Legal

Privacy Policy

Last updated:

Photobooth Free is a free photo booth in your browser. The key point first: your photos and collages never leave your device. They are not uploaded to our servers. There is no account. The only exception is the "with a friend" mode: there, live video and photos go directly to the browser of the person you take photos with — again not via our servers.

Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Steffen Knödler
Rothschildallee 41
60389 Frankfurt am Main
Germany
Email: hello@guest-pictures.com
Contact form: photobooth-free.com/contact

We have not appointed a data protection officer because there is no legal obligation to do so. For questions, write to hello@guest-pictures.com.

Overview

DataWhereDeletion
Camera image, photos, collagesonly on your deviceby you (gallery or clear site data)
Photo booth settingsonly on your deviceby you
"With a friend" mode: live video and photosdirectly between your browser and your friend's (peer-to-peer)on your friend's side, by that person
"With a friend" mode: connection setup data (random IDs, IP addresses and ports)Google Cloud Firestore, EU (eur3)once connected, at the latest after 2 hours
Anonymous daily countersGoogle Cloud Firestore, EU (eur3)totals only, no personal data
Feedback, error reportsGoogle Cloud Firestore, EU (eur3), processed via USA (us-central1)365 / 90 days
Server logs (IP, user agent)Google (Firebase Hosting, Cloud Logging)Cloud Logging: 30 days

Hosting and server log files

photobooth-free.com is served via Firebase Hosting, a service of Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, USA), through Google's worldwide content delivery network (CDN). When you open a page, your browser necessarily transmits your IP address, the date and time, the requested address, the referrer and browser/operating-system details (user agent). Google processes this data to deliver the pages and to protect the service against abuse and attacks.

Requests to our server functions (e.g. counters, feedback, photo uploads) are additionally recorded in Google Cloud's logs (Cloud Logging); these logs may contain IP address and user agent and are deleted automatically after 30 days. We only look at them when there is a reason, e.g. to fix errors or to fend off attacks.

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure and stable provision of the website. Google acts as our processor under the Google Cloud/Firebase data processing terms (Art. 28 GDPR).

Photo booth and camera

The photo booth only uses your device's camera after you allow it in your browser's prompt; you can revoke that permission at any time in the browser settings. The camera image is processed exclusively in your browser. No sound is recorded, no video is recorded and nothing is transmitted to us or third parties (except to your friend in the "with a friend" mode, see below); there is no face recognition. On some devices (e.g. iPhone) the phone's camera app opens instead, or you pick an existing photo; that image, too, is processed only on your device, and metadata such as location data is removed.

The booth keeps your collages in a gallery on your device (in browser storage) so you can view, share or print them again later. The gallery is on by default; you can switch it off in the booth settings and delete individual collages or everything. If you use a shared device (e.g. a tablet as a photo booth at a party), please clear the gallery after the event.

Downloading, printing and sharing are handled by your device: when you share via the share menu, you hand the collage to the app you choose there; that app's privacy terms apply.

As we never receive your photos, we do not process them within the meaning of the GDPR. You are responsible for what you do with your photos (e.g. sharing photos of other people).

Photo booth with a friend (remote)

In the "with a friend" mode (/photobooth/together) two people in different places take photos together. Live video and photos go directly between the two browsers (peer-to-peer via WebRTC, encrypted by WebRTC); they are not uploaded to our servers. No sound is transmitted. Each device takes its own photos and sends them to the other, so both get the same photo strip.

So that the two browsers can find each other, our server only relays the connection setup data: a random room ID, random participant IDs and technical connection details (WebRTC offers and so-called ICE candidates, which contain the IP addresses and ports of your device or internet connection). This data is held in Google Cloud Firestore (EU, eur3). Each browser deletes its connection data as soon as the connection is up; at the latest 2 hours after the link was created it can no longer be retrieved and is deleted automatically (technically, usually within 24 hours after that). There is no account or sign-in; nothing is stored on your device for this mode, unless you keep finished photo strips in the gallery on your device (see above).

To find out its public address, your browser asks a STUN server operated by Google (stun.l.google.com), which receives your IP address in the process. Like with any direct connection, your friend receives the IP address of your internet connection as well as your live video and your photos. Anyone who has the invite link can join the room, so only share it with the person you want to take photos with. The room ID is in the part of the link after "#", which browsers do not send to servers.

