Privacy Policy
For the Albumbox app on iPhone and Android and for the website albumbox.app.
Last updated: October 9, 2026
This policy explains what data Albumbox processes, why, on what legal basis, who receives it and how long it is kept. In German, the same app is called “Fotokiste” (fotokiste.app). It is the same app from the same company, and this policy covers both. The German version is at https://fotokiste.app/datenschutz.
In short
Your photos stay on your phone unless you share an album or have a photo restored. The app detects, crops and enhances your photos on the device. An account is optional. There are no ads, no tracking and no analytics.
Data only goes to service providers when you share an album by link, have a photo restored, sign in, buy something or email us. Buying includes the app checking at startup whether you have Albumbox Plus. All it sends for that is a random ID without your name.
“Delete my data” in the settings deletes your data on our server and on your device.
Who is responsible
The controller is PL Core GmbH, Rohrbacher Str. 5/7, 69115 Heidelberg, Germany.
Represented by its managing director, Philipp Längle
Email: hello@albumbox.app
More details are in our imprint at https://albumbox.app/imprint.
Data protection officer
We have not appointed a data protection officer. [check: whether we are required to appoint one; if so, add name and contact here]
For any privacy question, email us at hello@albumbox.app.
What stays on your device
The app stores your photos and albums only on your device. This includes any title, date, place and description you add. Detecting the photos on an album page, cropping, straightening, enhancing and refreshing the colors of color photos also happen on the device. None of this reaches us.
To turn photos the right way up, the app looks for faces in the picture on your device. It does not recognize who is in the picture. This information never leaves your device. [check: On Android, face detection comes from Google (ML Kit). According to Google, ML Kit may send usage and performance data, but no images, to Google. Confirm and then state it here.]
On iPhone, the photos in the app are part of your device’s iCloud backup if you have it turned on. Your agreement with Apple covers that. If you delete the app, the photos in the app are gone unless you saved them first.
The app keeps a few small items in your device’s protected storage: the Keychain on iPhone and the Keystore on Android. These are a counter of how many photos you have saved or sent from the app, and the access key to an anonymous account if there is one (see “Anonymous account”). None of this contains photos.
Legal basis: This data does not reach us. Storing it on your device is strictly necessary for the app to work (Section 25(2) no. 2 of the German TDDDG). To the extent we process any data here at all, the legal basis is Art. 6(1)(b) GDPR, because you want to use the app.
Permissions on your device
The app only asks for the permissions it needs. You decide in your system’s prompt, and you can revoke any permission later in your device settings.
Camera. The app uses the camera only to photograph your album pages. The pictures stay on your device.
Photos app and gallery. On iPhone, the app only asks for “Add Photos Only” access. That lets it save photos to your Photos app, but it cannot see the photos you already have. On Android up to version 12, the app needs write access to save photos to your gallery. From Android 13 on, it needs no permission for that.
Importing pictures. For this, the app opens your system’s photo picker. The app only sees the picture you choose there.
Share menu. When you send photos or a PDF photo book through your system’s share menu, they go to the app you pick there, such as your email app. We are not involved. The PDF photo book is created on your device.
Signing in
An account is optional. You only need one to restore photos. You can sign in with Apple, with Google or with a code sent by email.
Why: So we can link your shared albums, your credits and your restoring jobs to you, including on a new device.
What data: Your email address, the ID that Apple or Google assigns to you, and your name if Apple or Google send it. Also the times you registered and signed in. With the email code, we also store the app’s language.
Legal basis: Art. 6(1)(b) GDPR. You create the account to use these features.
Recipients: Supabase, our server provider. The data is stored in a data center in Ireland (EU). When you sign in with Apple or Google, Apple or Google are involved too, and their privacy policies apply.
How long: Until you delete your account with “Delete my data”. Signing out alone does not delete the account.
Sign-in code by email
Why: So you can sign in without a password, we email you a six-digit code.
What data: Your email address, the code and the app’s language, so the email arrives in your language.
Legal basis: Art. 6(1)(b) GDPR.
Recipients: Supabase creates the code. The email is sent through Resend (Resend Inc., USA) from a data center in Ireland (EU). For transfers to the USA, see “Service providers outside the EU”.
How long: Resend keeps a sending log. [check: retention period at Resend]
Sharing an album by link
With Albumbox Plus you can share an album by link. To do this, we upload a copy of the album to our server.
Why: So the people you send the link to can view and download the album in their browser, without the app and without an account.
