Privacy.

Last updated 3 September 2026. Written to be read, not scrolled past.

Who we are

Get Candid is a small Australian service, operated from New South Wales. It lets a host collect photos from the guests at their event. If anything here is unclear, or you want something removed, email matt@getcandid.photos and a person will reply.

We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).

Two kinds of people use this

Hosts create events. They sign in with an email address and get a private workspace. There are no passwords; a code is emailed each time.

Guests scan a code at an event and take photos. They never create an account, never give an email address, and never set a password. The app gives their device an anonymous identity so it knows which photos are theirs. That identity is a random string; it is not linked to a name, a number or an email.

What we collect, and from whom

From hosts: an email address, the details of each event (its name, dates, settings and the words on the sign), and a record of sign-ins.

From guests: the photos they choose to take or upload through the app, at the size the host set; a first name only if they type one, which is optional; and the technical details an upload needs — file size, dimensions, a fingerprint of the file so the same photo cannot land twice, and when it was taken.

From everyone: the ordinary server logs any website keeps — the address a request came from, the browser, the page, the time. These are used to keep the service running and to find faults, and are not joined to photos.

Not collected: location. We do not read where a photo was taken, and we strip nothing else from your camera's files; we simply do not look. We do not run advertising or analytics trackers.

Why we collect it

To do the one thing the service does: get a guest's photo into the host's album, safely, and let the host look after it afterwards. Email addresses exist so hosts can sign in and so we can tell them something that matters about their event. The fingerprint exists so a retry after a bad connection cannot duplicate a photo. Nothing is collected for any other purpose, and nothing is sold or shared for marketing.

Where it is kept

Photos and event data are stored in Australia, in a Sydney data centre, on infrastructure run by Supabase. The website itself is served by Vercel, whose network has points around the world including Sydney; page requests may pass through servers outside Australia on their way to you.

Sign-in emails are sent through Resend, whose sending region for us is Tokyo, Japan. That means a host's email address, and the one-time code, pass through Japan on their way to the host's inbox. This is the only personal information that routinely leaves Australia, and it is the minimum an email needs.

These providers process information on our behalf, under their own privacy commitments, and do not use it for their own purposes.

Who can see the photos

The host of the event, and anyone the host has added to their workspace.

You, the guest, on your own device — but only the photos you took, and only for as long as the app is installed or your browser keeps its data.

Nobody else. Albums are private. There is no public gallery, no shared link, and event pages are marked not to be indexed by search engines. We — the people who run Get Candid — can technically access stored photos to fix a fault or answer a deletion request, and do so only for those reasons.

How long we keep things

Photos are kept until the host deletes them, or deletes the event, or asks us to close their workspace. Deleting is permanent: the file is removed from storage and cannot be recovered.

We intend to delete photos automatically a set time after an event finishes unless the host chooses to keep them. That feature is not built yet. Until it is, nothing is removed on a timer; this page will be updated when that changes.

A guest's copy on their own phone is theirs, and outside our control.

Children

Family events include children, and the service is designed with that in mind: albums are private to the host by default, there is no public gallery, and any photo can be hidden or deleted by the host at any time.

If you are a parent or guardian and want a photo of your child removed, contact the host, or email us and we will remove it.

Your choices and rights

Guests can delete any photo they took while the event is still open, from the app. After that, ask the host, who can delete any photo at any time — or email us.

Hosts can delete any photo, any event, and download everything they hold at any time. To close a workspace entirely, email us.

Anyone can ask what personal information we hold about them, ask for it to be corrected, or ask for it to be deleted. Email matt@getcandid.photos. We will reply within 30 days, usually much sooner.

If you are not satisfied with how we have handled a privacy concern, you can complain to the Office of the Australian Information Commissioner.

Cookies and storage on your device

A host's browser holds a sign-in cookie so they stay signed in. A guest's browser holds an anonymous session cookie so the app knows which photos are theirs, and keeps photos in the browser's own storage until they have been sent — that is what lets a photo survive a dead spot. The app also remembers a guest's first name, if they gave one, so they are not asked twice.

None of this is used to track you across other websites. There are no third-party advertising cookies.

Security

Everything travels over HTTPS. Photos are uploaded directly from the phone to storage using single-use, time-limited links, so they never pass through our web servers. Access to stored data is enforced by database rules that check who is asking on every request. Storage buckets are private; there are no public file URLs.

No system is perfect. If we become aware of a breach that is likely to cause serious harm, we will tell the people affected and the Commissioner, as the law requires.

Changes

If this policy changes in a way that matters, the date at the top changes and hosts with an active event are told by email. The current version is always at getcandid.photos/privacy.

See also the Terms of use.