safepic

safepic Privacy Policy

Last updated: 30 July 2026

This English version is provided for users who use safepic in English and reflects the Polish Privacy Policy dated 30 July 2026.

1. Controller and contact

  1. The controller of data related to the Account, security, analytics, Service operation, and support is Supplier Patryk Sęk-Heljasiński, sole proprietor Patryk Sęk-Heljasiński, Polish tax ID (NIP): 8371868079, REGON: 385776653, address: Czerwonka-Parcel 4, 96-500 Czerwonka-Parcel, Poland.
  2. Privacy contact: contact@safepic.app, telephone: +48 508 444 076.
  3. The Service may be offered globally in countries supported by Stripe Managed Payments.
  4. Persons in the European Economic Area have GDPR rights, and persons in other countries also have rights granted by applicable local laws.

2. Safepic roles in data processing

  1. Safepic acts as controller for Account, authentication, Subscription, security, limits, analytics, correspondence, and legal-obligation data.
  2. Where a business customer determines the purpose and manner of using personal data contained in Albums, safepic acts in that respect as a processor, and the business customer remains the controller.
  3. Article 28 GDPR processing terms are set out in Attachment No. 2 to the Terms and are accepted electronically together with the Terms by a business customer.
  4. Processing terms cover in particular instructions, confidentiality, security, sub-processors, assistance with rights, deletion or return of data, and international transfers.
  5. Stripe/Link and Google may act as independent controllers within the scope described in their own privacy documents.

3. Categories of data processed

3.1. Account and authentication

We process in particular:

  1. email address, name, and profile picture;
  2. Account and login-provider identifiers;
  3. data provided by Google OAuth and, depending on integration scope, tokens necessary to connect the account;
  4. OTP codes and verification data;
  5. tokens, dates, IP address, user-agent, and other session data;
  6. data about connected accounts and active sessions.

3.2. Albums and Content

We process in particular:

  1. Album names, original Photos, including photographs, graphics, illustrations, and visual designs, file names, dimensions, sizes, and order;
  2. generated videos, thumbnails, covers, and other technical materials;
  3. Cloudflare R2 and Mux asset identifiers and metadata;
  4. Share Links, expiry dates, and passwords stored as a hash and in encrypted form so that the User can display them again;
  5. comments, likes, and creation times.

3.3. Recipients and invitations

  1. Account and Recipient features are available only to persons aged 18 or older.
  2. In connection with Recipients and invitations, we process in particular:

3.4. Subscription and payments

We process in particular:

  1. Stripe customer, Subscription, and schedule identifiers;
  2. plan, status, billing period, and start, renewal, and cancellation dates;
  3. information needed to present price and currency, including approximate request country;
  4. transaction data received from Stripe/Link.

Safepic does not store full payment card data.

3.5. Technical, security, and playback-protection data

We process in particular:

  1. IP address, user-agent, device type, operating system, and browser;
  2. Album, Link, Mux asset, and playback identifiers;
  3. short-lived signed access tokens for streams and DRM licenses and the technical restrictions contained in them;
  4. license server requests and responses, supported DRM type, and result of technical playback authorization;
  5. if Apple FairPlay Streaming is launched in a compatible web browser on the Apple platform - a technical device identifier contained in the Server Playback Context (SPC), which itself does not contain User data but, when linked to a request, is treated cautiously as pseudonymous data;
  6. information about device and software compatibility and availability of required protected-playback components;
  7. data about login attempts, incorrect passwords, exceeded limits, errors, and suspected abuse;
  8. request logs, diagnostics, and information needed to protect the Service and Content.

Until web FairPlay support is launched, data specific to this mechanism, including SPC, is not processed by safepic or Mux for purposes of the Service.

The processed information is used only to assess technical compatibility, verify access, issue a time-limited playback license, protect Content, and diagnose errors.

