papershot Privacy Policy
Last updated: 2026-09-24
Applies to: https://papershot.qbyte.tech and the papershot apps for iOS and Android.
1. Who We Are
papershot is operated by Wellbayt LLC-FZ ("papershot", "we", "us", "our"), a free zone limited liability company registered in Dubai, United Arab Emirates. We are the data controller for personal data processed through papershot, except where a business customer uses papershot for its own participants, in which case we act as a processor under our Data Processing Addendum.
Contact: papershot@wellbayt.com
Postal address: Wellbayt LLC-FZ, Dubai, United Arab Emirates (full registered address on request).
United Arab Emirates Data Office. We are subject to Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "UAE PDPL"). You can also raise questions about our compliance with the UAE Data Office, the federal data protection authority.
2. What papershot Is
A host makes a moment: a private, time-boxed shared roll. Guests join from an invite card, by scanning its QR code or opening its link, with or without an account, in the iOS or Android app. The web page at /join only shows the invite and the app store links. Photos, videos and memos are made in the app. There is no web app, no public feed and no public search: only the people in a moment can see what is in it.
The host decides when the roll develops: as it happens, when the roll closes, or after a delay the host sets. Until then, what other guests add stays on our server and is sent to nobody but the host and the person who added it.
3. Data We Collect
Account and identifiers
- The identifier Apple or Google gives us when you sign in, plus your name and email address if the provider shares them
- If you sign in with a code sent by email instead, the email address you type in. We use it only to send you that code and to recognise your account next time.
- Your display name and, if you set one, your profile photo
- For guests without an account, an install identifier: a signed, device-stable token so your shots stay yours across app launches. If you later sign in, you can claim the media you added as a guest.
- Your device platform and when the app last checked in
Your content
- The photos, videos and memos you add to a moment, with the film look you chose applied at capture, plus their width, height and the time they were taken. Before upload, the app keeps only a short allow-list of EXIF fields (exposure settings, lens, camera make and model, and the time taken); location, maker notes and serial numbers are dropped.
- Moment details: name, dates, film stock, shots per guest, video and memo lengths, guest capacity, and the reveal setting
- Prompts the host writes for videos, memos and the Guest Lens shot list (stored on our server). Which Guest Lens prompts you have ticked off is stored only on your device.
- Studio drafts (backdrops, photos off the roll, stickers and text) are stored only on your device, and exports are rendered on your device
- Favourites (the hearts you tap)
Reports and blocks
- Reports you make about a photo, video or memo, with the reason you pick, and the participants you block or, as a host, block from posting
Purchases
- Purchase receipts and product identifiers from Apple or Google, and from Stripe for web purchases. We never see your card number.
Notifications
- A push notification token issued by Apple (APNs) or Google (Firebase Cloud Messaging)
- On iOS, Live Activity tokens so the roll can show on your lock screen while a moment runs
Consent records
- Each consent you give or withdraw: its kind, whether it was granted or revoked, the time, and the IP address it came from
Crash and performance data
- Crash reports and performance traces go to Sentry with a pseudonymous user id only. Your email, username and IP address are stripped before anything is sent. No screenshots, no view hierarchy, no session replay.
Product analytics
- The apps send usage events to Firebase Analytics (Google Analytics 4): event names such as
moment_create,photo_captureandupload_complete, with no personal data in the values and sizes bucketed - User properties such as whether you are signed in, pro mode, app language, theme, and whether you have purchased, under a pseudonymous id
- Google infers a coarse location from your IP address. The apps do not read the advertising identifier on either platform.
- This is on by default. Turn it off in Settings under Help improve papershot.
Website cookies
- Strictly necessary cookies and, only with your consent, first-party analytics on https://papershot.qbyte.tech. See /cookies for the full list and your controls.
Camera, microphone and photo library
- Camera access only while you are taking a photo or video
- Microphone access only while you are filming or leaving a memo
- Photo library access only when you are picking a photo or saving one
- Each needs your device-level permission. Nothing runs in the background.
