Papershot Privacy Policy
Last updated: 2026-05-30
Applies to: https://papershot.qbyte.tech, the papershot mobile applications (iOS and Android), the papershot App Clip, and the papershot Progressive Web App.
1. Who we are
Papershot is operated by Quantum Byte Technologies ("Papershot", "we", "us", "our"), a company registered in the Republic of Kenya. We are the data controller for personal data processed through the papershot service, except where a customer uses papershot as a processor for its own end users, in which case we act as a processor under our Data Processing Addendum.
Contact: legal@papershot.com
Postal address: Quantum Byte Technologies, Nairobi, Kenya (full registered address available on request).
EEA representative (Article 27 GDPR): [EEA Representative: TBD]. We will appoint and disclose an EU-based representative before offering paid services to EEA residents.
UK representative (Article 27 UK GDPR): [UK Representative: TBD]. We will appoint and disclose a UK-based representative before offering paid services to UK residents.
Kenya Office of the Data Protection Commissioner. We are subject to the Kenya Data Protection Act 2019 and the Data Protection (General) Regulations 2021. Inquiries about our compliance may also be directed to the Office of the Data Protection Commissioner at www.odpc.go.ke.
2. Data we collect
Account & identifiers
- Email address (account sign-up or guest claiming)
- Display name
- Apple
subor Googlesubfrom the sign-in provider - Device identifier or guest token (so guest activity persists)
- Push notification token (issued by Apple APNs or Firebase Cloud Messaging)
Your content
- Photos you upload
- Moment details (name, description, dates, film stock, photo and guest caps)
- Stickers, captions, and edits you apply to photos
EXIF metadata. When you upload a photo, we strip GPS coordinates and camera-serial fields from the EXIF data before the photo leaves your device. Other EXIF (capture time, exposure settings) is preserved so the album feels true to the moment. This stripping applies to all uploads from May 2026 onward; we are scheduling a server-side backfill for older uploads.
Purchases
- Purchase receipts and product identifiers from Apple, Google, and Stripe. We never see your card number.
Usage & diagnostics
- App and website analytics events (only when you consent)
- General location (city / region) inferred from IP address
- Device and operating system information
- Performance metrics and crash reports collected via Firebase Crashlytics. Crash reports may include device model, OS version, stack traces, and your user ID. They do not include your photos or message content. You can disable crash reporting in app settings.
Website cookies
- Authentication, security, and (with consent) analytics cookies onhttps://papershot.qbyte.tech. See /cookies for the full list and your controls.
Camera & photo library
- Camera access only while you are using the capture feature
- Photo library access only when you are picking a photo (for example, a cover image)
- Requires device-level permission. No background use of either.
Age
We collect a single self-attestation that you are 13 or older the first time you launch the app. See section 11 for details.
App Store privacy labels summary. Data linked to you: identifiers, purchases, user content, usage data, diagnostics. No tracking data and no third-party advertising. NSPrivacyTracking is false in our iOS Privacy Manifest.
3. How we use data and our legal bases
We use personal data for the purposes listed below. The legal bases listed apply to data subjects in the EEA and UK; equivalent grounds apply under Kenya DPA 2019 and other regional laws.
| Purpose | Data used | Legal basis (GDPR Article 6) |
|---|---|---|
| Operate the service (moments, invites, uploads, viewing) | Account, content, identifiers | Contract (Art. 6(1)(b)) |
| Process purchases and prevent fraud | Purchase receipts, identifiers, IP | Contract, legal obligation (Art. 6(1)(b), 6(1)(c)) |
| Send transactional email and push notifications | Email, push token, account | Contract (Art. 6(1)(b)) |
| Marketing communications | Email, account | Consent (Art. 6(1)(a)) |
| Improve reliability via analytics and diagnostics | Usage events, crash reports, device info | Consent for analytics; legitimate interests for essential diagnostics (Art. 6(1)(a), 6(1)(f)) |
| Enforce our terms, respond to legal process | Account, identifiers, content as needed | Legal obligation, legitimate interests (Art. 6(1)(c), 6(1)(f)) |
Where we rely on legitimate interests, you can object at any time by writing to legal@papershot.com.
