Privacy policy

Last updated September 27, 2026

Draft for review. This text has not been reviewed by a lawyer yet, and the items in brackets are still to be filled in.

Aside is a disposable camera for events. A host creates an event, guests take photos with their phones, and the photos stay hidden until the host's reveal. This policy explains what we collect, why, and the choices you have. Aside is operated by [legal entity name and address]. Contact: [privacy contact email].

What we collect from guests

  • Your display name, shown with your photos in the album.
  • Your photos: the version with the film look (in several sizes) and an untouched copy, so the photo can be re-rendered later. Each photo keeps its capture time.
  • Your email address, only if you give it, to tell you when this event's photos develop. It is used for nothing else and deleted 30 days after the reveal.
  • An anonymous account identifier, created when you open the camera, so your shots and photos stay yours. It isn't linked to your phone number, email or any other account.
  • A notification token if you allow notifications in the iPhone App Clip. It expires after about 8 hours.

What we collect from hosts

  • The name and email address that Apple or Google share when you sign in.
  • Your events, their settings, and the photos taken at them.
  • Purchase records. Payments are handled by the App Store or Google Play through RevenueCat; we never see your card details.

What we don't collect

  • Location. Location data is removed from every photo on your phone, before it is uploaded.
  • Your contacts, your other photos (unless you choose to upload one), or advertising identifiers.
  • We don't sell personal data and we don't show ads.

Who can see photos

  • Before the reveal, guests can't see any photos, not even their own. The host can, to remove unwanted photos.
  • After the reveal, the host decides whether everyone who joined the event can see the album, or only the host. You can always see your own photos.
  • Photos are stored privately. They are only shown through links that expire after an hour, to people who joined the event.

Diagnostics and analytics

To fix bugs, we record error reports (Sentry). To understand how Aside is used, we record anonymous product events such as "camera opened" or "photo uploaded" (PostHog). Neither ever includes photos, names, email addresses or event codes.

Service providers

We use Supabase (database and sign-in), Cloudflare (website and photo storage), Resend (email), Apple Push Notification service, RevenueCat (purchases), Sentry and PostHog. They process data only to provide their service to us. [Data locations and transfer mechanisms to be added.]

How long we keep data

  • Albums from paid events are kept until the host deletes them.
  • Albums from free events are deleted 12 months after the event, unless the host buys "Keep forever". We email the host 30 and 7 days before.
  • Guest email addresses are deleted 30 days after the reveal.
  • Deleted photos disappear from the album immediately and from storage shortly after.

Your choices and rights

  • Guests can delete all their photos from an event at any time, from the camera's menu or the album.
  • Hosts can delete any photo, a whole album, or their account and all its data from the app.
  • You can ask us for a copy of your data, or to correct or delete it, at [privacy contact email]. Depending on where you live, you may have further rights under laws such as the CCPA or GDPR.

Children

Aside isn't directed at children under 13, and we don't knowingly collect their personal information.

Changes

If we change this policy, we'll update the date above, and tell hosts in the app about important changes.