Privacy Policy
What we hold, why we hold it, who can see it, and how to make it go away.
This is an old version, kept for the record.
It was in force from 12 September 2026 until 15 September 2026. Read the current Privacy Policy or see every version.
Last updated: 12 September 2026
The short version
The whole policy in nine lines. The detail below controls if the two ever disagree, but they shouldn’t.
- We collect what the app needs to work: your email, your name, and whatever you and your group put into it.
- No analytics, no tracking pixels, no advertising code. Not “we don’t use them for ads” — they’re not installed.
- We do not sell or share your information. Never have.
- We don’t train AI on your photos or messages, and nothing runs face recognition on them.
- Your photos get their location data stripped out in your browser, before they ever reach us.
- Your groups can’t see each other. Nobody can tell which other groups a photo or a person belongs to.
- Birthdays are day-and-month only unless you personally switch the year on.
- The only cookies we set are the ones that keep you logged in.
- Delete your account and your photos go with it, files and all. Section “Where deletion isn’t complete” tells you honestly where it stops short.
The rules that govern your use of Photo Fort live in the Terms of Use. This page is only about information.
Who we are
Photo Fort is operated by Photo Fort, LLC, a Florida limited liability company, of 7901 4th St N, St. Petersburg, FL 33702, United States. For the purposes of the EU and UK General Data Protection Regulation, Photo Fort, LLC is the controller of the information described here.
Write to us about anything on this page at privacy@myphotofort.com.
What we collect
Your account
Your email address, which is also how you log in — sign-in is passwordless, so we send a link or a code instead of storing a password. Your first and last name. Optionally a phone number and a date of birth. Your email preferences, and a random token that lets an unsubscribe link work without logging in.
Whether an account is suspended, and the limit on how many groups it can create, are set by us rather than by you. Authentication itself runs through Supabase Auth, which holds your email and session records separately from your profile.
What you and your group create
Photos and the thumbnails made from them. Captions — the same photo can carry different captions in different groups. Chat messages, and who you tagged in them. Calendar events. Annual dates: labelled birthdays and anniversaries with a month and day and, optionally, a year. Group names and pinned notes. Reactions. And any report you submit about content that breaks the rules, which includes a snapshot of the content complained of.
Annual dates belong to the group, and any member can add or edit one. They are frequently about people who don’t have accounts — see below.
Things the system records by itself
Timestamps on essentially everything, which together amount to a record of activity. When you last opened each group, so we can show you what’s new — visible only to you, because there are no read receipts. The size of each photo and the internal keys that locate the file. The time a photo was uploaded, which is not the time it was taken: we never read camera metadata.
Our hosting provider records standard technical information about requests, including IP addresses. That is the platform doing what every web host does; Photo Fort’s own code neither logs nor stores them.
When we take an operational action on an account or a group — acting on a report, for instance — we record who acted, what was affected, why, and when.
Payment
Paid groups are billed through Stripe. Card numbers never reach us. Checkout and the billing portal are Stripe’s own pages. We keep only an identifier linking your group to your Stripe records; Stripe holds your name, email and payment method.
What we deliberately don’t collect
These are design decisions, and we state them because they’re the kind of promise you should be able to hold us to.
No analytics, tracking pixels, session recording, fingerprinting or advertising software. There is no third-party measurement code anywhere in Photo Fort.
No camera or location data from your photos. EXIF, XMP and IPTC metadata — including GPS coordinates, camera serial numbers and original timestamps — are removed from JPEG photos in your browser, before the file is uploaded. The removal is lossless: the picture itself is untouched and its colour profile is preserved. We never receive that data, which means we cannot disclose it, be compelled to produce it, or lose it in a breach.
No biometrics. Nothing runs face detection, face recognition, or any other biometric identification on your photos. We build no face templates and no automatic “people” groupings.
No AI training. We do not use your photos, captions or messages to train machine-learning models, ours or anyone else’s, and we don’t hand them to a third party to do it.
No public profiles, discovery or search. A stranger cannot find you here. Groups are reachable by invitation only.
People who don’t have an account
This section matters, and most privacy policies skip it. Photo Fort inevitably holds information about people who never signed up and never agreed to anything: people in photographs, including children; people named in annual dates, sometimes with a birth year; people who’ve been invited but haven’t joined, whose email address sits in the roster as a pending invitation; and people quoted in a content report.
