Privacy Policy

Last updated: April 2026

1. Who we are

Elbum is a photo sharing service operated by IdeaWorks ApS, a Danish company. Our registered address is in Denmark. If you have questions about this policy, contact us at support@elbum.app.

2. What data we collect

Account holders (hosts)

  • Email address and password (via Supabase Auth)
  • Name (optional, used on events)
  • Payment information β€” processed by Stripe; we do not store card details
  • Events you create and their settings

Guests (no account required)

  • Photos you upload to an event
  • Optional display name you choose when uploading
  • IP address and browser user-agent (for abuse prevention)
  • Anonymous session identifier (stored in a cookie)

All visitors

  • Standard server logs (IP, request path, timestamp) for security and debugging

3. How we use your data

  • To provide and operate the Elbum service
  • To process payments and manage subscriptions
  • To send transactional emails (account confirmation, password reset, receipts) β€” we do not send marketing email without consent
  • To prevent abuse and ensure platform security
  • To improve the service based on aggregated, anonymised usage patterns

4. Cookies

We use essential cookies to maintain your session. For full details, see our Cookie Policy.

5. Third-party services

We share data with the following third-party processors to operate the service:

ProcessorPurposeData shared
SupabaseAuthentication & databaseEmail, account data
CloudflareCDN, hosting, storage (R2)All data transits Cloudflare
StripePayment processingName, email, payment data
AdaptyMobile in-app purchasesUser ID, purchase data
Apple / GoogleSign-in (optional)Name, email (if you choose)

We do not sell your personal data to any third party.

6. Data retention

  • Event photos are stored for the duration you choose when creating the event (1, 3, or 6 months depending on your plan), then automatically deleted.
  • Account data is retained while your account is active and for 30 days after deletion to allow recovery.
  • Server logs are retained for up to 30 days for security purposes.

7. Your rights under GDPR

If you are in the European Economic Area (EEA), you have the following rights:

  • Right of access β€” request a copy of data we hold about you
  • Right to rectification β€” correct inaccurate data
  • Right to erasure β€” request deletion of your data
  • Right to data portability β€” receive your data in a portable format
  • Right to object β€” object to processing based on legitimate interests
  • Right to restrict processing β€” ask us to pause processing in certain circumstances

To exercise any of these rights, email support@elbum.app. We will respond within 30 days. You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk.

8. Data deletion

To delete your account and all associated data, go to Settings β†’ Delete Account in the app, or email support@elbum.app. Guest-uploaded photos are deleted automatically when the event expires, or can be removed by the event host at any time.

9. International transfers

We use Cloudflare (US-based) and Supabase (US-based) which may process data outside the EEA. Both operate under Standard Contractual Clauses (SCCs) and the EU–US Data Privacy Framework where applicable.

10. Children's privacy

Elbum is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it promptly.

11. Changes to this policy

We may update this policy from time to time. We will notify account holders by email of material changes. The date at the top of this page always reflects the latest revision.

12. Contact

IdeaWorks ApS, Denmark
Email: support@elbum.app