The legal basis is Art. 6(1)(b) GDPR (providing the function you chose under our terms of use), alternatively Art. 6(1)(f) GDPR (legitimate interest in a working connection between the two devices).

Installable app and offline use

The photo booth can be installed as a web app and then also works offline. For this, a so-called service worker stores the program files (no photos, no personal data) in your browser storage.

Embedding on other websites

Operators of other websites can embed the photo booth in a frame (iframe). It then still runs from our domain and this privacy policy applies: photos stay on your device, and we only receive the counters, feedback and error reports described here (including the information that the booth was opened in embedded form). The operator of the embedding website is responsible for that website itself.

Interface for AI assistants

At photobooth-free.com/mcp we provide an interface (Model Context Protocol) through which AI assistants can retrieve a link to the photo booth and effect suggestions. When an assistant calls this interface, we only receive the parameters it passes (language, effect, layout, optionally a short occasion such as "wedding" and a caption for the collage such as names and a date). We use them solely to generate the response and do not store them; only the server logs apply. The card in the chat loads example images of the effects from our website; as with any page visit, your browser transmits its IP address (server logs). Your conversation with the assistant is processed by its provider under its own responsibility. The legal basis is Art. 6(1)(f) GDPR.

Guides and links

You can read our guides without signing in; there is no comment function. Links to our sister service guest-pictures.com contain a source parameter (e.g. ?ref=photobooth-free) that only indicates which site you came from. The privacy policy of guest-pictures.com applies there.

Usage counters, feedback and error diagnostics

We use no third-party analytics or tracking services (no Google Analytics, no advertising pixels) and set no cookies. Instead we run three small first-party functions. The data goes to our own server functions on Google Cloud (region us-central1, USA) and is stored in our Google Cloud Firestore database in the EU (region eur3).

Anonymous usage counters

When certain pages are opened and at individual steps (e.g. "photo booth opened", "collage created", "feedback sent"), your browser sends only the name of the event and the website to our server. We use it to increase a daily counter (e.g. "12 × collage created today"). Only these totals are stored – no IP address, no identifier, no URL, nothing that relates to a person. If you arrive via a link with a source parameter (e.g. ?ref=…), we count that source as a total as well. To limit abuse, your IP address is used briefly as a truncated hash in the server's memory and is not stored.

Feedback form and quick ratings

If you send us feedback via the feedback form or a quick rating (e.g. 👍/👎 after a collage), we store what you submit (rating, selected reasons, your message) and – only if you enter it yourself – your email address, which we use solely to reply to you. Please do not include sensitive data in your message. The technical details described in the next paragraph are attached automatically. If you report a camera problem, we also store the full browser identifier (user agent), because camera errors can often only be traced with it. Feedback is deleted automatically after 365 days. If the form cannot be sent, your email program opens instead; the section "Contact by email" then applies.

Error diagnostics

When a technical error occurs in our app, or when you send us feedback through the feedback form, we automatically transmit technical details to our own server (Google Firebase / Google Cloud): device type, operating system and browser (family and major version only), screen size, language, connection status, the app pages you visited most recently (page type only, e.g. "event upload page", without URL parameters), your most recent steps in the app (e.g. "upload started", "camera error"), an error message without any content you typed, and a random session identifier that exists only in your browser's memory and is lost when you close or reload the page. We do not store cookies, IP addresses, names, photos or file names for this purpose. The sole purpose is to detect and fix errors and keep the service secure. There is no profiling and no disclosure to third parties. Error reports and technical details are deleted automatically after 90 days.

Legal basis for all three functions is Art. 6(1)(f) GDPR (legitimate interest in a working, secure and improving service); for feedback also your voluntary submission. Reading technical device properties (e.g. screen size, connection type) serves to keep the service you are using working (Section 25(2) no. 2 TDDDG). For the transfer to the USA see "Recipients and transfers to the USA". You may object to this processing at any time under Art. 21 GDPR.

Storage on your device (no cookies)

We set no cookies and use no tracking technologies. To make the app work, we keep a few entries in your browser storage (localStorage, sessionStorage, IndexedDB, Cache Storage). These entries stay on your device; a value is only sent to our server where stated below. All entries are strictly necessary for functions you explicitly use (Section 25(2) no. 2 TDDDG) and therefore require no consent. You can remove them at any time in your browser settings ("clear site data").

