Scope
This policy explains how Photerra, Inc. collects, uses, shares and protects personal information in connection with the Photerra mobile app, photerra.com, the share links served from map.photerra.com, the Photerra Nearby embeddable widget, and related services (the "Service"). Read it with our Terms of Service.
Photerra is the controller of the personal information described here.
Quick reference — what we collect and what happens to it
| Category | What that is here | Where it comes from | Why we have it | Who we disclose it to | How long we keep it |
|---|---|---|---|---|---|
| Identifiers | Username, display name, email, account ID, device identifiers, IP address, push token, social sign-in ID | You; your device; Google/Apple at sign-in | Run your account, authenticate you, send notifications, prevent abuse | Hosting, email, push, analytics, crash vendors (§8) | Until you delete your account; server logs 30 days |
| Customer records | Phone number, if you provide one | You | Verify a social sign-in; account recovery | Firebase (Google) for SMS verification | Until you delete your account |
| Commercial information | Affiliate link clicks, bookings attributed to you | Your use of the Service; Booking Partners | Attribute and reconcile commissions | Booking Partner affiliate networks | 24 months |
| Internet / device activity | Screens viewed, features used, session duration, crash reports, app version, OS | Your device | Diagnose faults, understand what to build | PostHog, Firebase Crashlytics | Events retained for up to 7 years under our current provider plan; session replay is off and previously held recordings were deleted on 2 August 2026 |
| Geolocation — precise. Sensitive. | Live device location while the app is open; coordinates attached to Spots you post; location tags read from photos in your camera roll | Your device, with your permission | Show what is nearby, tag Spots, build your travel map | Nobody except our hosting provider. Spot coordinates you publish become public. | Spot coordinates while the Spot exists; live location not stored beyond the session; scan summary until you delete it |
| Geolocation — coarse | Home country and city derived from your camera-roll scan; ~1.1 km grid squares for the clusters your photos fall into; country from your device locale | Derived on your device from your photos, then snapped to a ~1.1 km grid before it is sent; device settings | Personalise your map and recommendations | Google, to turn a grid square into a city name | Until you erase your travel map or delete your account |
| Sensory / visual | Photographs you upload and publish | You | Publish your Spots; screen them for safety; generate captions and categories | AI vendors (per request, §8); content-safety vendors; CDN; anyone, once you publish | Until you delete the content or your account |
| Biometric, genetic, health, financial account, government ID, union membership, sex life, immigration status, race, religion, political opinion, message contents | We do not collect any of these. We do not run face recognition and do not derive biometric identifiers from photographs. | ||||
| Inferences | A "traveller archetype" and travel statistics derived from your camera-roll scan and your Spots; recommended Spots | Derived by us from the above | Personalise your profile, map and recommendations | Nobody | Until you erase your travel map or delete your account |
Sensitive personal information. Under California law the precise geolocation above is "sensitive personal information". We collect it with your permission and use it only to provide the location features you asked for, plus security, plus the travel map and archetype described openly in §3.4 and §4. We never use it for advertising and never sell it. See §11.4 for your right to limit — and note that the app now has a one-tap control that is faster than any request you could send us.
Information we collect
3.1 What you give us
- Account: a username (a display name you choose, not your legal name), your email address, a password (stored only as a bcrypt hash), and anything else you choose to add — profile photo, bio, home city.
- Phone number: if you sign in with a social account we may ask you to add and verify a phone number, and you may add one yourself. Verification uses an SMS code sent through Firebase Authentication (Google). We do not use your phone number for marketing.
- Content: Spots, photographs, descriptions, ratings, tips, itineraries, comments — with their metadata, including capture time and coordinates.
- Communications: what you send us for support, feedback, a deletion request, a report, or a legal notice.
3.2 What your device tells us automatically
- Device and usage: device type, operating system, app version, unique device identifiers, screens viewed, features used, session duration, crash logs.