We hold it because a private group can’t work otherwise — a family album that can’t contain photographs of the family isn’t a product. Under the GDPR our basis is legitimate interests, ours and our members’, in running a closed, invitation-only space. We think that’s proportionate specifically because Photo Fort isn’t public: content is visible only to the small group it was shared into, isn’t indexed by search engines, isn’t used for advertising or profiling, and isn’t analysed to identify anyone.
We are relying on our members. If you upload a photograph of someone else, or record their date of birth, you are responsible for having their agreement where it’s needed — and for a child, a parent’s or guardian’s. Please don’t put other people into a group who wouldn’t want to be there.
If you are one of these people, write to privacy@myphotofort.com. You have the rights set out below even though you have no account. Because the content is private and we can’t see into a group to find you, we may need enough detail to locate it — the member likely to have uploaded it, for instance. Where we can’t verify a request without collecting more about you than we already hold, we’ll say so rather than expand our records.
We haven’t sent individual notices to these people because in most cases we have no way to contact them and no way to know they exist — the situation Article 14(5)(b) of the GDPR contemplates. This page is our public notice.
Why we use it, and on what legal basis
For members in the EEA and the UK, the GDPR requires us to name a lawful basis for each use. Everyone else may find the list a useful summary anyway.
To perform our contract with you (Art. 6(1)(b)): creating and running your account, signing you in, storing and displaying your content to your groups, showing a group roster, sending service email such as sign-in links and invitations, and taking payment for paid groups.
With your consent (Art. 6(1)(a)): showing your birth year or age to your groups. Off unless you turn it on, and you can turn it off again whenever you like.
For our legitimate interests (Art. 6(1)(f)): sending the weekly digest of your groups’ activity, which you can switch off; keeping the service secure; preventing abuse and investigating reports; and holding information about people who aren’t members, as described above.
Because the law requires it (Art. 6(1)(c)): keeping payment records for tax and accounting, responding to privacy requests, and complying with valid legal demands.
Where we rely on legitimate interests we have weighed them against your rights, and you can object at any time.
Sensitive information. Photo Fort isn’t designed for information revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, health, sex life or sexual orientation, and it isn’t for genetic or biometric data. We don’t analyse photos or messages to infer any of it. We do recognise that ordinary family photographs can reveal such things anyway — a photograph taken at a place of worship, or of someone in hospital. Where you upload that about yourself we rely on your explicit consent; where you upload it about someone else, you need theirs, and you shouldn’t upload it without.
No automated decisions. We don’t make decisions about you by automated means that have legal or similarly significant effects, and we don’t profile you.
Who sees it
The people in your groups
This is the point of the product, and it’s the biggest sharing we do. Inside a group you’ve joined, the other members can see your name and email address in the roster, your phone number if you gave one, and the day and month of your birthday if you gave one. They can see your photos and captions, your messages and reactions, and the events and dates you add. They can see your birth year or age only if you have turned that on.
They cannot see anything at all about your other groups. Group leaders can also see the email addresses of people who have been invited but haven’t joined yet.
The companies that run it for us
Each of these processes information only on our instructions, under a written data-processing agreement, and for no purposes of its own:
- Supabase — the database and authentication.
- Cloudflare — photo and thumbnail storage.
- Vercel — web hosting, including the server logs that contain IP addresses.
- Resend — email delivery: sign-in emails, invitations, digests.
We don’t add advertising, analytics or data-broker relationships to that list, and we’ll update this page before adding anyone who receives your information.
Stripe is different, and we want to be accurate about it. Stripe handles your name, email, payment method and billing records so we can take payment. For part of that it acts on our instructions — but for verifying identity, preventing fraud, and meeting anti-money-laundering and card network obligations, Stripe decides for itself what it needs to do and acts as an independent controller. We can’t instruct it otherwise and we don’t control what it keeps for those purposes. Stripe’s own privacy policy governs that, and a request about it should go to Stripe as well as, or instead of, to us.
Legal and safety
We may disclose information where the law requires it, or where we reasonably believe it necessary to investigate a violation of the Terms, to protect someone’s rights or safety, or to bring or defend a legal claim. Because Photo Fort holds photographs of children, we will report material we are legally obliged to report. We’ll tell you about a legal demand for your information unless we’re prohibited from doing so or think notice would create a risk of harm.
If the business changes hands
If Photo Fort is acquired or its assets sold, information may transfer with it. We’ll give you notice before your information becomes subject to a materially different privacy policy, and any buyer stays bound by this one until then.