Age
You confirm that you are old enough to use papershot, and accept the Terms and this policy, at sign-up and at your first join as a guest. See section 11.
App store privacy labels, in short. Data linked to you: identifiers, purchases, user content, usage data, diagnostics. No tracking across other companies' apps or websites, and no third-party advertising.
4. How We Use Data and Our Legal Bases
We use personal data for the purposes below. The legal bases apply to people in the EEA and the UK; equivalent grounds apply under the UAE PDPL and other regional laws.
| Purpose | Data used | Legal basis (GDPR Article 6) |
|---|---|---|
| Run the service (moments, invites, uploads, reveal, viewing) | Account, install identifier, content, moment details | Contract (Art. 6(1)(b)) |
| Process purchases and prevent fraud | Purchase receipts, identifiers, IP address | Contract, legal obligation (Art. 6(1)(b), 6(1)(c)) |
| Send transactional email, push notifications and Live Activities | Email, push and Live Activity tokens, app language | Contract (Art. 6(1)(b)) |
| Keep moments safe: automated screening, reports, blocks, human review | Thumbnails and poster frames, reports, blocks, account or install identifier | Legitimate interests, legal obligation (Art. 6(1)(f), 6(1)(c)) |
| Fix crashes and keep the app fast | Crash reports and performance traces (pseudonymous) | Legitimate interests (Art. 6(1)(f)) |
| Understand which features get used (app analytics) | Usage events and user properties (pseudonymous) | Legitimate interests (Art. 6(1)(f)), with an opt-out in Settings |
| Website analytics | First-party usage data | Consent (Art. 6(1)(a)) |
| Enforce our terms and respond to legal process | Account, identifiers, content as needed | Legal obligation, legitimate interests (Art. 6(1)(c), 6(1)(f)) |
We send no marketing email and there is no product-update mailing. Where we rely on legitimate interests, you can object at any time by writing to papershot@wellbayt.com.
5. Automated Screening and Reports
Every finished upload is screened automatically by Amazon Rekognition. Only the thumbnail of a photo or the poster frame of a video is sent, never the original file and never audio. A high-confidence match hides the item and files a report, which a person reviews within 24 hours. The screening fails open: if it cannot run, the item stays visible. No decision with legal or similarly significant effects is made automatically.
Any participant can report a photo, video or memo (nudity or sexual content, violence or graphic content, harassment or hate, spam, or something else) and block another participant. Hosts can block a guest from posting. We review reports within 24 hours. If something of yours was hidden or removed, you can appeal by emailing papershot@wellbayt.com.
6. How We Share Data
We do not sell personal information. We do not share personal information for cross-context behavioural advertising. We do not permit cross-app tracking.
Within a moment
Your display name is shown to the other participants. What you add is visible to the moment's participants according to its reveal setting; until the roll develops, only the host and you can see it.
Service providers (subprocessors)
- Amazon Web Services: media storage (S3), delivery (CloudFront), the database (RDS Postgres), key management (KMS), automated screening (Rekognition) and transactional email (SES). Region: Ireland (
eu-west-1). - Apple: in-app purchases and App Store Server Notifications, the Apple Push Notification service, and Sign in with Apple.
- Google: Firebase Cloud Messaging for Android push, Google Play Billing, Google Sign-In, and Firebase Analytics (Google Analytics 4).
- Sentry: crash and performance monitoring.
- Stripe: web payments and receipts.
Each provider gets only the data it needs for its service, under a data processing agreement, with the protections the law requires. See /subprocessors for the full list with regions and data categories.
Legal disclosures
We may disclose personal data to comply with a binding legal demand (a subpoena, court order or regulator request) or to protect our rights, property or safety, or those of participants or the public. We tell the people affected where that is lawful and practicable.
Business transfers
If we go through a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred with the same protections. We will tell you about any change of controller.
