How 10AM handles event photos and guest data.
Last updated: August 5, 2026.
1. Controller
AMRV GbR, An Lyskirchen 7, 50676 Köln, Germany is responsible for processing your personal data. Contact: support@10am.cam.
2. What we collect
Depending on how you use 10AM, we process account details such as your email address and authentication identifier; an email address and consent record when you join the Android availability waitlist; event setup details; guest session identifiers and nicknames; short-lived one-way hashes used to transfer the same guest session from a computer to a phone; a random essential gallery-report scope that is stored only as a one-way event-specific subject with reports; uploaded photos and related metadata; photo reports and moderation information; push-notification installation, device-token, subscription, and delivery state; timestamps; technical logs; minimal internal product-interaction analytics; and support messages when you contact us. During an interrupted browser upload, a temporary photo copy and upload state may also be held in the browser’s IndexedDB. Guest data can be linked to an account where a guest is signed in.
Before a photo can enter a shared album, we create a reduced, metadata-free copy for automated content-safety classification. We retain the allow or reject decision, limited category scores, the version of the 10AM decision policy, check time, and a SHA-256 digest used to prove that the checked image matches the finalized image. A rejected photo does not enter the album.
When you buy capacity for an event in the iOS app, Apple provides a signed StoreKit transaction for server-side verification. We process the Apple transaction and original-transaction identifiers, product identifier, app-account token, StoreKit environment, purchase and signature timestamps, and the resulting event-credit state. We retain a SHA-256 verification digest rather than the signed transaction body. If Apple supplies later refund or revocation information, we may also record its status and timestamp. We do not receive or store your full payment-card details.
For an account that uses Sign in with Apple as its login, the server verifies and encrypts Apple’s identity, refresh, and access tokens so it can validate the credential at most once per day, respond to revocation, and revoke Apple access when you delete the account. These credentials are server-only and are deleted with the account or when the verified Apple state requires removal. When an Apple web login opens an existing account that uses another verified login provider, the fresh Apple grant is revoked and the transient Apple identity is removed instead; no app-managed Apple credential is retained.
3. Why we use it
We use this information to create and manage events, let guests join with a link or QR code, receive and display event photos, provide reveal and gallery features, send film-ready notifications you enable, send the Android availability notice you explicitly requested, verify Apple in-app purchases and issue single-event capacity credits, keep accounts signed in, prevent abuse, secure the service, measure product reliability with internal analytics, and provide support. We do not currently use third-party marketing or advertising analytics.
4. Legal bases
Depending on the processing activity, we rely on the performance of the service and our contract with you, consent where it is explicitly requested, our legitimate interests in security, service reliability, and minimal internal product analytics, and applicable legal obligations.
5. Photo visibility
Event photos stay hidden until the reveal time. After reveal, anyone with the valid gallery link may be able to view and download the album unless access is changed or the event is deleted.
You can report a photo through the in-app report action or report a gallery by emailing support@10am.cam. We process the report and related correspondence to review content, protect people, and comply with legal obligations.
Automated safety checks can make mistakes. If your photo is rejected and you believe this was incorrect, contact support@10am.cam; do not send sensitive image attachments unless support specifically asks for them through a secure process.
6. Storage and processors
The web application and production server functions are hosted by Vercel. The Supabase project used for the database, authentication, storage, and internal product analytics is hosted in Central EU (Frankfurt, eu-central-1). Vercel production server functions are configured for Frankfurt (fra1). Before storage, a reduced metadata-free JPEG sample of an uploaded photo (at most 1 MiB) is sent through Google Cloud Vision’s EU endpoint for SafeSearch classification; the online API returns safety-likelihood labels and the application does not ask Google to persist the sample. Account emails — address confirmation, password reset, and recovery — are delivered by Resend; your email address and the message are processed there, and Resend stores delivery metadata and logs in the United States. Support correspondence sent to support@10am.cam is handled through Google’s email service. Apple processes Sign in with Apple, App Store in-app purchases and refunds, and Apple Push Notification service delivery under Apple’s own terms and privacy policy. We do not currently use a third-party advertising or marketing-analytics provider. These service providers may process data according to their applicable terms, data processing agreements, and subprocessors.
