QR Album
Privacy

Where your media is stored

Responsible
Martin Freiwald, Founder
Written
Last checked
Reading time
4 min
Short answer

Files live in private object storage. There is no directory to browse and no address that hands a file to whoever asks — access is issued per file, per request, and expires.

Each contribution exists as the original your guest sent plus a smaller copy the album displays.

Object storage, not a shared folder

Each file is an object with its own identifier rather than a document sitting in a browsable directory. Nothing lists the contents to an outsider, and there is no path you can walk up to find somebody else s event.

For you that difference shows up in 1 practical way: you cannot bookmark a photo, because there is no permanent address to bookmark.

  1. Treat the album as the front door. It is a page, not a folder. Individual file links are short-lived.
  2. Download for anything you want to keep. That is the only copy without an expiry date.
  3. Read the privacy page for the formal detail. It is linked in the footer and it is the authoritative text.

The original and the display copy

What arrives is kept as it was sent. Alongside it a smaller version is prepared for the album, so a page of contributions loads quickly on a phone network rather than pulling several gigabytes through it.

That is why the album can look modest in size and a download of the same event can run to gigabytes.

What exists per contribution
CopyUsed forYou get it via
The originalPrinting, archiving, a photo bookA download, on a paid tier
The display copyThe album and the live wallLooking at the album
A thumbnailGrids and previewsLooking at the album

Screenshotting the album gives you the display copy. Only a download gives you the original.

Nothing is reachable by guessing

A request for a file has to be authorised first, and the authorisation is short-lived and specific. Changing a number in a link does not step sideways into another photo, and it does not step into another event either.

The album link is the thing designed to be shared. Everything below it is issued on demand.

What deletion actually removes

Deleting a contribution removes it from the album and from every future download, and the stored objects behind it are cleared as part of that. Deleting an event does the same for everything it holds.

Hiding is different: the file stays and still occupies storage. Only deleting frees space.

And what expiry removes

At the end of an album s retention window, plus a 14-day grace period, the media is removed. That happens on our side too — there is no archive to ask for afterwards and no copy waiting to be restored.

Which is why the download in the week after the party is the part that actually matters.

The formal text

The privacy page linked in the footer is the authoritative document for what is processed and on what basis, and it is the right place for anything a help article should not be paraphrasing.

If you need something it does not answer, write to us rather than inferring it from this page.

Common questions

Can I get a permanent link to 1 photo?

No. File links are issued per request and expire. Share the album link instead.

Why is the download so much larger than the album looks?

The album shows a smaller copy. The download hands you the originals.

Does deleting really remove the file?

Yes, from the album, from future downloads and from storage.

Does hiding free up space?

No. The file stays and still counts against storage.

Where is the formal privacy text?

On the privacy page linked in the footer.

Still open? Contact

Pass it on
Related articles
Contact

You need a specific detail

The privacy page in the footer carries the formal wording. Write to us for anything beyond it.