We do not sell or share it
We do not sell personal information, and we do not share it for cross-context behavioural advertising, in the sense those terms carry under California law and its equivalents elsewhere. We haven’t in the past twelve months, including for anyone we know to be under 16. We don’t hand your information to third parties for their own marketing.
Because we don’t sell or share, an opt-out signal such as Global Privacy Control has nothing to act on — but we honour it, and we’ll keep honouring it if that ever changes.
Cookies
We set only strictly necessary cookies: the Supabase session cookies that keep you signed in. They expire after 30 days without use, at which point you sign in again. Your light/dark preference is kept in your browser’s local storage, which never reaches us.
No analytics cookies, no advertising cookies, no third-party cookies — which is why you haven’t been shown a cookie banner. Under EU and UK rules, cookies strictly necessary to deliver a service you asked for don’t need consent. If we ever introduce one that isn’t, we’ll ask you first. Blocking ours will sign you out and prevent sign-in.
Where your information is held
Our database is hosted in Canada. Photo files are stored with Cloudflare R2 in Eastern North America; we haven’t applied a jurisdictional restriction, so Cloudflare may serve copies from other locations to whoever is looking at them. Our hosting, payment and email providers operate principally from the United States. Your information is therefore processed outside your own country, and members in the EEA and the UK should understand it is processed outside the EEA and the UK.
Where we move information out of the EEA or the UK we rely on the European Commission’s adequacy decision for Canada, where the recipient falls within it; on the Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, which are built into our agreements with providers that don’t; and, where it applies, on a recipient’s certification under the EU-US Data Privacy Framework. Ask us at privacy@myphotofort.com and we will send you a copy of the safeguards we rely on.
How long we keep it
Your account information until you delete your account. Your photos, captions, messages and reactions until you or your group delete them, or you delete your account — a photo shared into several groups leaves storage when the last group releases it. Events and annual dates until a member deletes them or the group goes.
Some things we keep until something removes them, rather than on a timetable. We’d rather describe what actually happens than publish a schedule we don’t yet run:
- Unaccepted invitations stay until the invitation is accepted, the group cancels it, or the group is deleted.
- Content reports are kept indefinitely, on purpose. A report has to outlive the thing it describes — otherwise acting on one would erase the record that anything happened.
- Records of our own actions — an administrator removing content, or suspending an account — are kept indefinitely as an audit trail, so there is always an answer to “who did this, and why”.
- Server logs, including IP addresses, are held by our hosting provider under their own retention policy, not by us. We keep no separate copy, and they are used only to diagnose faults and abuse.
- Payment records are held by Stripe for as long as their obligations and tax law require. We store only the identifiers linking a group to its subscription — never card details.
We don’t currently run automatic deletion on a fixed schedule. If we add one, we’ll set the periods out here.
Deleted content can persist briefly in routine database backups until those are overwritten in the normal course. We don’t restore them to bring back deleted content.
Where deletion isn’t complete
Over-promising deletion is the commonest way a privacy policy becomes untrue, so here is exactly where ours stops short.
Content reports outlive the content. When someone reports a message or a caption, the report keeps a copy of the words and a record of who posted them. If it didn’t, resolving a report would destroy the evidence that anything happened and the same content could go straight back up with no record. Reported text can therefore survive deletion of the original, for the period above.
Records of our own actions are kept — who acted, on what, and why — after the action, for the period above.
Calendar events survive the person who made them. When an account goes, we cut the link between that person and the events they added rather than deleting the events, so a shared family calendar isn’t gutted when one person leaves. The event stays; the author doesn’t.
A photo in several groups persists until every group releases it. Removing it from one group removes it from that group only.
Anything we are legally required to preserve stays, whatever you do. If we report material to the National Center for Missing and Exploited Children as US law requires, we are obliged to preserve that content and the associated records for one year from the report, and we will. Deleting it, leaving the group or closing your account does not shorten that. The same goes for content covered by a court order, a subpoena or a preservation request, for as long as the demand stands.
What deletion does do: deleting your account removes your account information and your photos from every group, including the underlying files in storage. Leaving a group, or being removed from one, takes your photos and messages out of that group.
What you can do without asking us
Edit or remove your name, phone number and date of birth in Account settings. Turn sharing of your birth year on or off — it’s off unless you turn it on, it’s yours alone to set, and nobody else can set it for you. Turn the weekly digest off, in Account settings or from the link at the bottom of any digest. Delete individual photos, captions, messages, events and dates. Leave a group, which takes your photos and messages with you. Delete your account.
