Privacy Policy
Effective date: September 27, 2026
1. Introduction
Photosgraph PBC ("we," "us," or "our") operates the photosgraph platform ("the Service"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
Photosgraph is built on a principle of consent. This extends to our privacy practices — we aim to collect only what is necessary to operate the Service and to give you meaningful control over your information.
Data Controller
The data controller for information processed through photosgraph is:
Photosgraph PBC
155 Woodland Avenue, Lexington, KY 40502
privacy@photosgraph.com
We do not currently have a Data Protection Officer. If you have questions about our data practices, contact us at privacy@photosgraph.com.
2. Information We Collect
Information you provide:
Account information: Your username, email address, and password (stored as a secure hash — we never store your actual password).
Profile information: Your display name (which must include your real name) and profile photo.
Photos & metadata: Photos you upload, captions, names and tags identifying people in photos, dates, places, and annotations.
Metadata inside photo files: Photos usually arrive carrying data the camera embedded in the file — the camera's make, model and serial number, timestamps, and, where the device recorded it, GPS coordinates of where the photo was taken.
We remove all of it from the file when you upload. Before removing it we read one value: the date the photo was taken, which we keep so it can fill in the photo's date for you. The photo page marks a date that came from the file, and you can change or clear it at any time.
We do not keep the coordinates, the camera details, or anything else the file carried. They are not stored in our database, and they are not in the copy we keep or display — the removal is permanent and applies to the file itself, not only to what is shown.
Approval decisions: Your approvals and revocations of tags on photos, your tagging preference (who may tag you), and any family relationships you record.
Information collected automatically:
Log data: When you use photosgraph, our servers may record standard log information including your IP address, browser type, referring URL, and access times. This data is used for security and service operation purposes only and is retained for 90 days.
Cookies and session data:
We use essential cookies only, to maintain your login session and protect against cross-site request forgery. We do not use tracking cookies, analytics cookies, or any third-party advertising cookies. No cookie consent banner is required because we use only cookies that are strictly necessary for the Service to function.
3. Lawful Basis for Processing (GDPR)
For users and data subjects in the European Economic Area (EEA), we process personal data under the following lawful bases:
Contractual necessity (Article 6(1)(b)): Processing your account information, profile, and uploaded content as necessary to provide the Service you signed up for. This includes showing your name and profile photo to the other members of albums you share — on member lists, on photo tags, and when someone is identifying the people in a photo — which is a core part of how the Service operates.
Consent (Article 6(1)(a)): Processing of your uploaded content for display within albums you have joined. Joining an album constitutes consent for viewing by the other members of that album, and by no one else. You may withdraw consent at any time by removing specific photos, revoking your tag, or leaving the album.
Legitimate interest (Article 6(1)(f)): Processing of photos in your personal Unsorted area prior to being added to a group album, where the photo is visible only to the uploader. Processing of depicted non-users' data as described in Section 9, balanced against their rights through the safeguards described therein.
Legal obligation (Article 6(1)(c)): Processing necessary to comply with applicable laws, such as responding to lawful requests from authorities.
4. How We Use Your Information
We use your information to:
— Operate and maintain the Service
— Show your name and profile photo to the other members of albums you share, so they can recognise and identify you in photos
— Notify you when you are tagged in a photo or invited to an album
— Invite you to an album when someone tags you in one of its photos. You choose whether to accept; you are not added without doing so
— Protect the security of your account and the Service
— Respond to your requests, reports, and inquiries
— Comply with legal obligations
We will never use your content or personal data to train machine learning models, for advertising, or for any purpose beyond operating the Service as described in this policy. Photosgraph does not accept AI-generated, AI-composited, or synthetically created images. All photos must depict real moments captured by a physical camera or scanner. See our Terms of Use for details on permitted and prohibited modifications.
5. What We Share
Profile information: Your profile page is private to you. No other member can open it. Your display name and profile photo appear to the other members of albums you share — in member lists and on photo tags — because identifying each other is what an album is for. There is no public people directory. You cannot be searched for by name unless you turn on "Let my family network be explored", which makes you findable so that relatives can add you.
Album content: Photos in an album are visible to the members of that album and to no one else. This includes the photo, associated metadata, and the names and profile photos of tagged people. Album content is not visible to non-members, to non-logged-in visitors, or to search engines.
We do not sell your data. We do not sell, rent, or trade your personal information to third parties for marketing, advertising, or any other purpose. We have not sold personal information in the preceding 12 months.
Service providers: We may share data with service providers who assist in operating the Service (e.g., hosting, email delivery), subject to contractual obligations to protect your data and use it only as directed by us.