- Session replay: turned off. We previously recorded a reconstruction of the screens you saw and the taps you made. Masking covered text you typed, images and photos — but not the map itself, which is drawn by your phone's own maps software and could not be masked. On 2 August 2026 we turned recording off and deleted every recording we still held. We are not recording sessions, and we will not turn this back on without asking you first.
- Log data: IP address, user agent, referring pages and timestamps, in ordinary server access logs.
- Install attribution (Android): if you installed the app from a link we published, Google Play passes us the campaign tag from that link once. It identifies the link, not you.
3.3 Live location
With your permission, we collect precise geolocation from your device to show nearby Spots, tag content you post, and power location-based discovery.
We collect it only while the app is in the foreground. We do not request or collect background location — the Android background-location permission is not declared in the app, and nothing in the app ever asks for the iOS "Always" level. You can turn location off at any time in your device settings; some features will stop working. And every six months, the app shows you an in-app reminder that location is in use, so this collection never becomes invisible.
3.4 The camera-roll scan — what happens on your device, and what leaves it
When you tap "Show me my map", and only after you grant photo access, Photerra reads the location tags and capture dates attached to the photos already in your camera roll. This is how we can show you where you have been before you have posted anything.
On your device, and staying there:
- Your photographs themselves. The scan never uploads them. Photos are uploaded only when you choose to publish a Spot or ask for cloud analysis.
- The exact coordinates of every photo. Nothing we send is more precise than a grid square of roughly 1.1 km.
- The home area we infer from where your photos cluster, as a coordinate. We never ask you for a home address and we do not store one; only the city and country name below are sent.
What we send to our servers and store, once the scan finishes:
- Counts: how many places, countries and continents, how many years you have been travelling, and your first year.
- Your home country and home city name — the city, not a coordinate. To turn a cluster into a city name we send its grid square to Google's geocoding service.
- A traveller archetype, a label derived from the pattern of where your photos were taken.
- A set of map pins: the clusters your photos fall into, snapped to a grid of roughly 1.1 km, with duplicate squares collapsed and no photo counts attached. These draw the map on your profile and share card.
- The time of the scan.
Together these amount to a coarse history of the regions you have visited. We are telling you that plainly because that is what it is. We designed it to be coarse — grid-snapped, de-duplicated, no exact coordinates, no timestamps per pin — and we re-apply the snapping on our servers as a second line of defence. It is still location information about you, and we treat it as sensitive.
Controls. You can decline the scan entirely; the app works without it. And you can have all of it erased — without deleting your account and without touching the Spots you have published — in the app — Settings → Erase scan data — or by emailing legal@photerra.com.
3.5 Information from third parties
- Social sign-in: if you use Apple or Google, we receive the basic profile information that service authorises — typically a stable user ID, an email address (or Apple's private relay address, if you chose that) and a name. We verify the token server-side.
- Booking Partners: when you complete a booking after clicking an affiliate link, the affiliate network may confirm the transaction to us for commission purposes. We do not receive your payment card details, and we do not receive your name or booking details unless the network sends them.
3.6 Photo metadata and EXIF
When you publish a photograph, we strip the EXIF metadata — including the embedded GPS tag, camera serial number and any personal fields — before the file is stored or served. The coordinate shown on a published Spot is the one you reviewed and confirmed in the app, not a hidden tag inside the file.
The one exception is content our child-safety screening identifies as apparent CSAM: those original bytes are preserved with metadata intact, in a locked evidence store, because federal law requires their preservation. See §7.4.
