Papped Privacy Policy
Last updated: 12 August 2026
Papped ("Papped", "we", "us") is a service that lets event organizers collect photos, and short video clips where the organizer turns them on, from their guests, delivered straight to the organizer's own Google Drive. This policy explains what we collect, what we deliberately do not keep, and where your data goes.
The short version: we never keep your photos or your clips. They pass through us and land in the organizer's Drive. Photos are screened automatically on the way; the one exception to "never keep" is a photo held for the organizer's review, which we store encrypted for at most 48 hours and then delete. Video works differently and we say so plainly in section 3: a clip is never screened by a machine, it goes straight into the organizer's Drive, and it waits there until the organizer approves it by hand.
1. Who this covers
- Organizers: the people who create and pay for events. Our customers.
- Co-organizers: people an organizer invites to help manage an event.
- Guests: event attendees who scan the QR code and take photos. Guests never create an account.
2. What we collect
Organizers and co-organizers
- Google identity: your name, email address, and Google account identifier, received when you sign in with Google.
- Drive access token: an encrypted token that lets Papped create an event folder in your Google Drive and deliver photos into it. We use Google's
drive.filescope, which means we can only see and touch folders and files our app created. We cannot read the rest of your Drive. - Event details: event name, dates, guest count, photo pool settings, whether video is switched on and how many clips each guest may record, and any stickers or a watermark you upload for guests to use.
- Payment records: if you pay for an event, we keep records of what was bought (event, amount, date) for legal and accounting purposes. We never see or store your card details; payments are handled by our payment provider (see section 5).
Guests
- Guests are anonymous. No account, no email, no phone number.
- Optional display name: a guest may enter a name so the organizer knows whose shots are whose. It is optional and can be skipped.
- Session data: an anonymous session identifier, shots taken, clips recorded, upload records, and a last-active timestamp, so the roll limits, the clip allowance, and the organizer's guest list work.
- Photos: the photos a guest takes pass through our service for screening and delivery. See section 3 for exactly how long they exist on our side.
- Video clips, with sound: only if the organizer has switched video on. Recording a clip asks for microphone access on top of the camera, and the clip is recorded and delivered with its audio intact. We do not strip the sound, transcribe it, or analyze it. If you refuse the microphone, recording still works and the clip is simply silent. A clip is at most one minute long. See section 3.
Everyone
- Basic technical logs: our infrastructure providers keep standard server logs (IP address, request time) for security and abuse prevention.
- Product analytics, organizers only: on our marketing site and the organizer dashboard we record a short list of named actions - a page view, a click on "Start your event", opening the pricing section and the guest count it was set to, opening the demo, signing up, creating an event, launching it, starting a checkout. We record the organizer's account id with them, never your email or name.
- What travels with each of those events: the address of the page it happened on, with anything after the
?or#removed before it leaves your browser; your browser and device type; an approximate location worked out from your IP address, which our analytics provider sees because any request to it carries one; and an identifier for that browsing session that is discarded when you close the tab. This is standard technical data that accompanies every event, not something we ask for separately, and none of it is used to build a profile that follows you between visits. - The guest camera is never measured. Nothing on a
/e/link - the join screen, the camera, the gallery - sends anything to an analytics service. A guest scanned a QR at somebody's event; they did not come to us and they have no account with us. - One first-party marker, for attribution: when you click a "Start your event" button we note which button it was in your own browser's storage, and if you later sign up we record that on your account so we know which part of the page works. It is our own storage on our own domain, never shared, and it is cleared as soon as you sign up.
- We use no advertising cookies, and our analytics sets no cookie at all: it keeps nothing in your browser and nothing that outlives the tab, which is why you are not asked to consent to it. The only cookie we set is a short-lived one used to secure the Google sign-in and Drive connection flows.
3. Photos and clips: in transit only
This is the core of the product, so here it is precisely.
Photos
- A photo taken by a guest is uploaded to us, automatically screened, and delivered to the organizer's own Google Drive. We do not keep a copy.
- Photos rejected by the screen are never stored at all, not even briefly.
