Legal

Privacy Policy

Last updated: September 2026

Who we are

RealTime.Photos is a live event photo sharing platform operated by Nanjing Zhiyin Trading Co., Ltd., reachable at hello@realtime.photos.

This policy explains how we process personal data in two distinct contexts: (1) data we collect about photographers who hold an account with us, and (2) data processed on behalf of photographers about their event guests. For guest data, photographers are the data controllers and RealTime.Photos acts as their data processor — a relationship governed by our Data Processing Agreement.

The short version

Guests don't need an account. We never ask guests for a name, email, or login. Selfies taken to find photos are used for that one search and never stored. Faces in event photos are processed on the photographer's behalf, as described in Face recognition below, and deleted with the event.

Photographer accounts require only your name and email address to operate. We store the minimum needed to run your account and manage your events.

All event data is automatically deleted. On standard plans, photos, face data, and event records are purged within a fixed window of your event's first photo (see Data retention below). Contract-based plans (Custom tier and agency accounts) follow the retention terms set out in the contract instead. In every case, biometric face data is deleted no later than 12 months after the first photo is uploaded, regardless of plan.

We do not sell your data. We never sell, rent, or share personal data with third parties for advertising or marketing purposes.

Data we collect

Photographer accounts. When you create an account or sign in, we collect your name and email address via our authentication provider (Clerk). We use this to identify your account, send transactional communications (such as payment receipts and data deletion warnings), and manage your events.

Event guests. Guests browse galleries without an account, email, or login, and we never ask them for identifying details. Like counts are stored against photo IDs with no user identifier attached, and sort preferences and liked photo IDs stay in your browser's storage. Faces that appear in event photos are processed on the photographer's behalf, as described in Face recognition below.

Demo and contact requests. If you submit a demo request or contact form, we collect your name and email address to respond to your inquiry, processed via Formspree.

Website analytics. We use Vercel Analytics and Vercel Speed Insights, cookieless tools that collect no personally identifiable information, to understand general traffic patterns (such as pages visited) and page performance.

Lawful basis for processing

Under the GDPR and equivalent applicable law, we rely on the following lawful bases for processing photographer account data:

  • Contract performance (Article 6(1)(b)): Processing your name and email to operate your account, send transactional emails (receipts, deletion warnings), and provide the service you signed up for.
  • Legitimate interest (Article 6(1)(f)): Cookieless website analytics to understand and improve the platform; responding to demo and contact requests; displaying customer names and logos in marketing materials (subject to opt-out — see our Terms of Service, Marketing Use section).
  • Legal obligation (Article 6(1)(c)): Retaining financial and billing records as required by applicable tax and accounting law (typically 7 years in Spain).

Providing your name and email address is a contractual requirement to create and use a photographer account — without it, we cannot provide the service. You are under no statutory obligation to provide this data.

For the processing of guest personal data (including biometric face data), the photographer is the data controller and is responsible for establishing a lawful basis — including an Article 9(2) basis for biometric special-category data. This is set out in our Data Processing Agreement.

Face recognition

RealTime.Photos uses Amazon Rekognition (operated by Amazon Web Services) to detect and match faces in event photos. Because this involves biometric data — a special category under GDPR Article 9 — we are fully transparent about how it works:

  • When a photo is uploaded, faces are detected and assigned a unique identifier and bounding box position. Faces that are too small or low quality are automatically ignored.
  • Similar face identifiers are grouped into clusters. Each cluster has a representative image crop — a small region of a photo showing the face. Clusters carry no names or identities.
  • When a guest takes a selfie to find their photos, the image is sent securely to the face recognition service for matching. The selfie is discarded immediately after the result is returned — it is never stored in any database, file system, or log.
  • Numerical face representations (embeddings) used for matching are stored in a per-event index and deleted permanently when the event data is purged.

Face clusters are used to help guests find photos of themselves and, where the photographer uses them, to produce event statistics. They are never used to find out who someone is, for surveillance, or for any purpose beyond the event.

