Papped Privacy Policy
Last updated: 6 July 2026
Papped ("Papped", "we", "us") is a service that lets event organizers collect photos from their guests, screened and delivered straight to the organizer's own Google Drive. This policy explains what we collect, what we deliberately do not keep, and where your data goes.
The short version: we never keep your photos. They pass through us, get screened, and land in the organizer's Drive. The one exception is a photo held for the organizer's review, which we store encrypted for at most 48 hours and then delete.
1. Who this covers
- Organizers: the people who create and pay for events. Our customers.
- Co-organizers: people an organizer invites to help manage an event.
- Guests: event attendees who scan the QR code and take photos. Guests never create an account.
2. What we collect
Organizers and co-organizers
- Google identity: your name, email address, and Google account identifier, received when you sign in with Google.
- Drive access token: an encrypted token that lets Papped create an event folder in your Google Drive and deliver photos into it. We use Google's
drive.filescope, which means we can only see and touch folders and files our app created. We cannot read the rest of your Drive. - Event details: event name, dates, guest count, photo pool settings, and any stickers or a watermark you upload for guests to use.
- Payment records: if you pay for an event, we keep records of what was bought (event, amount, date) for legal and accounting purposes. We never see or store your card details; payments are handled by our payment provider (see section 5).
Guests
- Guests are anonymous. No account, no email, no phone number.
- Optional display name: a guest may enter a name so the organizer knows whose shots are whose. It is optional and can be skipped.
- Session data: an anonymous session identifier, shots taken, upload records, and a last-active timestamp, so the roll limits and the organizer's guest list work.
- Photos: the photos a guest takes pass through our service for screening and delivery. See section 3 for exactly how long they exist on our side.
Everyone
- Basic technical logs: our infrastructure providers keep standard server logs (IP address, request time) for security and abuse prevention.
- We do not use advertising cookies or analytics trackers. The only cookie we set is a short-lived one used to secure the Google sign-in and Drive connection flows.
3. Photos: in transit only
This is the core of the product, so here it is precisely:
- A photo taken by a guest is uploaded to us, automatically screened, and delivered to the organizer's own Google Drive. We do not keep a copy.
- Photos rejected by the screen are never stored at all, not even briefly.
- If the automated screen flags a photo as borderline, or cannot screen it, it is held encrypted, for a maximum of 48 hours, so the organizer can approve or reject it. Approved photos are delivered to the organizer's Drive and the held copy is deleted. Rejected or unreviewed photos are deleted automatically.
- Photos in the shared event gallery are fetched from the organizer's Drive. To keep the gallery fast we briefly cache a copy at our CDN edge for up to one hour; that cache is purged the moment a photo is deleted or reported, and it is never a lasting store.
- The gallery is private to the event: every photo request requires a signed guest session or organizer credential scoped to that specific event.
- We do not use your photos to train AI models, and neither does our screening provider: automated screening uses Amazon Rekognition under an AI-services opt-out policy, which means Amazon does not retain the images or use them to improve its services.
We do not claim "zero storage ever": the 48-hour review hold described above is the single, deliberate exception. Everything else is in transit only.
4. How long we keep things
- Photos: not stored. Review holds: maximum 48 hours.
- Event metadata (guest sessions including display names, upload records, sticker/watermark files): deleted 30 days after the event ends. Aggregate numbers (how many guests joined, how many photos were taken) stay on the event record so the organizer keeps their history.
- If an organizer deletes an event before it launches: its data is removed immediately. Events that have run are purged on the 30-day schedule above.
- Guest links: shooting stops when the organizer ends the event or shortly after its scheduled end (the organizer sets how long the link stays open, 24 hours by default); the shared gallery stays readable to guests until the 30-day purge.
- Drive access tokens: encrypted at rest, and deleted the moment you disconnect Drive or delete your account.
- Payment records: kept as long as law and accounting require.
- Organizer accounts: kept while you have an account; contact us to delete it (see section 8).
5. Who we share data with
We share data only with the services that make Papped work, and only what each needs:
- Google (sign-in and Drive): photos are delivered to the organizer's Drive; the organizer's own Google account holds them from then on. Papped's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Amazon Web Services (Rekognition, US region): automated photo screening, with the AI opt-out described in section 3.
- Cloudflare (US/global): hosting, content delivery, and the encrypted 48-hour review hold.
- Neon (US region): our database (event and session metadata, never photos).
- Resend (US region): sends our transactional emails (event ready, payment receipts, photo review alerts, photo pool alerts, guest film requests, co-organizer invites, and post-event summaries). Our emails contain no tracking pixels or tracked links.
- Dodo Payments (merchant of record): processes payments and holds card details when you pay. As merchant of record, they issue the invoice and handle payment-related taxes.
- Zoho: hosts our support mailbox, so your emails to us live there.
We do not sell personal data, and we do not share it with advertisers.
International data transfers
Papped is operated from India, and the providers listed above are largely in the United States. If you use Papped from the EU, the UK, or anywhere else, your personal data is transferred to and processed in India, the United States, and the other countries where these providers operate. We rely on appropriate safeguards for these transfers (such as our providers' standard contractual clauses) and keep the personal data we process to a minimum.
6. The organizer's role
Photos delivered to an organizer's Drive belong to and are controlled by the organizer. Once delivered, the organizer decides what happens to them, like any photos in their own Drive. If you attended an event and want a photo removed, guests can delete their own photos in the app at any time until the gallery closes; deleting removes it from the gallery immediately and requests removal of the delivered file from the organizer's Drive. Reporting a photo hides it from the gallery immediately pending the organizer's review. For anything else, the organizer is the right person to ask.
7. Security
- Photos in the review hold are encrypted at rest, as are Drive access tokens.
- All traffic is encrypted in transit (HTTPS).
- Uploads are validated and rate-limited; event links expire; photo reports are rate-limited so a gallery cannot be abused into hiding.
- The credential we use for automated screening can do exactly one thing (screen an image) and nothing else.
- Access to production systems is limited to the two founders.
No system is perfectly secure, but we hold almost nothing: the most privacy-protective thing about Papped is how little of your data exists on our side at any moment.
8. Your choices and rights
- Guests: skip the display name, delete your own photos from the gallery at any time until the gallery closes, or simply stop using the link. Your session data is deleted about 30 days after the event ends.
- Organizers: disconnect Google Drive at any time (we delete the token), cancel an unlaunched event (immediate removal), end an event early, or ask us to delete your account.
- Your rights, wherever you live: you can ask to access, correct, delete, or receive a copy of your personal data, and to object to or restrict how we use it; where we rely on consent, you can withdraw it. This applies globally, including the EU, UK, and California. Email [email protected] and we will honor these rights within the timeframes your law requires. If you are in the EU or UK, you also have the right to complain to your local data protection authority.
- Legal basis (EU/UK): where GDPR or UK GDPR applies, we process personal data to perform our agreement with organizers (running events and delivering photos), on our legitimate interests in operating and securing the service, and on your consent for optional data (such as a guest display name) and for connecting your Google Drive.
9. Children
Papped is built for corporate and professional events and is not directed at children. Organizers are responsible for what happens at their events, including who attends.
10. Changes
If we change this policy, we will update this page and the date above. Meaningful changes will be flagged to organizers by email.
11. Contact
Operated by the founders of Papped, based in India.