EntryTypePurposeDuration
languagelocalStorageThe language you choseuntil you clear the site data
photobooth_settings_v1, photobooth_sound_muted, booth_camera_modelocalStorageYour photo booth settings (effect, layout, custom text, countdown, sound, camera mode)until you clear the site data
photobooth-localIndexedDBOn-device gallery: your photo booth collages, so you can view, share or print them again later (can be switched off in the booth settings; entries can be deleted)until you delete the entries or the site data
feedback_asked_*localStorageRemembers that a short feedback question was already shown, so it does not appear againuntil you clear the site data
staleBuildReloadAtsessionStorageTechnical guard against endless reloads after a website updateuntil the tab is closed
booth-v1-pages, booth-v1-assets (Service Worker)Cache StorageOffline use of the photo booth as an installable web app (program files only, no photos)until the next update or until you clear the site data

Contact by email and contact form

If you write to us by email, we process your email address, your name (if given) and the content of your message to handle your request. Our mailboxes are provided by Microsoft (Outlook.com) and Google (Gmail); data may also be processed in the USA. Emails to addresses at guest-pictures.com (e.g. hello@guest-pictures.com, the reply address of our emails) are forwarded to our mailbox by Cloudflare Email Routing (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA) without storing their content; Cloudflare, Inc. is certified under the EU-US Data Privacy Framework. We delete the correspondence once it is settled and no statutory retention obligations (e.g. for business letters, up to 6 years) apply.

Through our contact form you send us your name, email address, topic and message. We store them with the time of receipt in Google Cloud Firestore (EU, eur3) and delete them automatically after 12 months. To prevent abuse we limit requests per IP address; for this the address is only used hashed in memory and is not stored with the message. We notify ourselves of a new message by email via Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA; sent from servers in the EU (Ireland); certified under the EU-US Data Privacy Framework, additionally EU Standard Contractual Clauses).

The legal basis is Art. 6(1)(b) GDPR where a contract or pre-contractual steps are concerned, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries and in preventing abuse).

Recipients and transfers to the USA

We do not sell data and do not use advertising or analytics services. The recipient is Google (Firebase Hosting, Google Cloud) as our processor (Art. 28 GDPR): the website is delivered via Google's worldwide delivery network, our server functions run in the USA (us-central1), and the database for counters, feedback, error reports and the connection data of the "with a friend" mode is in the EU (eur3). In the "with a friend" mode, your friend (live video, photos, IP address) and Google's STUN server (IP address) also receive data, see above. For email we use Microsoft (Outlook.com) and Google (Gmail), and Resend to notify us of contact-form messages (see "Contact by email and contact form"). Authorities only receive data where we are legally obliged to provide it.

Transfers to the USA: Google LLC (USA) is certified under the EU-US Data Privacy Framework. For transfers to certified companies there is an adequacy decision of the European Commission (Art. 45 GDPR). Where data is not covered by the certification, the transfer relies on the EU Standard Contractual Clauses offered by Google (Art. 46(2)(c) GDPR). Despite these safeguards, US authorities may be able to access data in certain circumstances.

Retention

  • Photos, collages, settings: only on your device, until you delete them.
  • Connection data of the "with a friend" mode: deleted once the connection is up; at the latest 2 hours after the link was created no longer retrievable and deleted automatically.
  • Feedback: 365 days; error reports and diagnostic data: 90 days.
  • Server logs in Google Cloud Logging: 30 days.
  • Usage counters: contain no personal data and are kept as daily totals.
  • Emails: until the request is settled, subject to statutory retention obligations.

Your rights

You have the following rights regarding your personal data:

  • access (Art. 15 GDPR),
  • rectification (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • withdrawal of consent with effect for the future (Art. 7(3) GDPR).

Right to object (Art. 21 GDPR): Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.

An informal message to hello@guest-pictures.com is all it takes. So that we can reliably identify your data (e.g. photos of a guest without an account), please send us the link to the event and describe the photos concerned as precisely as possible.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the authority responsible for us: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, Germany, datenschutz.hessen.de.

No automated decision-making

We do not make automated decisions, including profiling, within the meaning of Art. 22 GDPR.

Obligation to provide data, security

You are under no statutory or contractual obligation to provide personal data. Without the technically necessary data (e.g. your IP address when opening a page), however, the website cannot be used. All connections are encrypted via TLS (HTTPS).

Changes to this privacy policy

We update this privacy policy when our service or the law changes. The version published here applies; the date at the top shows when it was last updated.