Demographic analytics. During photo processing, Rekognition also returns per-face quality signals (sharpness, head angle), which are kept with each detected face to power the photographer's clean-up tools, and estimates of age range, gender, smile, and emotion. The raw per-face estimates are folded into running counts for each face cluster, usually within minutes of face recognition finishing, and then permanently deleted; a scheduled job enforces an outer limit of 48 hours. Each cluster keeps a summary of those counts (estimated gender, average age, smile rate, and emotion averages) until the event is deleted. These summaries power the photographer's event statistics (for example people detected, gender distribution, and age distribution) and, for guests who opt in, their personal event recap. They are never shown to other guests. As Amazon's own documentation puts it, this output is a reading of how a face appears in a photo, not a determination of anyone's internal emotional state.

The consent experience depends on how the photographer or event organiser has configured the event.

Pre-event consent. Photographers and event organisers who collect consent from attendees before the event — through a registration form or their own privacy notice — configure this in the event dashboard. RealTime.Photos provides ready-to-use consent language directly from the dashboard for inclusion in those materials, covering the purpose of the face recognition processing, the data retention period, and the right to request deletion at realtime.photos/forget-me. Under this setup, the photographer or organiser collects consent before photos are uploaded, and guests can use face search directly in the gallery, without an in-app prompt.

In-app consent (default). Where the photographer has not collected pre-event consent, guests who choose to use face search are shown a consent screen before any photos of them are surfaced. Face indexing runs when photos are uploaded so that results are available instantly when a guest initiates a search. Guests who decline, or who never use the selfie search feature, are never shown face-matched results. Their face data still counts towards the photographer's anonymous event statistics and is deleted automatically when the event is purged.

Under both configurations, guests who never interact with face search have no face data surfaced, attributed, or disclosed to them in any way.

Expression and networking insights. These are offered only where the organiser collected consent before the event, through their registration form or privacy notice, and as a separate, genuinely optional consent from the one covering face search. They are never offered in the gallery: an event with no registration has no way to ask in advance, and someone already standing at an event is not in a position to weigh it up. They are also unavailable for company events and education events, whatever anyone consents to. Where they are active, a guest who has matched their face can remove themselves in one tap, on the card shown after their selfie — that removes them from the event's expression statistics, from the connection map, and from their own recap. They can also remove all of their face data at realtime.photos/forget-me. Per-cluster expression summaries are deleted with the event data at the end of the retention period.

Minors. Events may include attendees who are below the age at which they can give consent on their own (14 in Spain under Article 7 of the LOPDGDD, or the age set by local law elsewhere). Whichever consent setup is used, the photographer, as data controller, is responsible for obtaining consent from a parent or guardian for those attendees. RealTime.Photos cannot know a person's age before face recognition runs, so it cannot check this itself. On the in-app consent screen, guests confirm that they are 14 or older or have a parent's or guardian's permission.

Photographers (as data controllers) are responsible for obtaining any required consent or other lawful basis from event attendees for the processing of their biometric data, as required by GDPR Article 9(2) or equivalent applicable law.

Third-party services

We work with a small number of trusted service providers to operate the platform. Each processes only the data necessary for their specific role. We do not share personal data with third parties for advertising or marketing purposes.

ClerkAuthentication and account management — processes photographer name and email for login and session management. Privacy policy ↗
Convex, Inc.Database and real-time backend — stores event metadata, face cluster data, analytics counters, and photographer account records. Privacy policy ↗
Amazon Web Services (AWS)Cloud storage for event photos (S3), and face and text recognition (Rekognition). Privacy policy ↗
Vercel, Inc.Application hosting and content delivery. Privacy policy ↗
Dodo PaymentsPayment processing (merchant of record) — processes billing and payment data for event purchases. Privacy policy ↗
ResendEmail delivery — sends deletion warnings and account communications to photographers, and delivers the analytics and brand exposure reports photographers request, which can include event photos and face thumbnails. Privacy policy ↗
FormspreeDemo request and contact form submissions — processes name and email of prospective customers. Privacy policy ↗
Vercel Analytics and Speed InsightsCookieless website analytics and performance monitoring — no personal data collected, no cookies set, aggregated patterns only. Privacy policy ↗

