ShutterID Privacy Policy
Effective August 26, 2026 · Polski
1. Controller
The controller of personal data processed in the ShutterID service (shutterid.com, studio.shutterid.com, library.shutterid.com) is Damian Dąbrowski ECHOTXMX, ul. Zielona 38/18, 12-220 Ruciane-Nida, Poland, VAT ID (NIP) 5272407037, REGON 141643088. Contact for personal data matters: damian@echotxmx.com.
For photographs and data of the people a photographer shares materials with through ShutterID, that photographer is the controller, and the Provider processes those data on the photographer's behalf as a processor (Art. 28 GDPR).
2. What data we process and why
Photo recipients (library)
- Private link / session — technical session identifiers and cryptographically protected link credentials; purpose: making photos available only to authorized people (Art. 6(1)(b) and (f) GDPR).
- Introducing yourself — a name (or nickname) and, where the photographer requires it, an e-mail address provided before downloading photos or with a comment; purpose: accountability of downloads and signing feedback, on terms set by the photographer.
- Recipient account — when signing in with Google or Apple we receive the account identifier (sub), the e-mail address (with Apple this may be a relay address of the "Hide My Email" service) and the display name; purpose: durably pinning shared libraries to the account (Art. 6(1)(b) GDPR). We never receive your password or the contents of your Google or Apple account.
- Mobile app — after signing in and granting the system permission for notifications, we store the device's push notification token (with the device platform and language); purpose: delivering notifications about new photos and approval requests (Art. 6(1)(a) and (b) GDPR). For a signed-in account we also keep "viewed" and "saved" marks on individual photos; purpose: marking in the app what you have already seen and saved (Art. 6(1)(b) and (f) GDPR).
- Invitations — the e-mail address named by the photographer, to which we send the invitation message; the invitation address and the sign-in address may differ.
- Feedback — reactions, comments and abuse reports attributed to the identity you introduced yourself with.
Photographers (Studio)
- account data (e-mail, sign-in data), billing data, the recipient register kept by the photographer (names, e-mail addresses, notes), Lightroom plug-in tokens, the account event log; purpose: providing the service and security (Art. 6(1)(b) and (f) GDPR).
All users
- technical request data (IP address, timestamps) to the extent necessary for security and abuse limiting; anti-abuse counters are stored exclusively as cryptographic hashes.
3. Cookies and device storage
We use only cookies and browser storage essential for the service to work: the library session, the account session, the form protection token (CSRF), the session expiry hint and local preferences (e.g. theme, libraries remembered on this device). The mobile app stores sessions in the device's system keychain, and the theme preference locally on the device. We use no advertising or analytics cookies and do not track users across sites.
4. Who we entrust data to
- Cloudflare, Inc. (USA) — service infrastructure: hosting, database, file storage, image and video processing. Transfers outside the EEA are protected by Standard Contractual Clauses and the EU–U.S. Data Privacy Framework certification.
- Resend, Inc. (USA) — sending e-mail messages (shares, invitations, notifications). Transfers protected as above.
- Google Ireland Ltd. — solely as a sign-in provider, when a recipient chooses to sign in with a Google account.
- Apple Inc. (USA) — the Sign in with Apple provider in the mobile app and the system channel for delivering push notifications (APNs). Transfers protected by Standard Contractual Clauses.
- 650 Industries, Inc. (Expo) (USA) — the technical intermediary for delivering push notifications to the mobile app (push token and notification content). Transfers protected as above.
We do not sell data and do not share it with advertisers.
5. How long we keep data
- sessions — up to 24 hours (library) or 30 days (recipient account),
- push notification tokens — until the device signs out, consent for notifications is withdrawn, or the system invalidates the token,
- "viewed"/"saved" marks — until the recipient account is deleted,
- unused invitations — 14 days from sending,
- photos, feedback and the recipient register — until the photographer deletes them or the service provided to the photographer ends,
- recipient account data — until the account is deleted at the recipient's request (you can delete the account yourself in the mobile app — "Close my account" — or by writing to the contact address),
- data required by law (e.g. billing) — for the periods the law prescribes.
6. Your rights
You have the right to access your data, rectify it, erase it, restrict its processing, port it, and object to processing based on legitimate interest. Requests: damian@echotxmx.com. If the data concerns photos shared by a specific photographer, we will also pass the request to that photographer as the controller. You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (uodo.gov.pl).
7. Providing data is voluntary
Providing data is voluntary but necessary to use the corresponding features: without introducing yourself you cannot download photos where the photographer requires it, and without signing in you cannot pin a library to an account. Merely viewing a shared library through a link requires no data at all.
8. Changes
We will announce changes to this policy on this page, indicating a new effective date.