3.6. Analytics and diagnostics

We process in particular:

  1. a technical cookieless usage identifier and, after consent, a persistent browser identifier and the pseudonymous Account identifier user.id;
  2. manually defined product events, for example login, Link creation, upload start, and Subscription purchase;
  3. page views, page leaves, web application performance data, and technical errors;
  4. after consent, automatic click, change, and submit events, heatmaps, and masked session recordings;
  5. the full current URL, pathname, query string, hash, referrer, and Album and public Link identifiers appearing in the address;
  6. element hierarchy, classes, permitted attributes, element text, and link href as part of autocapture, subject to the exclusions described in section 5;
  7. technical environment properties needed to analyze compatibility and errors;
  8. error context that may contain technical information about the performed operation.

We process in particular:

  1. correspondence content, contact details, and information provided in a support request;
  2. data needed to verify a person requesting access or deletion;
  3. data required by law or needed to establish, pursue, and defend claims.

3.8. Terms acceptance and Content licenses

To prove contract formation and license grant, we process:

  1. Account identifier and email address;
  2. version and cryptographic hash of the accepted Terms;
  3. date and language connected with acceptance;
  4. acceptance identifier assigned to the upload or Album record, license grant date, and metadata of uploaded files.

3.9. Data stored locally in the browser

The browser may store:

  1. safepic-locale cookie with language preference;
  2. cookies and tokens used to maintain session and Account security;
  3. a cookie storing the extended-analytics decision;
  4. after consent, PostHog cookies used to persistently recognize the browser and connect visits.
Purpose Data categories Legal basis
Account creation, login, and Service provision Account, sessions, Albums, Content, settings Article 6(1)(b) GDPR - performance of contract
Paid Plan and Subscription handling plan and Subscription status identifiers, billing data received from Link/Stripe Article 6(1)(b) and (c) GDPR - contract and legal obligations
Sending invitations Recipient address, Link, Album name, and password if set Article 6(1)(f) GDPR - legitimate interest of the User and Controller in performing a one-off invitation
Security, limits, and abuse prevention session data, IP, logs, technical data, and security events Article 6(1)(f) GDPR - protection of the Service, Content, users, and claims
Playback protection and technical compatibility asset and playback identifiers, tokens, license requests, and device/software/DRM information Article 6(1)(b) and (f) GDPR - performance of the Service and Content protection
Basic cookieless analytics and diagnostics cookieless technical identifier, manual events, page views, performance, and errors Article 6(1)(f) GDPR - Service development, stability, and basic usage measurement
Extended PostHog analytics cookies, user.id, autocapture, heatmaps, and session recordings Article 6(1)(a) GDPR - consent
Support and rights handling correspondence, contact and verification data Article 6(1)(b), (c), or (f) GDPR depending on the request
Legal obligations and claims legally required documentation and evidence Article 6(1)(c) or (f) GDPR
Contract formation and proof of license Account identifier, email, Terms version and hash, date, language, and upload or Album record Article 6(1)(b) and (f) GDPR - performance of contract and establishment, pursuit, and defense of claims
Processing customer B2B Albums Content and metadata entrusted by the customer customer's instructions as controller, in accordance with Article 28 GDPR
  1. Legitimate interests include security, fraud prevention, rights protection, stability, usage analysis, and enabling the User to invite a designated person.
  2. A person may object for reasons related to their particular situation.
  3. Providing Account data is voluntary but necessary to conclude and perform the contract. Failure to provide it prevents Account creation or use of a given feature.
  4. Withdrawal of consent applies only to operations for which consent was expressly indicated as the basis. It does not affect lawfulness of earlier processing.

