Privacy
Last updated 10 June 2026 · plain English on purpose
What we collect
From hosts: an email address (for sign-in links and album notices) and payment records handled by Stripe; card details never touch our servers. From guests: the name you type with your uploads and the photos and videos themselves. We also keep short-lived technical logs (like IP addresses on sign-in requests) to prevent abuse.
Where it lives and who sees it
Everything is stored on Cloudflare's infrastructure. Albums are private: photos are only served to people who have the album's link and passphrase (or uploaded to it). We don't sell data, run ads, or share content with anyone except the services that make the product work (Cloudflare for hosting and email, Stripe for payments).
Deletion is real
Albums have an expiry date. After the post-expiry grace period, photos and videos are permanently deleted from storage, not archived. Hosts can also delete any upload, or an entire album's contents, at any time. To have your account or a specific photo removed, email hello@shotbyeveryone.com.
Cookies
We use a small number of strictly functional cookies: one to keep a host signed in and one per album to remember that a guest unlocked it. No tracking, no analytics cookies, no third-party pixels.