Privacy
Data controller
Mathis Royer, individual entrepreneur trading as PicPeers, 1 rue du Moustoir, 56450 Theix-Noyalo, France, is responsible for processing needed to operate the service. Data protection contact: support@picpeers.com.
Data we use
For organizers: email address, account identifier, nickname, language, projects and photos. For guests: a random identifier stored on their device, votes, uploaded photos and an optional nickname. Original photos may contain metadata from your phone.
Legal bases and choices
Accounts, projects, votes and uploads are processed to provide the requested service. Abuse prevention, security and support rely on the publisher’s legitimate interests. An email address and nickname are required to organize a project; guests do not need to provide an email and their nickname is optional. Without the necessary data, the requested feature cannot operate. Marketing emails and advertising trackers are disabled.
Purpose
Data is used to sign you in, display projects, record votes and uploads, prevent abuse and handle support requests. Notifications relate to service operation, not marketing campaigns. Network addresses are hashed for abuse prevention.
Photo access
Files are stored privately. Guests receive previews through temporary links; originals are restricted to the project owner. Previews stay hidden until scheduled reveal when configured. A previously shared temporary link may remain usable until it expires.
Providers
Supabase manages authentication and the database in Europe; Cloudflare stores R2 files in the EU jurisdiction, routes support email and uses Turnstile to verify the browser during sign-in (IP address and technical security data); Resend delivers transactional emails. Support messages are received in a Gmail mailbox. Google is involved if you choose Google sign-in. Sentry receives filtered JavaScript diagnostics in its EU region (error type, code position and app version). Detailed messages, identities, photos, private links and session recordings are excluded; server scrubbing masks IP addresses and location fields. GitHub Actions runs backups: data and photos are temporarily processed on its runners, then encrypted archives are stored in R2 in Europe. Providers may process technical data outside the EU under their contractual safeguards. PostHog analytics are disabled by default.
Retention and removal
Photos and projects are retained for 90 days after first opening, or 90 days after creation for unpublished drafts. Deletion queues handle removal after expiration or a request. Account deletion blocks access during cleanup. Encrypted database backups are retained for seven days. Encrypted photo copies stop being refreshed after removal and expire after seven days, subject to the storage provider’s processing delay. After restoration, erasure requests received since the snapshot must be reapplied before reopening the service. Filtered Sentry error diagnostics are retained for up to 90 days; API and database logs accessible under our Supabase Free plan cover up to one day. Organizer accounts are kept until deletion.
Device storage and recipients
The app stores session information, the guest identifier and language on your device to support sign-in and voting. Projects are visible to people authorized through their links and rules; organizers and their moderators access the data needed to manage them. European hosting does not mean every provider operation takes place exclusively in the EU: provider support, Google and Gmail may involve international transfers covered by their data protection commitments.
Your requests
To request access, correction, erasure, portability, restriction or objection where applicable, email support@picpeers.com with the project and photo details. Never send login codes, passwords or PINs. You can also contact the relevant data protection authority, including the CNIL in France.