Privacy Policy
Last updated
Who we are
Ourview is operated by an independent developer. This policy covers the marketing site at ourview.events and the app at app.ourview.events. It describes, in plain language, what actually happens to your data. The rules for using Ourview are in the Terms of Service. Questions go to support@ourview.events.
The short version
- Guests give us a name and nothing else. No account, no email address, no phone number.
- Hosts sign in with Google or an email link. We never see or store a password.
- Photos and videos are private to the event and are deleted 90 days after the event starts.
- Payments are handled by Lemon Squeezy. Card details never reach us.
- No ads, no data sales, no tracking cookies on the marketing site.
If you host an event
Your account
You sign in with a Google account or with a one-time link we email to you. The link works for five minutes. We store your name, your email address, the profile image Google provides (if you use Google), and the time your account was created and last updated. If you sign in with Google, we also store the tokens Google issues so the sign-in keeps working; we do not use them to read anything else in your Google account.
Sessions
Each time you sign in we create a session that lasts seven days. The session record includes the IP address and browser identifier (user agent) of the device that signed in. We keep these so a session can be tied to a device and so unusual sign-ins can be investigated if you report a problem.
Payments
Paid events are bought once per event on a checkout page run by Lemon Squeezy, which is the merchant of record. When you start a checkout we send Lemon Squeezy your name, your email address, the event name, and the price. Lemon Squeezy collects your card or other payment details on its own page; we never receive them. After a purchase we store the Lemon Squeezy order number and identifier, the amounts charged and refunded, the currency, and the status of the order. Receipts are issued by Lemon Squeezy and are not stored by us.
The only email we send is the sign-in link, delivered through Resend. We do not send newsletters or marketing email.
If you join an event as a guest
You open the private invitation link or scan its QR code and enter a display name (up to 80 characters). That name is the only personal information we ask for. We do not record your IP address, your browser, or your email, and no account is created.
When you join, your browser receives a cookie called ourview_guest. It holds a random credential that identifies you as a participant of that one event so your uploads are attributed to your name. The cookie is limited to that event, cannot be read by scripts on the page, and expires when the event's storage expires. It cannot be used to recognise you at a different event. If you clear it, you can rejoin under a new name and will appear as a new participant.
Your display name is shown next to what you upload. The host always sees it. In a shared gallery, other guests who have the invitation link see it too.
Photos and videos
Guests can upload JPEG, PNG, WebP, GIF, HEIC, and HEIF images up to 25 MiB and MP4, WebM, and MOV videos up to 500 MiB. Hosts can add a cover image. Files are stored exactly as uploaded, in original quality, in a private Cloudflare R2 bucket. Nothing in the bucket is public: every view or download uses a link that expires within 15 minutes. We do not generate thumbnails or edited copies.
Because files are kept as uploaded, any metadata embedded in them is kept too. Photos from a phone often include the time they were taken, the device model, and, if location services were on, the GPS position. Anyone who can download a file can read that metadata. If you would rather not share it, remove it before uploading (most phones offer this when sharing) or turn off location tagging in your camera settings.
We also store the original file name, its size and type, and when it was uploaded. The host's download uses the original file names.
Who can see them
- The host can see and download every upload at any time, regardless of the gallery setting, and can download the whole event as a ZIP archive.
- In a shared gallery, anyone with the invitation link can browse all uploads once the host's chosen reveal time has passed. Guests do not need to join to browse.
- In a host-only gallery, guests can upload but the collection is visible to the host alone.
The invitation link is a long random token. The host can replace it at any time, which immediately stops the old link from working.
How long we keep things
Every event has a fixed storage period: 90 days from the event's start time. After that the invitation stops working and photos and videos can no longer be viewed or downloaded by anyone, including the host. A cleanup job then deletes the files from storage, normally within a few days of expiry.
If a host deletes an event, the invitation stops working immediately and the files are deleted by the next cleanup run. This cannot be undone. A guest can cancel an upload while it is still in progress; once it has completed, ask the host to delete the event or contact us to remove a specific file.
After the files are gone, we keep the event's records: its settings, guest display names, file names, sizes and timestamps, and the order records for paid events. Order records are kept for accounting. Everything else can be deleted on request (see “Your choices and rights”).
Host accounts are kept until you ask us to delete them. There is no self-service deletion yet; email us from your account address and we will remove the account and its events.
Cookies and browser storage
The app sets these cookies. None of them are used for advertising.
| Cookie | Purpose | Lifetime |
|---|---|---|
better-auth.session_token | Keeps a host signed in. | 7 days |
ourview_guest | Identifies a guest within one event. | Until the event's storage expires |
| Sign-in state cookies | Protect the Google sign-in handshake. | Minutes |
While a host is paying for an event, the browser temporarily keeps the chosen cover image in its own storage so it can be uploaded after returning from checkout. It is discarded within 24 hours. The marketing site at ourview.events sets no cookies at all.
Analytics on the marketing site
ourview.events uses PostHog, hosted in the European Union, to count page views and clicks on the sign-up buttons. It runs in cookieless mode: no cookie is set and no identifier is stored on your device, so visits cannot be linked to you or to each other across days. The app at app.ourview.events has no analytics.
Who we share data with
We do not sell personal data and do not share it for advertising. These services process data on our behalf to run Ourview:
| Service | What it does | Where |
|---|---|---|
| Vercel | Hosts the app and marketing site; keeps standard request logs | United States |
| Neon | Database (accounts, events, guest names, file records) | United States |
| Cloudflare R2 | Stores photos and videos | Cloudflare's global network |
| Sign-in for hosts who choose Google | Per Google's policy | |
| Resend | Delivers the sign-in email | United States |
| Lemon Squeezy | Checkout, payment, receipts, and sales tax as merchant of record | Per Lemon Squeezy's policy |
| PostHog | Cookieless analytics on the marketing site | European Union |
We will disclose data if a law, court order, or lawful request requires it, and only what is required.
Where data is processed
The app and its database run in the United States. Photos and videos are stored on Cloudflare's network. Marketing-site analytics are processed in the European Union. If you use Ourview from elsewhere, your data is transferred to those locations.
Your choices and rights
Where your local law provides them, you can ask us to access, correct, export, or delete your personal data, or object to how we use it. In practice:
- Hosts can download everything from an event as a ZIP archive, delete an event from its settings, and ask us by email to delete the account.
- Guests can ask the host to delete the event, or email us with the event name and the display name you used and we will remove your uploads or your name.
- Anyone who appears in a photo they did not upload can email us; we will work with the host to remove it.
Hosts should write from the email address on the account so we can verify the request. We answer within 30 days.
Children
Ourview has no age gate. Guests provide only a display name, and the host decides who receives the invitation. If you are a parent or guardian and want a child's contribution or name removed, contact us and we will remove it.
Security
All traffic uses HTTPS. Photos and videos sit in a private bucket and are only reachable through links that expire within 15 minutes and never outlive the event. Guest credentials and sign-in link tokens are stored as hashes, not in the clear. Session and guest cookies cannot be read by scripts in the page. No system is perfectly secure; if you find a problem, email us and we will respond quickly.
Changes to this policy
When we change how Ourview handles data, we update this page and the date at the top. For a change that reduces your privacy, we will say so here before it takes effect.
Contact
Questions about this page go to support@ourview.events.