Provider information: Vercel Data Processing Addendum, Supabase Data Processing Addendum, Google Cloud Vision Data Usage FAQ, Google Cloud Data Processing Addendum, and Resend Data Processing Addendum.
7. International transfers
Account emails are delivered by Resend, which stores delivery metadata and logs in the United States; that transfer rests on the Standard Contractual Clauses in Resend’s data processing agreement and on Resend’s certification under the EU-US Data Privacy Framework. Beyond that, Vercel distributes static content through a global delivery network, and our providers may use subprocessors or operational services in countries outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on an applicable legal transfer mechanism and safeguards under the relevant provider agreement, such as an adequacy decision or Standard Contractual Clauses where applicable.
8. Retention and deletion
Accounts are retained until you delete them. A deletion request immediately freezes access and new account-owned writes. Because a photo-upload link issued shortly beforehand can remain valid for up to two hours, we keep the deletion manifest for that window plus a short safety margin, sweep storage again, and only then remove the relational account and authentication record; the scheduled worker resumes interrupted cleanup. If Sign in with Apple is the account’s only login and Apple notifies us that you revoked consent or permanently deleted your Apple Account, we treat that verified notice the same way. On the web, when Apple shares a verified email with an account that uses another login provider, the verified sign-in flow revokes the fresh Apple grant, removes the transient Apple identity, stores no app-managed Apple credential, refreshes the session, and opens the existing account. Native Sign in with Apple continues to require a retained, revocable Apple credential. Every event created under the current free or per-event model—including events with paid capacity for 25, 100, 250, or 500 guests—is scheduled for deletion 30 days after its reveal. The daily cleanup removes the event record, photos and thumbnails, gallery and guest-participation data, and event-linked analytics, reports, and notification records, ordinarily during the next cleanup cycle. A capacity purchase changes only the guest limit; it does not extend storage. Data may be deleted earlier when an account or event is deleted or when deletion is required by law.
A narrow grandfathered exception applies only to events marked as legacy and hosted by an account with a still-valid legacy lifetime entitlement. Those legacy events may remain without a fixed expiry. This exception is not a current product, is not created by a per-event purchase, and does not apply to newly created events.
After an event is physically deleted, we retain a minimal expired-link record for 90 days so an existing valid gallery link can say when the roll was deleted. It contains a one-way event-link hash, the event name, a one-way gallery-secret hash, the deletion reason, and deletion and expiry dates; it contains no raw link or secret, event or host identifier, photo, or participant data. Account cleanup directly removes hosted events without creating a new expired-link record. A record created by an earlier event deletion cannot be linked back to an account and remains until its own 90-day expiry. One-time computer-to-phone handoff links expire after ten minutes and are deleted when used; only a one-way hash is held server-side and expired hashes are removed by scheduled cleanup. Purchase-verification and event-credit records remain associated with your account until the account is deleted. An unused event credit remains until it is used or the account is deleted. Once a credit is used, deleting the event removes the link to that event, but a limited record that the one-time credit was consumed, including the consumption time, remains until the account is deleted. This prevents the consumed credit from becoming available again when the event is deleted or the same Apple transaction is processed again. Apple controls its separate App Store transaction and refund records. Android waitlist email and consent records are retained until the availability notice is sent, you withdraw consent, or the waitlist is discontinued. Each event uses a separate essential guest-session cookie; no anonymous session token is reused across unrelated events. A cookie may remain in a browser for up to 180 days, but this does not extend the server-side retention period for expired event data. Temporary browser upload data is removed after the upload is completed or the local queue is cleared.
9. Your rights
You may have rights to access, correct, delete, restrict, or receive a copy of your personal data, and to object to certain processing. Where processing is based on consent, you may withdraw that consent at any time. Contact support@10am.cam to exercise your rights. You also have the right to lodge a complaint with a data protection supervisory authority.