What data: The album’s photos in the version your app currently shows. The album’s title, year, place and description. Each photo’s date, description and text from the back, where you added them. Your name from your Apple or Google account, if there is one, for the “shared by” note. We also count how often the album was viewed and downloaded. You see these numbers in the app.
Legal basis: Art. 6(1)(b) GDPR. You want to share the album, and that is not possible without a copy on the server.
Recipients: Supabase, storage and database in Ireland (EU). Anyone who has the link can see and download the photos.
How long: Until you delete the link, delete the album in the app or choose “Delete my data”. We then delete the copy on the server, and the link stops working right away. If your Plus ends, the copy stays and the link only shows a notice. Once Plus is active again, the same link works again.
Protection: The link contains a random 144-bit ID that cannot be guessed. We only store it encrypted. The album page does not appear in search engines and is not listed anywhere.
For visitors to an album page
This section is for people who open a shared link in their browser.
Why: To show you the album, to offer the download as a ZIP file and to slow down misuse.
What data: When you open the page, your browser sends technically necessary information, mainly your IP address, the time and your language setting. The page picks its language from that setting. To stop anyone loading the page too often in a short time, the server briefly counts requests per IP address in memory, without storing them. For the album’s owner, we only count how often the album was viewed and downloaded. We do not store who it was. The page sets no cookies and uses no analytics. [confirm for the future website] For server logs, see “Server and access logs”.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest, and the owner’s, is to show the album reliably and securely.
Recipients: Supabase (EU). Your browser loads the photos directly from our storage at Supabase, through addresses that expire after one hour. [check: once the website is live, also name the hosting provider]
How long: The counts are kept as long as the link exists.
Reporting content. On the album page, “Report content” lets you report content you believe is illegal. It opens an email to us that includes the link’s ID. We review reports under the EU Digital Services Act. The legal basis is Art. 6(1)(c) GDPR together with Art. 16 of Regulation (EU) 2022/2065. Your email is handled as described under “Support emails”.
Anonymous account
You can create a link without signing in. But every link needs an owner, so that only you can manage and delete it. That is why the app quietly creates an anonymous account the first time you create a link without signing in. It contains no email address and no name.
Why: So your link belongs to you and you can delete it later.
What data: A random ID and timestamps. The app keeps the access key to this account in your device’s Keychain or Keystore, so it can find your links again after you reinstall.
Legal basis: Art. 6(1)(b) GDPR.
Recipients: Supabase (EU).
How long: As long as a link belongs to the account. We automatically delete an anonymous account without a link once it is 30 days old. If you sign in later, your account takes over the anonymous account and its links. Your purchase is then linked to your account as well.
Restoring photos
Restoring removes scratches and tears, or adds color to black-and-white and sepia photos. This is done by automatic image processing using machine-learning models on our service provider’s servers. You need an account for this, and each photo costs one credit. Color photos, on the other hand, are refreshed by the app on your device, and nothing is sent to us. Your original always stays on your device.
Why: To process the one photo you selected and deliver the result to you. After a repair, our server compares before and after. If the photo had hardly any damage, you get your credit back.
What data: The one photo in the version your app currently shows, the type of job (repair or colorize) and your credit balance. For each job we store its type, status and timestamps.
Legal basis: Art. 6(1)(b) GDPR. You place the order, and it cannot be carried out without the transfer.
Recipients: The photo first goes to private storage at Supabase in Ireland (EU). From there we pass it to Replicate (Replicate, Inc., USA) through an address that expires after one hour. Replicate runs the image processing: the “Dust and Scratch v2” model by Topaz Labs for repairs and the “DDColor” model for colorizing. [check: whether Replicate passes the photo on to Topaz Labs for repairs; if so, list Topaz Labs as a recipient with location and transfer basis] The transfer is encrypted. For transfers to the USA, see “Service providers outside the EU”.
How long: If you keep or discard the result, we delete the photo and the result on our server immediately. The same applies if the job fails or you cancel it. Otherwise we delete both after 7 days. That way the result still arrives if the app was closed in between. Replicate deletes its copy under its own rules. [check: retention at Replicate; according to Replicate, data from API jobs is deleted after a short time] The job details, without the photo, stay with your account until you delete it.
Purchases and subscriptions
You buy Albumbox Plus through Apple’s App Store or Google Play, and you top up credits there too. Payment happens only there. We never see your payment details.
Why: To check whether you have Plus, to unlock and restore purchases and to add credits you top up. For this, the app asks RevenueCat at every startup whether Plus is active.
