1. Information We Collect
Account & Identity Information
When you create an account or sign in, we process your name, email address, internal user ID, authentication provider details, and session tokens required to maintain security.
Content You Submit
To provide gallery, Studio, comment, and interaction features, we process content you upload or create, including:
- Photos, videos, Live Photos, and generated thumbnails;
- EXIF metadata, capture timestamps, camera and lens models, titles, tags, ratings, and site configurations;
- Comments, replies, emoji reactions, public profile details, and subscription relationships.
Photo metadata may contain precise GPS coordinates. Afilmory does not access your device's real-time location for map display; location data is processed solely when embedded in media files you choose to upload.
Device, Notification & Operational Information
When you enable gallery update notifications, we process Apple Push Notification service (APNs) device tokens, notification environments, locale, and subscription bindings. Servers may also log IP addresses, user agents, request timestamps, errors, and security events to operate and protect the service.
Purchase Information
Sponsorship in-app purchases are handled by Apple via StoreKit. Transactions are verified and completed on-device; Afilmory servers do not receive or store payment card details or full purchase histories. Apple manages billing records in accordance with its privacy standards.
2. How We Use Information
- Create and maintain accounts, Workspaces, authentication sessions, and security;
- Upload, store, transcode, synchronize, index, and display your photography;
- Provide public galleries, comments, reactions, subscriptions, and push notifications;
- Process sponsorship transactions and mitigate fraud or abuse;
- Troubleshoot technical issues, optimize performance, enforce terms, and fulfill legal duties.
We do not sell personal data, nor do we track users across third-party apps and websites for advertising.
3. Public Content & Visibility
When you mark a gallery as public, photographs, metadata, profile details, and public comments within it can be accessed by anyone and indexed by search engines. Please review and remove sensitive metadata or private coordinates before publishing.
Private Workspaces, unpublished drafts, and administrative settings are not made public by using public gallery features.
4. Information Sharing & Service Providers
We share data strictly to the extent necessary with the following recipients:
- Apple: Sign in with Apple, StoreKit, APNs, and App Store distribution;
- Authentication providers of your choice, such as GitHub or Google;
- Hosting, database, object storage, CDN, email, and security infrastructure providers;
- Regulatory, law enforcement, or judicial authorities upon lawful and valid request;
- Successor entities in the event of restructuring, merger, or asset transfer assuming this policy's obligations.
Third-party service providers processing data on our behalf are bound by contractual confidentiality and security commitments.
5. Retention, Deletion & Export
We retain data only as long as necessary to provide the service, resolve disputes, maintain security, or comply with legal requirements. Retention periods depend on data type, Workspace configuration, and backup rotation schedules.
You may request account deletion at any time via Profile → Delete Account in the app. Deletion removes accounts, Workspace ownership, third-party authentications, and hosted content, subject to limited records retained for fraud prevention or legal compliance. Backups are purged on standard rotation cycles.
Additionally, long-inactive free accounts may be subject to cleanup pursuant to Section 9.3 of the Terms of Service: deactivated first, then permanently deleted after 14 days. Signing in prior to permanent deletion cancels the scheduled cleanup. See the Account Cleanup Policy for exact thresholds.
To request access, correction, export, or deletion of personal data, you may reach out via our contact channels. Identity verification may be required.
6. Data Security
We employ transport layer encryption (TLS), access controls, least-privilege principles, and security monitoring to safeguard your data. While no internet service is completely immune to risks, we will notify affected users of any eligible security incidents in accordance with applicable laws.
7. Cross-Border Transfers
Afilmory and its service providers may process data outside your country of residence. We implement appropriate organizational, contractual, and technical safeguards to ensure cross-border data transfers comply with applicable privacy regulations.
8. Children's Privacy
Afilmory is not intended for children under the age of 13, and we do not knowingly collect personal information from minors. If you become aware that a child has provided us with personal information, please contact us for prompt removal.
9. Your Rights & Choices
Depending on your jurisdiction, you may hold rights to access, rectify, delete, restrict processing, port your data, or withdraw consent. You can manage account data, privacy visibility, and notification permissions directly inside the app, or submit requests to us.
10. Policy Updates
We may revise this Privacy Policy to reflect feature additions, operational adjustments, or legal obligations. Substantial changes will be communicated on this page or through the app, and the update date at the top of the page will be refreshed accordingly.
11. Contact Us
Privacy requests and inquiries can be submitted via the Afilmory Support Channel. Please do not disclose passwords, access keys, government identity documents, or unreleased private photos in public issues. For sensitive inquiries, we will arrange private communication channels.