Your photos, your privacy
How your data is handled โ no legalese, just the facts
Last updated: August 31, 2026
Information Collected
When you use Knipsmig, the following information is collected to provide the service:
- Your name, email, and profile picture when you sign in with Google or Apple
- Event names, descriptions, and dates you create
- Photos and media uploaded by you and event guests
- Event access information, including who has viewed or contributed to events
- Basic usage analytics to improve the service
How Your Information is Used
The information collected is used to:
- Authenticate you securely using Google or Apple OAuth
- Provide the photo sharing service for your events
- Store and organize photos uploaded by guests
- Display contributor information (name) alongside uploaded photos
- Enable real-time photo updates through WebSocket connections
- Improve the service and develop new features
- Ensure the security and proper functioning of the platform
Google user data
When you sign in with Google, Knipsmig accesses your Google account identifier, name, email address, profile picture, and locale. This information is used to create and secure your Knipsmig account, identify you in the service, and communicate with you about the service.
If you separately enable Google Drive or Google Photos sync, Knipsmig stores encrypted OAuth access and refresh tokens and uses the limited permissions you grant to create a Knipsmig folder or album and upload your selected event photos and videos. These permissions do not give Knipsmig access to unrelated files in your Google Drive or unrelated items in your Google Photos library.
When Google user data is disclosed
Knipsmig does not sell, rent, or use Google user data for advertising. Google user data is shared, transferred, or disclosed only in these limited circumstances:
- To service providers that process data on Knipsmig's behalf to host and store the service, deliver transactional email, process a purchase, or fulfill a print order, and only as needed to provide those services
- To Google when it is necessary to sign you in or when you direct Knipsmig to copy selected event media to Google Drive or Google Photos
- To people who can access an event, when your display name is shown beside media you contribute; your email address and Google profile details are not displayed to them
- To authorities or other parties when required by law, needed to protect users and the service, or as part of a merger, acquisition, or sale of the business subject to this Privacy Policy
Google user data is not provided to data brokers, used for targeted advertising, or used to train generalized artificial intelligence or machine-learning models.
Google OAuth tokens are protected with encryption at rest and in transit and are retained while your Google connection or Knipsmig account remains active. You can stop event sync in Knipsmig, revoke Knipsmig's access in your Google Account, or delete your Knipsmig account. Account deletion removes the Google profile data and tokens held by Knipsmig, subject to limited legal, security, and backup retention. Media already copied to your Google account remains under your control there.
Data Security
Your photos and data security is taken seriously. All uploads are encrypted in transit using HTTPS and stored securely. Photos are processed and stored using industry-standard cloud storage solutions.
Event photos are accessible to anyone with the event's unique link or QR code. It's recommended to only share event links with people you trust. Event organizers have full control and can delete events and their associated photos at any time.
EU data storage & GDPR
Knipsmig's application data and media storage are located within the European Union: servers and database in Germany, and photos and videos in the Netherlands, Germany and Ireland. This means that data benefits from strong EU data protection laws, including the General Data Protection Regulation (GDPR). A few processing steps involve providers outside the EU under standard contractual clauses or the EU-US Data Privacy Framework: automated captioning and tagging of uploaded images (OpenAI, which event owners can turn off per event), transactional email (Resend), content delivery (Cloudflare), and, only when you choose them, Google sync, payment, and print fulfillment. The full list is in the data processing agreement.
- Data stored in EU data centers with strict privacy regulations
- Protected by GDPR - one of the world's strongest data protection frameworks
- Right to erasure, data portability, and access are legally enforced
- Mandatory 72-hour breach notification requirement
Running a company event? See how Knipsmig fits your privacy notice on the GDPR-compliant event photo sharing page, and read the data processing agreement that applies when your organisation is the data controller.
Data Retention
Event data and photos are retained until you choose to delete them. You have full control over your events and can delete them at any time through your account.
Contact
If you have any questions about this Privacy Policy, please reach out through the contact page.