Privacy Policy
Effective 28 August 2026 · Version 1.4
What changed: crash reporting (Firebase Crashlytics) is now described explicitly — what a report contains, what we strip before sending it, and how long it is kept (sections 2, 4 and 5). Nothing else about how we handle your data has changed.
PhotoShare is an app for sharing photos taken together on a trip. Photos are automatically sorted by the people in them, so each person can collect the photos they appear in. This policy explains exactly what the app collects, where it is stored, how long it is kept, and how to delete it.
The three things that matter most.
- The app analyses faces on your device and uploads only a numeric vector — never a cropped face image.
- A trip and everything in it is deleted automatically 4 days after it is created — up to 7 days if extended with a rewarded ad, and never longer than that. There is no long-term archive.
- Photos are uploaded with their original EXIF metadata intact, which may include GPS coordinates. See “Photos you upload”.
1. Who is responsible
PhotoShare is developed and operated by an individual developer. For any privacy question, request or complaint, contact: ehwogns1@gmail.com. We reply to data requests within 30 days.
2. What we collect and why
Account information
You can browse the app without an account. Signing in is required only when you create a trip or join one, because a trip needs a stable owner and member list.
When you sign in with Google, Firebase Authentication (a Google service) stores your Google account's email address, display name, profile photo URL and a unique user ID. Of these, only the unique user ID is used by the app itself — it identifies you as a member of a trip. We do not copy your email address or name into the trip database, and other members never see them.
Before you sign in, the app uses an anonymous Firebase identity so it can start up without asking anything of you. That anonymous identity holds no personal information.
Nickname
When you create or join a trip you choose a nickname (1–20 characters) which is shown to the other members of that trip. It is entirely your choice and does not have to be your real name.
Photos you upload
For each photo you upload, three files are stored:
- the original file, unmodified;
- a downscaled copy used for viewing in the app;
- a small thumbnail.
The original keeps its embedded EXIF metadata. Depending on the camera and settings used, this can include the capture date and time, the camera or phone model, orientation, and — if location tagging was enabled when the photo was taken — GPS coordinates. We do not read, index or use these coordinates, but they travel with the file and are therefore stored on our storage provider and available to anyone you share the trip with, exactly as they would be if you sent the file by email or messenger. If you do not want that, remove location data from the photo before uploading, or turn off location tagging in your camera app.
We also store, in the trip database, the photo's capture time (read from EXIF), its file size, a content hash used to detect duplicates, and which member uploaded it.
Face data
This is the app's core feature and we describe it in full.
- Face detection and analysis run entirely on your device, using models bundled inside the app. Photos are not sent anywhere for analysis.
- Each detected face is converted on-device into a 512-number vector (a "face embedding"). This vector, its position in the photo, and a quality score are uploaded to the trip database.
- Cropped face images are never uploaded or stored. Only the numbers are.
- Vectors are compared only with other vectors inside the same trip, to group photos containing the same person. They are never compared across trips, never matched against any external database, and never used to identify anyone by name. A face is linked to a member only when a member of that trip explicitly taps it and assigns it.
- Vectors are deleted together with the trip, on the schedule in section 4.
Depending on where you live, a face embedding may be classified as biometric or otherwise sensitive personal data. For that reason this processing happens only with your separate, explicit in-app consent: before your first upload the app asks for your choice, and faces are analyzed only in photos uploaded by people who agreed. If you decline, you can still share photos — the automatic people sorting is simply skipped. You can withdraw consent any time under Settings → People sorting (face analysis); withdrawal applies to subsequent uploads, and vectors already stored are deleted with the trip on the schedule in section 4. We keep a record of your choice, the policy version you consented to, and when.
Photos of other people. When you upload a photo containing other people, you are responsible for having their agreement to do so. Anyone who appears in a photo in a trip you belong to can ask us to remove it at ehwogns1@gmail.com, and we will act on that request.
Usage statistics
The app uses Google Analytics for Firebase to understand which features are used. We deliberately send only aggregate values: counts (for example, how many photos an upload contained) and speed ranges (for example, "under 1 second"). We do not send your user ID, trip ID, nickname, file names or invite codes.
Google Analytics itself automatically records the country, device model, operating system version and app version associated with each event, and assigns a randomly generated app instance identifier. You can reset that identifier by clearing the app's data or reinstalling the app.
Crash reports
When the app crashes or hits an internal error, it sends a crash report through Firebase Crashlytics. A report contains the type of error, the stack trace showing where the code stopped, the device model, the operating system and app version, and a randomly generated installation identifier.
Before a report is sent we strip file paths, photo URLs and raw server messages. Your photos, face vectors, trip names, trip IDs, invite codes, nickname and sign-in identity are never included in a crash report.
What we do not collect
- We do not collect your contacts, calendar, call logs or messages.
- We do not request or use your device's live location.
- We do not share your photos, face vectors, trip names, invite codes or nicknames with advertising networks. See section 6 for the ads shown in the app.
- We do not sell personal information to anyone, in any sense of the word "sell".
