CAPTHIS.APP
Privacy Policy
This Privacy Policy explains which data CapThis processes when the app, the admin area, and the galleries are used. CapThis is an event camera: guests join an event by QR code, take photos, and upload them to an event-specific gallery.
1. Controller and contact
- The controller is the operator of the CapThis app and capthis.app.
- Contact for privacy and support requests: support@capthis.app
- When CapThis is used for a specific event, the respective organizer may also decide on purposes such as release, moderation, or deletion of event photos.
2. Purpose of the service
- CapThis is used to create and manage shared event galleries.
- Guests join an event via QR code or deep link.
- Photos are assigned to the respective event, the entered name, and the app installation.
- Organizers can view, release, hide, delete photos, and manage QR access codes.
- Guests can report photos and request removal; reported photos are hidden temporarily and reviewed.
3. Data processed from guests
- Display name entered by the guest after scanning a QR code.
- Device ID of the app installation, platform, operating system version, device model, and app version.
- Event token or access token and derived permissions.
- Push token, push platform, and push environment if notifications are used.
- Captured or uploaded photos, thumbnails, and technical metadata such as file size, content type, upload time, and, if provided, capture time.
- IP address during uploads and web access where required for operation, security, and abuse prevention.
- Emoji reactions in the guest gallery if this feature is enabled for the event.
4. Data processed from organizers and admins
- Event data such as name, date, location, event type, start time, and end time.
- QR access codes, permissions, limits, camera settings, branding, and gallery settings.
- Admin session data and CSRF protection data for secure operation of the admin area.
- Scheduled push notifications with title, body, time, status, and delivery statistics.
- Moderation decisions such as photo visibility or deletion.
5. How data is used
- Pair an app installation with an event.
- Upload, store, display, release, hide, and delete event photos.
- Enforce event-wide limits, device limits, QR permissions, and device blocks.
- Support offline usage, retry pending uploads, and show the most recently used event.
- Provide the guest gallery, organizer gallery, web upload, and admin area.
- Deliver scheduled push notifications and local reminders.
- Maintain operational security, diagnose errors, and protect against abuse, spam, and excessive server load.
6. Legal bases
- Processing may be necessary to perform a user or event-related agreement, especially for uploads, galleries, and administration.
- Some features such as notifications or access to camera/photo library require permission on the device.
- Operational, security, and abuse-prevention processing may be based on legitimate interests in a secure and reliable service.
- Legal retention or documentation obligations may require longer storage of some data.
7. Local storage in the app
- The app stores the current event token, the most recently used event, participant name, cached event data, and pending uploads.
- Sensitive values are stored using the iOS Keychain or Android Keystore.
- Pending photos may be cached locally in the app support directory until connectivity is restored.
- On Android, app backups are disabled and cleartext traffic is not allowed.
8. Recipients and external services
- Photos and event data are transmitted to and stored by the CapThis backend for the respective event.
- Apple Push Notification service (APNs) is used for iOS push notifications.
- Firebase Cloud Messaging (FCM) is used for Android push notifications.
- Push notifications contain title, body, deep-link route, and an internal notification ID, but no photos.
- CapThis does not sell data and does not integrate advertising networks.
9. Services not used
- CapThis currently does not use Firebase Analytics.
- CapThis currently does not use Google Analytics.
- CapThis currently does not use Firebase Crashlytics.
- CapThis currently does not use Sentry.
- CapThis currently does not use advertising or tracking SDKs.
- CapThis currently does not use automatic AI image moderation. Photos are not sent to AI services for automatic content review.
10. Storage periods and deletion
- Photos remain stored until they are deleted by organizers, authorized moderators, or admins, or until the event is deleted.
- Each event can have an automatic deletion period; after that period photos, thumbnails, device data, and push data are removed or anonymized.
- Reported photos are hidden immediately and remain hidden until the report is reviewed.
- When an event is deleted, related photos, tokens, and links are removed; old public links only show a generic not-found page.
- Device and access data remain stored while needed for the event, limits, blocks, push delivery, or abuse prevention.
- Invalid push tokens are removed automatically when APNs or FCM report corresponding errors.
- Locally stored app data can be deleted by leaving the event, removing the app, or resetting app data.
11. Security
- The app accepts HTTPS API base URLs only.
- Event and access tokens are sent to the API as Authorization Bearer headers, not as API URL parameters.
- Admin actions are protected by sessions and CSRF protection.
- Gallery, organizer, and QR access links use non-guessable tokens.
- Uploads are validated, limited, and protected against duplicate uploads on the server.
- Private and semi-private areas are marked with noindex/nofollow.
12. Data subject rights
- Data subjects may request access, correction, deletion, restriction of processing, and data portability where the legal requirements are met.
- Photos can be sent for review through the reporting function if a person does not want to appear in the image.
- Permissions such as notification consent can be withdrawn in the device system settings.
- For event-specific deletion or hiding requests, the respective organizer may also be contacted.
- Requests can be sent to support@capthis.app.
13. Changes to this policy
- This Privacy Policy will be updated when features, external services, or data processing activities change.
- In particular, future automatic content moderation or additional external services will require an update to this policy.
Last updated: 2026-07-07. This technical privacy policy is not legal advice and should be reviewed legally before publication.