- If the automated screen flags a photo as borderline, or cannot screen it, it is held encrypted, for a maximum of 48 hours, so the organizer can approve or reject it. Approved photos are delivered to the organizer's Drive and the held copy is deleted. Rejected or unreviewed photos are deleted automatically.
- Photos in the shared event gallery are fetched from the organizer's Drive. To keep the gallery fast we briefly cache a copy at our CDN edge for up to one hour; that cache is purged the moment a photo is deleted or reported, and it is never a lasting store.
- The gallery is private to the event: every photo request requires a signed guest session or organizer credential scoped to that specific event.
- We do not use your photos to train AI models, and neither does our screening provider: automated screening uses Amazon Rekognition under an AI-services opt-out policy, which means Amazon does not retain the images or use them to improve its services.
Video clips
Video is off unless the organizer switches it on. When it is on, clips work differently from photos in ways that are worth stating plainly rather than burying:
- A clip is never screened automatically. There is no AI check on video at all. The only gate is a human one: the organizer watches the clip and approves or rejects it, and no guest can see it before they do.
- A clip is streamed through us directly into a "Pending review" folder inside the organizer's own Google Drive. We never store the video, not even briefly, and there is no 48-hour hold on our side because the file was never on our side. The honest consequence: from the moment a clip finishes uploading it is in the organizer's Drive and the organizer can watch it, before any approval and even if they later reject it.
- Approving a clip moves it into the event folder, and it appears in the shared gallery. Rejecting it deletes the file from the organizer's Drive permanently, not into the Drive trash.
- Clips keep their sound, exactly as recorded.
- An approved clip plays in the gallery streamed from the organizer's Drive through a short-lived signed link that expires in minutes. Unlike photos, clip video is never cached at our CDN; only the small preview frames are, on the same one-hour basis as photos.
- We do not use clips, or their audio, to train AI models, and we send them to no automated screening or analysis service.
We do not claim "zero storage ever": the 48-hour photo review hold described above is the single, deliberate exception. Everything else, video included, is in transit only.
4. How long we keep things
- Photos: not stored. Review holds: maximum 48 hours.
- Clips: not stored by us at any point. A clip awaiting approval sits in the organizer's Drive, so how long it stays there is the organizer's decision, not ours; rejecting it deletes it permanently. We hold only the record that a clip exists, which is event metadata and is purged on the schedule below.
- Event metadata (guest sessions including display names, upload and clip records, sticker/watermark files): deleted 30 days after the event ends. Aggregate numbers (how many guests joined, how many photos and clips were taken) stay on the event record so the organizer keeps their history.
- If an organizer deletes an event before it launches: its data is removed immediately. Events that have run are purged on the 30-day schedule above.
- Guest links: shooting stops when the organizer ends the event or shortly after its scheduled end (the organizer sets how long the link stays open, 24 hours by default); the shared gallery stays readable to guests until the 30-day purge.
- Drive access tokens: encrypted at rest, and deleted the moment you disconnect Drive or delete your account.
- Payment records: kept as long as law and accounting require.
- Organizer accounts: kept while you have an account; contact us to delete it (see section 8).
5. Who we share data with
We share data only with the services that make Papped work, and only what each needs:
- Google (sign-in and Drive): photos and clips are delivered to the organizer's Drive; the organizer's own Google account holds them from then on. Papped's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Amazon Web Services (Rekognition, US region): automated photo screening, with the AI opt-out described in section 3. Video is never sent to Rekognition, or to any other automated screening service.
- Cloudflare (US/global): hosting, content delivery, and the encrypted 48-hour photo review hold. Clip bytes pass through Cloudflare in transit on their way to and from the organizer's Drive and are not stored there.
- Neon (US region): our database (event and session metadata, never photos).
- Resend (US region): sends our transactional emails (event ready, payment receipts, photo review alerts, photo pool alerts, guest film requests, co-organizer invites, and post-event summaries). Our emails contain no tracking pixels or tracked links.
- Dodo Payments (merchant of record): processes payments and holds card details when you pay. As merchant of record, they issue the invoice and handle payment-related taxes.