3.7 Cookies and similar technologies
| Where | What | Purpose | Set by |
|---|---|---|---|
| photerra.com (outside the EEA/UK) | ph_* cookie and local storage | Product analytics — which pages are visited, which buttons clicked | PostHog |
| photerra.com (EEA/UK visitors) | Nothing. Analytics run in memory only and write no cookie and no storage. | — | — |
| Photerra app | Local storage on your device | Session, preferences, caches | Photerra |
| Photerra app | Secure keychain / keystore | Your login tokens | Photerra |
| Photerra Nearby widget | Nothing at all. | — | — |
There are no advertising cookies, no cross-site trackers, no remarketing pixels and no data-broker tags on any Photerra surface. Because visitors in the EEA and the UK get a build that stores nothing, we do not need to ask them for cookie consent, and we do not show a cookie banner.
How we use information
| Purpose | What we use | Legal basis (EEA/UK) |
|---|---|---|
| Create and run your account; authenticate you | Identifiers, phone | Contract |
| Show nearby Spots; tag content; build your travel map | Precise and coarse location | Consent (device permission), withdrawable any time |
| Publish the Spots and content you choose to make public | Content, username | Contract |
| Personalise your map, recommendations and profile — including the archetype and statistics in §3.4 | Location-derived inferences | Legitimate interests; consent for the underlying location |
| Generate captions, spot categories and trip suggestions with AI | Photographs, Spot metadata | Legitimate interests / contract |
| Screen every uploaded photograph for illegal and prohibited content, before publication and before any other automated processing | Photographs | Legal obligation; legitimate interests (platform safety) |
| Detect and prevent fraud, abuse and Terms violations | Identifiers, activity, content | Legitimate interests |
| Diagnose crashes and understand product usage | Device and usage data, session replays | Legitimate interests |
| Attribute affiliate commissions | Click and transaction data | Legitimate interests |
| Send service, security and transactional messages | Identifiers | Contract |
| Send marketing, where you opted in | Identifiers | Consent |
| Comply with law; respond to lawful requests; preserve evidence | As required | Legal obligation |
We will not use your information for a materially different purpose without telling you first and, where the law requires it, getting your consent.
We do not use your photographs, content or personal information to train, fine-tune or develop artificial-intelligence or machine-learning models. See §8.
Automated decisions, and how to get a human
Two things happen automatically on Photerra:
- Content screening. Every uploaded photograph is screened by automated systems — image classifiers and hash-matching against known illegal-content databases — before publication. Content the systems flag may be blocked from publishing, hidden pending review, or removed. Some of these outcomes occur without a person seeing the item first.
- Ranking and recommendation. Which Spots you see is decided by distance, recency, engagement and the categories associated with a place. This does not restrict your account or your rights.
If an automated decision affects your content or your account, we will tell you (see Terms §12.3), and you can ask for a human to review it by replying to that notice or emailing legal@photerra.com. We do not make decisions producing legal or similarly significant effects about you by automated means alone.
How we share information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by California and other US state privacy laws. We have not done so in the preceding 12 months.
6.1 Publicly, because you chose to publish
Spots, photographs, ratings, tips and itineraries you make public are visible to other users, and also appear on photerra.com (for example destination pages at photerra.com/spots), in share links and share cards, and in the Photerra Nearby widget on third-party sites. Search engines can index the public website.
Your username and profile photo appear alongside your contributions. Your email address, phone number, precise location history and account details never do.
If you turn on Quiet Mode, your name is not displayed alongside your content on surfaces visible to third parties, including the public website, share cards and the widget.
Share links and share cards. When you or another user shares a Spot or a trip, we generate a link served from map.photerra.com together with a share card — an image rendered from the shared content, stored on our CDN and reachable by anyone who has the link. Share links are unlisted, not secret. You can revoke a share link at any time, which disables the link and removes the card; deleting the underlying content revokes it automatically.
Publishing is a one-way door in one respect: we can remove content from every Photerra surface, and we do, immediately. We cannot retrieve copies that other people already saved or shared.
Some places are never published. We withhold from public output any Spot whose place name, label or description indicates a sensitive location — healthcare delivery, reproductive health, mental-health or addiction treatment, and shelters for people escaping violence. The Spot still exists and you still see it; it just does not go onto the open web with your name attached.
