Privacy policy

Last updated: 15 August 2026

Data controller

The data controller is AIM Studio, a French sole trader registered under SIRET 10028288800013. Contact: support@wepixapp.com.

The data we process

Organiser account: email address, optional name, language, declarative billing information (company name, address, numbers).

Events and albums: uploaded photos and their technical metadata (capture date, dimensions), activity messages and answers, nicknames chosen by guests.

Guests: no account creation. An anonymous technical session (token) links a phone to its uploads, allowing for instance the deletion of one's own photos for two hours.

Payment: processed by Stripe; we never see or store card numbers.

Biometric data: face recognition, precisely

The “find my photos” feature relies on biometric processing. It works this way, and only this way:

Consent first: before any capture, a screen explains the processing in plain language and asks for active agreement. Declining has no consequence on the rest of the album.

The search selfie is never stored: it is transmitted in memory, compared, then discarded. It is written nowhere, not even temporarily.

The face prints computed on the album's photos are partitioned per event and serve only this search, within this event.

Early purge: these prints are deleted when guest access ends, even though the photos themselves remain stored for the organiser. Deleting an account also deletes them.

The comparison provider is Amazon Web Services (Rekognition), acting as a processor.

Purposes and legal bases

Providing the service (performance of the contract): accounts, albums, uploads, downloads, activities, transactional emails.

Face recognition (explicit guest consent, revocable at any time by ceasing to use the feature).

Billing and accounting obligations (legal obligation).

Service security: rate limiting and technical logs (legitimate interest).

Processors

Application hosting: Vercel. Database, authentication and realtime: Supabase.

Photo storage: Cloudflare R2. Payment: Stripe. Emails: Resend. Rate limiting: Upstash. Face recognition: Amazon Web Services (Rekognition). Job orchestration: Inngest. Technical error monitoring: Sentry.

Each acts under instruction, within GDPR-compliant processing agreements.

Retention

Photos and event data: the retention duration of the chosen plan, shown before purchase; at the deadline, permanent deletion from storage and records, preceded by a warning.

Biometric prints: until the end of the event's guest access, at the latest.

Account: until you or support delete it. Billing data: statutory accounting durations.

Your rights

Access and portability: a full export of your data is available at any time from your account.

Deletion: deleting the account, available from your account, removes events, photos and prints. Both rights remain exercisable even if the account is suspended.

Rectification, restriction, objection: on request at support@wepixapp.com. You may also lodge a complaint with the CNIL (cnil.fr).

Cookies

The service only uses strictly necessary cookies and storage: the organiser's sign-in session, the guest's technical session, the language preference. No advertising cookies, no third-party trackers, no third-party analytics.

That is why no consent is requested: there is nothing to consent to. Should this change, compliant consent collection would be put in place before anything is set.