Privacy Policy
Photolio ("Photolio", "we", "us") is a photo-first contacts app operated by Jun Wang. This policy explains what information the app collects, how we use it, and the choices you have. By using Photolio you agree to this policy.
The short version
- We collect only what the app needs to store and sync your contacts.
- We do not sell your data.
- We do not show ads, use third-party advertising SDKs, or track you across other apps.
- You can use the app as a guest, with your data kept only on your device.
- An account owner may separately opt an approved Public identity into an anonymous Web Profile that anyone can view without signing in.
- Optional Pro subscriptions increase identity and photo limits; they are billed by Apple and managed through RevenueCat, and we never receive your payment-card details.
- You can permanently delete your account and data from within the app at any time.
Information we collect
The information we process depends on whether you create an account.
- Account information (only if you sign up): your email address, an encrypted password, and a display name. If you sign in with Apple or Google, we receive a basic identifier and the name/email you authorize that provider to share.
- Content you create: profile photos and group photos you add, names, descriptions, photo tags/regions, nicknames, and the contact details you enter (such as phone numbers, email addresses, and social handles), and the groups you create.
- Identifiers: a user account ID and profile IDs used to store and sync your data. If you claim a Public Profile Username, we also process that Username and a versioned, keyed one-way fingerprint used to enforce permanent non-reuse.
- Social interactions: Follow requests, relationship status, and related in-app notifications, including the profile identifiers, display names, and timestamps needed to provide these features.
- Public-directory searches: when you search the public directory, we process the search text to return matching public profiles and apply an account-scoped short-window rate limit. Photolio does not keep a product-level history of the searches you submit.
- Subscription information (only if you buy Pro): your subscription status, the plan you chose, and its renewal or expiry date. Purchases are made through Apple's App Store and recorded by our billing provider, RevenueCat — we never receive or store your payment-card details.
- Device permissions: with your permission, the app uses your camera (to take photos and scan QR codes you choose to scan) and your photo library (to pick photos you choose to add). The app does not read your device's system contacts.
- On-device logs: the app keeps diagnostic logs in local storage on your device (retained about 7 days) to help troubleshoot problems. In this version these logs are not transmitted off your device.
- Aggregate safety diagnostics (signed-in use only): the app sends a fixed success/failure category and bounded duration for safety-critical operations such as access revocation, local cache sanitation, and runtime safety-configuration refresh. The server also counts fixed outcomes for Block/Unblock and share-link resolution. These records are stored only as hourly aggregates and do not contain or retain an account/profile/report identifier, name, report text, operator note, photo path, snapshot, or raw error message. A separate account-scoped counter limits diagnostic submission abuse; it does not contain content and is deleted with the account.
- Anonymous Public Profile diagnostics: the public profile and approved-avatar endpoints count only fixed outcomes such as success, not found, rate limited, disabled, or error, plus bounded duration. These are stored as hourly aggregates without a Username, IP address, account or Profile ID, Storage path, content, or raw error message. Short-window abuse controls use keyed buckets rather than retaining the raw IP address or Username in safety telemetry.
- Safety reports: if you report a profile, we collect the reporting and reported profile identifiers, the reason you select, any optional details you provide, the submission time, and a snapshot of the reported profile as it appeared when submitted. The reported account does not receive your report or its details.
- Publication review records: when an identity may be shared outside your account, we process an immutable snapshot of that identity, review status, decision reason, and decision time. This lets us prevent unreviewed or rejected changes from being shown to others.
How we use information
- To create and secure your account and sign you in.
- To store your contacts, photos, and identities and sync them across the devices you sign in to.
- To process optional Pro subscriptions and apply the higher identity and photo limits included with Pro.
- To deliver the information you choose to share when you generate a QR code or share link.
- To process Follow requests and relationships and deliver related in-app notifications.
- To let signed-in users find reviewed public profiles by approved name, subtitle, public tags, or eligible social and website handles.
- To provide an anonymous Public Profile when its owner has claimed a Username, made the identity Public, received publication approval, and independently enabled anonymous access.
- To operate, maintain, and troubleshoot the app.
- To investigate reports, review externally shared identities, enforce our Terms, prevent abuse, and protect users and the service.
Safety review and operator access
Safety reports and externally shared identity revisions may be reviewed manually by authorized Photolio operators. Operators may access the report details, captured profile snapshot, relevant photo previews, and account identifiers needed to investigate and act on the case. Operator decisions and access-related actions are recorded in restricted audit records. This information is not exposed to other app users or sent to general analytics.
Photolio currently does not send report text, reported profile snapshots, or publication-review content to an external moderation provider. Review is performed using Photolio's own restricted operator tools. Our infrastructure provider, Supabase, stores and processes this data on our behalf as described below.
How we store and process information
When you create an account, your data is stored and processed using Supabase (authentication, database, and file storage), our cloud infrastructure provider, on our behalf. Data is transmitted over encrypted connections (HTTPS/TLS) and protected by row-level access controls so that, in general, only you can access your own data.