6.2 With service providers
| Provider | What it does | What it receives |
|---|---|---|
| Amazon Web Services (US) | Hosting, database, image storage and CDN | Everything, as our infrastructure |
| PostHog (US) | Product analytics | Pseudonymous ID and events. Session replay was turned off and existing recordings deleted on 2 August 2026. |
| Google — Firebase | Push notifications, crash reporting, social and phone sign-in | Device token, crash data, phone number for SMS verification, social sign-in identity |
| Google — Maps Platform (Maps, Places, Geocoding, Directions, Static Maps) | Map display, place search and autocomplete, reverse geocoding, route lines, PDF maps | Search text you type, coordinates and routes — sent from your device or our server when you use the feature. Google's own Privacy Policy applies to what it does with them. |
| Wikimedia Foundation — Wikipedia API | The cited "nearby fact" card in the app | A coordinate snapped to a ~1.1 km grid square when you open a nearby fact — never your precise location. Wikimedia's Privacy Policy applies to what it does with it. |
| Anthropic (Claude) and OpenAI | Generating spot categories, captions and trip suggestions; screening images for safety | The photograph or text for that one request, with a pseudonymous ID |
| Amazon SES | Transactional email | Your email address and message content |
| jsDelivr (CDN) | Serves the map software any page with a map needs | Your IP address and browser user-agent, whenever you load a page that shows a map. These two were previously disclosed only in the widget section (§9) — but photerra.com itself makes the same requests for every visitor, so they belong here. |
| OpenFreeMap | Serves the map tiles themselves | Your IP address and the map area you are looking at |
Providers act on our instructions under written terms, may use the information only to provide their service to us, and may not sell it.
6.3 With Booking Partners
When you tap an affiliate link, the Booking Partner and its affiliate network receive your IP address, device information and the referring URL — the ordinary consequence of following a link. We share only what commission attribution requires. We do not send them your name, email or account information. Once you are on their site you are subject to their privacy policy.
6.4 Through the API
If we launch a paid API, only public Spot data is eligible, and only from contributors who have opted in to the commercial licensing programme in Terms §7.5. Private itineraries and non-public content are never included. API customers are bound by API Terms restricting use and redistribution and prohibiting AI training.
If any such programme would constitute a "sale" or "sharing" under applicable law, we will update this policy, publish a Notice of Financial Incentive, provide the required opt-out including Global Privacy Control, and obtain any required consent before any distribution begins. See §11.6.
6.5 For legal reasons
We may disclose information where we believe in good faith it is required by law, regulation, legal process or governmental request; to enforce our Terms; to protect the rights, property or safety of Photerra, our users or the public; or to detect and prevent fraud or security incidents. Where we are legally permitted to tell you about a request for your data, we will.
Child safety is not discretionary: we report apparent child sexual abuse material to NCMEC and preserve the associated content and records as 18 U.S.C. § 2258A requires.
6.6 In a business transfer
If Photerra is involved in a merger, acquisition, financing, reorganisation or sale of assets, information may transfer as part of it. Any acquirer is bound by this policy for information collected before the transfer, and we will notify you before your information becomes subject to a materially different policy, with any choices you have.
6.7 With Photerra staff
A small number of Photerra personnel can access accounts and content through an internal admin tool, to run the Service, respond to reports and investigate abuse. Access is role-limited and administrative actions are logged.
Retention and deletion
7.1 Deleting your account
Delete your account in the app (Settings → Delete account) or at photerra.com/delete-account.
In the app, deletion is immediate and permanent. When you confirm, we delete — in one transaction — your account record, your Spots and their images, your posts, comments, likes, follows and followers, your saved places and trips, your notifications, your device tokens, your reports and your travel-map scan summary. We then delete the underlying image files from storage. If you signed in with Apple, we also revoke Photerra's Apple sign-in token so the connection is severed on Apple's side too.