Sign-in emails, invitations and notices about your account aren’t marketing and can’t be switched off while your account is open.
Your rights
In the EEA and the UK
You have the right to access your information and get a copy; to correct it; to have it erased; to restrict what we do with it; to object to anything we do on the basis of legitimate interests, the weekly digest included; to portability — a machine-readable copy of what you gave us, and transmission to another controller where that’s technically feasible; and to withdraw consent at any time, which doesn’t undo processing that already happened.
You also have the right to complain to your supervisory authority — in the UK, the Information Commissioner’s Office; in the EEA, the authority where you live, where you work, or where the problem arose. We’d rather you came to us first, but that’s your right, not our permission.
In the United States
Depending on your state you may have the right to know and access what we’ve collected, where it came from, why we have it and who we disclose it to; to correct it; to delete it; to a portable copy; to opt out of sale, sharing or targeted advertising — already the case here, since we do none of them; and to limit the use of sensitive information, likewise. You have the right not to be treated differently for exercising any of this, and we offer no financial incentives for your information.
California residents may also ask for the disclosures described in Civil Code § 1798.83 about information shared with third parties for their direct marketing. We share none.
How to exercise any of it
Write to privacy@myphotofort.com, or use the controls listed above, which handle most of this immediately and without involving us.
We’ll acknowledge and respond within 30 days where the GDPR applies and within 45 days where US state law does, extending only where the law allows and telling you if we do. We’ll verify who you are before acting on a request about a specific person, normally by confirming control of the account email — we won’t ask you for identity documents we would then have to store. We’ll act on a request from an authorised agent where you’ve given them written permission and we can confirm it. We won’t charge you unless a request is manifestly unfounded or excessive, and we’d tell you why before doing anything.
If we say no, you can appeal by replying to our answer or writing to privacy@myphotofort.com with “Appeal” in the subject line. We’ll respond within 45 days with a decision and our reasons, and we’ll tell you how to reach your state Attorney General if you’re still unhappy. Several states require that route; we offer it to everybody.
Children and teens
Children appear here in two very different ways, and they need different answers.
As account holders. You must be at least 13 to have an account. In the European Economic Area you must be at least 16. We don’t knowingly create accounts below those ages, and if we find we have one, we delete it and its contents. If you think a child has an account they shouldn’t, write to privacy@myphotofort.com. We don’t knowingly collect personal information from children under 13 in violation of COPPA, and we don’t use anything from a member we know to be a minor for advertising, profiling or recommendation — because we do none of those things for anyone.
As subjects of photographs and dates. Photo Fort holds a great many photographs of children, uploaded by the adults in their families, and dates recording their birthdays. That is what a family album is, and this page won’t pretend otherwise. Content in a group is visible only to that group: not public, not indexed, not searchable by strangers, not analysed. If you’re a parent or guardian and you want a photograph or a date about your child removed, write to privacy@myphotofort.com and we’ll act on it, whether or not you have an account.
How we protect it
Traffic between your browser and Photo Fort is encrypted, and our storage providers encrypt data at rest. Sign-in is passwordless — we never store a password, so we can’t lose one.
Group isolation is enforced in the database, not just in the interface, through row-level security rules. A request for content from a group you don’t belong to fails at the data layer.
Photo files are never served from a public address. Every link to a photo or thumbnail is generated on demand, signed, and expires after an hour; upload links expire after two minutes. A photo URL that gets copied, forwarded or left in a browser history simply stops working. There is no permanent public URL for any photo on Photo Fort.
Photo metadata, including location, is removed before upload. Access to production systems is limited to those who need it, and administrative actions are recorded.
No service can promise perfect security and we won’t. If a breach affects your information we will notify the relevant supervisory authority within 72 hours where the GDPR requires it, and we’ll tell you directly and without undue delay where the breach is likely to put your rights at high risk, or where state law requires it.
Changes to this page
If we change this policy we’ll update the date at the top, and where the change is material — a new kind of information, a new purpose, a new company receiving your data, or a reduction in your rights — we’ll tell members by email or in the app before it takes effect. We won’t apply a materially different use to information we already hold without your consent where the law requires it.
Contact us
Photo Fort, LLC
7901 4th St N, St. Petersburg, FL 33702
United States
Privacy and data-rights requests: privacy@myphotofort.com
General support: photofort@myphotofort.com
If you’re in the EEA or the UK and you’re not satisfied with our answer, you can complain to your local supervisory authority as described above.