7. International Data Transfers
We store and process data in the European Union, in AWS eu-west-1 (Ireland). Some providers process data in the United States, and we operate from the United Arab Emirates, so personal data may be transferred to those countries.
Where personal data of people in the EEA, the UK or Switzerland leaves those places, we rely on:
- the European Commission Standard Contractual Clauses (Module Two and Module Three, June 2021) for transfers from the EEA;
- the UK International Data Transfer Addendum to the EU SCCs, or the UK International Data Transfer Agreement, for transfers from the UK;
- the mechanism recognised by the Swiss Federal Data Protection and Information Commissioner for transfers from Switzerland.
For transfers from the United Arab Emirates, we follow Articles 22 and 23 of the UAE PDPL (cross-border transfer) and the UAE Data Office's guidance.
Copies of our transfer agreements are available from papershot@wellbayt.com.
8. Data Retention
- Free moments. Media is kept for 48 hours after the roll closes.
- Paid moments. Media is kept for 30 days after the roll closes.
- When a moment expires. A scheduled job deletes the media files and the database rows and tells the host. The host gets a warning 4 days and 24 hours before.
- Guest data. Lives and dies with the moment.
- Account data. Kept while your account is active.
- Deleted accounts. Deleting your account removes your moments and media at once. The account row is purged after a 30-day grace period, during which you can email us to recover it.
- Purchase records. Kept for up to 7 years to meet tax, accounting and legal obligations.
- Reports and blocks. Kept for as long as needed to act on them and to show we did.
- Crash and analytics data. Held by Sentry and Google under their retention settings; aggregated data may be kept longer.
9. Security
- Encryption in transit via HTTPS / TLS, including forced TLS to the database
- Encryption at rest with AWS-managed keys (KMS)
- Media goes straight from your phone to storage over short-lived signed URLs, and is delivered through CloudFront
- Least-privilege access for our systems and staff
- An audit log of every tester and administrator action on the service
Limits. No security method is perfect. We cannot promise absolute security.
Security incidents. Where the law requires it, we notify the people affected and the supervisory authorities (including the UAE Data Office and EEA and UK authorities) within 72 hours of becoming aware of a personal data breach. To report a vulnerability, see our security.txt.
10. Your Choices and Rights
In-app controls
- Delete your account in Settings under Delete account. Your moments and media go at once; the account row is purged after 30 days, and you can email us during that window to recover it.
- Export your data in Settings under Request my data. The app gives you a JSON file with your profile, up to 50 moments you own with up to 200 items each, your consents log, your devices and your past requests. You can ask up to three times an hour.
- Turn app analytics off in Settings under Help improve papershot
- Manage push notifications in your device settings
- Report a photo, video or memo, or block a participant, from the item itself
Data requests
Email papershot@wellbayt.com to access, correct, port or delete personal data, or to appeal a moderation decision. We respond within 30 days (or sooner where the law requires). We may keep limited data where the law requires it, to prevent abuse, or in backups until they roll off.
11. Children
papershot is for people aged 13 or older, 16 where the EEA requires it, and 18 where the law where you live requires it. You confirm this, and accept the Terms and this policy, at sign-up and at your first join as a guest. We do not knowingly collect personal information from children under 13 in breach of the Children's Online Privacy Protection Act (COPPA), and we do not knowingly collect personal data of children where parental consent would be needed under GDPR Article 8, the UK Age Appropriate Design Code, or the UAE PDPL. If you believe a child has given us personal data, email papershot@wellbayt.com and we will delete it.
12. Regional Rights and Addenda
EEA, UK and Switzerland (GDPR / UK GDPR / FADP)
You have the rights of access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on consent, you can withdraw it at any time without affecting what was done before. You can complain to your local supervisory authority. Our EEA and UK representatives (Article 27) are named in the note at the top of this page once appointed.
Automated decision-making. Automated screening can hide an item until a person reviews it (section 5). We make no decision with legal or similarly significant effects by automated means alone.
