QapturEvent

Privacy Policy

This describes what QapturEvent actually collects and why — plainly, not as legal boilerplate. If you're deploying this app yourself, review and adapt this to your actual jurisdiction and setup before relying on it as a real policy.

What we collect

  • Account owners: email address, display name, and a hashed password (never the password itself).
  • Guests uploading photos: no account or personal information is required. The photos themselves, their filenames, and file metadata (size, type) are stored.
  • IP addresses: logged temporarily for rate-limiting and abuse prevention, and recorded in a security audit log for account-related actions (login, password reset, etc.). Not used for tracking or advertising.
  • No cookies for tracking. Sign-in uses a token stored in your browser's local storage, not a tracking cookie.

What we don't collect

  • No advertising identifiers or third-party tracking scripts.
  • No payment information (there's no paid tier currently).
  • No location data beyond what your IP address coarsely implies for rate-limiting purposes.

How photos are stored

Photos are stored in object storage (AWS S3 or a self-hosted equivalent, depending on how this instance is deployed) and are never made publicly accessible — every access goes through a short-lived, signed URL generated on demand. Event owners can delete individual photos or an entire event at any time. Platform administrators can only see an event's photos when its guest gallery is turned on — the same photos anyone with the event link can see — and only to handle abuse reports, legal requests, or support you asked for. Every such view is logged.

Account deletion

Deleting your account anonymizes your account record and archives (not deletes) any events you own — uploads are disabled but existing photos remain, since guests who uploaded them have a stake in that content too. See your account settings for details.

Email

We send account-related email only: email verification, password reset, collaborator invites, and account deletion confirmation. We don't send marketing email.

Analytics and crash reporting

This deployment may use lightweight, self-hosted analytics and crash reporting to understand usage and fix bugs. No data is sold or shared with advertisers. If a specific third-party analytics or error- tracking provider is enabled on this deployment, it will be named here by the operator.

Questions

See the Contact page for who to reach out to about anything not covered here.

See also the Terms of Service.