in.photo

Privacy policy

How personal data are processed when you visit in.photo, request a launch notification, use an account, or share and view photos. The operator’s and business customers’ roles are explained below.

Operator and data controller

Adam Cooper Softwareentwicklung

c/o GAM, Pappelallee 64, 10437 Berlin, Germany

mail@in.photo

Website and hosting

Hetzner Online GmbH, Germany, provides website and mailbox hosting in Germany. We use BunnyWay d.o.o., Slovenia (bunny.net), to deliver public website files, including scripts, fonts and illustrative images, through cdn.in.photo. Private collection photos are not delivered through this public CDN. Requests expose IP address, request time, requested file, browser and connection information to the delivery infrastructure. We configure CDN delivery to use EU locations. Public-asset CDN access logs are retained for up to three days with IP truncation; truncation does not make all request data anonymous. Delivery, performance and protection against abuse serve our legitimate interests (Article 6(1)(f) GDPR). When private photo delivery is enabled, a separate Bunny zone at photos.in.photo serves validated display images after checking current access on every request. This zone uses EU-only routing and has request logging disabled. Original files remain private in Hetzner storage; validation and image processing run in Germany. We have data processing agreements with these providers. For videos, Bunny Stream receives validated video and audio to encode and deliver playback versions. Originals remain in private Hetzner storage in Germany; Bunny playback storage is configured in Frankfurt, with EU-only CDN and edge-script routing. The locations of ingestion, encoding and temporary processing have not been fully verified; EU routing does not establish that every processing step stays in the EU. Video request logging, AI transcription and other AI features are disabled. Our own player does not embed Bunny's player or its telemetry.

Hetzner privacy information · Bunny privacy information

Accounts and access

We process your email address, account identifier, verification status, login tokens and sessions to provide and protect your requested account (Article 6(1)(b) GDPR). Access is currently restricted to approved in.photo accounts; invited guests can use shared collections without creating an account. Providing an email address is voluntary, but an email-based account cannot function without it. We use keyed hashes of email/IP identifiers and short rate-limit windows to prevent abuse (Article 6(1)(f)). Expired rate-limit records are cleaned when further requests are made.

Email, launch notifications and accounts

We process your email, language, request time and consent record for a requested launch notification (Article 6(1)(a) GDPR). Withdraw by emailing us at any time. Login and service requests use Article 6(1)(b); general enquiries and abuse prevention use Article 6(1)(f). MailPace (OhMySMTP Ltd, UK) is the configured email provider and receives recipients, message contents and delivery data when enabled. MailPace stores email data in France and sends through UK servers. UK transfers rely on the European Commission’s adequacy decision (Article 45 GDPR). Messages are retained for up to 30 days, plus seven days in backups. Delivery also involves your chosen email provider. Providing data is voluntary, but email-based features cannot work without your address. A launch notification is sent only after you open the confirmation link and confirm on the page. We record the confirmation time and consent version. Confirmation links expire after 24 hours; merely opening them does not subscribe you.

MailPace privacy information · MailPace data-processing agreement

Contact and correspondence

When you contact us, we process your contact details, message and any attachments to answer you. The legal basis is Article 6(1)(b) for contractual or pre-contractual enquiries, otherwise our legitimate interest in responding (Article 6(1)(f)). Hetzner hosts our mailboxes. Postal correspondence sent to our c/o address passes through our address provider, Dnkfbrk GmbH (Geschäftsadressemieten.com), for receipt and forwarding. This serves our legitimate interest in reliable business correspondence. Please include only information needed for your enquiry.

Photos, videos and sharing

Galleries are private and are not published in a public gallery or directory. The event host decides whether to share the gallery or show photos on an event wall. The host is responsible for informing guests about the intended display and obtaining their consent before showing their photos on the wall. Uploading a photo or entering an event does not by itself establish that everyone depicted has consented. Enabled collections store uploaded photos, original metadata (potentially location), collection names, identifiers and technical image data. Display images remove private metadata, including GPS, capture time and camera details; private originals retain their metadata. Account and requested sharing functions rely on Article 6(1)(b). Photos may depict people who did not upload them: the uploader is the source, and their contract does not itself justify processing everyone depicted. For incidental depictions, we rely on our legitimate interest in facilitating private sharing requested by participants (Article 6(1)(f)), balanced against the rights of those depicted. Upload only photos you are entitled to share and inform the people shown. Contact mail@in.photo to object or request removal. Anyone with an enabled invitation can view and contribute; revocation cannot recall copies already obtained. Gallery access remains private and invitation-based. Enabling sharing grants access to anyone who obtains the invitation, including through forwarding or a displayed QR code. Shared images and the live wall are visible to those participants. We do not use your photos for advertising, facial recognition or AI training. If you are depicted in a photo uploaded by someone else, that uploader is the source of the image and associated information. Please send us the collection reference and enough information to locate a disputed photo; no account is needed to exercise your rights. These sharing rules and the prohibition on advertising, facial recognition and AI training also apply to videos and their audio. Video uploads store the original and technical data such as duration, codecs, dimensions and rotation. Private originals can retain embedded metadata. Encoding creates playback versions; we do not promise that all embedded video metadata is removed. Upload only video and audio you are entitled to share, and inform the people depicted or heard.

