Your bursts are made from your private photos and videos, so privacy isn't fine print for us — it's
the product working as it should. This policy explains what we store, where, and why — under the Swiss
Federal Act on Data Protection (FADP), the GDPR where it applies, and other privacy laws around the
world where they apply to you.
Your photos and videos. The items you pick are prepared on your device (resized,
converted) and uploaded to our storage so your burst can be delivered to the people you share it
with. That is the only purpose. We do not scan your content for advertising, train AI models on
it, or sell it — to anyone, ever.
Photo and video metadata. Your photos and videos carry capture dates and, often, GPS
coordinates. We read the capture dates to order your burst chronologically — nothing else. We do
not read or use the location data (flyover locations are places you type in), and because your
items are re-encoded on your device before upload, the copies we store don't carry the original
metadata.
Account data. If you sign in with Apple or Google, we receive your e-mail address and a
user ID; with e-mail sign-up, your e-mail address and a password (held by our sign-in provider
only as a secure hash — we never see it). We store the e-mail and user ID to anchor your account,
your free trial, and your bursts.
Sharing and engagement data. For bursts you share we store technical records (burst ID,
creation time, open counts and reactions) so we can show you that your burst was seen.
Payment data. Subscriptions are sold by our payment partner as merchant of record. Card
details go to them, never to us; we only learn that your account is subscribed.
Push notifications. Only if you enable them: a push subscription token.
Phone number (group bursts, optional). If you contribute to a group burst without the
app, you can leave a phone number so we can text you the link when the finished burst is ready.
That is its only use — one text per group burst, no marketing. We delete the number
automatically right after that text is sent, and you can clear it on the same page at any time
before that.
Server logs. Delivering a page or a burst technically involves the visitor's IP address and
browser type. We keep such logs briefly, for delivery and abuse prevention only.
Local storage. The app stores functional data on your device (your sign-in session, device
token, cached settings). No tracking cookies.
Product analytics. We measure how the app is used (screens opened, bursts played and
shared, sign-ins) with PostHog, hosted in the EU. It is cookie-less: visitors are counted
under a random identifier stored on the device. If you sign in, that usage is linked to your
account so we can understand usage across your devices. No cross-site tracking, no ad networks,
no fingerprinting, and we never sell usage data.
3. Where your content lives, and who processes it
Cloudflare — media storage (R2), delivery network, and our application database.
Supabase — account sign-in (stores your e-mail and, for e-mail sign-up, your hashed
password). Apple / Google — identity providers when you sign
in with them, under their own privacy policies.
PostHog (EU) — product analytics, as described above. Loads only from our own domain.
Crisp — support chat. Loads only if you open "Chat with us"; what you type there (and the
e-mail you choose to leave) goes to Crisp so we can reply.
Twilio — SMS delivery. If you leave a phone number for a group burst, the number and the
one-off message go through Twilio to reach your phone.
Map data providers — building and displaying a flyover fetches map imagery; those requests
expose the map region (the locations you typed for the flyover) but none of your content.
Netlify — hosts this website.
Google Fonts — serves this website's typeface (your browser requests it from Google).
The app itself does not use Google Fonts.
Some providers process data outside Switzerland/the EEA (notably in the US). We rely on
recognised safeguards (adequacy decisions and standard contractual clauses) for those
transfers. All providers process data on our instructions.
A shared burst is reachable by anyone holding its link. Links use long random identifiers and are
never listed publicly — but treat a share link like the photos themselves. Recipients don't need
an account; for them, only the technical server logs above apply.
4. How long we keep things
Photoburst plan: bursts expire 7 days after creation.
Keep Forever plan: content is retained while your subscription is active.
Deletion: deleting a burst removes it for recipients immediately; it stays recoverable by
you for 30 days, then is permanently erased from storage.
Account deletion: delete your account yourself in the app (Settings → Account → Delete
account, with a double confirmation). Your content, account data and analytics history are then
erased automatically — within 30 days at the latest, subject to legal retention duties. You can
also request deletion at the contact address.
Server logs: kept days, not months.
5. Legal bases
Where the GDPR applies: we process your content and account data to perform our contract with you;
server logs and abuse prevention rest on our legitimate interest in running a safe service; push
notifications only with your consent, which you can withdraw anytime in your device settings.
6. Your rights
You can request access to, correction of, export of, or deletion of your personal data, and object to
processing, by writing to hello@photoburst.app.
You may also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your
local supervisory authority.
7. Security
Content is transferred over encrypted connections (Transport Layer Security, TLS) and stored with
access restricted to the delivery of your bursts.
No internet service can guarantee absolute security — keep your own originals.
Visibility of shared bursts: bursts are unlisted. Their links use practically unguessable
identifiers, we never publish them anywhere, and we instruct search engines not to index
burst pages or your media (robots exclusion and noindex headers), so your bursts do not
appear in search results. Anyone who receives a link can open it and could pass it on —
share your links with people you trust.
8. Children
Photoburst is not directed at children under 16. If you believe a child has provided us personal
data, contact us and we will delete it.
9. Changes
We'll update this policy as the product evolves; the "Last updated" date reflects the current
version. Material changes will be announced in the app.