FOCL ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use FOCL — the wedding-day planning app, and FOCL Galleries, where photographers deliver photographs to their clients.
1. Information We Collect
Account Information
- Email address
- Password (encrypted)
- Name and studio name (optional)
- Phone number (optional)
Wedding Project Data
- Couple names and wedding details
- Guest/people names and roles
- Shot lists and timeline information
- Vendor contact information
- Location details
Galleries: photographs and video
- Photographs and video you upload to a client gallery, with the file information that comes with them (filename, size, dimensions, capture date)
- Gallery settings: title, cover, sections, passwords, download PINs and expiry dates
- Your studio branding: logo, colours, typefaces, bio and contact links
Gallery visitors
When a couple or a wedding guest opens a gallery shared with them, we may collect:
- Email address, where they enter one to view a gallery, download photographs, save favourites or use photo search
- Their name, where they choose to give one alongside a favourites list
- Which photographs they view, favourite, hide or download, and when
- Standard request information (IP address, browser type), used to apply rate limits and prevent abuse
Face data (photo search)
Photographers can switch on selfie search for a gallery. Where it is on, we use Amazon Rekognition to
create a mathematical representation of each face appearing in that gallery's photographs — a
"face template". A face template is a biometric identifier. It is not a photograph and cannot be
turned back into one.
- What is stored: face templates, held in a collection belonging to that one gallery and used only to match faces within it.
- The selfie itself is never stored. When a guest searches by selfie, that photo is used for the single search and discarded immediately. Neither we nor Amazon retain it.
- Deletion: a gallery's face templates are deleted when the gallery is deleted, and when the account is deleted.
- Control: the photographer switches it on or off per gallery, and no guest is required to use it.
We do not use face data to identify anyone outside the gallery it came from, do not build a profile
across galleries or weddings, and do not sell, licence or disclose it to anyone other than Amazon Web
Services, the processor that performs the matching.
Print orders
- Shipping name and address, and an email address for order updates
- Which photographs were ordered, and the products and sizes chosen
- Order total, tax and status. Card details go directly to Stripe and never reach our servers.
Usage Data
- App usage patterns and feature interactions
- Device information (for mobile apps)
- Error logs for troubleshooting
2. How We Use Your Information
| Purpose |
Legal Basis |
| Provide and maintain the Service |
Contract performance |
| Send account-related emails |
Contract performance |
| Improve and optimize the Service |
Legitimate interest |
| Respond to support requests |
Contract performance |
| Detect and prevent fraud |
Legitimate interest |
3. Data Storage and Security
Your data is stored securely using Supabase, a trusted cloud infrastructure provider. We implement the following security measures:
- Encryption in transit (TLS/SSL)
- Encryption at rest
- Secure authentication with password hashing
- Regular security audits
- Access controls and monitoring
4. Data Sharing
We do not sell your personal data. We only share data in the following circumstances:
- With your consent: When you share a wedding project with collaborators, or publish a gallery to the people you choose to send it to
- Service providers: the processors listed below, each handling only what their part of the service requires
- Legal requirements: If required by law or to protect our rights
| Provider |
What they handle |
| Supabase |
Database, accounts and application hosting |
| Cloudflare |
Photograph and video storage, delivery and streaming |
| Amazon Web Services |
Face matching for photo search (Rekognition), where a photographer has switched it on |
| Stripe |
Subscription and print-order payments, and photographer payouts. Card details go to Stripe directly. |
| WHCC |
Printing and shipping. Receives the photographs ordered and the shipping address. |
| Resend |
Email delivery |
| Sentry |
Error reporting, with gallery links and personal details removed before sending |
| Google (Gemini) |
Reading uploaded documents into shot lists and timelines, in the planning app |
5. Your Rights
You have the right to:
- Access: View all data we have about you
- Export: Download your data in JSON format via Settings
- Correct: Update your profile information anytime
- Delete: Request account deletion via Settings (30-day grace period)
- Withdraw consent: Stop using the Service at any time
6. Data Retention
We retain your data for as long as your account is active. When you delete your account:
- 30-day grace period to recover your account
- After 30 days, all data is permanently deleted — including photographs, video and galleries
- Backups are purged within 90 days
Some things follow their own schedule:
- Face templates are deleted when the gallery they belong to is deleted, and when the account is deleted. They are not kept after the gallery is gone.
- Galleries deleted on their own sit in a trash for 30 days so they can be restored, then their photographs and face templates are permanently removed.
- Gallery visitors' details (email addresses, favourites, view history) are deleted with the gallery.
- Print order records are kept for as long as tax and accounting law requires, because they are records of a sale.
- If a subscription lapses or a gallery expires, nothing is deleted. Your photographs are kept for at least 12 months and you get at least 30 days' notice by email before anything is removed, as the Terms of Service set out. Galleries within the free allowance stay online throughout.
7. If You Are in Someone's Gallery
Most people who appear in a FOCL gallery never signed up for FOCL. You were photographed at a
wedding, and the photographer delivered those photographs through us. This section is for you.
The photographer decides what is in their gallery and who can see it. We host it on their behalf.
That makes them the controller of those photographs and us the processor, so the quickest route to
having a photograph taken down is to ask the photographer directly.
You can also come to us at privacy@getfocl.app to:
- Ask what we hold about you
- Ask for your face template to be deleted, or for your face to be excluded from photo search
- Ask for your email address and activity in a gallery to be deleted
- Object to how your information is being used
We will act on a face-data request without asking you to prove a subscription or an account, because
you will not have one. Where we need the photographer's involvement — deleting a photograph they own,
for instance — we will tell you so rather than leave the request unanswered.
Illinois, Texas and Washington residents
Face templates are biometric identifiers under the Illinois Biometric Information Privacy Act, the
Texas Capture or Use of Biometric Identifier Act and Washington's biometric privacy law. Where those
laws apply:
- We collect face data only to let people find themselves in one gallery, and for no other purpose.
- We do not sell, lease, trade or otherwise profit from biometric data, and we never will.
- We keep a face template only while the gallery exists. It is destroyed when the gallery is deleted, when the account is deleted, or within three years of the last interaction with that gallery, whichever comes first.
- We disclose face data to no one except Amazon Web Services, which performs the matching on our instruction and does not use it for anything else.
8. Cookies and Local Storage
FOCL uses minimal cookies and local storage:
- Authentication: Session tokens stored in local storage
- Preferences: Dark mode and UI settings
- Offline data: Cached project data for offline access
We do not use third-party tracking cookies or advertising cookies.
9. Children's Privacy
FOCL is not intended for users under 18 years of age. We do not knowingly collect information from children. If you believe a child has provided us with personal data, please contact us.
10. International Data Transfers
Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where required.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the app. The "Last updated" date at the top indicates when the policy was last revised.
12. Contact Us
If you have questions about this Privacy Policy or your data, please contact us:
13. For California Residents (CCPA)
California residents have additional rights under the CCPA, including the right to know what personal information is collected, request deletion, and opt-out of the sale of personal information. We do not sell personal information.
14. For EU/UK Residents (GDPR)
If you are in the EU or UK, you have additional rights under GDPR including the right to lodge a complaint with a supervisory authority. Our legal basis for processing is contract performance and legitimate interest as described above.