LEGAL
Privacy Policy
Effective July 29, 2026
Our Camera is a shared disposable camera for trips. A host creates a film, friends join it, everyone shoots on a limited roll, and the photos stay sealed until the film is revealed. This policy explains what data the app collects, why, and what happens to it. We have tried to keep it short and honest, not written to be argued over.
The short version
- We collect only what the product needs: a display name, the photos you take in the app, optional social handles, and a push token for reveal notifications.
- Your photos are private, sealed until reveal, and automatically deleted 7 days after they are revealed.
- Camera style looks (Film, Black & White, and so on) are rendered on your own device. We do not send your photos to any AI or image-generation service to apply them.
- We do not sell your data, we show no ads, and we currently use no analytics or tracking SDKs.
- Guests can use the app without an email address or any account signup.
What Our Camera does
Our Camera is a free mobile app (with optional paid capacity upgrades, described under Payments below). A host starts a film, invites people by code, QR, or link, and everyone shoots photos that stay sealed until the film's reveal time. This section, and this policy, cover the consumer product; a small number of companies license Our Camera for their own group trips under a separate arrangement described under Business ("brand") accounts below.
Accounts and sign-in
Signing up with Apple or Google is required to use the app, for both hosts and guests. When you do, we receive the basic identity your provider shares (such as your name and the account identifier); we use it only to create and secure your account. To let you start shooting before that step, the app opens under a temporary anonymous session the moment you create or join a film; you are then asked to link an Apple or Google identity to it, which keeps the same film and photos and adds a real sign-in credential. No part of the app leaves you signed in anonymously only.
What we collect
- Display name. The name you enter so other people on your film know whose shots are whose.
- Photos. The photos you take inside the app, on films you are a member of.
- Optional social handles. If you add them in settings, they are shown to people you share films with.
- Push token. A device token so we can send you the reveal notification when a film unlocks.
- Film data. The films you create or join: their names, covers, schedules, day names, and membership.
- Purchase records. If you buy additional capacity for a film, we keep a record that a purchase happened and what it unlocked (see Payments).
What we do not collect: we do not access your contacts or address book, your device location, or your camera roll or photo library. The app only ever handles photos taken inside it.
Your photos
Photos are private to the film they were taken on. They are stored on Supabase infrastructure (hosted on AWS in us-west-1, United States) and are sealed by server-side access rules until the film's reveal time: before reveal, nobody can view a shot except the person who took it. After reveal, shots become visible to the film's members so everyone can save what they want. A film set to daily reveal unlocks one day's photos at a time on that schedule; each day's shots stay sealed until their own unlock, even after earlier days have opened.
Photos are automatically deleted from our servers 7 days after reveal. That window is the product: download what you want to keep, and after that the roll is gone.
The camera-style looks you can apply (Film, Black & White) are rendered on your device using on-device image processing. Your photos are never sent to a third-party AI or machine-learning service to produce these looks, and they are not used to train any model.
Payments
Films above the free capacity can be upgraded for a fee. On Android and web, payment is processed by Stripe: your card details go directly to Stripe and never touch our servers, and we only receive confirmation that a payment happened so we can unlock the film's capacity. On iOS, the same upgrade is purchased as a native Apple in-app purchase, processed by Apple and RevenueCat: your payment method is handled entirely by Apple, and we receive only confirmation of the purchase and which film it applies to. Stripe's and Apple's handling of your payment data is covered by their own privacy policies.
Business ("brand") accounts
A small number of companies (for example group-travel operators) use Our Camera under a separate business arrangement, billed directly with us and not through the app. If you join a trip run by one of these business accounts, the difference from an ordinary film is: there is no capacity limit and no in-app payment, and the company's account administrators can see all of that trip's photos, including ones not yet revealed to other guests. Everything else in this policy, including the 7-day deletion window after reveal, still applies.
We send transactional email only, via Resend, and only to hosts: for example a receipt after a purchase or a reminder before a download window closes. Guests have no email on file unless they separately sign in with a provider that shares one, so most guests receive no email at all. We do not send marketing email.
What we do not do
- No advertising, and no ad networks in the app.
- No selling or renting of your data to anyone.
- No sending your photos to a third-party AI service to apply camera looks, generate content, or anything else.
- No third-party analytics or tracking SDKs at this time. If we ever add crash reporting or analytics, we will update this policy first.
Service providers
We use a small number of providers to run the product, each only to provide their service to us:
- Supabase - database, authentication, and photo storage.
- Stripe - payments on Android and web.
- RevenueCat and Apple - in-app purchases on iOS.
- Resend - transactional host email.
- Expo - push notifications and app builds.
- Vercel - this website and the invite pages.
Deleting your account
You can delete your account at any time in the app under Settings. Deletion is real and immediate: your sign-in credentials are destroyed, your profile is anonymized (your name becomes "Deleted user" and your push token is removed), and you can no longer be contacted or identified through the app.
Photos you took on shared films survive your account deletion, attributed to an anonymous profile. This is deliberate: a film's roll holds other members' memories of the same trip, and honoring one person's deletion should not destroy everyone else's photos. Those photos still expire on their normal schedule, 7 days after their film's reveal.
Data retention
- Photos: deleted 7 days after their film's reveal.
- Account and film records: kept while your account exists; anonymized on deletion.
- Purchase records: kept as long as required for accounting and legal obligations.
Where your data is processed
Our servers and photo storage run in the United States (AWS us-west-1). If you use the app from outside the United States, your data is transferred to and processed there. As with any internet service, data may also transit through other regions as a normal part of network routing.
Children
Our Camera is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has used the app, contact us and we will delete the data.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your data, and to object to certain processing. Account deletion is built directly into the app under Settings; for anything else, including the rights described above, email us and we will help within 30 days.
We do not sell or share your personal information for money or other valuable consideration, so there is nothing to opt out of on that front. We have not received any requests that would require a designated representative in the EEA, UK, or elsewhere; if that changes as the app grows, we will update this policy with that contact.
Security
Data in transit between the app and our servers is encrypted (TLS). Photos are private by default: server-side access rules, not just app behavior, enforce who can see a shot and when, so a sealed photo cannot be read even by directly querying our database with a member's own credentials. We do not store your payment details ourselves; those are handled by Stripe or Apple as described under Payments.
Changes to this policy
This policy may be updated as the product evolves. When it changes, we will update the effective date at the top of this page, and for significant changes we will let you know in the app.
Contact
Questions about this policy or your data: markpyvovarov@gmail.com. We aim to respond within 30 days.
This policy describes our practices as of the effective date above and is not a substitute for legal advice about your own rights in your jurisdiction.