Legal

Privacy Policy

Last updated: June 2026

Who we are

RealTime.Photos is a live event photo sharing platform operated by Nanjing Zhiyin Trading Co., Ltd., reachable at hello@realtime.photos.

This policy explains how we process personal data in two distinct contexts: (1) data we collect about photographers who hold an account with us, and (2) data processed on behalf of photographers about their event guests. For guest data, photographers are the data controllers and RealTime.Photos acts as their data processor — a relationship governed by our Data Processing Agreement.

The short version

Guests leave no trace. We do not store, retain, or transmit any personal data about event guests. Guest selfies taken for face matching are processed in memory and discarded immediately — they never touch a database or permanent storage.

Photographer accounts require only your name and email address to operate. We store the minimum needed to run your account and manage your events.

All event data is automatically deleted. On standard plans, photos, face data, and event records are purged within a fixed window of your event's first photo (see Data retention below). Contract-based plans (Custom tier and agency accounts) follow the retention terms set out in the contract instead. In every case, biometric face data is deleted no later than 12 months after the first photo is uploaded, regardless of plan.

We do not sell your data. We never sell, rent, or share personal data with third parties for advertising or marketing purposes.

Data we collect

Photographer accounts. When you create an account or sign in, we collect your name and email address via our authentication provider (Clerk). We use this to identify your account, send transactional communications (such as payment receipts and data deletion warnings), and manage your events.

Event guests. We collect no personal data about guests. Guests browse galleries anonymously — no account, email, or login is required. Like counts are stored against photo IDs with no user identifier attached. Sort preferences and liked photo IDs are stored in your browser's local storage only and never leave your device.

Demo and contact requests. If you submit a demo request or contact form, we collect your name and email address to respond to your inquiry, processed via Formspree.

Website analytics. We use Vercel Analytics — a cookieless, privacy-first analytics tool that collects no personally identifiable information and sets no cookies — to understand general traffic patterns such as pages visited and session duration.

Lawful basis for processing

Under the GDPR and equivalent applicable law, we rely on the following lawful bases for processing photographer account data:

  • Contract performance (Article 6(1)(b)): Processing your name and email to operate your account, send transactional emails (receipts, deletion warnings), and provide the service you signed up for.
  • Legitimate interest (Article 6(1)(f)): Cookieless website analytics to understand and improve the platform; responding to demo and contact requests; displaying customer names and logos in marketing materials (subject to opt-out — see our Terms of Service, Marketing Use section).
  • Legal obligation (Article 6(1)(c)): Retaining financial and billing records as required by applicable tax and accounting law (typically 7 years in Spain).

Providing your name and email address is a contractual requirement to create and use a photographer account — without it, we cannot provide the service. You are under no statutory obligation to provide this data.

For the processing of guest personal data (including biometric face data), the photographer is the data controller and is responsible for establishing a lawful basis — including an Article 9(2) basis for biometric special-category data. This is set out in our Data Processing Agreement.

Face recognition

RealTime.Photos uses Amazon Rekognition (operated by Amazon Web Services) to detect and match faces in event photos. Because this involves biometric data — a special category under GDPR Article 9 — we are fully transparent about how it works:

  • When a photo is uploaded, faces are detected and assigned a unique identifier and bounding box position. Faces that are too small or low quality are automatically ignored.
  • Similar face identifiers are grouped into clusters. Each cluster has a representative image crop — a small region of a photo showing the face. Clusters carry no names, identities, or personal attributes.
  • When a guest takes a selfie to find their photos, the image is sent directly to the face recognition service for matching. The selfie is discarded immediately after the result is returned — it is never stored in any database, file system, or log.
  • Numerical face representations (embeddings) used for matching are stored in a per-event index and deleted permanently when the event data is purged.

Face clusters are used solely to help guests find photos of themselves. They are not used for identification, surveillance, or any purpose beyond navigating event photos.

Demographic analytics (aggregate-and-delete). Rekognition also captures per-face quality signals (sharpness, brightness) and, during photo processing, demographic indicators (estimated age range, gender) and emotion signals (smile, emotion classification). These raw per-face attributes are stored transiently — for up to 48 hours after the last photo upload — to allow photographer clean-up tools (removing blurry faces, merging duplicate clusters) to complete before aggregation runs. The 48-hour window exists because this review improves the accuracy of the resulting statistics; if the photographer completes all clean-up earlier, aggregation and deletion happen immediately. Once clean-up is done, or after 48 hours, the raw attributes are permanently deleted and replaced by aggregate event-level statistics (e.g. total people detected, gender distribution, age distribution). These aggregates are non-personal — no individual can be identified from them — and are retained for the lifetime of the event for photographer analytics.

The consent experience depends on how the photographer or event organiser has configured the event.

Pre-event consent. Photographers and event organisers who collect consent from attendees before the event — through a registration form or their own privacy notice — configure this in the event dashboard. RealTime.Photos provides ready-to-use consent language directly from the dashboard for inclusion in those materials, covering the purpose of the face recognition processing, the data retention period, and the right to request deletion at realtime.photos/forget-me. Under this setup, face recognition indexing runs after attendee consent already exists. Guests arrive at the gallery and can use face search directly, without an in-app prompt.