5. PostHog analytics

  1. We use PostHog in the web application and API for analytics and diagnostics. The PostHog project uses the European data region. The web application sends events through relay.safepic.app, while the API sends directly to https://eu.i.posthog.com.
  2. Before a decision and after refusal or withdrawal, the web application performs basic cookieless measurement. It does not store PostHog cookies, connect visits with a persistent identifier, or enable autocapture, heatmaps, or session recording.
  3. After voluntary consent, PostHog stores cookies, connects visits, may assign a signed-in person's events solely to the internal user.id, automatically captures click, change, and submit interactions, creates heatmaps, and records the session.
  4. Consent given on the homepage or in the web Drive applies during a later visit to a public Album. A public Album does not display the banner or consent settings, but after prior consent it may be covered by autocapture, heatmaps, and session recording.
  5. PostHog may receive full URLs including query strings and hashes, referrers, Album and public Link identifiers in URLs, and, for autocapture, element text, structure, and link href values. This information may allow authorized team members to reconstruct the visited path.
  6. Session replay is configured to mask all form fields and the text of comments, Album and file names, emails and Account details, first name, last name and company, Link passwords, billing information, and active-session data before sending.
  7. Photos, thumbnails, covers, upload previews, the Mux player, video, and full-screen Album media are fully blocked in recordings. Masked or blocked elements are also excluded from autocapture so their content is not included in $el_text.
  8. Recordings exclude network request bodies and headers, console logs, canvas, and cross-origin iframe content. Copied text and form-field values are not captured.
  9. Events assigned to user.id are pseudonymous, not anonymous. We do not send email address, first name, last name, or company name as PostHog person properties.
  10. PostHog does not store the IP address as an analytics event property. The IP address may nevertheless be processed briefly by the proxy and infrastructure when handling a request, including for security.
  11. Session recordings are retained for 30 days. Use of the European region and proxy does not exclude all possible transfers connected, for example, with support, infrastructure maintenance, and sub-processors, which are subject to section 8.

6. Recipients and data sources

Recipient Role Scope
Cloudflare processor or sub-processor depending on data category and feature Workers infrastructure, R2, Hyperdrive, network protection, and email sending; Hyperdrive intermediates database connection but does not host the database
PlanetScale processor or sub-processor for database data managed PostgreSQL database host in AWS region eu-central-1 in Frankfurt
Mux processor or sub-processor for video materials and playback data receiving video materials, transcoding, encryption, stream distribution, and DRM license server operation; after web FairPlay launch, also operation of its licenses on behalf of safepic
PostHog processor for analytics and diagnostics analytics and diagnostics in the European project region; web application through relay.safepic.app, API directly to https://eu.i.posthog.com
Stripe/Link independent controller for payments and transaction handling merchant of record for payments, taxes, transaction documents, support, and transaction disputes
Google independent controller for OAuth login authentication through Google OAuth
Advisers and authorities independent controllers or data recipients depending on disclosure basis recipients of data where required by law or necessary to protect claims
  1. If FairPlay is launched in a compatible web browser on the Apple platform, the browser may create an SPC containing a technical device identifier and data needed to obtain a license.
  2. The license request will be handled by Mux as a Technology Provider acting on behalf of safepic.
  3. FairPlay use alone will not mean that Apple receives Content or Account data as part of each license request or that Apple sponsors, approves, or certifies safepic or Content protection effectiveness. Apple and FairPlay are trademarks of Apple Inc., registered in the United States and other countries. HLS (HTTP Live Streaming) is technology of Apple Inc.
  4. Invited Recipient data comes from the User.
  5. Information required by Article 14 GDPR should be provided no later than on first invitation, for example through a link to this Policy in the email message.
  6. The User is responsible for having a basis to provide the Recipient's address and data of persons depicted in the Album.

7. PlanetScale and database location

  1. The production PostgreSQL database is hosted by PlanetScale in AWS region eu-central-1 in Frankfurt.
  2. PlanetScale indicates that data of a database created in a European region remains in that region unless the customer creates a replica in another region.
  3. The production safepic database does not create replicas outside the Frankfurt region without prior Policy update and transfer assessment.
  4. PlanetScale services are covered by its DPA.
  5. Support access, telemetry, and sub-processors may be subject to transfer rules in section 8.

8. Transfers outside the EEA

  1. Some providers or their sub-processors may process data outside the EEA, in particular in the United States.
  2. Transfer takes place, depending on the recipient, on the basis of a European Commission adequacy decision, the EU-US Data Privacy Framework, standard contractual clauses, or another mechanism permitted by GDPR.
  3. Information about the appropriate mechanism for a specific provider and a copy or description of safeguards can be obtained at contact@safepic.app.
  4. Merely choosing an EU data region does not justify an absolute assurance that no data is ever accessible or processed outside the EEA.