The web form is different, because someone who cannot log in cannot prove the account is theirs. It sends a verification request to our privacy team, who confirm ownership and then delete. We complete this within 30 days, and usually far sooner.
7.2 What survives deletion, and why
- Backups: encrypted database backups roll off after 90 days. Your data is not restorable to the live Service from them, and they are overwritten in the ordinary course.
- Server logs: access logs containing IP addresses persist up to 30 days.
- Analytics: pseudonymous event data is retained by our analytics provider for up to 7 years under our current plan; session replays are deleted automatically after 30 days. You can ask us to delete your analytics data and we will pass the request to our provider.
- Aggregate and de-identified data: counts and statistics that cannot be linked back to you may persist. We will not attempt to re-identify them.
- Legal holds: content and records subject to a preservation obligation — principally a NCMEC child-safety report — are retained for the period the law requires, and an account with content under an active hold cannot be deleted until the hold ends. This is the only situation in which we will refuse a deletion request outright, and we will tell you if it applies.
- Records of the deletion itself, so we can prove we honoured it.
7.3 If you delete a single item
Deleting a Spot or photo removes it from the Service, from the public website and from every widget embed, within minutes. The image files are deleted from storage. Copies already cached by a CDN expire shortly afterwards.
7.4 CSAM evidence
Content that our screening identifies as apparent child sexual abuse material is never stored in our normal systems. The original file is written to a locked, access-restricted evidence store with retention controls designed to hold it for the statutory period, and reported to NCMEC. This is a legal obligation, not a choice.
AI providers, in detail
Photographs you upload are processed by AI vision services — currently Anthropic (Claude) and OpenAI — to generate spot categories, captions and discovery metadata, to power AI features you invoke such as trip suggestions, and to screen content for safety before publication.
- Each request carries the image and a hashed, pseudonymous identifier — never your name, email or contact information.
- Under our agreements with these providers, content submitted through their APIs is not used to train their models.
- Photerra does not train models on your content either. We have no training, fine-tuning or embedding pipeline. If that ever changes, it will be opt-in, it will be announced before it happens, and it will not be retroactive.
- AI providers process content transiently and retain it only as long as their abuse-monitoring policies require.
See Anthropic's and OpenAI's privacy policies for their own practices.
The Photerra Nearby widget
Photerra offers a free widget that other site owners can embed. If you are reading this because you met the widget on someone else's website:
- No cookies, no storage, no identifier. The widget sets no cookies, writes nothing to local or session storage, and creates, reads or transmits no visitor identifier. It cannot recognise you across pages, sites or visits. It is not used for advertising or profiling.
- What we receive. Your browser requests photographs and spot data from Photerra, so — as with any HTTP request — we receive your IP address and user agent in ordinary server logs, used only to serve the request, prevent abuse and diagnose faults. The widget also sends one diagnostic message per load describing the embed, not you: the domain it is on, which location was requested, whether it rendered, and how many photographs it displayed. No identifier, no page path, no referrer, no query string, no coordinates.
- Third-party requests. If you open the map view, your browser loads map software from jsDelivr and map tiles from OpenFreeMap; those requests go directly from your browser to those services, which will see your IP address, and their terms apply. Photographs come from our CDN (Amazon CloudFront). The default gallery view loads neither.
- The host site. The site you are visiting cannot read anything inside the widget — it is isolated by the browser as a sandboxed cross-origin frame. In the other direction, the widget's small loader script reads only the host page's background and text colors, so the widget can render legibly on that site's theme, and the frame and page exchange only that color information and the widget's height. It reads no page content, forms, cookies, or storage.
- Site owners. Embedding the widget does not disclose your visitors' personal data to us beyond the above, and we are not a processor of your customer data.
Security
- Encryption in transit everywhere (TLS 1.2+).
- Encryption at rest for the database and for stored images.
- Login tokens held in the iOS Keychain / Android Keystore, never in plain application storage.