Business customers and processing roles

Where a business customer determines the purposes and essential means of event-photo processing and in.photo processes those data solely on its instructions, the customer is the controller and in.photo is the processor. The customer must establish the lawful basis and provide the required information to the people concerned. The legal bases described here for in.photo apply to its own processing as controller, not as a substitute for the customer’s lawful basis. Requests concerning commissioned event data are forwarded to the customer and supported by in.photo; independent legal duties remain unaffected. The linked B2B data processing agreement is currently a review draft. An effective agreement and verified safeguards are required before processing under that arrangement.

Data processing agreement

Cookies and access

Login sessions last up to 30 days; guest access lasts seven days; login links expire after 24 hours. Security and login cookies support requested access (§ 25(2)(2) TDDDG; Article 6(1)(b)/(f) GDPR). The page language is set by its URL. When you choose a language, a first-party cookie remembers that choice for 180 days. Closing the language suggestion is remembered in session storage for the current tab session. Without a saved choice, the homepage uses your browser’s language preferences, with English as the fallback. No advertising cookies are implemented. Non-essential storage or device access needs separate consent before activation.

Diagnostics and audience measurement

Self-hosted GlitchTip and operational monitoring receive filtered errors, logs and performance data to keep the service reliable (Article 6(1)(f)). Enabled Umami counts homepage visits using a temporary random identifier; no photos, email, real visitor IP or browser user-agent are forwarded to Umami. DNT/GPC signals are respected. This limited measurement serves our legitimate interest in understanding homepage use (Article 6(1)(f)). You can object using DNT/GPC or by contacting us.

Retention

We retain launch signups until the requested notification is sent, consent is withdrawn or the launch plan is abandoned. Accounts and photos are retained while needed for the requested service; request deletion at mail@in.photo. There is no automatic deletion on logout or invitation expiry. Enquiries are retained until resolved and any necessary follow-up ends. Operational logs: 14 days; traces: seven days; errors and metrics: 30 days. Necessary legal obligations or specific legal claims may require restricted further retention. Collection owners can remove individual photos. Removal blocks further downloads immediately. Browsers may reuse previously downloaded photos for one hour without another download; downloaded or saved copies cannot be recalled. Background tasks delete the stored files and clear the private CDN cache, retrying failures. Temporary upload files expire after one day as a cleanup backstop. Account and collection deletion requests are handled by the operator. Homepage event records have no automatic expiry in the current analytics system. Their continued need and removal must be assessed separately from the time-limited operational logs. Any longer retention for legal claims is restricted to the information needed for that claim (Article 6(1)(f)); mandatory legal retention uses Article 6(1)(c). Unconfirmed launch requests have no automatic deletion deadline. They remain excluded from launch notifications, receive no automatic reminders and can be removed on request at mail@in.photo. Video owners can also remove individual videos. New playback requests are then denied, and background cleanup removes the original and Bunny playback copies with retries. Already buffered or downloaded video cannot be recalled; browsers may cache delivered playback data privately for one hour.

Your rights

Subject to the GDPR conditions, you may request access, correction, erasure, restriction and portability. You may object on grounds relating to your situation to processing based on legitimate interests, and to direct marketing at any time. Withdrawal of consent does not affect earlier lawful processing. Contact mail@in.photo. We normally respond within one month. You may complain to a supervisory authority, especially where you live, work or the alleged infringement occurred. Our supervisory authority is Berliner Beauftragte für Datenschutz und Informationsfreiheit. We make no solely automated decisions with legal or similarly significant effects. Requests are free unless the GDPR permits a fee or refusal. We may ask for proportionate information to verify identity. For complex or numerous requests, the GDPR permits an extension of up to two further months; we will explain any extension within the first month.

Berliner Beauftragte für Datenschutz und Informationsfreiheit

Last updated: September 21, 2026

ImprintPrivacy policyTerms of use