Privacy Policy
Last updated: 2026-08-26
This policy explains what personal data teil.ing processes, why, and what rights you have. The data controller is the operator named in the imprint.
1. Data we process
Account data
When you create an account we store your email address, display name, a hash of your password (never the password itself), and account settings. If you sign in via GitHub or Google, we receive your email address and name from that provider; we never see their passwords.
Uploaded content
Images and videos you upload are stored together with technical metadata (file size, format, upload time) and the sharing settings you choose (password, expiry, view limits, privacy). If you enable EXIF stripping, embedded camera metadata is removed before storage. Uploads are linked to your account, or — for anonymous uploads — to a random session identifier stored in a cookie.
Technical data
We process your IP address for rate limiting and abuse prevention, and in short-lived server logs for security and troubleshooting. We do not use analytics or tracking services.
Payment data
Pro subscriptions are processed by Stripe. We store your subscription status and a Stripe customer reference; card details are handled by Stripe only and never reach our servers.
Support requests
When you contact support, your message, email address, and name are stored in our help desk system so we can answer you.
2. Cookies
We use only cookies that are strictly necessary to operate the service: a session cookie for signed-in users and an anonymous session cookie that links anonymous uploads to your browser. There are no advertising or tracking cookies, so no cookie consent banner is required.
3. Automated content analysis
Every upload is automatically analyzed for prohibited content (content moderation), and — unless you opt out in your settings — for descriptive tags and contained text to make your own uploads searchable. For this, the image (or individual video frames) is transmitted to our AI provider (OpenAI) and processed there; it is not used to train models. Content moderation is a legitimate interest (Art. 6(1)(f) GDPR) and cannot be opted out of. Moderation results may lead to automatic removal of content that violates our terms.
4. Processors and recipients
We use the following service providers under data processing agreements:
- bunny.net (BunnyWay d.o.o., Slovenia) — file storage, content delivery network, and video streaming
- Stripe — payment processing for Pro subscriptions
- OpenAI — automated content moderation and, unless opted out, tagging/text recognition
- Odoo — support ticket system
- GitHub / Google — only if you choose to sign in with them
Some providers process data outside the EU/EEA; transfers rely on adequacy decisions (e.g. the EU–US Data Privacy Framework) or standard contractual clauses.
5. Legal bases
- Providing the service, accounts, and subscriptions: performance of a contract (Art. 6(1)(b) GDPR)
- Content moderation, rate limiting, security, abuse prevention: legitimate interest (Art. 6(1)(f) GDPR)
- Optional tagging/text recognition: legitimate interest, with an opt-out in your settings
6. Retention and deletion
Uploads are kept until you delete them, until their configured expiry or view limit is reached, or until they are removed by moderation. Anonymous uploads are additionally deleted after their retention period. When you delete your account (self-service here), all your uploads are deleted and your email address is anonymized; limited records required for security and audit purposes (e.g. moderation logs) are retained.
7. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interest (Art. 15–21 GDPR). You may lodge a complaint with a data protection supervisory authority. To exercise your rights, contact the address in the imprint.