- PostHog (EU region): product analytics for the named organizer actions in section 2. Configured with autocapture off, session recording off, and no cookies, so it records no action of yours beyond the ones named in section 2 - it does not watch clicks or replay sessions. Each of those events carries the standard technical data described there. It receives nothing at all from the guest camera.
- Zoho: hosts our support mailbox, so your emails to us live there.
We do not sell personal data, and we do not share it with advertisers.
International data transfers
Papped is operated from India, and the providers listed above are largely in the United States. If you use Papped from the EU, the UK, or anywhere else, your personal data is transferred to and processed in India, the United States, and the other countries where these providers operate. We rely on appropriate safeguards for these transfers (such as our providers' standard contractual clauses) and keep the personal data we process to a minimum.
6. The organizer's role
Photos and clips delivered to an organizer's Drive belong to and are controlled by the organizer. Once delivered, the organizer decides what happens to them, like any file in their own Drive. If you attended an event and want something removed, guests can delete their own photos, and their own clips once those are in the gallery, at any time until the gallery closes; deleting removes it from the gallery immediately and requests removal of the delivered file from the organizer's Drive. Reporting a photo or clip hides it from the gallery immediately pending the organizer's review. For anything else, the organizer is the right person to ask.
One limit worth being straight about: a clip that is still waiting for the organizer's approval cannot be withdrawn from the app by the guest who recorded it. It is already in the organizer's Drive by then, which is exactly why they can see it. If you want a pending clip destroyed, ask the organizer to reject it, which deletes it permanently, or email us at support@papped.co and we will help.
Video adds one responsibility that sits with the organizer, not with us: recording people, and their voices, at an event is theirs to notice and to comply with wherever they are. They choose whether video is on at all, and they see every clip before anyone else does.
7. Security
- Photos in the review hold are encrypted at rest, as are Drive access tokens.
- All traffic is encrypted in transit (HTTPS).
- Uploads are validated and rate-limited; event links expire; reports are rate-limited so a gallery cannot be abused into hiding.
- Clip playback runs on short-lived signed links tied to one specific clip and one specific viewer, so a link cannot be reused for anything else or shared onward once it expires. A clip still awaiting approval is reachable only by the organizer reviewing it.
- The credential we use for automated screening can do exactly one thing (screen an image) and nothing else.
- Access to production systems is limited to the two founders.
No system is perfectly secure, but we hold almost nothing: the most privacy-protective thing about Papped is how little of your data exists on our side at any moment.
8. Your choices and rights
- Guests: skip the display name, refuse the microphone and record silently (or not record at all), delete your own photos and your own gallery clips at any time until the gallery closes (for a clip still awaiting approval, see section 6), or simply stop using the link. Your session data is deleted about 30 days after the event ends.
- Organizers: switch video off for an event at any time, disconnect Google Drive at any time (we delete the token), cancel an unlaunched event (immediate removal), end an event early, or ask us to delete your account.
- Your rights, wherever you live: you can ask to access, correct, delete, or receive a copy of your personal data, and to object to or restrict how we use it; where we rely on consent, you can withdraw it. This applies globally, including the EU, UK, and California. Email support@papped.co and we will honor these rights within the timeframes your law requires. If you are in the EU or UK, you also have the right to complain to your local data protection authority.
- Analytics: guests are never measured, so there is nothing to opt out of. Organizers who would rather not be measured can use any browser setting or extension that blocks analytics requests - the product works identically with them blocked, and we do not detect or work around them.
- Legal basis (EU/UK): where GDPR or UK GDPR applies, we process personal data to perform our agreement with organizers (running events and delivering photos), on our legitimate interests in operating and securing the service - which is also the basis for the organizer-only product analytics in section 2, kept to named actions with no cookies and no tracking across sites - and on your consent for optional data (such as a guest display name) and for connecting your Google Drive.
9. Children
Papped is built for corporate and professional events and is not directed at children. Organizers are responsible for what happens at their events, including who attends.
10. Changes
If we change this policy, we will update this page and the date above. Meaningful changes will be flagged to organizers by email.
11. Contact
support@papped.co
Operated by the founders of Papped, based in India.