Legal requirements: We may disclose information if required by law, legal process, or to protect the rights, property, or safety of Photosgraph PBC, our users, or the public.
6. International Data Transfers
Our servers are located in the United States. If you are accessing the Service from outside the United States, your data will be transferred to and processed in the United States. For transfers from the EEA, we implement appropriate safeguards as required by GDPR Chapter V, which may include Standard Contractual Clauses or reliance on adequacy decisions. Details of the specific safeguards applied to each transfer are available upon request at privacy@photosgraph.com.
7. Your Rights & Controls
All users:
Who may tag you: People in an album with you can always tag you in that album's photos — that is what being in an album means, and you can remove any tag. Beyond that album you choose: people you share an album with may also tag you in their other albums (the default), only inside albums you are both in, or any member at all. You can change this at any time in your profile.
Family relationships: You may record how you are related to another member. This is your own label; the other person is notified and can remove it, and once they have, you cannot reinstate it. People you are actually related to — where the family links recorded on Photosgraph connect you to each other — can see you in a family tree. That is what a family tree is, and it is not something you turn on. Beyond your relatives, you choose how far your links carry: by default only people you share an album with or are directly linked to, and you may opt in to being visible to anyone connected to you through family links, which also makes you findable by name. Being findable by name is never on unless you turn it on. Separately, you choose who may record a relationship with you at all: by default, people you share an album with and people already in your family, and you may widen this to any member. Whichever you choose, a relationship recorded about you is always yours to remove.
Approval & revocation: You control which photos you appear in. You can remove any photo of yourself from an album, leave an album entirely, or revoke your tag, which removes the photo from every album across the platform. None of these require anyone else's agreement.
Profile editing: You can update your name, profile photo, password and privacy settings at any time.
Account deletion: You may delete your account at any time. This will remove your profile, revoke all your tags (removing you from the photos you appear in), delete photos you uploaded, and transfer albums you organized. Personal data will be deleted within 30 days; backups purged within 90 days.
Data access: You may request a copy of the personal data we hold about you.
Data portability: You may request your data in a structured, commonly used, machine-readable format.
We will respond to verified data access and portability requests within 30 days (or 45 days if we notify you of an extension, as permitted under CCPA). For GDPR subject access requests, we will respond within one calendar month as required by Article 12(3).
Additional rights for EEA residents (GDPR):
Right to rectification: You may request correction of inaccurate personal data.
Right to erasure: You may request deletion of your personal data, subject to any legal retention obligations.
Right to restrict processing: You may request that we limit how we process your data in certain circumstances.
Right to object: You may object to processing based on legitimate interest.
Right to lodge a complaint: You have the right to lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, contact us at privacy@photosgraph.com.
Additional rights for California residents (CCPA):
Categories of personal information collected: Identifiers (name, email, username, IP address); internet or electronic network activity (log data, session information); place names a member chooses to add to a photo; and audio, electronic, visual, or similar information (photos).
We do not collect precise geolocation. Coordinates embedded in photo files by the camera are removed on upload and are never stored. The only location information we hold is a place name a member has typed.
Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
Right to delete: You may request deletion of personal information we hold about you.
Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
Do Not Sell My Personal Information: We do not sell personal information. We have not sold personal information in the preceding 12 months.
8. Photo Privacy
Photosgraph uses a layered consent model with two visibility contexts:
Group albums (private):
— Photos are visible to all group members immediately upon upload, whether or not anyone has been tagged yet
— Being a member of the group constitutes consent for viewing within that group
— Any member who appears in a photo can remove it from the group at any time
— Any member can leave a group, removing all photos of them from that group
Community Commitments:
— At registration, every user agrees to the Community Commitments — covering photo standards, album integrity, and community conduct — by accepting the Terms of Service, which set them out in full at Section 4a
— These commitments apply to all activity on the platform and are not re-confirmed per photo or per album
— Reminders appear when uploading photos and creating albums
— The commitments attest that photos are genuine, do not violate rights, and are not AI-generated. Photos of minors are permitted in group albums under specific restrictions (see Section 12).
Additional protections:
— Any member of an album can tag or name the people in its photos, subject to the tagging preference of the person being tagged
— Uploaders must tag or name every reasonably identifiable person, or obscure them
— No identity record, tag, name or account is created for anyone under 16 (see Section 12)
— AI-generated, AI-composited, or synthetically created images are prohibited
— Deleted photos are permanently removed
— Any tagged person can remove a photo from all albums across the platform (permanent revocation)
We design the Service so that individuals maintain ongoing control over their appearance in photos.