California (CCPA / CPRA)
California residents have the right to know what personal information we collect; to access, correct and delete it; to opt out of sale or sharing for cross-context behavioural advertising (we do neither); and to limit the use of sensitive personal information. We do not treat you differently for exercising these rights. To exercise any right, email papershot@wellbayt.com or use the in-app controls. We verify your identity through the email address on your account; an authorised agent can act for you with written authorisation. To submit a Do Not Sell or Share My Personal Information request, email the address above with that phrase in the subject line, although we do not sell or share personal information as California law defines those terms.
Shine the Light. California Civil Code section 1798.83 lets California residents ask what personal information we shared with third parties for direct marketing. We shared none in the preceding calendar year.
Sensitive personal information. We use sensitive personal information only for the purposes it was collected for, such as running and securing the service.
Other U.S. state privacy laws (CO, CT, UT, VA, TX, OR, MT, IA, FL, DE)
Residents of states with comprehensive consumer privacy laws have rights of access, correction, deletion and portability, and rights to opt out of targeted advertising, sale and certain profiling. We do not sell personal data, do not run targeted advertising, and do not profile people for legal or similarly significant decisions. To exercise your rights, email papershot@wellbayt.com. Where a law gives you a right of appeal, you can appeal a denied request by replying to our response.
Brazil (LGPD)
If you are in Brazil, you have rights under Law No. 13.709/2018 (LGPD), including confirmation of processing; access; correction; anonymisation, blocking or deletion of unnecessary or excessive data; portability; deletion of personal data processed with consent; information about the public and private entities we share data with; and information about your right to refuse consent and what follows from that. To exercise these rights or to reach our Encarregado (data protection officer), email papershot@wellbayt.com with "LGPD" in the subject line. You can also complain to the Autoridade Nacional de Proteção de Dados (ANPD).
Canada (PIPEDA and provincial laws)
We follow the Personal Information Protection and Electronic Documents Act (PIPEDA) and the substantially similar provincial laws in Quebec (Law 25), Alberta (PIPA) and British Columbia (PIPA). You have the right to access and correct your personal information. Contact papershot@wellbayt.com. You can complain to the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner.
Australia (Privacy Act 1988)
We handle personal information under the Australian Privacy Principles. You can ask to access and correct your personal information by emailing papershot@wellbayt.com. Raise a complaint with us first; if it stays unresolved, you can take it to the Office of the Australian Information Commissioner (OAIC).
United Arab Emirates (PDPL)
We are established in the United Arab Emirates and subject to the UAE PDPL. If you are in the UAE, you have rights under Articles 13 to 18 of the PDPL, including the right to be told how your personal data is used, to access it, to have it corrected or deleted, to restrict or object to processing, and to data portability. To exercise any right, email papershot@wellbayt.com. You can also complain to the UAE Data Office.
Other regions
Where local law gives you more rights, those rights apply. To ask about your jurisdiction, contact papershot@wellbayt.com.
13. Cookies and Similar Technologies
See /cookies for the cookies the website uses, the storage the apps use, and your controls. The website shows a cookie banner on first visit, and you can change your choices at any time from the Cookie choices link in the site footer.
14. Notifications and Live Activities
Push notifications are rendered on our server in your app language and tell you about a moment starting, ending soon or ended, a recap two days later, and deletion warnings. On iOS, a Live Activity can show the running roll on your lock screen. Both are optional: manage them in your device settings.
15. Policy Changes
We post updates to this page. We tell you about material changes in the app or by email. The "Last updated" date at the top shows when the policy last changed. Using papershot after a material change means you accept it, except where the law requires fresh consent.
16. Contact
Controller: Wellbayt LLC-FZ (United Arab Emirates)
Email: papershot@wellbayt.com
Response time: 30 days (or sooner where the law requires).
Urgent requests: Put "URGENT: Privacy Request" in the subject line.