Draft — not yet in force. Details marked “to come” are being filled in.
Pictorium Privacy Policy
Effective date: [to come: effective date] Who is responsible: Switch'N'Plugs, [to come: mailing address] Privacy officer: privacy@pictorium.ca
Pictorium is a private photo and video sharing app for groups. This policy explains what we collect, why, how long we keep it, and what you can do about it. We follow Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
The short version. We collect what the app needs to work and nothing more. Your photos are shown only to the group you put them in. We never sell personal information, we show no ads, and we do not use your photos to train anything. We do not scan your photos; the people in your group, and the organizer's approval, are what keep it safe.
1. What we collect, why, and for how long
| What | Why | How long |
|---|---|---|
| Email address | To sign you in (one-time links), and to send expiry warnings, receipts, and recovery messages | Until you delete your account; then replaced with an anonymous placeholder |
| Display name (optional) | So group members know who posted what | Until you change it or delete your account |
| Sign-in link tokens (stored hashed) | To make the emailed link work once | 15 minutes, or until used |
| Device tokens (stored hashed) with a device label and platform (iOS/Android/web) | To keep you signed in on each device and let you sign devices out | Until you sign out, or 180 days after last use |
| Push notification tokens | To send organizer alerts and expiry reminders, if you allow notifications | Until you sign out that device or turn notifications off |
| Photos and videos you upload, including the smaller copies your phone makes, and the original file on paid tiers | To show them to the group | According to the group's tier (section 4) |
| Photo details: file name, type, size, dimensions, video length, and the capture time from the photo's metadata | To order the gallery by when photos were taken and to display them properly | Same as the photo |
| Location | Not collected. Standard GPS tags are removed from every photo and video on your phone before upload, and our servers have nowhere to store a location. Proprietary camera metadata and any telemetry track inside a video (for example from an action camera) may remain in original-quality files, which only paid groups keep. | — |
| A content fingerprint (a partial checksum of the file) | To spot duplicate uploads within a group | Same as the photo |
| Comments and likes | To show them in the group; likes only reorder photos (counts are never shown) | Until removed, or until the photo or your account is deleted |
| View counts | To show how many times a photo has been viewed. Stored as a single number per photo with no record of who viewed it; hidden when under 3. | Same as the photo |
| Group details: title, description, event date, invite code, settings, tier | To run the group | Until the group is purged (section 4) |
| Membership: which groups you are in, your role, whether you are pending, approved, or removed | To decide what you can see | Until the group is purged or you delete your account |
| Reports you file or that are filed about you, with the reason and any note | Safety: so organizers and we can act on them | Kept as safety history, even after account deletion (the reporter's identity is anonymized when they delete) |
| Blocks | To hide you and the blocked person from each other | Until you unblock or delete your account |
| Failed invite-code attempts, with your account ID and IP address | To stop people guessing codes (10 wrong codes per hour) | Swept automatically after a short period |
| Purchase status for a group (tier, start and end dates) | To apply the right limits and retention | Until the group is purged |
| Safety incident records and any file preserved as evidence (section 3) | To meet our legal reporting duties | Not deleted by any automatic process; kept as long as the law requires |
| Operational logs (request timestamps, error messages, rough device info) on Cloudflare | To keep the service running and find faults | Short-term, rolling |
We do not collect: your contacts, your photo library (only the photos you choose to upload), your precise location from the device, advertising identifiers, or anything from third-party analytics.
2. How your photos and videos are used
- They are shown only to approved members of the group you uploaded them to. There are no public pages and no public links. Members waiting for approval see nothing. Members who have been removed see nothing.
- The organizer sees uploads first (unless they have turned on auto-approve) and decides whether the group sees them.
- We do not scan them. Uploads are not compared against databases of known images or sent to any outside service for checking. If someone reports a photo, we act on the report (see section 3).
- A basic "possibly not safe for work" flag may be attached automatically and shown to the organizer only.
- That is all. We do not look at your photos, use them for advertising, use them to train AI or any other software, or share them with anyone outside the group except as described in section 3.
Your phone resizes photos before upload. On free groups we store only the resized copies. On paid tiers we also store the original file you chose.
3. Who we share information with
We do not sell personal information. We do not share it with advertisers. We share it in only these situations.
Service providers (sub-processors)
These companies process data on our behalf, under contracts that restrict what they can do with it.
| Provider | What they do | Where |
|---|---|---|
| Cloudflare, Inc. | Runs our servers, database (D1), and file storage (R2), and sends our sign-in links and reminder emails | Global network; data may be stored and processed in the United States |
| Apple Inc. | App distribution, in-app purchases, push notifications on iOS | United States |
| Google LLC | App distribution, in-app purchases, push notifications on Android | United States |
Inside a group
Your display name, your uploads, your comments, and your likes are visible to the approved members of that group. The organizer also sees the NSFW flag and reports about content in their group. We do not show anyone your email address.
