Privacy Policy

Photodex helps adults preserve and share family photographs. This Policy explains how Photodex Ltd ("Photodex", "we") handles personal information about Account holders, people depicted or named in Photos, invitees and Public Link visitors. Contact info@photodexapp.com with privacy questions or rights requests. Read the Shared Definitions for product terms. This text describes the intended production service after its Cloudflare migration; technical and supplier facts requiring confirmation before publication appear in the separate Legal Review Notes.

1. Information we handle and its sources

We receive Account names, display names, email addresses, credentials handled by our authentication provider, verification and account status, and information you supply to support. We record Albums, ownership, membership, invitations and permissions; invitee email, inviter name, album title and optional personal message; uploaded original Photos and file metadata (filename, file type, size and dimensions); uploader identity; descriptions, dates, places, people and other free-text labels, including pinned labels; favourites and Album activity. A Photo or label can contain personal or sensitive information about someone who does not use Photodex. Original files may contain camera, location and other embedded EXIF metadata. We do not automatically remove it from originals supplied for download.

We handle Public Link tokens, status, expiry, download setting and view count; reports, supporting material, moderation actions and correspondence; Subscription and trial status, billing cycle and Stripe customer/subscription references. Stripe collects payment-card details directly; Photodex does not store complete card numbers. The application uses authentication and technical identifiers in browser storage; a separate Cloudflare image-delivery session cookie is planned. Base44 analytics is enabled in the audited application; its identifiers, events, retention and legal configuration need confirmation. Hosting, security and payment suppliers may receive IP, device and request information through their infrastructure, but the precise categories and retention have not been verified. We do not claim to use facial recognition: dormant AI fields in the audited database do not establish an active AI feature.

Information may come from you, an Album Owner or Member who invites you or labels or uploads a Photo, Public Link users, reporters, Stripe and technical logs. If another person names or depicts you, you can contact us even without an Account. Photodex cannot assure that an uploader obtained every depicted person's consent; each case depends on rights and context.

2. Purposes and lawful bases

PurposeTypical informationProposed UK GDPR basis
Create and secure an Account, verify email, provide Albums, permissions, sharing and permitted downloadsAccount, invitations, Content, access dataContract with Account holder; legitimate interests in enabling invited people and protecting access
Process paid plans, invoices and customer supportContact, Subscription, transaction referencesContract; legal obligation for financial records
Send service and invitation messagesNames, email, Album details, message and join linkContract or legitimate interests in operating collaboration; legal obligation where relevant
Prevent abuse, investigate reports, protect people and preserve evidenceContent, reports, logs, identifiersLegitimate interests, legal obligation, and where applicable vital interests
Respond to privacy requests, complaints, court orders or authoritiesRelevant records and correspondenceLegal obligation; legitimate interests in establishing or defending claims
Measure and improve the serviceUsage and technical informationLegitimate interests or consent where required; separate PECR rules apply to device storage/access and must be satisfied before analytics is used

We will document legitimate-interest balancing where used. We do not rely on an Account holder's contract as the lawful basis for all information about non-users. Content may incidentally reveal health, beliefs, ethnicity, sexuality or other special-category information; that raises separate Article 9 questions for active processing and moderation. Free-text people labels are not, by themselves, a claim that biometric identification is performed. We will assess any special-category condition and data-protection impact before new identification or AI features. We do not make solely automated decisions with legal or similarly significant effects on you as part of the described photo features; automated flags may trigger human review.

3. Who can see information

Owners and authorised Members see Album Content, labels and uploader names according to permissions. Owners and members authorised to invite may see member names, email addresses and permissions; Owners see Album activity. Invitees receive the inviter name, Album title and any invitation message. A person with an active Public Link needs no Account and may see the Album title and description, up to the Photos delivered by the public view, original filenames, date, location, people and other labels, descriptions, and uploader names. If the Owner enables downloads, the original file and any embedded metadata may be received. Recipients can retain and redistribute material outside Photodex. An Account deletion may change an uploader name in another Owner's Album to "Deleted user" while the contributed Photo remains.