Photos in more than one album:
A member of an album may add a photo from it into another album they also belong to, without the uploader's agreement. They cannot add it to an album they are not a member of, and adding it never makes the photo visible to anyone who could not already see the album it is added to.
Two separate facts are recorded: who uploaded the photo, and who added it to that particular album. The uploader record never changes, and a photo is never credited to the person who filed it. Where the two differ, both names are shown.
How much of an uploader's identity travels with the photo depends on context. Their name is always shown, because a photo credited to nobody — or to the wrong person — is a worse outcome for them than a name appearing. Their profile picture is shown only to members of an album they themselves belong to. This follows the same rule we apply everywhere else: one member sees another's name and face only where a shared album calls for it.
If someone adds your photo to an album you are not a member of, we notify you. We do not ask permission first, and we state that plainly rather than leaving it to be discovered: requiring per-photo approval for filing would make albums unworkable, so we have chosen to make it visible and reversible instead. Every control described above remains available to you — removing the photo from that album, or revoking it across the platform.
Deceased persons:
When a depicted person has died, the standard consent flow cannot apply, because consent has to come from the person themselves. Instead, one named person stands in for them: their steward. This is whoever first recorded that person on Photosgraph, and they must confirm in good faith that they believe the person or their family would not object to the photo being shared.
A steward holds the same choices for that person that a living member holds for themselves — their name and picture, who may tag them, whether their family tree may be explored, and who may record family relationships involving them. A steward may also remove them from an individual photo, or delete their record altogether. Because there is nobody to give approval, a tag naming a deceased person takes effect when it is created rather than waiting; it stays removable by their steward.
We are direct about the limits of this. There is one steward per person, assigned by who recorded them first, it is not currently transferable, and we do not presently verify a steward's relationship to the person they look after. It is a practical stand-in, not a claim of authority.
Photosgraph does not currently offer legacy contacts or memorialized accounts. If a member dies, their account and settings remain as they left them until a family member or representative contacts us.
Any person with a legitimate familial relationship to a deceased depicted person may request review, changes, removal, or a change of steward by contacting privacy@photosgraph.com, whether or not they hold an account. That route overrides a steward's choices. This is a limited exception to our standard consent model, documented here for transparency. See our Terms of Use (Section 4g) for full details.
Revocation and deletion:
When a tagged person revokes their tag, the photo is immediately removed from every album it appears in. The photo file is retained in the uploader's private storage as part of the uploader's account content, accessible only to the uploader and other tagged individuals. This retention is based on the uploader's legitimate interest in maintaining their own photo collection. Any tagged person may request full deletion of the photo file by contacting privacy@photosgraph.com, which we will process within 10 business days.
9. Data Processing of Depicted Non-Users
Photosgraph processes photographic images that may contain the personal data of individuals who are not registered users of the Service ("depicted persons"). Uploaders are required to identify depicted non-users by name through the Photosgraph system.
When a non-user is named in an album photo, they receive an invitation that references the album and the number of photos waiting for them. Registering through that invitation is how they accept it, so they join the album at that point and can see all photos of themselves immediately. They may then remove any photo they don't want there, or leave the album entirely.
When we contact a non-user by email (at the uploader's direction), the invitation will include: a link to this Privacy Policy, the name of the person who tagged them, the name of the group album, the number of photos in which they appear, and instructions for requesting removal without creating an account.
What data we process: Photographic images in which a depicted person may be identifiable, along with the name (and optionally email address) provided by the uploader.
Lawful basis (GDPR): Legitimate interest of the uploader and the platform in facilitating consent-based photo sharing (Article 6(1)(f)). We balance this against the depicted person's rights by:
— Requiring uploaders to tag or name all reasonably identifiable persons
— Limiting visibility of every photo to the members of the album it is in
— Never displaying photos outside their album, to non-members, or to search engines
— Providing album context in invitations so non-users understand how their photos are being shared
— Providing a reporting mechanism accessible to non-users
— Removing content promptly upon valid takedown request
Your rights as a depicted non-user: If you believe you are identifiable in a photo on Photosgraph, you have the right to:
— Request confirmation of whether your personal data is being processed
— Request removal of any photo in which you are identifiable
— Object to the processing of your image
— Lodge a complaint with your local data protection authority
Family members of deceased depicted persons: If you are a family member of a deceased person who is identifiable in a photo on Photosgraph, you may request review, changes to visibility, or removal of photos depicting your family member. You may also ask who is recorded as their steward, and ask for that to be changed. We may request documentation of the familial relationship before acting on such requests. You do not need a Photosgraph account to make one.
To exercise these rights, contact privacy@photosgraph.com. You do not need a Photosgraph account. We will act on verified requests within 10 business days, or within 24 hours for reports involving minors.