Child protection and law enforcement
If we learn, through a report or otherwise, that an upload may be child sexual abuse material, we preserve the file and related account information, report it to the Canadian Centre for Child Protection (Cybertip.ca), and notify the police, as Canadian law requires. We may also disclose information when a court order, warrant, or other legal requirement compels us, or when we believe in good faith it is necessary to prevent serious harm to someone.
Business changes
If Switch'N'Plugs is sold or merges, your information may be transferred to the new owner under this policy. You will be told.
4. How long we keep your photos (retention)
Retention is set by the group's tier. The organizer chooses and pays for the tier; members never pay.
| Tier | Photos and videos kept for | Originals? |
|---|---|---|
| Free | 30 days from when the group is created | No |
| Event pass | 12 months | Yes |
| Big event | 24 months | Yes |
| Organizer subscription | Life of the subscription plus 90 days | Yes |
When that time is up, the group is hidden for 7 days (nobody can view or download; the organizer can still upgrade to bring it back), and then everything in it is permanently deleted from our storage: photos, videos, resized copies, originals, comments, likes, and view counts. Deletion is permanent. We do not keep backups of deleted media.
The organizer gets a reminder about 7 days and about 24 hours before a free group expires.
Upgrading extends retention in place and never shortens it; nothing is re-uploaded or copied.
5. Your rights and choices
- Access and correction. You can see and change your display name and email in the app. For a copy of the other information we hold about you, or to correct something, email privacy@pictorium.ca. We will answer within 30 days.
- Delete your account. "Delete my account" in the app is immediate and does not need an email to us. It signs out every device, permanently deletes every photo and video you uploaded in every group, removes your comments and likes, removes you from every group, closes any group where you were the only organizer (deleted 7 days later), and anonymizes your account record. Files preserved as evidence under section 3 and reports you filed are not deleted.
- Delete a photo or comment. Delete your own from inside the app. Organizers can delete anything in their group.
- Ask for a photo of you or your child to be removed. Ask the organizer, use the in-app report, or email support@pictorium.ca. We will remove it.
- Withdraw consent. You can leave a group, delete photos, turn off notifications, or delete your account at any time. Withdrawing consent for the processing the app needs (your email, your uploads) means the app cannot work for you, so the way to do that is to delete your account.
- Notifications. Push notifications are controlled in your phone's settings. Expiry warnings and receipts by email are part of the service and are sent while you have an account.
6. Children
Pictorium is for adults and teens aged 13 and up who are sharing photos of an event. Children under 13 must not have accounts, and we do not knowingly collect information from them. Parents and guardians share photos of their children; the children themselves do not use the app.
Photos of children are personal information about those children. Uploaders are required to have the permission of the child's parent or guardian (see the Terms of Service). Any parent or guardian may ask us to remove a photo of their child, and we will.
If you believe a child under 13 has an account, or a photo of a child has been shared without permission, email privacy@pictorium.ca.
7. Security
- Photos and videos are only ever served through signed, time-limited links that work for a short time and only for the member who requested them. There are no permanent URLs.
- Sign-in uses a one-time emailed link (expires in 15 minutes, works once) or a passkey. There are no passwords to leak.
- Device tokens are stored as one-way hashes; the token itself lives only on your phone, in its secure storage.
- Data is encrypted in transit (TLS) and at rest on Cloudflare's storage.
- Access to production systems is limited to the people who run the service. Files preserved as evidence can be accessed only by our designated safety officer.
No system is perfectly secure. If we discover a breach that creates a real risk of significant harm to you, we will tell you and the Office of the Privacy Commissioner of Canada as PIPEDA requires.
8. Where your information is stored
Switch'N'Plugs is in Ontario, Canada. Our service providers (section 3) store and process data on servers that may be outside Canada, including in the United States. While it is there, it may be accessible to the courts, law enforcement, and national-security authorities of that country under their laws. We use contracts and technical measures to protect it, but we cannot override foreign law.
9. Cookies
The app itself uses no cookies. The member website at https://pictorium.ca uses a single session cookie to keep you signed in during your visit. It is not used for tracking or advertising, and there are no third-party cookies.
10. Privacy officer and complaints
Our privacy officer is responsible for this policy and for answering your questions and requests:
privacy@pictorium.ca Switch'N'Plugs, [to come: mailing address]
If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner of Canada: priv.gc.ca, 1-800-282-1376.
11. Changes to this policy
We will post any changes at https://pictorium.ca/privacy and update the effective date. If a change affects how we use your information in a way that matters, we will tell you in the app or by email before it takes effect.
12. Contact
- Privacy: privacy@pictorium.ca
- Support: support@pictorium.ca
- Child safety: safety@pictorium.ca