4. How we share data
We do not sell personal information. We do not share personal information for cross-context behavioural advertising. We do not permit cross-app tracking.
Within a moment
Moment details and photos are visible to invited participants per the moment's settings. Your display name is shown to other participants.
Service providers (subprocessors)
- Amazon Web Services: hosting, object storage (S3), CDN (CloudFront), Postgres (RDS), key management (KMS). Primary region:
eu-west-1(Ireland). - Stripe: web payments and receipts.
- Apple: in-app purchases on iOS, push delivery via APNs, Sign in with Apple.
- Google: in-app purchases on Android, Firebase Cloud Messaging for push, Firebase Crashlytics for crash reporting, Sign in with Google.
- Resend: transactional email delivery.
Each subprocessor accesses data only for the service it provides, under a data processing agreement, with the protections required by law. See /subprocessors for the full list with regions and data categories.
Legal disclosures
We may disclose personal data to comply with a binding legal demand (subpoena, court order, regulator request) or to protect our rights, property, or safety, or those of users or the public. We notify users of such disclosures where lawful and practicable.
Business transfers
If we engage in a merger, acquisition, financing, reorganisation, or sale of assets, personal data may be transferred subject to the same protections. We will notify you of any change in controller.
5. International data transfers
Our primary processing region is the European Union (AWS eu-west-1). Personal data may be transferred to and processed in the United States, Kenya, and other countries where our subprocessors operate.
Where personal data of EEA, UK, or Swiss residents is transferred outside those jurisdictions, we rely on:
- European Commission Standard Contractual Clauses (Module Two and Module Three, June 2021) for transfers from the EEA;
- the UK International Data Transfer Addendum to the EU SCCs, or the UK International Data Transfer Agreement, for transfers from the UK;
- the Swiss Federal Data Protection and Information Commissioner's recognised mechanism for transfers from Switzerland.
For transfers from Kenya, we comply with section 48 of the Kenya Data Protection Act 2019 (cross-border processing) and the corresponding Office of the Data Protection Commissioner guidance.
Copies of our transfer agreements are available from legal@papershot.com.
6. Data retention
- Account data. Retained while your account is active.
- Deleted accounts. When you delete your account we mark it for deletion and remove personal data within 30 days, subject only to legal retention obligations.
- Photos from free moments. Deleted 48 hours after the moment ends.
- Photos from paid moments. Deleted 30 days after the moment ends, or when you delete the moment, whichever is sooner.
- Purchase records. Retained up to 7 years to meet tax, accounting, and legal obligations.
- Analytics events. Aggregated or anonymised data may be retained longer.
- Crash reports. Retained for 90 days.
- Backups. Roll off after 35 days.
7. Security
- Encryption in transit via HTTPS / TLS 1.3
- Encryption at rest via AWS-managed keys (KMS)
- Role-based access, least-privilege IAM, and audit logging
- Mobile auth tokens stored in Apple Keychain and Android EncryptedSharedPreferences
- Annual third-party penetration testing
Limitations. No security method is perfect. We cannot guarantee absolute security.
Security incidents. Where required by law we notify affected users and supervisory authorities (including the Kenya ODPC and EEA/UK authorities) within 72 hours of becoming aware of a personal data breach. To report a vulnerability, see our security.txt.
8. Your choices and rights
In-app controls
- Delete your account via Settings → Delete Account (permanent within 30 days, with a grace window during which the deletion can be reversed by contacting us)
- Export your data via Settings → Privacy & Data → Request my data. We email a ZIP containing your profile, moments, photo metadata, and consents log.
- Toggle analytics and marketing consent in Settings → Privacy & Data
- Manage push notifications in your device settings
Data requests
Contact legal@papershot.com to access, correct, port, or delete personal data. We respond within 30 days (or as required by applicable law). Limited retention may occur for legal requirements, abuse prevention, or backups.
9. Regional rights and addenda
EEA, UK, and Switzerland (GDPR / UK GDPR / FADP)
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. You may lodge a complaint with your local supervisory authority. EEA and UK representatives are listed in section 1.
Automated decision-making. We do not use personal data for automated decision-making with legal or similarly significant effects.