International transfers

Event photos and face recognition run on AWS in Spain (eu-south-2), and our database runs on Convex in Ireland (eu-west-1). Clerk, Convex, AWS, Vercel, Resend, and Formspree are US companies, and some processing, such as authentication, hosting, and email delivery, takes place in the United States. Where personal data of individuals in the EEA or UK is transferred outside those regions, we protect the transfer using one or more of the following mechanisms:

  • Standard Contractual Clauses (SCCs) — EU Commission Decision 2021/914 for EEA-origin transfers; the UK ICO's International Data Transfer Addendum (IDTA) for UK-origin transfers — incorporated into our agreements with each provider.
  • EU-US Data Privacy Framework (DPF) certification, where the provider is currently certified under the framework, which may supplement or substitute the SCCs.

You may request details of the transfer mechanism applicable to any specific provider by contacting us at hello@realtime.photos.

Data retention

Raw per-face biometric attributes (age range, gender, smile, emotion signals) captured during photo processing are permanently deleted within 48 hours of the last photo upload, and in practice within minutes of face recognition finishing for that upload. They are first folded into a summary for each face cluster (estimated gender, average age, smile rate, and emotion averages), which is kept until the event is deleted; the 48-hour figure is an outer limit enforced by a scheduled job, not a waiting period. The individual per-photo estimates cannot be reconstructed from the summary.

Event data (uploaded photos, face recognition data, and associated records) on Trial, Basic and Pro plans is automatically and permanently deleted within a fixed number of days after the event's first photo was uploaded — between 7 and 60 days, depending on the plan. Events on the legacy Large plan are deleted after 90 days.

Contract-based retention (Custom plan and agency accounts). Events on our Custom tier — including events created under an agency volume plan — are not on this automatic day-count schedule. Their photo and event data is instead retained for the period agreed in the applicable contract, and we set the event's deletion date accordingly (agency accounts: deleted automatically within 30 days after the contract's end date). Photographers with a Custom-tier event can request the applicable retention date by contacting us.

Regardless of plan, face recognition biometric data (face embeddings stored in AWS Rekognition) is always purged no later than 12 months after the first photo was added, to limit long-term biometric data storage. Photos and face avatar filters remain fully accessible after biometric data is purged; only selfie-based photo search is affected.

Photographer account data (name and email) is retained for the duration of your account. You can delete your account at any time from your account settings; your account profile and events are then deleted straight away. Records we must keep by law, such as payment records, are retained as described below.

Payment records are retained for the period required by applicable tax and financial reporting law — typically 7 years in Spain — after which they are permanently deleted.

Demo and contact requests are retained for up to 12 months or until the inquiry is resolved, whichever comes first.

Anonymised engagement statistics (gallery page views, interaction counts, upload activity) collected via the analytics system contain no personal data and are not deleted when an event is deleted. They are retained indefinitely as aggregate product analytics and cannot be attributed to any individual.

Your rights

Event guests. Even without an account, you have rights over your biometric data. To request removal of your face data from all active events, use our self-service data removal tool. We search every event that uses face recognition for your face and delete the matching face data we find, usually within a minute. Your photos stay in the gallery; only the face data used to find you is removed. Because we never know who you are, we cannot recognise you in photos uploaded later, so you can use the tool again at any time. You may also email hello@realtime.photos with the event name and date. Where an event has expression or networking insights, you can also remove yourself from them in one tap, on the card shown after your selfie, without contacting anyone.