In-app consent (default). Where the photographer has not collected pre-event consent, guests who choose to use face search are shown a consent screen before any photos of them are surfaced. Face indexing runs when photos are uploaded so that results are available instantly when a guest initiates a search. Guests who decline, or who never use the selfie search feature, are never shown face-matched results — their data is held dormant and deleted automatically when the event is purged.

Under both configurations, guests who never interact with face search have no face data surfaced, attributed, or disclosed to them in any way.

Emotion and networking opt-in. Under the in-app consent setup, guests who use face search are offered two additional, optional consents: (1) an emotion analytics opt-in, which provides the guest with a personal snapshot of how they felt during the event (smile rate, top emotions) and contributes their data to event-level emotion aggregates; and (2) a networking opt-in, which shows the guest how many people they appeared alongside and may display their face in the event's connection map visible to the organiser. Both are freely given (declining has no effect on the face search feature) and can be withdrawn at any time by contacting hello@realtime.photos. Under the pre-event consent setup, these analytics apply in accordance with the photographer's event configuration and are covered by the consent the organiser has collected from attendees. Per-cluster emotion snapshots are deleted with the event data at the end of the retention period.

Minors. The platform processes images from events which may include attendees under the age of 16 (or the applicable age in the relevant EU member state). Under GDPR Article 8, processing biometric data of children requires parental or guardian consent. The photographer, acting as data controller for each event, is solely responsible for ensuring appropriate consent is in place for all attendees, including minors. RealTime.Photos cannot verify the ages of event attendees and relies entirely on the photographer fulfilling their controller obligations in this regard.

Photographers (as data controllers) are responsible for obtaining any required consent or other lawful basis from event attendees for the processing of their biometric data, as required by GDPR Article 9(2) or equivalent applicable law.

Third-party services

We work with a small number of trusted service providers to operate the platform. Each processes only the data necessary for their specific role. We do not share personal data with third parties for advertising or marketing purposes.

ClerkAuthentication and account management — processes photographer name and email for login and session management. Privacy policy ↗
Convex, Inc.Database and real-time backend — stores event metadata, face cluster data, analytics counters, and photographer account records. Privacy policy ↗
Amazon Web Services (AWS)Cloud storage for event photos (S3) and face recognition processing (Rekognition). Privacy policy ↗
Vercel, Inc.Application hosting and content delivery. Privacy policy ↗
Dodo PaymentsPayment processing (merchant of record) — processes billing and payment data for photographer subscriptions. Privacy policy ↗
ResendTransactional email delivery — sends deletion warning notifications and account communications to photographer email addresses. Privacy policy ↗
FormspreeDemo request and contact form submissions — processes name and email of prospective customers. Privacy policy ↗
Vercel AnalyticsCookieless website analytics — no personal data collected, no cookies set, aggregated traffic patterns only. Privacy policy ↗

International transfers

Clerk, Convex, AWS, Vercel, Resend, and Formspree are based in the United States. When we use these services to process personal data of individuals in the EEA or UK, data is transferred internationally. We protect these transfers using one or more of the following mechanisms:

  • Standard Contractual Clauses (SCCs) — EU Commission Decision 2021/914 for EEA-origin transfers; the UK ICO's International Data Transfer Addendum (IDTA) for UK-origin transfers — incorporated into our agreements with each provider.
  • EU-US Data Privacy Framework (DPF) certification, where the provider is currently certified under the framework, which may supplement or substitute the SCCs.

You may request details of the transfer mechanism applicable to any specific provider by contacting us at hello@realtime.photos.

Data retention

Raw per-face biometric attributes (age range, gender, smile, emotion signals) captured during photo processing are permanently deleted within 48 hours of the last photo upload, or sooner when the photographer completes the face-cleanup tools (hide blurry faces, merge duplicate clusters). The 48-hour window allows the photographer to complete quality review before aggregation runs; completing review early triggers immediate deletion. After deletion, only non-personal aggregate statistics remain.

Event data (uploaded photos, face recognition data, and associated records) on Trial, Small, Medium, and Large plans is automatically and permanently deleted within a fixed number of days after the event's first photo was uploaded — between 7 and 90 days, depending on the plan.

Contract-based retention (Custom plan and agency accounts). Events on our Custom tier — including events created under an agency volume plan — are not on this automatic day-count schedule. Their photo and event data is instead retained for the duration set out in the applicable contract, and deleted once that contract ends (agency accounts: within 30 days after the contract's end date). Photographers with a Custom-tier event can request the applicable retention date by contacting us.

Regardless of plan, face recognition biometric data (face embeddings stored in AWS Rekognition) is always purged no later than 12 months after the first photo was added, to limit long-term biometric data storage. Photos and face avatar filters remain fully accessible after biometric data is purged; only selfie-based photo search is affected.

Photographer account data (name and email) is retained for the duration of your account. If you delete your account, your personal data is removed from active systems immediately. Residual copies in encrypted backups are purged within 90 days of deletion.

