Photogether

Privacy Policy

Photogether · Last updated: 2026-08-22

Photogether is built to know as little about you as possible. This is the whole truth about what we handle, for how long, and why.

Who runs Photogether

Photogether is operated by We Remagine One AB (org. nr 559316–0228), Sandbäcksgatan 20 C, 653 48 Karlstad, Sweden — the data controller for the data described here.

No accounts, no profiles

You never have to register. Your name in an album is something you type yourself; it's visible only to the others in that album, and it's deleted with the album. In an encrypted album, your name and the album's own name are stored encrypted too. Photogether doesn't know who you are.

Photos

Photos you share are stored encrypted in the EU and shown only to the album's participants. Every album has its own key, held separately from the photos so that the people in the album can open them — that's what makes joining by a simple code possible — while the storage itself holds nothing readable. We build no tools to look inside albums.

When the album expires or is ended, the album's key is destroyed first — from that moment the photos are unrecoverable, even in places where deletion takes time to reach — and then everything is deleted: the photos, the names, all of it. Deleted means removed from storage, not hidden.

Encrypted albums arrive with app version 1.1.0. Albums created before that remain as they were and are deleted on their ordinary schedule — albums live a few weeks at most, so nothing older remains for long.

Location and photo metadata

The app never uses your device's location services — it doesn't even ask. If your camera embeds GPS in a photo, we reduce it to an approximate area (about a kilometre) and never keep exact coordinates. That rough area stays with the photo — so a copy you download carries it, and it can place the moment on a map — but never anything more precise. A shared photo also keeps its technical details — such as camera and capture settings; device-identifying metadata is removed.

Country

When an album is created, and when someone joins one, we note which country the request came from — the country, and nothing narrower. Working that out happens entirely in our own systems: we look the request's IP address up in a copy of a public geolocation database that we host ourselves, and keep only the two-letter country code. Your IP address is not stored, not logged, and not sent to anyone — it never leaves our systems — and it isn't used for anything else: not advertising, not profiling, not tracking you between albums. When the answer can't be told, we record nothing rather than guess.

It exists so we can see where Photogether is really used, and eventually keep photos close to the people looking at them. The country is deleted with the album, like everything else.

Identifier

The app uses an anonymous identifier to understand how the product is used in aggregate (for example, how many people come back). It can't be linked to your name or identity, and it resets if you reinstall the app.

Push notifications

If you allow notifications, a push token is stored in your album session and deleted when the session or the album is deleted. Delivering a notification means handing that token and the message to Apple's or Google's notification service — there is no other way to reach a phone.

Purchases

Paid unlocks are bought through the App Store or Google Play. Payment is handled entirely by Apple or Google — Photogether never sees your card details, your store account, or your identity. To confirm a purchase we receive an anonymous transaction reference from the store, which we verify and keep as a bookkeeping record.

What survives a deleted album

Anonymized statistical records of how the wave grew and ebbed, and equally anonymized service-level tallies — how many albums of each kind were active over time. The records of a wave keep its shape in rounded ranges: roughly how many people added photos, how many only looked, how many did neither, and which countries were involved as plain two-letter codes. No names, no photos, no photo IDs, no album identities — nothing that can be linked to a person or a specific gathering.

If an album was paid for, the purchase record also remains — the store's transaction reference, the product, and the level it unlocked — because bookkeeping and refund handling legally outlive the album. Its link to the deleted album is severed, and it contains nothing about the people or the photos.

Children

Photogether isn't aimed at children — it's a tool for people organizing and attending real-world gatherings. If a child does end up in an album (a family party, say), nothing changes: there's nothing here a parent would need to consent to — no accounts, no advertising, no profiling, no tracking. The same minimal handling described above applies to everyone, whatever their age.

Your rights (GDPR)

You have the right to access, rectification, and erasure. The honest answer to most requests: Photogether holds no identified personal data about you — that is the architecture, not a policy claim. Contact: hello@photogether.one. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), the supervisory authority for data protection in Sweden.

Who else is involved

We don't sell your data and we don't share it for anyone else's purposes. But running a service means other companies handle parts of it on our behalf, and you should be able to see exactly who and for what. This is the complete list — big and small, named the same way.

Supabase runs the database, the anonymous sessions and the server code behind the app. It receives everything the app stores, hosted in Germany (Frankfurt).

Cloudflare stores the photos and carries traffic to our servers. It receives the photos — encrypted, for encrypted albums — kept in the European Union.

Vercel hosts this website and our internal console, and counts page views. It receives requests to this website, served from the European Union.

Apple and Google deliver push notifications to your phone. They receive a push token and the text of the notification.

Each of them processes it only to provide their service to us, under their own data-protection obligations. If this list changes, this page changes with it.

The website

This site counts page views, so we can see which pages are actually read. It sets no cookies, stores nothing on your device, and cannot follow you to other sites — there is no profile, no advertising, and so nothing to opt out of. The fonts and images come from our own domain, so reading this page doesn't quietly tell anyone else that you were here.

Changes

We may update this policy from time to time. The date above shows when it last changed.