Our authorised administrators have technical read access to private Album and Photo records under the audited role rules, although private Photos are not routinely manually reviewed. Access may be used when reasonably necessary for reports, suspected illegal activity, security or safety, automated flags or lawful requests. Backend service roles and infrastructure providers may technically access data to operate the Service. The audited application did not log each administrator read; do not infer a per-access audit trail from Album activity logs.

4. Suppliers and international processing

Base44 hosts the app, database, authentication, backend functions and built-in analytics. In the proposed production architecture, private original Photos are held in Cloudflare R2; Cloudflare Workers authorise image delivery; a Workers Images binding transforms R2 bytes for thumbnails and display; Cloudflare CDN/DNS supports delivery. Stripe handles checkout and payments. Outgoing invitation and other transactional email currently uses a Google/Gmail connector for noreply@photodexapp.com; whether this is a Google Workspace account and which messages are retained in Sent require confirmation. We may disclose information to advisers, authorities or a successor operator where lawful and necessary.

Our suppliers and CDN edge locations can involve processing outside the UK. A proposed Western Europe R2 location hint does not prove exclusive European processing, nor does it locate Base44, analytics, email, payment or global edge activity. We will document each restricted transfer and use adequacy arrangements or appropriate safeguards, such as the UK IDTA or UK Addendum, where required. Specific regions, subprocessors, contracts and safeguards must be confirmed before publication; we do not promise UK-only storage.

5. Retention, deletion and backups

Operational Photos, Albums and associated records are generally kept while the relevant Album or Account exists, then deleted through the service process, subject to errors, lawful preservation and residual copies. Under the intended Cloudflare design, deleting a Photo removes its R2 object and requests relevant cached image invalidation before deleting its database record; an asset deletion failure should leave a record for retry. Deleting an owned Album removes its Photos and related memberships, links and records. Account deletion cancels its Subscription, deletes Albums owned by that Account and relevant Account records; a Photo previously contributed to another Owner's Album may remain with its uploader name anonymised. A link can be paused without deleting its token or view count. An expired invitation may remain as an invalid pending record until removed; a paused Public Link may remain until removed. We will set and disclose definite retention schedules for these records before publication.

Operational deletion is not necessarily immediate removal from caches, backup or version-history copies, logs, sent email or Stripe records. Such copies are restricted and removed or expired under applicable supplier schedules and legal requirements. Financial records may have to be kept for statutory periods. Reports and evidence may be kept while needed to investigate and resolve a matter or defend a claim, followed by a defined review period. Precise retention for Base44 versions, Cloudflare objects and caches, Google Sent, Stripe, analytics, reports and logs is awaiting verification; we will not state a fixed number we cannot support. A planned independent second backup of originals and Base44 database export must not be presented as implemented until tested.

6. Security and rights

We use access controls, HTTPS and supplier security measures appropriate to the risks, and restrict operational review of private Content. No online service is risk free. The future Worker authorisation and R2 bucket privacy require end-to-end testing, especially after Member removal or link revocation. We do not promise multi-factor authentication, logged administrator reads, a particular restoration period or unconditional recovery unless implemented and verified. Keep your own copy of important Photos.

Subject to law, you may request access, correction, erasure, restriction, portability or objection; withdraw consent where consent is the basis; and complain to the Information Commissioner's Office. Rights can differ depending on the basis, other people's rights and lawful retention. An Account download button for all data is not currently verified, so contact us for a portability or access request. If another person uploaded or labelled your Photo, identify it as best you can; we will consider your rights and the uploader's and Owner's interests rather than automatically treating one request as conclusive. We will verify identity proportionately and normally respond within the statutory period, with permitted extensions and explanations.

For UK residents the ICO can be contacted at https://ico.org.uk/make-a-complaint/. We would appreciate the chance to address your concern first. We will notify the ICO and affected people about a personal-data breach where law requires.

7. Changes and contact

We will update this Policy for material changes, particularly after migration, new suppliers, analytics controls or AI features. We will state the effective date and give additional notice where appropriate. Privacy contact: info@photodexapp.com.