Payment records are retained for the period required by applicable tax and financial reporting law — typically 7 years in Spain — after which they are permanently deleted.

Demo and contact requests are retained for up to 12 months or until the inquiry is resolved, whichever comes first.

Anonymised engagement statistics (gallery page views, interaction counts, upload activity) collected via the analytics system contain no personal data and are not deleted when an event is deleted. They are retained indefinitely as aggregate product analytics and cannot be attributed to any individual.

Your rights

Event guests. Even without an account, you have rights over your biometric data. To request removal of your face data from all active events, use our self-service data removal tool. We will search for your face across all events and delete any matching data within minutes. You may also email hello@realtime.photos with the event name and date. You may withdraw your emotion or networking opt-in consent at any time via the same email address.

If you are a photographer with an account, you have the following rights over your personal data:

  • Access (Article 15): Request a copy of the personal data we hold about you.
  • Rectification (Article 16): Request correction of inaccurate or incomplete data.
  • Erasure (Article 17): Request deletion of your personal data, subject to our obligations to retain certain records under applicable law. Note: where demographic aggregation has already run, your individual contributions to aggregate event statistics (total people, age/gender/emotion distributions) cannot be individually reversed — these statistics contain no personal identifiers and are not personal data under GDPR.
  • Restriction (Article 18): Request that we limit how we process your data while a dispute is resolved.
  • Portability (Article 20): Request your personal data in a structured, machine-readable format so you can transfer it to another service.
  • Objection (Article 21): Object to processing based on our legitimate interests. We will stop unless we have compelling grounds that override your interests.
  • Withdraw consent: Where processing relies on your consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

To exercise any of these rights, email us at hello@realtime.photos. We will respond within one month of receiving your request and may ask you to verify your identity before processing. For complex or numerous requests, we may extend this period by up to two further months; if so, we will notify you of the extension within the first month.

Right to complain. You have the right to lodge a complaint with a data protection supervisory authority. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD), reachable at www.aepd.es. If you are located in another EU member state, you may also complain to your local supervisory authority. UK residents may complain to the Information Commissioner's Office (ICO) at ico.org.uk.

US privacy rights

If you are a resident of California, Virginia, Colorado, Connecticut, or Utah, you have additional rights under applicable state privacy law (CCPA, VCDPA, CPA, CTDPA, and UCPA respectively):

  • Right to know what personal information we collect, use, disclose, and sell.
  • Right to request deletion of your personal information, subject to certain exceptions.
  • Right to correct inaccurate personal information (California, Virginia, Colorado, Connecticut).
  • Right to data portability — to receive a copy of your personal information in a portable, usable format.
  • Right to opt out of the sale or sharing of personal information and of targeted advertising. We do not sell or share personal information for these purposes — this right is preserved but not currently applicable.
  • Right to non-discrimination — we will not deny, degrade, or charge differently for our services because you exercised a privacy right.

To exercise any of these rights, email hello@realtime.photos. We will respond within 45 days (extendable by a further 45 days where reasonably necessary, with notice to you). We will not charge a fee unless requests are excessive or repetitive.

Event guests and attendees

If your photo appears in an event gallery on RealTime.Photos, the photographer who created that event is the data controller for your personal data (your image). RealTime.Photos processes that data only on the photographer's behalf, as set out in our Data Processing Agreement.

To exercise your rights over photos of yourself — including requesting removal — please contact the photographer who organised the event. If you cannot reach the photographer, contact us at hello@realtime.photos and we will do our best to assist.

All guest gallery browsing is anonymous. RealTime.Photos holds no personal data about event guests in its own systems — no name, email, account, or tracking identifier is collected or stored in connection with gallery browsing.

Automated decision-making

We do not carry out automated decision-making within the meaning of GDPR Article 22 — that is, decisions based solely on automated processing that produce legal effects or similarly significant effects on you.

Face clustering is an automated process, but it produces only a navigational aid (grouping photos by apparent visual similarity) and has no legal, financial, or otherwise significant effect on any individual. Photographers review and manage face clusters manually.

Photographer responsibilities

Photographers using RealTime.Photos are responsible for ensuring they have the necessary legal basis to photograph and publish images of event attendees, and that attendees have been informed of face recognition processing. By creating an event, you confirm this, consistent with applicable laws in your jurisdiction.

If a guest requests removal of photos showing them, photographers can hide individual photos from the gallery at any time from the dashboard. Photographers who receive formal data subject requests from guests should notify us at hello@realtime.photos so we can provide any necessary technical assistance.

Changes to this policy

We may update this policy as the product evolves. Material changes will be notified to photographer account holders by email at least 14 days before they take effect. The current version is always available at realtime.photos/privacy. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

Contact

For any privacy-related enquiries, to exercise your rights, or to request further information about our data practices, contact us at hello@realtime.photos. RealTime.Photos is operated by Nanjing Zhiyin Trading Co., Ltd.

EU Representative (Article 27 GDPR). For the purposes of Article 27 of the GDPR, our representative in the European Union is Pablo Martín Larriu, reachable at hello@realtime.photos, located in Irún, Gipuzkoa, España, 20301.