Privacy Policy — Znap
How Znap handles photos, accounts, and event data for creators and guests.
- Email address and password (via Supabase Auth)
- Optional full name
- Camera event settings and metadata
- Display name chosen by the guest
- Optional email (only for reveal notifications)
- Photos you capture or upload for an event (stored for up to 15 days after reveal)
- Timestamps/EXIF where available, file size and technical metadata
- Apple crash logs only (no third‑party analytics SDKs)
We use data only to provide and operate Znap, including:
- Creating and managing camera events
- Uploading, storing, and revealing event photos to the event creator and participants
- Sending reveal notifications if you opt‑in with an email
- Keeping the service secure and stable
- Contract: to provide the app and event features you use.
- Legitimate interests: to prevent abuse, secure the service, and understand basic product usage.
- Consent: for optional email notifications and where local law requires consent.
We use trusted processors to run Znap, for example:
- Supabase for authentication, database, and storage
- Apple / App Store infrastructure for app distribution and crash logs
We do not sell your data. We only share data where needed to run the service, comply with law, or protect rights and safety.
- Events/galleries: auto‑deleted 15 days after reveal.
- Creator deletes an event: we delete all photos and metadata in that event immediately.
- Account deletion: removes your account and personal data. If your events have active participants, galleries remain available to them until the 15‑day window ends, then are purged.
- Crash logs: retained per Apple policies.
You may request access, correction, deletion, portability, restriction, or object to processing. Contact support@znapcam.com. You can also complain to your local Data Protection Authority.
The service is not for under‑13s. Do not create accounts for children.
We use measures like private storage, Row‑Level Security, expiring signed URLs, TLS in transit, and restricted access to production systems to protect your data.
Primary processing occurs in the EU (Frankfurt). If we use other regions, we apply adequacy or appropriate safeguards (e.g., Standard Contractual Clauses).
We may update this policy. We will post changes here and update the “Last updated” date above.