercise any of these, email ehwogns1@gmail.com. We do not charge for these requests and we do not treat you differently for making one.

Our legal basis for processing, where the GDPR applies, is performance of the service you asked for (Art. 6(1)(b)) for trips, membership and photos; your explicit consent (Art. 9(2)(a)) for face vectors; and our legitimate interest in operating and improving the app (Art. 6(1)(f)) for aggregate usage statistics.

9. Children

PhotoShare is not directed at children and is not intended for anyone under 16, or under the minimum age of digital consent in your country if that age is higher. In the Republic of Korea, children under 14 may not use the service. We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact us and we will delete it.

10. Changes to this policy

If we change how we handle personal data — a new processor, an additional ad format — we will update this page and change the version and effective date at the top before the change takes effect. Material changes will also be announced inside the app.

11. Contact

ehwogns1@gmail.com