9. Data retention and deletion - 30 days

  1. Data is normally stored for the duration of the active Account or Album and for the time needed to provide a given feature.
  2. The User may delete an Album in the web interface.
  3. A request to delete an Account is submitted through support at contact@safepic.app; the Controller may verify the requester's identity.
  4. After effective Album deletion or acceptance of an effective Account deletion request, related service data is deleted or anonymized no later than within 30 days.
  5. This rule covers Account data, Albums, Photos, generated videos and thumbnails, Share Links, invited persons' addresses, comments, likes, and DRM license identifiers and logs under the Controller's control that relate to the deleted Account or Album.
  6. The 30-day period covers active systems and the ordinary backup deletion cycle to the extent under the Controller's control.
  7. Session data is stored until expiry, revocation, or Account deletion and then is subject to the same maximum 30-day period.
  8. Billing data, legal documentation, and evidence may be stored longer if required by law or necessary to establish, pursue, or defend claims. Evidence of Terms acceptance and upload-license linkage is stored for 6 years from contract termination or Account deletion.
  9. Stripe/Link and other independent controllers apply their own retention periods for which they are independently responsible.
  10. Data anonymized in a way that prevents identification is not subject to personal-data retention periods.
  11. PostHog session recordings are retained for 30 days. The decision cookie and analytics cookies after consent expire after 180 days.

10. Rights of persons

  1. To the extent provided by law, a person has the right to:
  2. Requests may be sent to contact@safepic.app.
  3. The Controller may request additional information necessary to confirm identity.
  4. The authority competent for a controller established in Poland is the President of the Personal Data Protection Office.
  5. A person may also contact the authority competent for their place of residence, work, or alleged infringement.
  6. If a request concerns Content processed for a B2B customer, safepic may forward it to the customer acting as controller or support the customer in fulfilling the request under the data processing terms in Attachment No. 2 to the Terms.

11. Automated decisions and profiling

  1. We do not use automated decision-making that produces legal effects or similarly significantly affects a person within the meaning of Article 22 GDPR.
  2. The Service automatically assesses technical compatibility of the playback environment and may allow or block access to protected playback or issuing a DRM license.
  3. The assessment referred to in paragraph 2 is a technical security mechanism.
  4. A Recipient may use a supported environment or contact support.
  5. We do not use PostHog analytics for automated decision-making about persons or to create personal analytics profiles.

12. Cookies and browser storage

  1. We use necessary and functional storage mechanisms:
  2. The analytics-decision cookie is necessary to remember the choice for 180 days. A new version of the consent mechanism may require a new choice.
  3. Without consent, PostHog operates cookieless. After consent, PostHog cookies are stored for 180 days and are used to persistently recognize the browser and connect visits between safepic.app and its subdomains.
  4. Consent can be withdrawn at any time through “Analytics settings” in the homepage footer, on the sign-in and support screens, or in Drive Account settings. Withdrawal immediately stops autocapture, heatmaps, and replay and removes persistent identification; it does not affect the lawfulness of earlier processing.
  5. Google and Stripe/Link may set their own cookies during login or payment and are responsible for them under their policies.

13. Security

  1. We apply technical and organizational measures appropriate to risk, including access control, transmission encryption, protection of authentication data, rate limiting, security event logging, and Link safeguards.
  2. The Link password is stored both as a value used for verification and in encrypted form enabling display to the Album owner.
  3. Playback protection mechanisms, including time-limited tokens and DRM licenses, reduce the risk of unauthorized Content copying but do not replace general personal-data security measures and do not guarantee complete elimination of screenshots, recording, or other copying methods.
  4. No system guarantees absolute security.
  5. Incidents are handled and reported to persons or authorities where required by law.

14. Changes to this Policy

  1. This Policy may be changed due to changes in law, Service, providers, purposes, or processing methods.
  2. Users will be informed in an appropriate manner before a change that materially affects persons takes effect.
  3. Last updated: 30 July 2026.