3. Device permissions
| Permission | Why |
|---|---|
| Photos / media | To let you pick photos to upload, and to save downloaded photos back to your gallery. Only the photos you select are read. |
| Notifications | To show upload progress while an upload continues in the background. Optional — uploads still work if you decline, but Android may pause them when the app is not in the foreground. |
| Internet / network | To upload and download photos. |
4. How long we keep it
| Data | Retention |
|---|---|
| Trip, membership, photo records, face vectors | 4 days from the trip's creation by default, or up to 7 days if extended with a rewarded ad — never more than 7 days, in any case. A scheduled backstop removes anything a failed cleanup left behind, at the latest 21 days after creation. |
| Photo files (original, viewing copy, thumbnail) | Deleted with the trip. An independent storage lifecycle rule removes any remaining object at the latest 10 days after it was uploaded. |
| Account (sign-in identity) | Kept until you delete it. See section 8. |
| Usage statistics | Retained by Google Analytics under its own retention setting, currently 2 months for event-level data. |
| Crash reports | Retained by Firebase Crashlytics under its own retention policy, currently 90 days. |
Deleting a photo, leaving a trip or deleting your account removes the data ahead of these deadlines. Deletion is permanent — we keep no backup from which a deleted trip could be restored.
5. Who else processes your data
We use two infrastructure providers. Neither is given your data for their own purposes; both act on our instructions.
| Provider | Purpose | Region |
|---|---|---|
| Google (Firebase Authentication, Cloud Firestore, Cloud Functions, Google Analytics for Firebase, Firebase Crashlytics) | Sign-in, trip database, server logic, usage statistics, crash reports | United States |
| Cloudflare (R2 object storage) | Storage of photo files | Asia-Pacific |
This means your data is transferred outside your country and, if you are in the European Economic Area or the United Kingdom, outside it as well. Both providers offer Standard Contractual Clauses for such transfers, and we rely on those. See Firebase privacy and Cloudflare's privacy policy.
Photo files are transferred directly between your device and Cloudflare R2 using short-lived signed links. They do not pass through any server of ours. Those links expire after 7 days at most; anyone who obtains one before it expires can open that photo, so treat an invite link as you would the photos themselves.
6. Advertising
This app shows ads from Google AdMob. Ads cover our server costs so the app can stay free.
- A full-screen ad right after you finish uploading photos (at most three per day)
- Native ads in the trip list and in the photo gallery grid (labelled as ads)
- Rewarded ads that only play when you tap them yourself, to raise a trip's storage or extend it. You can use every feature without watching any.
We do not place ads in the screens you use to download photos.
What is processed for ads
To show and measure ads and to prevent fraud, Google processes your advertising ID (an identifier you can reset in your device settings), your IP address and the approximate region inferred from it, device and app information, and records of ad views and clicks. For this purpose Google acts as an independent controller under its own policy — see how Google uses data in advertising.
Photos, face vectors, invite codes, nicknames and trip names are never sent to the ad network. Only when you finish watching a rewarded ad, a trip identifier and a user identifier (both random strings) travel back to our server through Google, so that we know which trip to raise the limit for.
Your choices
- In the EEA, the UK and Switzerland we ask for your consent to personalised ads when you first open the app (through Google's consent management tool). You can refuse and still use every feature; you will see non-personalised ads instead. You can change your choice any time under Settings → Ad settings.
- Anywhere, you can reset your advertising ID or turn off personalised ads in your device settings (Android: Settings → Google → Ads).
7. Security
- All traffic is encrypted in transit (TLS). Stored data is encrypted at rest by both providers.
- Trip contents are readable only by approved members of that trip. This is enforced on the server, not just in the app.
- Joining a trip requires the invite code and the trip owner's approval.
- Photo files are reachable only through signed links that expire.
- Through our storage providers' admin tools, the operator technically has the ability to access stored data. The operator does not access your photos or face vectors except where minimally necessary to fix a fault, answer your request, or comply with the law. This access is limited to the operator alone.
No system is perfectly secure. If a breach affects your personal data, we will notify affected users and the competent authority where the law requires it.
8. Your rights and how to exercise them
You can, at any time:
- Delete a photo you uploaded — from the photo screen in the app.
- Leave a trip, choosing whether to take your photos with you.
- Delete a trip you own, which deletes it for every member.
- Delete your account and all associated data — in the app, Settings → Delete account. Instructions, including how to request deletion without the app, are on the account deletion page.
Depending on your jurisdiction you may also have the right to access a copy of your data, correct it, restrict or object to its processing, withdraw consent, receive it in a portable format, and lodge a complaint with your data protection authority. To exercise any of these, email ehwogns1@gmail.com. We do not charge for these requests and we do not treat you differently for making one.
Our legal basis for processing, where the GDPR applies, is performance of the service you asked for (Art. 6(1)(b)) for trips, membership and photos; your explicit consent (Art. 9(2)(a)) for face vectors; and our legitimate interest in operating and improving the app (Art. 6(1)(f)) for aggregate usage statistics.
9. Children
PhotoShare is not directed at children and is not intended for anyone under 16, or under the minimum age of digital consent in your country if that age is higher. In the Republic of Korea, children under 14 may not use the service. We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact us and we will delete it.
10. Changes to this policy
If we change how we handle personal data — a new processor, an additional ad format — we will update this page and change the version and effective date at the top before the change takes effect. Material changes will also be announced inside the app.