Guest information

How we use your photos

Moment Medley is designed to collect event photographs without requiring guests to create an account. This page demonstrates where the complete privacy notice will sit in the finished service.

What we collect

For organisers, we collect a name, verified email address, account and consent records, event details and an essential session identifier. For guests, we collect photographs they choose to keep, the event and table they came from, the submission time, and limited technical information needed to complete the upload.

Authentication and email providers

Organiser passwords are transmitted over encrypted HTTPS to Supabase Auth for verification. Moment Medley does not log or retain them. Resend delivers confirmation and password-reset emails. Cloudflare hosts the application, event records and private photograph storage. These providers process only the information needed to supply their part of the service.

What guests can see

Your photograph disappears from the capture device after upload. It is not visible to other guests until the event organiser approves it and releases the gallery.

Who controls the collection

The event organiser reviews submissions, decides which photographs to publish, and can hide or delete a photograph before or after release.

When Moment Medley may access a photo

Authorised Moment Medley administrators may access photograph content only where reasonably necessary to provide requested support, investigate misuse, security or safeguarding concerns, fulfil a deletion or rights request, restore the service, or comply with law. We will not routinely browse event collections. Administrative access will be restricted by role and recorded in an audit log.

What we will not do

We will not sell event photographs or use them for advertising, behavioural profiling or training artificial-intelligence models.

How long photos are kept

During the founding beta, all submitted photographs and released gallery copies are kept for 30 days after the event date and are then automatically deleted. Organisers will be reminded before the collection expires so they can download anything they want to keep.

Requesting removal

The upload receipt provides a submission reference. In the production service, guests will use that reference—or contact the organiser—to request deletion.

Cookies and device storage

We do not use advertising cookies or behavioural tracking. Read our cookies and device storage explanation for details of the essential storage used to deliver the service.

Service terms

Our beta terms of service explain the responsibilities of organisers and guests, the limited permission needed to host photographs and the rules governing administrative access.