What data: A random ID that RevenueCat assigns to your app, or, after you sign in, your account ID. Also receipts and your subscription status from Apple or Google. [check: which device data the RevenueCat SDK also sends, such as device model, OS version, language and IP address] On our server, we store for your account whether Plus is active, which plan you have and until when. That is how your shared links know whether they are valid.
Legal basis: Art. 6(1)(b) GDPR. Without this check we cannot unlock Plus and credits for you.
Recipients: RevenueCat (RevenueCat, Inc., USA). Apple and Google handle the purchase as independent controllers under their own privacy policies. Supabase (EU) stores your Plus status with your account.
How long: At RevenueCat, as long as your purchases exist and under RevenueCat’s rules. [check: retention period at RevenueCat] On our server, until “Delete my data”.
You cancel a subscription in your Apple or Google account. The app takes you there from your profile and the settings.
Credits
Why: To keep your balance correct. We add credits you top up, use one credit when a job starts and give it back if the job fails, is canceled or the photo had hardly any damage. When Plus starts, you get 3 credits as a gift.
What data: Your balance and each booking with its reason, time and the store transaction ID or job ID. This ID makes sure nothing is booked twice.
Legal basis: Art. 6(1)(b) GDPR.
Recipients: Supabase (EU).
How long: Until “Delete my data”. Credits never expire, so the balance is kept until then.
Support emails
Why: To answer your questions.
What data: Your email address, your name if you give it, and what you write. When you write to us from the app, the app adds your device, OS version, app version and language to the message, so we can help faster. The app never attaches photos. You see this information before sending and can delete it.
Legal basis: Art. 6(1)(b) GDPR when your question is about using the app or a purchase. Otherwise Art. 6(1)(f) GDPR; our legitimate interest is answering questions.
Recipients: Our mailbox is at Zoho Mail in a data center in the EU. [check: contracting entity and location at Zoho] Emails to addresses at fotokiste.app, the German version of the app, are forwarded to this mailbox by ImprovMX. [check: operator, location and place of processing at ImprovMX] We reply from hello@albumbox.app.
How long: As long as we need the email for your request. [set retention period]
Server and access logs
Why: To run our server and keep it secure, for example to find errors and fend off attacks.
What data: For every request to our server, Supabase logs the IP address, the time and which part of the server was called. This applies to app users and to visitors of an album page.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is secure and stable operation.
Recipients: Supabase (EU).
How long: [check: retention period at Supabase]
Store ratings
Now and then the app asks you for a rating. The rating window comes from Apple or Google. The app does not learn whether or how you rate it. We receive no data from it. On your device, the app only remembers when it asked and how you answered. Apple’s and Google’s privacy policies apply to the rating itself.
Website albumbox.app
Why: To show you the pages of the website.
What data: When you open a page, your browser sends technically necessary information, mainly your IP address, the time, the page you open and your browser type. Our hosting provider Vercel processes it to deliver the pages and to protect the website from misuse. [check: what Vercel logs and for how long] The website sets no cookies and loads no content from other providers; fonts are served from our own server.
Visitor statistics: We count page views with Umami, without cookies and without profiles. Umami receives the page you open, the page you came from, your browser type, your operating system, your screen size and the country it derives from your IP address. The IP address itself is not stored. No statistics run on the shared album pages under /s/.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is to provide the website securely and reliably and to learn which pages are visited.
Recipients: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA (hosting, servers in Frankfurt); Umami Software, Inc., USA (statistics) [check: server location of Umami Cloud]. [check: agreements under Art. 28 GDPR and the basis for transfers to the USA]
How long: We keep statistics without personal reference indefinitely. [check: log retention at Vercel]
People in your photos
Old photos often show other people, such as your family. As long as the photos stay on your device, none of this reaches us. When you share an album or have a photo restored, we also process the images of these people. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest, yours and ours, is that you can share and repair your family photos. We do not analyze who is in a photo.
Service providers at a glance
These service providers process data on our behalf. We have data processing agreements with them under Art. 28 GDPR. [check: signed with every provider in the table] They may only process the data as we instruct.
| Provider | What for | Based in | Where the data is stored |
|---|---|---|---|
| Supabase [check: contracting entity, probably Supabase, Inc.] | Server for accounts, shared albums, credits, restoring and logs | [check: probably USA] | Data center in Ireland (EU) |
| Resend Inc. | Sending sign-in codes | USA | Sent from Ireland (EU) |
| Replicate, Inc. | Automatic image processing for restoring | USA | [check] |
| RevenueCat, Inc. | Checking purchases and subscriptions | USA | [check] |
| Zoho Mail [check: contracting entity] | Email mailbox | [check] | Data center in the EU |
| ImprovMX [check: operator] | Forwarding emails sent to fotokiste.app | [check] | [check] |
| Vercel Inc. | Website hosting | USA | Servers in Frankfurt (EU) [check] |
| Umami Software, Inc. | Website visitor statistics, without cookies | USA | [check: server location] |
Apple and Google do not act on our behalf. For purchases, for signing in with their accounts and for the rating window, they are independent controllers under their own privacy policies. [check: name the relevant contracting entity in the EU]
Service providers outside the EU
Some service providers are based in the USA: Resend, Replicate, RevenueCat, Vercel and Umami. [check: also Supabase] This means data may be transferred to the USA or be accessible from there.
