If you own an album
We store the email address you signed up with, and a hash of your password made with Argon2id. The password itself is never stored and cannot be recovered from the hash.
We also store the albums you own, their settings, and the sessions you currently have open.
If you added a memory to an album you do not own
You need no account, and we do not create one for you behind your back.
What we keep is the file you upload and the name you type on the form, if you type one. Nothing else about you is recorded alongside the memory.
Photographs, and what is hidden inside them
A photograph carries metadata you cannot see: the camera, the moment, and very often the exact coordinates where it was taken.
Every copy this service shows anyone is re-encoded from scratch, and the copy you save carries what your file carried: the camera and its lens, the moment the shutter opened, the coordinates if your photograph had them. It is copied across whole rather than rebuilt tag by tag, so whatever can be read in your original can be read in the copy. Where your file carried nothing at all, the copy still carries the memory's own location, written from scratch. The one thing we change is the line that says which way up the picture is, because we have already turned it.
The small tiles an album page loads are the exception: nobody is ever handed one as a file, so all a tile carries is the location, and only if the memory has one.
Where a photograph was taken is also part of the memory rather than only a detail of the file, so it is stored alongside the caption and shown as a place name. If you would rather a photograph did not carry any of this, the place to decide is before you upload it. Your phone can leave the location out, and once a photograph is in an album the only way to remove what it carries is to delete the memory.
The file you sent is kept as you sent it, metadata and all, in private storage. It is never served to a visitor: every photograph anybody browsing an album sees is one of the re-encoded copies. Two doors hand back the file itself: an owner downloading one original, and an owner or an administrator exporting the whole album. Both of them need the album to be on the full-quality plan. It is kept for those, and so that a memory can be re-processed later without asking you for it again.
Video is different, and we would rather say so
Video stays with this service. The file is uploaded to the same private storage the photographs use, nothing transcodes it, and playing it back is a short-lived signed link to the file exactly as it arrived.
That has one consequence worth stating plainly: what another person watches is the file you uploaded, not a copy made from it. We do not strip metadata from video, and unlike a photograph there is no re-encoding step here that would drop it even by accident. If that matters to you, the place to decide is before you upload.
Taps
When an NFC tag is used to open an album, we record that the tag was opened and when.
The table that records it has no column for a network address, no column for a browser, and no column for a person. There is nothing in it that could identify who did it, because there is nowhere to put such a thing.
It exists so that an owner can work out which of their unlabelled tags is the one they have mislaid.
What we know about a purchase
Apple processes the payment. We never receive a card number, a billing address, or anything else about how you paid: none of it reaches this service, and there is no column anywhere in our database to put it in.
What we store is Apple's receipt and the identifiers in it: the transaction id, the original transaction id that stays the same across a subscription's renewals, which product was bought, the album's own identifier that the receipt echoes back, whether the purchase was made in Apple's test environment or for real, and when it happened. A refund adds the date it was refunded and the reason Apple gave for it.
Those are kept against your account and against the album they paid for, so that an album can explain why it exists here and so that a refund can be matched to the album it was for.
The signed receipt itself is stored beside them, exactly as Apple issued it, so that a dispute can be checked against what Apple actually said rather than against our summary of it. Whatever else Apple chose to put inside that receipt is therefore kept as well.
This record outlives the album. If the album is deleted and later erased, the row explaining its payment stays behind, carrying the album's old identifier. A payment history with holes in it is not a payment history, and money that moved has to remain accountable.
Cookies
Signing in sets one cookie that keeps you signed in for 30 days. Unlocking a password-protected album sets one that lasts 12 hours, so you are not asked again on every photograph.
The web app also remembers, for a year, which layout and which sort order you chose for your library, so it looks the way you left it.
None of them are analytics cookies, because there are no analytics.
No analytics, no advertising, no trackers
There is no analytics script, no advertising pixel and no third-party tracker anywhere in this application. Not switched off. Absent.
Nothing you do here is reported to anybody else.
The records that abuse control needs
To stop somebody creating a thousand accounts or guessing their way into yours, the service counts requests against the network address they arrive from, in hourly buckets. For sign-in attempts the bucket is keyed to that address together with the email address that was typed.
Those rows are deleted after 25 hours by a job that runs every hour. Nothing about them is kept beyond that.
The server also writes an ordinary request log, which includes the network address of each request. It is rotated and capped: it is a rolling window of recent traffic, not an archive, and old entries are discarded as new ones arrive.
Backups
Backups of this service's database are kept for 7 days and then age out.
That matters more than it sounds. Deleting a row does not delete it from a backup, so this window is the real deadline by which deleted data has genuinely gone from every copy we hold.
Deleting, and erasing
Deletion here happens in two stages. Something you delete is marked deleted and disappears from view immediately; a purge job removes it permanently once its window has passed. For an album that window is 30 days, and you can restore it at any point before the end of it.
Clearing an author's name from a memory is a separate operation from deleting the memory, deliberately: when somebody leaves and the photographs they left are the ones everybody else treasures, removing the name while keeping the memory is very likely the right answer.
Deleting your whole account is the stronger of the two, and you do it yourself in the app, or on the web from your profile page, where the last panel is Delete my account. You do not have to write to anybody. It deletes the albums you own and everything in them, including memories other people added to them. The memories, comments and reactions you left in other people's albums go with it.
An album with more than one owner is the exception, and it survives: somebody else owns it too, and their copy of those photographs is theirs. What leaves that album is you.
Children
An account is for people aged 16 or over. That is a term of use, not a check: there is no age verification anywhere in this service, nothing here establishes anybody's age, and we are not claiming otherwise.
Article 8 of the GDPR sets an age below which a child cannot consent on their own behalf. The minimum above is how we address it, and it is stated rather than enforced. An album of a family's photographs will of course contain children, which is a different thing from a child holding an account.
If you believe an account belongs to somebody under 16, write to us and we will close it.
Asking us anything
Write to info@nfc.cool. That is the address for anything about your own data: what we hold, correcting it, or erasing it. It is also the address for anything you think should not be in this service.
The person answering is Nicolo Stanciu, at Rua Carminé Nobre 6, 3040-193 Coimbra, Portugal.