UNVEIL

Privacy policy

Last updated August 30, 2026

The short version

Unveil is built around one promise: photos stay hidden until the album opens. This policy explains what we collect to make that work, who processes it, how long we keep it, and the rights you have over it.

Who we are

Unveil is operated by Brink Studio AS (org. no. 837 452 562), a company registered in Norway. Brink Studio AS is the data controller for the information described here under the GDPR.

Postal address: Torshovgata 15H, 0476 Oslo, Norway. You can reach us any time at support@unveil.camera.

What we collect and why

We collect only what an event needs to run:

  • Account and identity. Sign in with Apple or Google gives us a private identifier and, if you choose to share it, your name. Signing in with your email address and a one-time code stores that address instead. Guests can join anonymously; an anonymous account holds their photos and nothing else.
  • Photos and event content. Shots taken at an event upload to our servers and stay there for that event's participants. We strip location data and other camera metadata while each photo is processed.
  • Purchases. In the app, event upgrades run through Apple's App Store or Google Play, and RevenueCat validates the receipt so we can grant the credit. Events bought on this website are paid through Stripe. Either way we receive the purchase record, never your card details. After a purchase on this website we email you the event's details, and a reminder if the setup was never finished.
  • Notifications. If you turn on unlock notifications, we store a push token so we can tell you when an album unlocks, delivered through Apple's push service on iPhone and Firebase Cloud Messaging on Android.
  • Usage data. We collect basic product analytics, like which screens get used, so we can improve the app. We never run analytics on your photos.
  • Support messages. If you email us, we keep that correspondence so we can help.

Who can see your photos

Before an album opens, photos are hidden from every participant. That includes the person who took them and the event's host.

After it opens, only the people who joined that event can see them.

Who we share it with

We don't sell your data. We rely on a few processors to run the service, each handling only what its job needs:

  • Supabase (EU, Stockholm region) hosts our database, authentication, and photo storage.
  • PostHog (EU) processes product analytics.
  • RevenueCat validates App Store and Google Play purchases.
  • Stripe handles payments made on this website. Your card and billing details go to Stripe; we never see them.
  • Resend (EU) sends our email: sign-in codes, and the messages about your purchase and your event.
  • Apple provides Sign in with Apple, handles App Store billing, and delivers push notifications on iPhone.
  • Google provides Google Sign-In, handles Google Play billing, and delivers push notifications on Android through Firebase Cloud Messaging.
  • Expo delivers push notifications to your device.
  • Vercel hosts this website.
  • Meta (Meta Platforms Ireland) measures our ads, only after you agree on an ad visit — see the next section. Some of that data may be transferred to Meta Platforms, Inc. in the United States under the EU standard contractual clauses and the EU-US Data Privacy Framework.

Cookies and ad measurement

This site sets no tracking cookies on its own. Our analytics run without cookies, and nothing follows you between visits.

The one exception is ads. If you arrive at the event creator from one of our ads, we ask before anything happens. If you agree, the Meta pixel sets its cookies in your browser, and we tell Meta about your visit, the start of a checkout, and, if you buy, the purchase — along with a hashed version of your email, your IP address, and browser details, so Meta can match it to the ad and we can tell whether the ad was worth running.

If you decline, none of that is set or sent, and the event creator works exactly the same.

Your choice is stored in your browser for about six months. Clearing this site's browser data resets it, and we'll ask again on your next ad visit.

Legal basis

We process your data to perform our contract with you (running the events you create and join), for our legitimate interests (improving the app and keeping it secure), with your consent where you give it (unlock notifications, and ad measurement when you arrive from an ad), and to meet legal obligations where they apply.

How long we keep it

Event content stays for the life of the event. Account data stays until you delete your account. Analytics are kept in aggregate to understand how the app is used over time.

Your rights

Under the GDPR you can:

  • Access the data we hold about you.
  • Correct anything that is wrong.
  • Delete your account and its data.
  • Receive a copy of your data, or ask us to move it.
  • Object to or restrict certain processing.
  • Withdraw consent, such as turning off unlock notifications or ad measurement.
  • Lodge a complaint with a supervisory authority. In Norway that is Datatilsynet.

How to exercise them

Delete your account from the app's settings and we remove your profile and photos. For anything else, email support@unveil.camera and we'll take care of it.

Where your data lives

Your account, photos, and analytics are stored in the EU. Some processors, such as Apple, Google, RevenueCat, Stripe and Meta, may handle limited data outside the EEA under appropriate safeguards like the standard contractual clauses.

Children

Unveil is not directed to young children, in line with the app's store age ratings. If you believe a child has given us data, email us and we'll remove it.

Changes

We'll post any updates to this policy here, and announce anything meaningful in the app.

Contact

Questions about privacy? Write to support@unveil.camera.