The transfer is based on [check for each provider: the EU-US Data Privacy Framework, i.e. the European Commission’s adequacy decision under Art. 45 GDPR, or the European Commission’s Standard Contractual Clauses under Art. 46(2)(c) GDPR]. You can get a copy of these safeguards by emailing hello@albumbox.app.
No ads, no tracking, no automated decisions
The app shows no ads. It uses no analytics services, no tracking and no crash reporting tool. It does not keep track of what you do in the app. That is why Apple’s prompt asking whether apps may track you across other apps never appears.
We do not build profiles about you. We make no decisions based solely on automated processing that have legal or similarly significant effects on you (Art. 22 GDPR).
Delete my data
You find “Delete my data” in the app’s settings. Before anything happens, the app tells you exactly what will be deleted.
If you have an account, including an anonymous account, we delete your account, your shared albums and your credits on our server. Your links stop working right away. [check: whether backups at Supabase still contain the data afterwards, and for how long] On your device, the app deletes everything, including your albums and photos. Only the counter in your device’s protected storage remains (see “What stays on your device”). It contains no photos and no names and never leaves your device.
This does not end a running subscription. Cancel it first in your Apple or Google account. Your purchases stay on record with Apple or Google and with RevenueCat. If you want us to have your data deleted at RevenueCat, email us.
If you only delete the app, your account, links and credits remain on our server. If you no longer have the app, email us at hello@albumbox.app and we will delete your account.
Your rights
Under the GDPR you have these rights:
| Right | What it means |
|---|---|
| Access (Art. 15 GDPR) | You can find out what data we hold about you. |
| Rectification (Art. 16 GDPR) | We correct inaccurate data. |
| Erasure (Art. 17 GDPR) | We delete your data when there is no longer a reason to keep it. |
| Restriction (Art. 18 GDPR) | We block your data instead of using it, for example while we check whether it is accurate. |
| Data portability (Art. 20 GDPR) | You receive data you gave us in a common format. |
| Objection (Art. 21 GDPR) | You can object to processing based on Art. 6(1)(f) GDPR (see below). |
| Withdrawing consent (Art. 7(3) GDPR) | You can withdraw consent at any time for the future. |
| Complaint (Art. 77 GDPR) | You can complain to a supervisory authority. |
If we correct, delete or restrict data, we also tell the recipients (Art. 19 GDPR).
At the moment, none of our processing is based on consent. You can revoke access to the camera and to the Photos app or gallery at any time in your device settings.
How to use your rights. Email us at hello@albumbox.app. Please include the email address of your account so we can find you. You can also delete your data on our server and on your device yourself with “Delete my data”. Without an account, we usually hold no data that we could link to you (Art. 11 GDPR).
Complaints. You can complain to any data protection supervisory authority, in particular in the EU country where you live or work. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg), Heilbronner Straße 35, 70191 Stuttgart, Germany, https://www.baden-wuerttemberg.datenschutz.de.
Your right to object
Where we process data based on Art. 6(1)(f) GDPR, you can object at any time on grounds relating to your particular situation. We will then stop processing that data, unless we can show compelling legitimate grounds that override your interests, or we need the data to establish, exercise or defend legal claims. An email to hello@albumbox.app is enough.
Do you have to give us data?
No. Scanning, albums and all free features work without an account and without any data being sent to us. Only sharing by link, restoring, buying and signing in need the data required for them.
Children
The app is mainly intended for adults. It does not check anyone’s age. It is meant for people aged [16] and over. Younger users need their parents’ consent. [confirm, same as in the terms of use] If you believe we are processing a child’s data without this consent, email us and we will delete it.
Security
The app only transfers data encrypted. Photos for restoring are kept in private storage that is not publicly accessible. Shared albums can only be opened by people who have the link.
Changes to this policy
We update this policy when the app, a service provider or the law changes. The version published at https://albumbox.app/privacy applies.
Last updated: October 9, 2026