- Passwords stored only as bcrypt hashes; we never see them.
- Refresh tokens are rotated, stored hashed, and revoked across all sessions if a token is ever replayed.
- Image storage is private and reachable only through our CDN.
- Role-based access controls on the internal admin tool, with an audit log of administrative actions.
No system is perfectly secure and we cannot guarantee absolute security. Report a vulnerability or a concern to legal@photerra.com; we will not pursue good-faith security research that respects user privacy and does not degrade the Service.
Breach notification. If a breach is likely to result in risk to you, we will notify you without undue delay, and notify regulators within the deadlines the law sets — including 72 hours to the relevant supervisory authority under the GDPR, and the timelines each US state requires.
Your rights
11.1 Everyone, everywhere
We give these to all users, regardless of where you live:
- Access and correct your account information in Settings.
- Download your data — request an export in the app (Settings → Download my data) and we will email you a link to a machine-readable export of your account and content. The link expires after 24 hours, and you can request one export every 30 days.
- Erase your travel map — in the app: Settings → Erase scan data. Removes the pins, home city, archetype and travel counts derived from your photo locations, without deleting your account or your Spots.
- Delete your account and content — §7.
- Turn location off at any time in device settings.
- Quiet Mode — hide your name from surfaces visible to third parties.
- Opt out of marketing — unsubscribe link, or in-app notification settings.
- Talk to a human about an automated decision — §5.
To exercise a right we cannot serve in the app, email legal@photerra.com. We will verify your identity in proportion to the sensitivity of the request, and respond within 45 days (extendable once by a further 45 days where a request is complex, in which case we will tell you). There is no charge unless a request is manifestly unfounded or excessive.
Appeals. If we decline a request, we will explain why, and you may appeal by replying to that decision or writing to legal@photerra.com with the subject "Privacy appeal". A different person will review it and respond within 45 days with a written explanation. If we deny the appeal, we will give you contact details for your state Attorney General or supervisory authority.
Authorised agents. You may use an authorised agent, with written permission and identity verification.
No retaliation. We will not deny service, charge different prices, or provide a different quality of service because you exercised a privacy right.
11.2 Global Privacy Control and Do Not Track
photerra.com honours the browser "Do Not Track" signal: if your browser sends DNT, our analytics do not run.
We do not sell or share personal information, so a Global Privacy Control signal currently has no sale or sharing to opt out of. We treat GPC as an opt-out preference anyway, and if we ever launch a programme that constitutes a sale or sharing, GPC will be honoured as a valid opt-out from day one.
We do not operate advertising trackers, cross-site tracking or behavioural remarketing on any surface, so the activity these signals exist to limit does not occur here.
11.3 California — CCPA/CPRA
If you are a California resident:
- Right to know the categories and specific pieces of personal information collected, the sources, the business or commercial purposes, and the categories of third parties to whom it is disclosed — set out in §2 and §6.
- Right to delete, subject to the exceptions in §7.2.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and have not in the preceding 12 months, so there is nothing to opt out of and no "Do Not Sell or Share My Personal Information" link is required. If that changes we will publish one before it does.
- Right to limit use of sensitive personal information — §11.4.
- Right to non-discrimination.
We have no actual knowledge that we sell or share the personal information of consumers under 16 years of age. The Service is for adults only.
Categories disclosed for a business purpose in the preceding 12 months: identifiers, customer records, commercial information, internet activity, geolocation, sensory information and inferences — to the service providers listed in §6.2, for the purposes stated there. Categories sold or shared: none.
11.4 Limiting our use of sensitive personal information
Precise geolocation is sensitive personal information. We use it only to deliver the location features you asked for, to secure the Service, and for the travel map and archetype we describe openly in §3.4 — never for advertising, never for inferring characteristics beyond those, and never sold.
You can limit it directly: turn off location permission in your device settings, which takes effect instantly. To erase the travel map, use Settings → Erase scan data in the app.