10. Data Retention
We retain data for the following periods:
Account information: Retained until you delete your account.
Group album photos: Photos in group albums are retained until removed by the uploader, a tagged member, or until the album is archived. Photos removed from a group album remain in the uploader's personal account unless separately deleted.
Unsorted photos: Photos that have not been added to any album are visible only to the uploader and are retained until added to an album, deleted, or the account is deleted.
Account deletion: Upon account deletion, all uploaded photos are removed, all tags are revoked, albums you organized are transferred to the next member, and personal data is deleted within 30 days. Backup copies are purged within 90 days.
When a member dies: Photosgraph does not currently memorialize accounts or offer legacy contacts. An account and its settings remain as the member left them, including their existing photo tags and approvals. A verified family member may request that the account be deleted, or that specific photos be reviewed, changed or removed, by contacting privacy@photosgraph.com.
People recorded as having died: Where a person who has died was recorded by a member rather than holding an account of their own, their record is looked after by a steward, and a verified family member may request review, changes, removal, or a change of steward. See Deceased persons above.
Server logs: Retained for 90 days, then deleted.
Takedown request records: Retained for 3 years for legal compliance purposes.
11. Security
We use industry-standard measures to protect your information, including secure password hashing, encrypted connections (TLS), and access controls. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11a. Third-Party Services
We use a limited number of third-party services to operate Photosgraph:
— Hosting provider — server infrastructure (processes all data stored on the Service)
— SendGrid (Twilio) — transactional email delivery (processes email addresses and message content for notifications and invitations)
— OpenRouter — AI advisory features for platform administration only (does not process user photos or personal data)
Each provider is bound by a data processing agreement. We do not use third-party analytics, advertising networks, social media trackers, or any service that profiles our users. An up-to-date list of sub-processors is available upon request at privacy@photosgraph.com.
12. Children's Privacy
Photosgraph is not intended for children under 16 years of age, and we do not knowingly collect personal information from them. At registration, everyone must affirm that they are 16 or older; we record that affirmation, with the date and the exact wording shown. We do not verify anyone's age, and we do not want you to read more into that affirmation than it is. If we learn that a member is under 16, we will close their account and delete their data promptly.
Photos of children in albums: Photos depicting children may appear within private albums where the uploader reasonably believes that the parents or guardians of those children would expect the photos to be shared among that album's members — a family reunion, a school event, a birthday party.
What is recorded when a child is marked in a photo: An uploader marks the child so that the album can record that everyone in the photo is accounted for. What is stored is the word “Minor” and nothing else — no name, no email address, no date, no invitation, no tag, no profile. Any name typed into the form is discarded before the record is written, and this is enforced when the record is created rather than in the interface, so it holds however the request arrives. The entry is a headcount marker, not a person.
Photos containing a child are never public. This is a rule rather than a setting: it is applied every time a photo's visibility is recalculated, and no member's approval can override it. Such a photo stays visible only to the members of its album.
No biometric data of children: Because children are never tagged, Photosgraph does not create, store, or process any biometric identifier, facial recognition template, or persistent identity record for any child. The marker carries no name and no linkage across photos, albums or sessions — two markers in two photos have nothing connecting them, including in our own data.
Removing one: Any member of the album who can tag can remove the marker or the photo. Because the marker deliberately holds no identity, we cannot search for photos of a particular child; a parent asking us to act will need to point to the album or the photo. We recommend that at least one parent or guardian of any depicted child be a member of the album, which is the most reliable way for them to see and manage what their child appears in.
Photos taken when a person was under 16 may be uploaded and tagged normally if that person is currently 16 or older.
We do not use age estimation, facial analysis, or any automated method to determine the age of anyone depicted in a photo. We rely on the affirmation and the Community Commitments agreed to at registration (Section 4a of the Terms of Service), and on reports. A report that a photo depicts a child hides that photo automatically, before anyone at Photosgraph has looked at it. If you believe a photo of a child on Photosgraph is being shared inappropriately, report it in the app or to privacy@photosgraph.com and we will act within 24 hours.
13. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes — particularly those affecting how we collect, use, or share your data — we will notify users via email at least 30 days before the changes take effect. For non-material changes, we will post the updated policy with a revised effective date.
For material changes affecting data already collected, we may seek your affirmative consent before applying the new terms to your existing data.
14. Contact
If you have questions about this Privacy Policy, wish to exercise your data rights, or need to report a concern:
Photosgraph PBC
155 Woodland Avenue, Lexington, KY 40502
privacy@photosgraph.com
For DMCA and copyright matters: dmca@photosgraph.com
For general inquiries: legal@photosgraph.com