PhotosInFrame is designed so that the service can deliver your photos without being able to view their contents.

This notice describes how PhotosInFrame (“we,” “us,” or “our”) handles information when you visit our website or use the PhotosInFrame apps and services. The product is currently in development; this notice will be updated if the service’s practices change before launch.

The short version

We do not sell personal information or use it for targeted advertising. Photo content is encrypted on your device before upload. We process limited account, household, device, sharing, and operational information to provide and protect the service.

Information we handle

Account and household information

When you sign in with Google, we receive information needed to authenticate you, such as your Google account identifier, verified email address, and basic profile information. We also process household names, membership and role information, device names, and the requests and decisions used to join or share between households.

Photos and captions

Photo files and thumbnails are encrypted on an approved device before upload. The service stores and delivers that encrypted content but does not hold the photo decryption keys. Optional captions are not end-to-end encrypted and may be visible to authorized service operators, so captions should not contain personal or sensitive information.

Photo and sharing metadata

We process information needed to operate the service, including an uploader and source household, timestamps, file sizes and types, encrypted-object identifiers, delivery status, sharing relationships, recipient exclusions, and whether a photo is available. This metadata is private information even though the underlying photo content is encrypted.

Device, security, and diagnostic information

We process device and app identifiers, device trust and revocation status, sign-in and security events, IP address and request information, storage use, error and reliability information, and generic push-notification tokens. We design logs not to include photo content, captions, access tokens, encryption keys, signed photo URLs, offer codes, or raw email addresses used in household lookup.

Website information

This public website does not use advertising trackers or analytics cookies. Like most hosting services, our infrastructure may process basic request information such as IP address, browser type, requested URL, and time of access for delivery, reliability, and security.

How we use information

  • Authenticate people and approved devices.
  • Create and administer households, memberships, roles, and sharing choices.
  • Store and deliver encrypted photos to authorized recipients.
  • Provide Photo Memories, slideshow, export, and notification features.
  • Prevent abuse, enforce limits, investigate failures, and protect the service.
  • Respond to support, privacy, and safety requests and comply with law.
  • Measure capacity and reliability using aggregated, nonidentifying metrics.

When we share information

We do not sell personal information. We may disclose limited information in these circumstances:

  • With people you choose. Household members and accepted receiving households receive the information and encrypted content needed for the sharing choices made in the app.
  • With service providers. We use providers such as Microsoft Azure for hosting and Google for sign-in. Apple may deliver generic push notifications on iPhone. Providers process information for us under applicable terms and safeguards.
  • For safety and legal reasons. We may preserve or disclose information when reasonably necessary to comply with law, protect people, investigate misuse, or defend our rights.
  • In a business transition. Information may be transferred as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to this notice and applicable law.

We do not put photo details, captions, email addresses, household names, or access credentials in push-notification text.

Security and the encryption boundary

We use technical and organizational safeguards designed to protect information, including transport encryption and device-bound access controls. Photo content is encrypted before upload, and approved recipient devices receive the keys needed to decrypt it.

No system is perfectly secure. People who can view a photo can save or export a copy, and access already delivered to an offline or modified device cannot always be recalled. Losing every approved key-holding device may make a household’s stored photos permanently inaccessible. PhotosInFrame does not keep a photo-recovery backup or an operator decryption key.

Retention and deletion

We retain information only for as long as needed for the service, security, legal obligations, and the purposes described here. Active encrypted photos and related metadata remain while they are retained in the service. When a photo is deleted or automatically removed at the household limit, we remove its encrypted files, key envelopes, caption, and active metadata without a photo trash or recovery copy. A minimal opaque deletion record may remain to prevent replay or restoration.

A user or household deletion request begins a 30-day restore window. Access is suspended during that window. After it ends, the applicable account, encrypted content, credentials, and identifying profile information are permanently purged, subject to narrow security, audit, or legal records that contain no photo content. Exported copies outside PhotosInFrame cannot be deleted by us.

Current operational targets include 30 days for application and HTTP logs, 365 days for administrative audit events, and 13 months for aggregated nonidentifying service metrics. Security denials may be retained longer to prevent revoked access from returning.

Your choices

Depending on the feature and your household role, you may manage household membership, devices, incoming sharing, slideshow visibility, notifications, and individual photo sharing. You may delete photos you uploaded; household Owners and Co-owners have additional controls. You may also request access to, correction of, or deletion of your personal information as provided by applicable law.

Revoking a share stops new access through PhotosInFrame but cannot recall copies or keys already saved by another person or device. Deleting the app does not by itself delete your account or household data.

Children’s privacy

PhotosInFrame is intended to be set up and administered by adults. It is not directed to children for creating independent accounts. Adults are responsible for deciding which family photos, including photos of children, they share through the service.

Changes to this notice

We may update this notice as the service develops or legal requirements change. We will post the revised notice here, update the effective date, and provide additional notice in the product when required.

Contact

Questions or privacy requests can be sent to privacy@photosinframe.com. Please do not send photos, passwords, encryption keys, sign-in tokens, or other sensitive content by email.