If you choose Sign in with Apple or Google Sign-In, that provider processes the sign-in request under its own privacy terms. Photolio receives the account identifier and the name or email you authorize it to share. Google Sign-In may also process device, coarse-location, and usage information to provide, secure, and measure its sign-in service; Photolio does not receive those additional fields. See Apple's Privacy Policy and Google's Privacy Policy.
Anonymous Public Profile pages are delivered through Cloudflare. Cloudflare processes the web request as our hosting and security provider, while the approved profile projection and approved thumbnail are fetched through controlled Photolio endpoints. Photolio does not make the underlying photo Storage bucket public or expose private Storage paths or signed URLs on these pages.
If you use the app as a guest (without signing in), your data stays on your device and is not uploaded to our servers.
If you buy a subscription, your purchase is handled by Apple (the App Store) and recorded through RevenueCat, our subscription-management provider, which verifies your entitlement and keeps your subscription status in sync. We share an account identifier and subscription events (such as purchases, renewals, and expirations) with RevenueCat for this purpose; we do not receive your payment-card details. See RevenueCat's privacy policy at revenuecat.com/privacy.
Sharing your information
We do not sell your personal information. We share information only:
- At your direction — when you share your identity card via a QR code or link, the recipient receives the information you chose to include on that card. When you send a Follow request, the target receives the profile identity needed to review it.
- Through the public directory — if you set an identity to Public, its last approved profile card may appear to signed-in users in Global Search. Matching can use its approved name, subtitle and public tags, plus normalized social or website handles from our searchable allowlist. Phone numbers and email addresses are never used for Global Search matching.
-
Through an anonymous Public Profile — if you
separately enable anonymous access for an eligible Public identity,
anyone with its stable
/p/usernameURL may view the claimed Username, last approved display name and subtitle, whether it is a person or group, group member count, and approved profile thumbnail or fallback. The page also displays a QR code and links for opening or installing Photolio. Handles, tags, lists, follower counts, galleries, original photos, photo regions, and internal IDs are not included in this anonymous projection. - With service providers — such as Supabase, which hosts and processes data on our behalf; Cloudflare, which delivers the Web Profile and protects web requests; Apple or Google when you choose their sign-in service; and, for subscriptions, Apple (payment processing) and RevenueCat (subscription management), each under their own terms and security obligations.
- For legal reasons — if required by law or to protect rights, safety, and security.
Public Profile choices and limits
Anonymous access is a separate owner choice and is off by default. You can turn it off at any time in that identity's Public Profile settings; changing the identity to Followers only or Private, a safety takedown, Profile deletion, or account deletion also prevents new anonymous page and avatar responses. Turning anonymous access off does not release or change the Username.
A claimed Username is permanent: it cannot be edited, transferred, released, or reused by another account, including after the Profile or account is deleted. A signed-in Block applies to interactions and signed-in access checks, but it cannot identify or prevent an anonymous person from opening a page that you chose to make available without login. Disable anonymous access or change Visibility when you need to stop new anonymous access.
Photolio applies no-store and noindex controls and stops serving a page after it becomes ineligible, but recipients, browsers, link-preview services, search tools, or other third parties may take screenshots or retain copies outside Photolio. We cannot recall those external copies.
Data retention and deletion
We keep your account data for as long as your account exists. You can
permanently delete your account at any time in the app at
Settings → Account → Delete Account. Deletion removes your
profiles, photos, contact details, and account identity from our servers.
The clear Username-to-Profile mapping is deleted, but the versioned,
keyed one-way Username fingerprint remains without an account or Profile
link solely to prevent the permanently reserved Username from being
claimed again. This action is irreversible. Guest-created app data can
be removed by deleting the app from your device.
Safety reports, their private operator cases, and related captured evidence are deleted when either the reporting account or the reported account is deleted. Publication-review records are deleted with the associated profile. After account deletion, only non-linkable hourly aggregate counters may remain; they contain no account/profile/report identifier, content, path, snapshot, operator note, or raw error and cannot be used to reconstruct the deleted account's activity.
If you subscribe and later let your subscription lapse, your account returns to the free identity and photo limits. We keep your cloud-stored photos for 90 days so you can resubscribe or retrieve them, after which they are deleted from our cloud storage. Your contact details and other text information remain available and continue to sync within the free tier. At any time you can save your photos onto your device or export a complete copy of your data (see “Your rights”).
Your rights
Depending on where you live, you may have rights to access, correct, or
delete your personal information, or to object to or restrict certain
processing. You can exercise the core of these rights directly in the app
(editing your content and deleting your account), or by contacting us at
the address below. You can also export a complete copy of your data at any
time from Settings → Your Data → Export my data, and download
your cloud photos onto your device.
Children's privacy
Photolio is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us and we will delete it.
Security
We use encryption in transit and access controls to protect your information. No method of transmission or storage is completely secure, but we work to protect your data and to limit access to it.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice.
Governing law
This policy is governed by the laws of Singapore, without regard to conflict-of-law principles.
Contact us
Questions about this policy or your data? Email us at [email protected].