California (CCPA / CPRA)
California residents have the right to know what personal information we collect; to access, correct, and delete it; to opt out of sale or sharing for cross-context behavioural advertising (we do neither); and to limit the use of sensitive personal information. We do not discriminate against you for exercising these rights. To exercise any right, email legal@papershot.com or use the in-app controls. We verify your identity using the email address associated with your account; you may use an authorised agent by providing written authorisation. To submit a Do Not Sell or Share My Personal Information request, email the address above with that phrase in the subject line, though, again, we do not sell or share personal information as those terms are defined under California law.
Shine the Light. California Civil Code §1798.83 allows California residents to request disclosure of personal information shared with third parties for direct-marketing purposes. We have not shared personal information for those purposes in the preceding calendar year.
Sensitive personal information. We do not use sensitive personal information beyond the purposes for which it was collected, such as operating and securing the service.
Other U.S. state privacy laws (CO, CT, UT, VA, TX, OR, MT, IA, FL, DE)
Residents of states with comprehensive consumer privacy laws have rights of access, correction, deletion, and portability, and rights to opt out of targeted advertising, sale, and certain profiling. We do not sell personal data, do not engage in targeted advertising, and do not profile users for legal or similarly significant decisions. To exercise rights, email legal@papershot.com. Where a law provides an appeal right, you may appeal a denied request by replying to our response.
Brazil (LGPD)
Brazilian data subjects have rights under Law No. 13.709/2018 (LGPD), including confirmation of processing; access; correction; anonymisation, blocking, or deletion of unnecessary or excessive data; portability; deletion of personal data processed with consent; information about public and private entities with which we share data; and information about the possibility of refusing consent and its consequences. To exercise these rights or to contact our Encarregado (Data Protection Officer), email legal@papershot.com with "LGPD" in the subject line. You may also file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).
Canada (PIPEDA and provincial laws)
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial laws in Quebec (Law 25), Alberta (PIPA), and British Columbia (PIPA). You have rights to access and correct your personal information. Contact legal@papershot.com. You may file a complaint with the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner.
Australia (Privacy Act 1988)
We handle personal information in accordance with the Australian Privacy Principles. You may request access to and correction of your personal information by emailing legal@papershot.com. Complaints about our handling of personal information may first be directed to us; if unresolved, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
Kenya (Data Protection Act 2019)
As a Kenyan controller we are registered with the Office of the Data Protection Commissioner. Kenya residents have rights under section 26 of the Act, including the right to be informed of the use of personal data, to access, to object to processing, to correction or deletion of false or misleading data, and to data portability. To exercise any right, email legal@papershot.com. You may also lodge a complaint with the ODPC at www.odpc.go.ke.
Other regions
Where local law confers additional rights, those rights apply. To request information specific to your jurisdiction, contact legal@papershot.com.
10. Children
Papershot is not intended for users under the age of 13. We require every new user to confirm that they are 13 or older the first time they launch the app or sign up on the website. We do not knowingly collect personal information from children under 13 in violation of the Children's Online Privacy Protection Act (COPPA), and we do not knowingly collect personal data of children where doing so would require parental consent under GDPR Article 8, the UK Age Appropriate Design Code, or section 33 of the Kenya Data Protection Act 2019. If you believe a child has provided personal data to us, contact legal@papershot.com and we will delete it.
11. Cookies and similar technologies
See /cookies for the categories of cookies we use, including the controls available to you. We display a cookie banner on first visit and allow you to revisit your choices at any time via the "Cookie choices" link in the site footer.
12. App Clip notes
The papershot App Clip uses minimal data to let you join a moment as a guest and add photos with permission. Camera and network access happen only during active use and follow this policy.
13. Policy changes
We post updates to this page. Material changes are notified via in-app message or email. The "Last updated" date at the top of this policy indicates when changes were made. Continued use of the service after material changes constitutes acceptance, except where additional consent is required by law.
14. Contact
Controller: Quantum Byte Technologies (Kenya)
Email: legal@papershot.com
Response time: 30 days (or sooner where required by law).
Urgent requests: Include "URGENT: Privacy Request" in the subject line.