QR Album
Privacy

How your event media is protected

Responsible
Martin Freiwald, Founder
Written
Last checked
Reading time
5 min
Short answer

Photos, videos and voice notes are held in private object storage. There is no public address for a file — nothing can be reached by guessing a URL.

Every view is served through a signed link that expires, and every upload uses a single-use link that can only write.

No public address

The storage holding your files is private. It is not a folder anyone can browse and there is no address that returns a photo to somebody who simply asks for it — every read has to be authorised first, and the authorisation is issued per file and per request.

That is why you cannot bookmark a photo and expect the link to keep working.

  1. Share the album link, not a file link. A file link is short-lived by design and will stop working.
  2. Use the switches for access. Private album, viewing password and review are what control who sees what.
  3. Download for anything permanent. A copy on your own disk is the only thing that does not expire.

Uploads carry no key

A guest s browser is handed a single-use link that can only write, never read, and only to the 1 place it was issued for. So a guest phone never holds a credential, and nothing about the upload page gives anybody a way into anybody else s files.

Large videos are sent in parts using the same mechanism, which is what makes a 2 GB file survive a shaky connection.

The album shows a smaller version

What the album displays is a reduced copy made for quick loading on a phone network. The original stays where it is and comes out only through a download, which is one of the reasons the download is worth doing rather than screenshotting the album.

Original-quality downloads belong to the paid tiers, for you and for guests alike.

Who can reach what

You reach everything in your own events, including what you have hidden. Guests reach the approved, unhidden contributions through the album, and only if you have left it open. Nobody reaches anything across events, because access is scoped to the event a request belongs to.

A guest link stops working the moment you close uploads, rather than degrading quietly.

What each party can reach
YouA guest with the linkAnyone else
Approved contributionsYesIf the album is openNo
Hidden contributionsYesNoNo
Items awaiting reviewYes, in the queueNoNo
Original filesOn a paid tierOnly if you open downloadsNo
Another eventOnly your ownNoNo

A guest never sees more than the album shows. Everything else needs your account.

What this does not protect against

Anything a guest has already seen, screenshotted or downloaded is out of reach of any switch. That is true of every platform and it is worth saying plainly rather than implying otherwise.

The controls decide who gets access from now on. They cannot recall a copy.

Common questions

Can somebody guess a photo URL?

No. Files have no public address, and every read is authorised per request.

Why did a copied image link stop working?

Because it was signed and short-lived by design. Share the album link instead.

Does a guest phone hold any credential?

No. Uploads use a single-use link that can only write, to 1 destination.

Is the album showing me the original file?

No, a smaller version for fast loading. The original comes out through a download.

Can a switch recall something already downloaded?

No. Access controls decide who gets in from now on.

Still open? Contact

Pass it on
Related articles
Contact

You need more detail than this

The privacy page in the footer carries the formal wording. Write to us for anything it does not cover.