Legal

Privacy policy

What SnapMila collects, why we need it, who can see it, and how to delete it — in plain English.

Last updated 9 October 2026

SnapMila (“we”, “us”) is run by Bijay Kanshi, Ratu, Ranchi, Jharkhand, India. This policy covers the SnapMila app, the website at snapmila.com and the guest galleries at snapmila.com/e/…. Questions go to [email protected].

The short version

  • Photographers sign in with Google or Apple. We get your name and e-mail address from that sign-in.
  • Your events, and the photos your camera sends, are stored in Cloudflare R2 so your guests can see them.
  • Guests never make an account. Galleries and this website set no cookies and run no analytics.
  • Galleries are unlisted and kept out of search engines, but anyone who has an event's QR code or link can open it.
  • Deleting your account deletes your events, their photos and your sign-in.

Photographers: what we collect

  • Sign-in details. When you sign in with Google or Apple, we receive your name, your e-mail address and an account ID through Firebase Authentication, a Google service. If you use Apple's “Hide My Email”, we receive the relay address Apple gives us instead. Your e-mail address is also the user name your camera uses to send photos.
  • Events. The name you give each event (for example “Rahul weds Priya”), its gallery code and when you created it.
  • Photos. The files your camera sends, plus smaller copies we make so guests can browse quickly. The original is kept exactly as your camera sent it. For each photo we record when it arrived and whether it is visible to guests, hidden by you, or could not be processed.
  • Camera transfer logs. For each connection from your camera: the time, the camera's network (IP) address, the transfer commands and file names, and whether each transfer worked. The app uses these to show you what arrived and what to resend.

Guests: what we collect

  • No account, no name and no e-mail address. The gallery sets no cookies and has no analytics or ad trackers.
  • When you open a gallery, our servers receive your device's IP address and the gallery code it asks for, as any website does. We use the IP address to stop people guessing gallery codes: a network that tries too many wrong codes is blocked for a few minutes. Server logs are kept for 30 days.
  • When you save a photo, it goes straight to your device. We do not record which photos you save.

Website visitors

snapmila.com is a set of static pages with no cookies, no analytics and no ad trackers. Fonts are served from our own site. Our hosting provider, Cloudflare, handles request details such as your IP address to deliver and protect the site.

How we use it

  • To run SnapMila: signing you in, receiving photos from your camera, showing galleries and delivering downloads.
  • To keep it safe: limiting repeated failed attempts and investigating misuse.
  • To contact photographers about their account or important changes to the service.

We do not sell personal information, and SnapMila shows no advertising.

Who can see what

  • Your guests. Anyone with an event's QR code or link can see its visible photos and save the originals. Galleries are not listed anywhere, and we tell search engines not to index them. Share the QR only with people you want to see the photos.
  • Hidden photos. A photo you hide stops being shown to guests; galleries that are already open drop it within a few minutes. You still see it in the app and can show it again.
  • Service providers who process data for us: Google (Firebase Authentication), Apple (Sign in with Apple), Cloudflare (website hosting and R2 photo storage) and Hetzner (the SnapMila servers and database).
  • Authorities, only when the law requires it.

Where it is stored and how long we keep it

Photos and transfer logs are stored in Cloudflare R2; event and photo records are stored in our database on a Hetzner server in Finland.

Events, photos and transfer logs are kept until you delete your account. Database backups are kept for 14 days, so a deleted account leaves the backups within 14 days. Copies that guests have already saved stay on their own devices.

Security

The app, the website and the galleries use encrypted connections (HTTPS). Cameras can send photos over FTPS, which is encrypted; plain FTP is accepted for cameras that cannot, so choose FTPS when your camera offers it. Each gallery has a 10-character code that is hard to guess, repeated wrong guesses are blocked, and the photo links a gallery hands out expire within about an hour.

Your choices

  • Hide any photo from guests at any time in the app.
  • Delete your account in the app (Profile → Delete my account) or by e-mail — see Delete your account.
  • Ask for a copy of your data, or for a correction, by writing to [email protected].
  • If you are in a photo and want it taken down, ask the photographer who shared the gallery, or write to us.

Complaints about how your data is handled go to our grievance contact, Bijay Kanshi, at [email protected]. If you are not satisfied with the answer, you can also complain to the Data Protection Board of India.

Children

Photographer accounts are for adults running a photography business. You must be 18 or older to create one.

Changes to this policy

When this policy changes, we update this page and the date at the top. If a change is significant, we tell photographers in the app or by e-mail first.

Contact

Bijay Kanshi, Ratu, Ranchi, Jharkhand, India. E-mail: [email protected].