11.5 Other US states
If you live in Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah or Virginia — or another state whose comprehensive privacy law has since taken effect — you have rights to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We do none of those three things, so there is nothing to opt out of. You also have the right to appeal — §11.1.
Universal opt-out mechanisms. We recognise Global Privacy Control as required by the states that mandate it.
Sensitive data consent. Several of these laws require opt-in consent before processing sensitive data, including precise geolocation. Photerra obtains that consent through your operating system's location and photo permissions, which you can withdraw at any time.
Maryland residents — a specific commitment. The Maryland Online Data Privacy Act prohibits the sale of a consumer's precise geolocation outright, even with consent, and permits processing of sensitive data only where strictly necessary to provide the product you requested. Photerra will not sell or license precise geolocation tied to an identifiable Maryland resident under any programme, at any price. More broadly, if we ever run the commercial licensing programme in Terms §7.5, contributor-linked precise coordinates will be excluded from what is licensed; what we would license is place-level data, de-identified from the contributor.
Washington and Nevada. We do not collect consumer health data, do not use location to infer health status or the receipt of health services, and do not sell any data that could constitute consumer health data. We also withhold sensitive locations from public output entirely (§6.1). We therefore do not maintain a separate consumer health data privacy policy.
11.6 Notice of Financial Incentive — if we launch revenue sharing
This programme does not exist yet. This section describes what we will publish if and when it launches.
If we offer contributors a share of revenue for licensing their public content, that is a financial incentive under California law. Before enrolment opens we will publish: what the programme is and what data it covers; the material terms, including the revenue-share percentage, payment threshold and schedule; how to enrol and how to withdraw, with withdrawal available at any time by a single control; a good-faith estimate of the value of the data to Photerra and the method used to calculate it — which will be the actual licensing revenue attributable to each contributor's content under the programme's own accounting, because that is the figure the revenue share is computed from; and a statement that the programme is reasonably related to that value.
Not enrolling costs you nothing. Your account, your visibility, your features and your support are identical either way. We will never make the Service worse for people who decline.
11.7 EEA, UK and Switzerland — GDPR
- Controller: Photerra, Inc., a Delaware corporation with its principal place of business in San Francisco, California. Contact: legal@photerra.com.
- Legal bases: the table in §4.
- Your rights: access, rectification, erasure, restriction, objection (including to processing based on legitimate interests), portability, and withdrawal of consent at any time without affecting prior processing.
- Transfers: your data is processed in the United States. We rely on the EU and UK Standard Contractual Clauses with our processors, supplemented by transfer risk assessments, with our processors.
- Complaints: you may lodge a complaint with your local supervisory authority.
- No DPO: Photerra's processing does not require the appointment of a Data Protection Officer under Art. 37. Privacy questions go to legal@photerra.com.
Children
The Service is for people 18 and over. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we delete the account and the information promptly.
Where an app store provides an age or parental-consent signal about your account, we use it solely to comply with the law that requires it, transmit it securely, and delete it after use.
If you believe a minor has given us personal information, email legal@photerra.com and we will act.
International users
Photerra is based in the United States. If you use the Service from elsewhere, your information is transferred to and processed in the United States, where data-protection law differs from your own. Where the law requires it, we implement safeguards including Standard Contractual Clauses. See §11.7.
Changes to this policy
We may update this policy. If a change is material, we will post the updated policy, update the effective date, and give you notice by email or in-app before it takes effect.
We will not apply a materially different use to information we already collected about you without asking you first. If we ever want to use existing data in a way this policy does not cover, we will seek your consent for that data, not just change the policy going forward.
Contact
Photerra, Inc. — a Delaware corporation, principal place of business in San Francisco, California
Privacy, deletion, access, appeals: legal@photerra.com
General: info@photerra.com
Want your data deleted?
Email us and we'll remove your account and associated data within 30 days.