Privacy
What we collect, and what we don't
Last updated 31 July 2026
Disposabl turns an event into one shared disposable camera. This page explains exactly what data that involves, who touches it, and how to get rid of it. It describes what the product actually does today — not what it might do later.
The short version
Guests don’t need an account and we never ask them for an email address. Hosts sign in, so we hold an email for them. Photos live in the event they were shot for and are visible to the people in that event. We don’t sell data, we don’t run ad tracking, and we don’t use your photos to train anything.
Who this covers
Disposabl has two kinds of people, and they are treated differently on purpose.
Hosts
Create and pay for events. Hosts sign in with Google, Apple, or an emailed one-time code, so we hold an account for them.
Guests
Join an event by QR or link and shoot the roll. Guests are accountless — there is no sign-up, no password, and we do not ask for an email address. Joining creates a per-event identity so your frames can be attributed to you inside that one event, and nothing more.
What we collect
Account details (hosts only)
Your email address, and — if you sign in with Google or Apple — the name and avatar those services return, plus the account identifier they use to recognise you next time. Signing in with Apple’s private relay means we only ever see the relay address.
Photos
The frames you shoot, stored as the original file plus the developed film-look render the server produces. We also store the image dimensions and the time the frame was taken.
Event details
The event title, its join code, the film look, the roll size, the reveal time, and who joined.
Push notification tokens
If you allow notifications, the device token needed to tell you an album has developed. That token is tied to the identity that registered it, so one phone can hold a separate token for each event it joins.
Purchases
When a host buys capacity for an event we keep an order record: what was bought, the amount and currency, and the payment provider’s transaction identifier. We never see or store your card details — payment happens inside Stripe, the App Store, or Google Play.
Reports and blocks
If you report a photo or block another guest, we keep that record so moderation works and stays auditable.
What we don't collect
We don’t ask for your contacts, your calendar, or your photo library — the camera writes only into the event’s roll. We don’t track you across other apps or websites, we don’t run advertising SDKs, and we don’t sell or rent personal data to anyone.
The album images we serve are re-rendered by our server, and that render does not carry the embedded metadata from the original file — so the location tags a camera may write are not present in the photos other people see. The private original is retained as your device uploaded it.
Who can see your photos
A roll is shared by design. Frames you shoot become part of that event’s album and are visible to the other people in that event once it develops. Nothing is visible to anyone — including us, in the product — before the reveal time; that wait is the point of the product.
Albums are not public. They are reachable only through the event link or QR code, and the server refuses to serve an album before its reveal time. Staff can access photos when responding to a report or a legal obligation, and every such action is logged.
Who processes data for us
We use a small number of infrastructure providers. They process data on our instructions in order to run the service, and nothing more.
Cloudflare (R2, CDN)
Stores and delivers photos.
Neon (PostgreSQL) and Railway
Hosts the database and the API.
Vercel
Hosts this website.
Resend
Sends sign-in codes and service email.
Google Firebase
Delivers push notifications.
Stripe, Apple, Google
Process payments. Which one depends on where you bought.
How long we keep it
Photos and event data are kept for as long as the event exists, so the album stays available to the people who were there.
Order records outlive the account that created them. We are required to retain proof of a transaction for financial reconciliation and tax purposes, so when an account is deleted the order is detached from it and kept with the email address recorded at the time of purchase.
Deleting your data
Hosts can delete their account from the app’s settings. Deletion is immediate and permanent — there is no recovery window. It removes your account, your push tokens, your event memberships, and your blocks.
Photos you shot stay in the albums of events you joined, attributed to nobody. This is deliberate: a shared roll belongs to everyone who was in the room, and removing one person’s frames would punch holes in other people’s memories of the night. If you want your frames gone as well, delete them individually before deleting your account.
One restriction: you cannot delete your account while you are still hosting an event that has not yet revealed, because guests may still be shooting or waiting on a reveal that only you can control. Develop the event first, then delete.
Guests have no account to delete. To have your frames removed from an event, write to us at the address below. Full details are on the data deletion page.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, or ask us to restrict how we use it. Write to us and we will action it — we may need to confirm you control the account first.
We operate from the United States and our providers process data in the United States and Europe. Where the law requires a safeguard for that transfer, we rely on standard contractual clauses with our providers.
Children
Disposabl is not intended for children under 13, and we do not knowingly collect their personal data. If you believe a child has used the app, write to us and we will remove the data.
Changes
If we change how we handle data we will update this page and move the date at the top. Material changes will be signalled in the app rather than made quietly.
Contact
Questions about privacy, or a request about your data:
abuse@disposabl.appWe aim to respond within one business day.