If you are a photographer with an account, you have the following rights over your personal data:

  • Access (Article 15): Request a copy of the personal data we hold about you.
  • Rectification (Article 16): Request correction of inaccurate or incomplete data.
  • Erasure (Article 17): Request deletion of your personal data, subject to our obligations to retain certain records under applicable law. Note: where demographic aggregation has already run, your individual contributions to aggregate event statistics (total people, age/gender/emotion distributions) cannot be individually reversed — these statistics contain no personal identifiers and are not personal data under GDPR.
  • Restriction (Article 18): Request that we limit how we process your data while a dispute is resolved.
  • Portability (Article 20): Request your personal data in a structured, machine-readable format so you can transfer it to another service.
  • Objection (Article 21): Object to processing based on our legitimate interests. We will stop unless we have compelling grounds that override your interests.
  • Withdraw consent: Where processing relies on your consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

To exercise any of these rights, email us at hello@realtime.photos. We will respond within one month of receiving your request and may ask you to verify your identity before processing. For complex or numerous requests, we may extend this period by up to two further months; if so, we will notify you of the extension within the first month.

Right to complain. You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work, or where you believe an infringement took place. In Spain, this is the Agencia Española de Protección de Datos (AEPD), reachable at www.aepd.es. UK residents may complain to the Information Commissioner's Office (ICO) at ico.org.uk.

US privacy rights

If you are a resident of California, Virginia, Colorado, Connecticut, or Utah, you have additional rights under applicable state privacy law (CCPA, VCDPA, CPA, CTDPA, and UCPA respectively):

  • Right to know what personal information we collect, use, disclose, and sell.
  • Right to request deletion of your personal information, subject to certain exceptions.
  • Right to correct inaccurate personal information (California, Virginia, Colorado, Connecticut).
  • Right to data portability — to receive a copy of your personal information in a portable, usable format.
  • Right to opt out of the sale or sharing of personal information and of targeted advertising. We do not sell or share personal information for these purposes — this right is preserved but not currently applicable.
  • Right to non-discrimination — we will not deny, degrade, or charge differently for our services because you exercised a privacy right.

To exercise any of these rights, email hello@realtime.photos. We will respond within 45 days (extendable by a further 45 days where reasonably necessary, with notice to you). We will not charge a fee unless requests are excessive or repetitive.

Event guests and attendees

If your photo appears in an event gallery on RealTime.Photos, the photographer who created that event is the data controller for your personal data (your image). RealTime.Photos processes that data only on the photographer's behalf, as set out in our Data Processing Agreement.

To exercise your rights over photos of yourself — including requesting removal — please contact the photographer who organised the event. If you cannot reach the photographer, contact us at hello@realtime.photos and we will do our best to assist.

Gallery browsing is anonymous: no name, email, account, or tracking identifier is collected or stored when guests browse a gallery. Faces in event photos are processed on the photographer's behalf, as described in Face recognition above.

Automated decision-making

We do not carry out automated decision-making within the meaning of GDPR Article 22 — that is, decisions based solely on automated processing that produce legal effects or similarly significant effects on you.

Face clustering is an automated process, but it produces only a navigational aid (grouping photos by apparent visual similarity) and has no legal, financial, or otherwise significant effect on any individual. Photographers review and manage face clusters manually.

Photographer responsibilities

Photographers using RealTime.Photos are responsible for ensuring they have the necessary legal basis to photograph and publish images of event attendees, and that attendees have been informed of face recognition processing. By creating an event, you confirm this, consistent with applicable laws in your jurisdiction.

If a guest requests removal of photos showing them, photographers can hide individual photos from the gallery at any time from the dashboard. Hiding removes a photo from the gallery; to have the file itself deleted, contact us. Photographers who receive formal data subject requests from guests should notify us at hello@realtime.photos so we can provide any necessary technical assistance.

Changes to this policy

We may update this policy as the product evolves. Material changes will be notified to photographer account holders by email at least 14 days before they take effect. The current version is always available at realtime.photos/privacy. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

Contact

For any privacy-related enquiries, to exercise your rights, or to request further information about our data practices, contact us at hello@realtime.photos. RealTime.Photos is operated by Nanjing Zhiyin Trading Co., Ltd.

EU Representative (Article 27 GDPR). For the purposes of Article 27 of the GDPR, our representative in the European Union is Pablo Martín Larriu, reachable at hello@realtime.photos, located in Irún, Gipuzkoa, España, 20301.